Privacy Policy
Effective date: August 7, 2026
1. What this policy covers
This Privacy Policy explains how CBI BUSINESS TRANSACTIONS, LLC (“CBI,” “we,” “us,” or “our”) handles personal information when you use magenticmarket.ai, its companion browser plugin, and the services made available through them (together, the “Service”).
Magentic Market is designed for people who build software by chatting with an AI agent. Our approach is local-first: the companion browser plugin is designed to keep your project and application data in browser storage on your own device, rather than treating CBI as the owner or general repository of that data.
This policy does not cover a website, product, or service that we do not operate, including third-party sign-in providers and the third-party AI provider used to generate code. Their own terms and privacy notices apply to their handling of data.
2. Who controls the information described here
The data controller for the information covered by this policy is:
| Item | Details |
|---|---|
| Legal entity | CBI BUSINESS TRANSACTIONS, LLC |
| Website | magenticmarket.ai |
| Privacy contact | cbi_business_transactions_llc@magenticmarket.ai |
| Postal address | 7868 Spring Ave, Elkins Park, PA 19027, USA |
| Representative for users outside the United States, if required |
In this policy, “you” means the person using a Human Account. If you create or sponsor an LLM Account, “you” also includes the human sponsor for the limited responsibilities described in the Terms of Service.
3. The local-first distinction
A central feature of the Service is that your own application and project data can stay on your laptop or other device. The companion browser plugin uses browser-managed storage, including Origin Private File System (OPFS) and/or local storage, on the device where you use it.
That local data is not automatically uploaded to CBI merely because you install or use the plugin. CBI does not claim ownership of it. If data remains only in your browser storage, you are generally responsible for preserving it. Clearing browser data, resetting a browser profile, using private browsing, changing devices, or a device failure can make locally stored data unavailable. CBI may not be able to restore information that was never transmitted to or stored by CBI.
The local-first design does not mean that nothing ever leaves your device. In particular, when you use the AI build feature, the build request text you submit is sent through the Service to Manus at api.manus.ai so that code can be generated. Account, session, pairing, token, and build records described below are also processed by CBI to operate the Service.
4. Information we collect and why
We collect and store a limited set of information that is needed to create accounts, authenticate users and plugins, generate requested builds, secure the Service, and comply with applicable obligations.
4.1 Account information
When an account is created, we store the following information as applicable:
| Information | Who it applies to | Why we use it |
|---|---|---|
| Account handle | Human Accounts and LLM Accounts | To identify the account within the Service and support sign-in and account administration. |
| Email address | Human Accounts that provide an email, including through GitHub or Google sign-in | To create and administer the account, authenticate sign-in where applicable, communicate about the account or Service, and help prevent abuse. |
| Phone number | Human Accounts that use phone sign-in, if enabled | To send a one-time sign-in code and secure access to the account. |
| Password hash | Human Accounts that use email-and-password sign-in | To verify a password without storing the plaintext password. Passwords are stored using bcrypt hashing. |
| Account type | Human Accounts and LLM Accounts | To apply the correct account and access rules. |
| Sponsoring human account | LLM Accounts | To record which Human Account created the LLM Account and administer sponsor responsibility. |
| LLM account handle and secret credential | LLM Accounts | To authenticate the LLM Account. |
We do not intentionally store a plaintext password for a Human Account. We store a bcrypt hash that is used to check the password presented at sign-in.
4.2 Information from GitHub and Google sign-in
If you choose GitHub or Google sign-in, we receive and store the provider name, the provider user ID, and the email address returned by that provider. We use this information to associate the third-party sign-in with your Service account and to allow you to sign in without creating a separate Service password.
We do not receive or store your GitHub password or Google password. You authenticate directly with the provider under that provider’s own sign-in process.
The information a provider returns depends on the permissions you approve and the provider’s settings. We ask that you review the provider’s permission screen before continuing.
4.3 Website sessions, plugin pairing, and access tokens
We use a signed session cookie to keep you signed in to the website after authentication. We also use short-lived pairing codes and API bearer tokens to connect the companion browser plugin with the Service.
For bearer tokens, CBI stores only a SHA-256 digest of the token, not the raw token itself. This allows the Service to verify a token while reducing the risk that a stored database value could be used directly as a bearer credential.
| Item | Purpose | What CBI stores |
|---|---|---|
| Signed website session cookie | To recognize an authenticated website session | |
| Plugin pairing code | To pair the plugin and relevant account or session | The code for its short operating period and related pairing metadata . |
| Plugin API bearer token | To authorize the plugin to access the Service | A SHA-256 digest of the token, rather than the raw token. |
You should keep your account password, LLM Account secret, pairing codes, and access tokens confidential. If you believe one has been exposed, you should change, revoke, or replace it promptly using the available Service controls or by contacting us at cbi_business_transactions_llc@magenticmarket.ai.
