Privacy Policy

Last updated: July 5, 2026

Who we are

MaxLift is an experimentation platform operated by Assured Futures LLC. This policy covers maxlift.io, the MaxLift application, and the MaxLift MCP connector. Contact: [email protected].

What we collect

  • Account data — your email and workspace name, used to authenticate you and create your workspace.
  • Experiment configuration — the flags, experiments, metrics, and warehouse connection settings you create.
  • Aggregate results — per-variant counts and statistics. In warehouse-native mode these are computed in your warehouse and only aggregates (no user-level rows, no PII) are returned to us. In no-warehouse mode, exposure and conversion counts are stored as counters keyed to client-side hashed identifiers.
  • Operational data — logs and usage needed to run and secure the service.

We do not receive your end users' personal data. By design, user-level data stays in your warehouse.

How we use it

To provide the service: authenticate you, run and analyze your experiments, compute results, enforce plan limits, process billing, and send you service-related email (magic links, alerts). We do not sell your data or use it for advertising.

The MaxLift MCP connector

The MaxLift MCP connector lets an AI client (such as Claude) manage your experiments on your behalf. It authenticates with a token you generate in your dashboard and acts only within your workspace. It reads your experiment configuration and results and can create or change experiments when you ask. The connector transmits only what is needed to perform the requested action and stores nothing beyond what the MaxLift application already stores.

Storage, retention, and sharing

Data is stored on our infrastructure providers (Supabase/Postgres, Vercel, Cloudflare) and processed by Stripe (billing) and Resend (email). Warehouse credentials are encrypted at rest and used only to issue read-only queries. We retain account and configuration data for the life of your account and delete it on request. We share data only with the subprocessors above, as required to operate the service, or when legally required.

Your rights

You can request access to, export of, or deletion of your data by emailing [email protected]. You can rotate or revoke your API and MCP tokens at any time from Settings.

Changes

We'll update this page when our practices change and revise the date above.