Privacy and security
This explains what we collect, why we collect it, who else sees it, how long we keep it, and what you can make us do about it. It also explains exactly what an expert can and cannot reach when you invite one into your own machine, because that is the part worth reading twice.
The short version
We read the conversations, because that is the only way to tell where people get stuck. We keep your email separate from everything else so it can be handed back or deleted on its own. We never take payment, so we never hold your card details. We do not sell your information, and we do not share it for advertising. If you invite an expert onto your machine, they work inside limits you set, everything they do is logged in front of you, and you can cut the access off at any moment.
Who this covers
Midsesh("we", "us") operates this website and the Get An Expert agent. We are the controller of the information described here. Our postal address is 704, 1 Western Avenue, Boston, Massachusetts, United States. You can reach us at midsesh.social@gmail.com.
What we collect
- What you type into the chat
- Every message you send and every reply we send back, along with which question it answered. This is how the service works: the assistant reads what you need in order to brief an expert.
- Your brief
- The structured summary the assistant builds from your conversation: the kind of expert you need, the field, and the specifics you gave.
- Your email address and name
- Only when you give them to us to request an introduction, a call back, a booking, a demo, or when you send us a message. We do not ask for them to browse the site.
- What you send us through a form
- The message and subject you type into the contact form. If you register as an expert or list your agents, also what you say you do, what you want to charge, and when you are free to meet. Stored with your email in the same table as every other enquiry, so a deletion request removes it with everything else.
- Session and device information
- An anonymous session identifier, your browser user agent, the page that referred you, and the times you arrived and last interacted.
- Your IP address
- Used to count requests per minute so that one visitor cannot exhaust the service for everyone else. It is used for rate limiting and abuse prevention, and is not used to build a profile of you.
- Search activity
- The query we ran to find candidate experts, how many results came back, how long it took, and whether we fell back to sample data.
- Call records
- If you ask to speak to a human: the time, the status of the call, who took it, and a short written summary. Calls carry audio only and are not recorded.
- Bookings
- If you book a session, the booking details and the brief summary passed to the calendar so the expert knows what you need.
We do not collect payment card details at any point. You pay the expert directly, after the work is delivered, so that information never passes through us.
Session replay, stated plainly
We record a replay of your visit, and that replay includes the conversation: what you wrote and what the assistant wrote back. This is deliberate. Knowing that someone left tells us nothing on its own. Knowing what the assistant had just asked them tells us what to fix.
Email and name fields are the exception. Those fields are blocked at the moment of recording, so what you type into them is never transmitted to our analytics provider at all. If you would rather not be recorded, enabling Do Not Track or blocking analytics in your browser will stop it, and the service works normally without it.
How expert access to your machine works
This section applies only if you install the Get An Expert agent and ask for help inside your own editor. Nothing on this website gives anyone access to anything on your computer.
- Nothing is granted until you grant it
- Access is split into three separate permissions: files, terminal and browser. Each one is granted by you explicitly. An expert who has not been given a permission cannot use the tools that depend on it.
- Confined to one project
- File and terminal access are limited to the project directory you started in. Attempts to reach a path outside it are refused. Browser access is pinned to the single port you approved.
- Secrets are excluded from file access
- Environment files, private keys, certificates, SSH and cloud credential directories and anything matching your project's own ignore rules are refused by the file tools.
- We never receive any of it
- Session data travels directly between your machine and the expert's, encrypted. Our relay performs the introduction and is then out of the path. It does not receive your files, your terminal output or your browser contents, so there is no copy of them for us to hold, hand over or lose.
- You watch it happen
- Every action an expert takes is written to a log you can read while the session is running. The log records the action and what it was aimed at, never the contents of your files or the output of your commands.
- You can end it instantly
- You can withdraw any single permission or all of them at once. The next action that relies on a withdrawn permission fails immediately. Ending the session withdraws everything.
- Reconnecting after a restart
- So that a request survives closing your editor, the agent keeps a small record on your own computer of the permissions you approved, and can restore them when it reconnects without asking again. That record is readable only by your user account, expires after 72 hours, and restoring it is written into the activity log. You can switch this off.
Why we are allowed to use it
Where the UK and EU General Data Protection Regulation applies, we rely on the following legal bases. We process your messages and brief because it is necessary to perform the service you asked for. We use your email address to send you the introduction you requested on the same basis, and your consent is recorded at the moment you submit it. We keep analytics, replay, rate limiting counters and security records on the basis of our legitimate interest in understanding, running and defending the service, having weighed that against your interests. Where we rely on consent, you can withdraw it at any time.
