maxlevel
ContactLog inStart free
Legal

Privacy policy

What personal data maxlevel collects, why we collect it, how long we keep it, and what you can ask us to do with it.

Version 1.0 · Last updated 2 August 2026

Who the controller is

For data about your own members, you are the controller and maxlevel is the processor — we handle it on your instructions under the terms of the DPA. For account data about the person who signs up, maxlevel is the controller.

What we collect

Account details (name, email, avatar), the communities you belong to, the actions you log and their timestamps, XP and level history, badges earned, and standard technical data such as IP address and browser for security and abuse prevention.

Why we collect it

To operate the service you asked for: calculating XP, ranking leaderboards, rendering the feed, and sending the digests you opted into. We also use aggregated, non-identifying data to understand which features are used.

What we do not do

We do not sell personal data, we do not use your action history to train models for other customers, and we do not use behavioural data for advertising targeting. Free-tier ads are contextual and served without profiling.

How long we keep it

Action history is retained for as long as the community exists, subject to the plan’s history window. Delete a community and its data is removed within 30 days, aside from anything we must retain for accounting or legal reasons.

Your rights

You can request access, correction, export, or deletion of your personal data. Where maxlevel is the processor, we route the request to the controller — your employer or community admin — and support them in fulfilling it.

AI drafting, and where those requests go

When a community admin uses "Suggest with AI", what they typed is sent to a large language model together with that community’s name, the names of its existing actions and their XP range — so the suggestions fit what the community already does. No member data is included: no names, no email addresses, no action history, no identifiers. Nothing is sent unless an admin presses the button; the feature never runs on its own. Requests are routed through OpenRouter, which forwards them to whichever provider currently serves the chosen model — so the specific company processing a given request is not fixed, and can differ between two requests made minutes apart. We choose the model, not the machine it runs on. We do not permit that content to be used for training. If you would rather nothing left the platform at all, the feature can be switched off for an entire instance, and every action and badge can still be written by hand.

Sub-processors

We use a small number of sub-processors for hosting, email delivery, and billing. The current list is available on request and we will give notice before adding a new one that touches personal data.

International transfers

Because the platform is cloud-agnostic, we can host a deployment in a specific region. Where a transfer outside the EEA is unavoidable, it is covered by standard contractual clauses.

Cookies and analytics

This website sets no cookies unless you allow them. We use Google Analytics 4 in Google’s "advanced consent mode": the Google tag loads on every page with analytics storage switched OFF by default, which means Google receives a cookieless signal that a page was viewed — including your IP address — before you answer the banner, but nothing is written to your device and no identifier is stored. Advertising storage, ad user data and ad personalisation are denied at all times, ad data is redacted, Google Signals is off and your IP is anonymised; we run no advertising here. If you allow analytics, Google sets its own cookies to measure which pages are read. Declining costs you nothing — the site is identical either way. Your choice is stored in your browser’s local storage rather than in a cookie, and you can change or withdraw it at any time from "Cookie settings" in the footer, which also deletes the analytics cookies. Updated 2 August 2026.

Contact

Privacy questions and data-subject requests go to [email protected] and reach a person on the founding team, not a ticket queue.