Principles
Data minimization
We collect only what is needed to provide the service.
User control
You can manage profile, language preferences, privacy settings and notifications.
Security
Permissions, review and logs help protect data.
Privacy
This policy explains how Machi handles account, content, region and interaction data.
We collect only what is needed to provide the service.
You can manage profile, language preferences, privacy settings and notifications.
Permissions, review and logs help protect data.
When you register, sign in or reset your password, we email a one-time code. Codes are stored hashed, expire after a short window and are invalidated once used — never kept in plaintext, written to logs or returned by any API.
To keep the service secure and prevent abuse, we record the visiting IP address, approximate region, time, request method and path, and response status. These logs are visible to administrators only and never record passwords, verification codes, tokens or sensitive form input.
Access logs are pruned automatically after about 90 days; you can manage your account details and privacy settings at any time.