PRIVACY POLICY
Last updated September 2026
The Mini Mainframe is a hobby paint-and-miniature management tool. This policy explains what we collect, why, and the choices you have. We aim to collect as little as possible.
What we collect
- Account: your username and a password (stored only as a salted hash), plus an optional recovery email.
- Your content: projects, recipes, paint inventory, collection items, sessions, and events you create.
- Billing: if you sponsor the Mainframe, Stripe processes your payment; we store your Stripe customer id and plan status, never your card details.
- Basic technical logs needed to run and secure the service.
How we use it
Third parties (subprocessors)
We share data with the following subprocessors, each only to provide their part of the service:
- Vercel — hosting, and Vercel Analytics for privacy-friendly, aggregate usage metrics.
- Sentry — error monitoring: when the app hits an error we send Sentry a diagnostic report (error details and basic request context) so we can diagnose and fix it.
- Our database provider — stores your account and content.
- Stripe — payments (if you sponsor).
- An email provider — transactional email (e.g. password resets, verification).
- Anthropic — powers our AI features: the prompts you send to the AI recipe creator, and the images you submit to the public gallery (which are checked by automated moderation).
- Groq — parses the army-list text you upload when importing a list.
Each processes data only to provide their service. The AI subprocessors (Anthropic, Groq) receive data only when you use the optional feature that relies on them.
Browser extension
The optional Mini Mainframe Collection browser extension adds the product page you're viewing to your collection. It handles two pieces of data, both only because you asked it to:
- Your extension token.Generated by you in Settings and stored in your browser's extension storage. It is sent to us only as an
Authorizationheader so we know which account to add the item to. The token is a signed value derived from your account id — we keep no copy of it, and regenerating it in Settings immediately invalidates the old one everywhere it's pasted. - The product page URL. Sent to us only at the moment you click the extension button, so we can read the product details and save the item. We do not read, collect, or monitor your browsing in the background — the extension has no access to any page until you open it, and it holds no history.
The extension talks to no server other than The Mini Mainframe. Neither the token nor the URLs are sold, shared with third parties, or used for advertising. Uninstalling the extension removes the stored token from your browser; you can also revoke it any time from Settings.