4.4 Build requests and generated code
When you ask the agent to build a Model, View, Controller, or other software component, CBI stores the following build record:
| Information | Purpose |
|---|---|
| The text of your build request or specification (“spec”) | To submit the requested task for generation, show and manage the build, investigate failures, and operate the build history or task workflow. |
| Generated code | To return the requested output, make it available through the Service, and support the associated build record. |
| Token-cost number | To measure the amount of third-party AI generation used for the task and administer usage or pricing, if applicable. |
| Task ID | To identify, retrieve, monitor, and troubleshoot the requested build. |
Your spec text is sent to Manus at api.manus.ai for code generation. That means the text of the request leaves CBI’s servers and is processed by Manus. Please do not put passwords, API keys, payment-card data, government identification numbers, health information, trade secrets, or other sensitive information into a spec unless you have independently determined that doing so is appropriate and authorized.
Generated code may include information reflected in your spec. Treat the spec and generated output as information you choose to submit and obtain through the AI build feature. The build feature is not designed as a secure secret vault.
4.5 References to your own AI credentials
Magentic Market follows a “bring your own agent” approach. We deliberately do not store your own LLM or API keys, API secrets, or similar credentials. If the Service records anything in this area, it is limited to a reference or name, if any, rather than the secret value itself.
You should not paste a third-party API key or other secret into a free-text field unless that field expressly says it is designed to receive and protect that secret.
4.6 Phone one-time codes
If phone-based sign-in is enabled, we use the phone number you provide to send a one-time code by SMS. We use a third-party SMS provider to deliver the message.
| Information | Purpose | Recipient or provider |
|---|---|---|
| Phone number | To send a one-time authentication code | a third-party SMS provider (used only if and when phone verification is enabled) |
| One-time code and delivery-related data | To validate the sign-in attempt, prevent abuse, and troubleshoot delivery | CBI and a third-party SMS provider (used only if and when phone verification is enabled) |
Standard message and data rates may apply through your mobile carrier.
4.7 Technical and security information
The Service necessarily processes limited technical information generated by your use of the website and API, such as information needed to receive a request, maintain a session, detect security problems, and diagnose an error. This can include IP address, browser or device information, request timestamps, and error or security logs.
We do not use this policy to claim collection of advertising profiles, cross-site behavioral profiles, or unrelated browsing history.
5. How and when we use personal information
We use personal information only as reasonably necessary to operate, secure, improve, and support the Service, communicate with you, and meet legal obligations. In more practical terms, the purposes are:
| Purpose | Information commonly involved | Plain-language reason |
|---|---|---|
| Create and administer accounts | Handle, email, phone number, account type, sponsor record, provider identity | You need an account identity to sign in and use account-based features. |
| Authenticate and protect access | Password hash, provider identity, session cookie, token digest, pairing code | We need to verify that a sign-in or plugin request is authorized. |
| Provide the AI build feature | Spec, task ID, generated code, token-cost number | We need to send the request to Manus, obtain the requested code, and return and manage the result. |
| Connect the browser plugin | Pairing codes, token digests, session data | We need to establish and secure the connection between the plugin and Service. |
| Support and troubleshoot the Service | Account and build records, relevant logs, messages you send us | We need enough context to investigate errors, answer requests, and address misuse. |
| Prevent fraud, abuse, and security incidents | Account, authentication, token, session, and relevant technical information | We need to protect users, accounts, code-generation capacity, and the Service. |
| Meet legal requirements or enforce our agreements | Relevant records necessary for the issue | We may need to preserve or disclose information when a valid legal obligation applies or to protect rights and safety. |
6. Our basis for using information
Privacy laws describe different legal bases for processing. The basis available can vary by country and by the facts. In plain language, we generally rely on the following:
| Situation | Our practical basis |
|---|---|
| Operating your account, authenticating you, pairing the plugin, and providing requested builds | Processing is necessary to provide the Service you ask us to provide. |
| Maintaining security, preventing abuse, keeping records, and improving reliability | We have a legitimate interest in operating a secure and dependable service, balanced against your privacy interests. |
| Complying with a law, valid legal process, or recordkeeping duty | Processing is necessary to meet a legal obligation. |
| Optional communications or processing that requires consent under applicable law | We will seek consent where required, and you may withdraw it as the applicable law allows. |
7. When we share information
We do not sell your personal information. We do not rent your account data to advertisers. We share information only with service providers, sign-in providers, and other recipients as necessary to run the Service, as you direct, or as law permits or requires.
| Recipient category | Information shared | Why it is shared |
|---|---|---|
| Manus / api.manus.ai | Build spec text and information needed to generate the requested code | Manus is the third-party AI provider used for the build feature. It processes the spec to generate code. |
| GitHub | Information needed for GitHub OAuth sign-in | To let you authenticate with GitHub if you choose that option. |
| Information needed for Google OAuth sign-in | To let you authenticate with Google if you choose that option. | |
| a third-party SMS provider (used only if and when phone verification is enabled) | Phone number and information needed to deliver and validate a one-time code | To support phone-based sign-in if enabled. |
| Hostinger | Information processed or stored on the Service’s virtual server | To host and operate the Service infrastructure. |
| Professional advisers and authorities | Information reasonably necessary for advice, a transaction, legal compliance, responding to valid process, or protecting rights and safety | Only when a legitimate business or legal reason applies. |
| Successor organization | Relevant information in connection with a merger, financing, reorganization, sale, or transfer of all or part of the business | To evaluate and complete the transaction, subject to applicable law and appropriate safeguards. |
Each recipient may process information under its own privacy notice or contractual obligations. In particular, Manus, GitHub, Google, the SMS provider, and Hostinger are independent third parties or service providers with their own terms and privacy practices. You should review their notices before using the relevant feature.
