Privacy Policy
This policy explains the data processed by Membara Commander when users authenticate, connect devices, and run tasks through Commander.
1. Scope
This policy applies specifically to Membara Commander at commander.membara.tech, including the web interface, MCP/OAuth endpoints, Commander Core, and Agents on enrolled devices. Membara Tech's general policy may separately apply to other products at membara.tech.
2. Identity and authentication data
For sign-in and principal binding, Commander may process identity information provided by authentication providers such as Google, including display name, email address, issuer/provider, subject identifier, and information required to verify OAuth/OIDC sessions. Commander does not receive or store Google passwords.
3. Device and connection data
When a device is enrolled, Commander may store metadata such as device identifier, device key/name, organization, connection status, heartbeat time, session state, capabilities reported by the Agent, and technical information needed for routing, revocation, and recovery.
4. Task and execution data
When a user issues a command, Commander may process and store data needed to perform the task and evidence its outcome, including objective/intent reference, task and correlation identifiers, principal, target device, action, technical parameters, status, timing, results, errors, and operational evidence.
For terminal or process tasks, commands, output, process status, and session metadata may be processed as necessary for execution, monitoring, auditing, troubleshooting, or recovery. Commander does not use task data to initiate new tasks outside the user's instructions and authority.
5. Credentials and sensitive information
Commander is designed so that bearer tokens, passwords, private keys, client secrets, and sensitive credentials are not displayed as ordinary evidence or logs. Certain logging and outputs use redaction or sanitization. Users should nevertheless avoid including secrets in commands or output unless necessary for the task.
6. Cookies and sessions
Commander uses sessions/cookies necessary for Owner sign-in, OAuth flows, replay protection, and browser-session binding. These cookies serve authentication and security functions, not advertising.
7. Purposes of data processing
- Verify principal identity and authority.
- Determine permitted target devices and resources.
- Execute, monitor, and recover tasks.
- Record audits, attribution, outcomes, and evidence.
- Detect credential abuse, replay, or revoked sessions.
- Maintain service stability, security, debugging, and operations.
8. Retention
Session, token, task, audit, and evidence data have different lifecycles according to their security and operational purposes. Tokens and sessions may expire or be revoked. Audit records and evidence may be retained longer for attribution, recovery, security, and operational needs. We do not currently specify one fixed retention period for all data categories; retention practices may be clarified or updated as the product evolves.
9. Third parties
Commander may interact with third-party services in accordance with configuration and user instructions, including Google for OAuth/OIDC, AI clients such as ChatGPT or Claude, Cloudflare for networking and security, and hosting/infrastructure providers. Each service has its own privacy policy and terms. Commander does not sell user data to advertisers.
10. AI clients
Prompts and context sent through an AI client are governed by that AI client's policies. Membara Commander receives requests forwarded to MCP/Commander and enforces identity, grants, device targeting, task attribution, and execution controls on the Commander side. Commander does not control all data storage or behavior of external AI-client services.
11. Security and access
Access to Commander is limited through authentication, enrollment, grants, device credentials, revocation, fencing/concurrency controls, and audit. Root or OS permissions on a device do not automatically grant administrative rights to Commander Core. Users must protect access to their OAuth accounts, AI clients, and enrolled devices.
12. Deletion or revocation of access
Users or authorized administrators may revoke OAuth connections, principals/grants, or device enrollment according to available capabilities. Revocation prevents new access relying on those credentials. Existing audit records or evidence may be retained as needed for integrity, security, recovery, or applicable obligations.
13. Children
Membara Commander is intended for professional and administrative use, not for children. We do not intentionally design Commander to collect children's data.
14. Policy changes
This policy may be updated when Commander's capabilities, integrations, security controls, or data practices change. The latest update date will appear on this page.
15. Contact
For questions about Membara Commander privacy, contact [email protected].
See also Membara Commander Terms of Service.