Who else sees it
We use the following providers. They act on our instructions and are not permitted to use your information for their own purposes.
| Provider | What they do | What they receive |
|---|---|---|
| Anthropic | Runs the assistant that asks the intake questions and ranks candidate experts. | Your chat messages and your brief. Not your email address or your name. |
| PostHog | Product analytics and session replay. | Pageviews, interaction events, device and browser information, and a replay of your visit that includes the conversation. Email and name fields are blocked at the moment of recording and never reach it. |
| Supabase | The database everything above is stored in. | Everything listed under what we collect. |
| Vercel | Hosts and serves the site. | Standard request logs, including IP address. |
| SerpAPI | Searches public web profiles for candidate experts. | A short search phrase built from the kind of work you need. The specifics you typed are deliberately never included in it. |
| Resend | Delivers email. | Your email address and the contents of the message we send you. |
| Cal.com | Handles scheduling when you book a session. | Your name, email address and a summary of your brief, as the booking notes. |
| Daily | Carries the audio when you ask to talk to a human. | Live audio for the duration of the call. Nothing is recorded or stored. |
| Telegram | Alerts the on-call person that someone is asking to talk. | A notification containing your first name and a one line summary of what you need. |
Beyond these, we share your brief with the expert we introduce you to, which is the entire point of the service. Every expert is under a signed confidentiality agreement before they take any work. We may also disclose information if the law requires it, or to establish or defend a legal claim.
We do not sell your personal information, and we do not share it for cross context behavioural advertising. We have not done so in the preceding twelve months. This includes the personal information of anyone under sixteen.
Where it goes
We and our providers are based in, and store information in, the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, using this service involves transferring your information there. We rely on the transfer mechanisms our providers have in place, which for these providers are standard contractual clauses. You can ask us for details.
How long we keep it
Deletion runs automatically, once a day, on this schedule.
- Email addresses and everything attached to a request
- Deleted after 12 months.
- Sessions, messages and searches
- Deleted after 12 months from your last activity.
- Internal API event records
- Deleted after 3 months.
- Rate limiting counters
- Deleted after 2 months.
Email addresses are stored separately from everything else, on purpose, so that a request to export or delete yours can be honoured without unpicking anything.
None of that schedule is the only way out. If you have an account you can delete it at any time from Your account, without waiting for a retention period and without asking anybody. What that removes and what it keeps is set out under Your rights below.
Profiles we find for you
When we search for experts, we keep what the search returned about each person: the name and photo on their public marketplace profile, the link to it, and their listed rating and price. We keep it so that the people we found for you are still there when you come back, rather than disappearing when you close the tab.
Alongside each one we store two short pieces of writing. The first describes what their public listing says. The second, shown to you under the heading “Why this could fit”, is our own view of how that listing lines up with what you asked for. It is our opinion and it is labelled as one. It is not a statement of that person's history, and we do not add facts about anyone that their public profile did not already say.
These records belong to the search that produced them, so deleting the search deletes them too. If you are one of the people we listed and you would rather we did not, write to midsesh.social@gmail.com and we will remove you.
How we protect it
Database access is closed by default and no public key can read or write any table. Every endpoint that changes something checks the request came from our own site, and is rate limited so it cannot be hammered. Text arriving from visitors and from the open web is stripped of hidden characters before it reaches anything else. The site sends a content security policy and the usual protective headers. No secret is present in anything the browser downloads.
We do not currently hold a SOC 2 or ISO 27001 certification, and we would rather say so than imply one. No system is perfectly secure, and we do not claim otherwise.
If a breach affects your information, we will notify you and the relevant regulator where the law requires it, without undue delay and within the timeframes those laws set.
Your rights
If you have an account, you can delete it yourself. Sign in, open Your account, and use Delete my data. It removes the account, the credit balance and its history, your saved searches and the people in them, and every request for quotes you have made. Orders stay, because we have to keep a record of work we did and were paid for, and your email address and name are taken off those rows so they stop naming you. You type a word to confirm before anything runs, and the page states all of this before you do.
Wherever you live, and with or without an account, you can also ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to midsesh.social@gmail.com and we will action it. We will not charge you, and we will not treat you differently for asking.
If the UK or EU GDPR applies to you, you also have the right to object to processing based on legitimate interests, to ask us to restrict processing, to receive your information in a portable format, and to complain to your data protection authority. In the United Kingdom that is the Information Commissioner's Office.
If you are a California resident, you have the right to know what we collect and why, the right to delete it, the right to correct it, and the right to opt out of sale or sharing. As set out above, we do not sell or share your personal information, so there is nothing to opt out of. You may use an authorised agent to make a request on your behalf.
Children
This service is for adults and is not directed at children. We do not knowingly collect information from anyone under sixteen. If you believe a child has given us information, tell us and we will delete it.
Changes
If we change this policy we will update the date at the top. If a change materially affects what we do with information we already hold, we will tell the people it affects rather than relying on them noticing.
Contact
Email midsesh.social@gmail.com and we will answer. If you are writing about your own information, say so in the subject line and it will be handled first.