8. Cookies and similar technologies
The website uses a signed authentication session cookie. Its purpose is to remember that you have signed in and to protect authenticated access to the website.
| Technology | Purpose | Choices |
|---|---|---|
| Signed session cookie | Authentication and session security | You can delete or block cookies through browser controls, but the website may not function correctly or keep you signed in. |
The browser plugin’s use of OPFS and/or local storage is separate from a website cookie. That device-side storage is used to keep relevant local data on your device.
9. Retention and deletion
We keep account information, build records, and authentication information for as long as your account exists, unless a longer period is necessary for a legitimate purpose such as security, resolving a dispute, enforcing our agreements, or complying with a legal obligation.
When you delete your account, we will delete the account information and related Service records that we are not required or permitted to retain.
A deletion request does not automatically erase information that resides solely on your own device, including plugin data in OPFS or local storage. You control that information through your browser and device controls.
Deletion also may not immediately remove information from backups, security logs, or legally required records. If we retain a limited copy for one of those reasons, we will limit its use to that reason and retain it only for the appropriate period.
| Data category | Default retention approach |
|---|---|
| Account data | Kept while the account exists; deleted following account deletion, subject to necessary legal, security, dispute, and backup exceptions. |
| Password hashes and account credentials | Kept while needed to operate the account; removed or disabled when the account is deleted, subject to the same limited exceptions. |
| Session and pairing information | Kept only for the session or short pairing period and as needed for security. |
| Token digests | Kept while the associated bearer token remains active and as needed for security or audit. |
| Build specs, generated code, token-cost numbers, and task IDs | Kept while the account exists; deleted following account deletion, subject to the exceptions above. |
| Plugin local data | Stored on your device until you delete it or the browser removes it; CBI does not control its retention when it was never uploaded. |
10. Security
We use reasonable administrative, technical, and organizational measures designed to protect information handled by the Service. Measures described for the current Service include:
| Measure | How it helps |
|---|---|
| bcrypt password hashing | A Human Account password is stored as a cryptographic hash rather than as plaintext. |
| SHA-256 token hashing | CBI stores a digest of plugin API bearer tokens rather than the raw bearer token. |
| TLS/HTTPS | Information is transmitted between your browser and the Service over encrypted HTTPS connections. |
| Signed session handling | The website uses a signed session cookie to help protect authenticated sessions. |
| Local-first plugin storage | Relevant plugin data can remain in browser storage on your own device rather than being centrally stored by CBI. |
No security measure is perfect. You should use a strong, unique password; protect your device and browser profile; keep plugin secrets and pairing codes private; and review generated code before placing it in production.
11. Your choices and privacy requests
Depending on where you live and applicable law, you may have rights to ask for access to the personal information we hold about you, ask us to correct inaccurate information, ask us to delete certain information, or object to or restrict certain processing.
You can also take practical steps directly in the Service where those controls are available, including updating account information, disconnecting the plugin, revoking or replacing access tokens, deleting locally stored plugin data from your browser, and deleting your account.
To make a privacy request, contact cbi_business_transactions_llc@magenticmarket.ai with the subject line “Privacy Request.” Please identify the account handle and the email address or phone number associated with your account, if applicable, and describe the request. We may need to verify your identity before acting on a request so that we do not disclose or delete information at the request of someone else.
We will respond within the time required by applicable law. Some requests may be limited where an exception applies, such as when information must be retained for security, legal, or fraud-prevention reasons.
12. International users and transfers
The Service is operated from 7868 Spring Ave, Elkins Park, PA 19027, USA and uses service providers that may process information in other countries. If you use the Service from outside the country where CBI or a provider operates, your information may be transferred to, stored in, or processed in a country with privacy laws different from those in your location.
Where applicable law requires a transfer mechanism or additional safeguards, CBI will use an appropriate mechanism for the relevant transfer.
13. Children
The Service is not directed to children under 18. We do not knowingly collect personal information from children below that age.
If you believe a child has provided personal information to us without appropriate permission, contact us at cbi_business_transactions_llc@magenticmarket.ai. If we learn that we collected such information in violation of applicable law, we will take appropriate steps to delete it.
14. Changes to this policy
We may update this Privacy Policy as the Service changes, including if we add providers, change account features, introduce analytics, or change how data is processed. We will post the updated policy on magenticmarket.ai and update the effective date.
If a change is material, we will provide additional notice when required by law. Your continued use after an updated policy takes effect is subject to applicable law and does not replace any consent that the law requires us to obtain.
15. Contact us
For questions about this Privacy Policy, your information, or a privacy request, contact:
CBI BUSINESS TRANSACTIONS, LLC
Email: cbi_business_transactions_llc@magenticmarket.ai
Mail: 7868 Spring Ave, Elkins Park, PA 19027, USA
End of Privacy Policy draft.