What MIA holds, where it goes, and how to get it back.
MIA processes account information and the maintenance and reliability data your authorized users load, in order to provide the service. It is not used to train models, sold, or shared for advertising.
What is collected
- Account and authentication. Name, email address, a salted PBKDF2-SHA256 password hash, and session records. MIA never stores a password.
- Organization and site configuration. Names, site codes, timezones, and — if you enter one — a site address and its coordinates.
- Operational records you load. Maintenance history, downtime, preventive-maintenance status, inventory and parts, open actions, and the labour data you choose to import.
- Your conversation with MIA. The questions you ask and the answers MIA gave, kept per user and site so it can be asked what it told you earlier. The most recent 200 exchanges are kept; older ones are discarded automatically.
- Security and operating logs. Sign-in attempts with the originating IP, and an audit trail of what was done in the workspace — access changes, exports, deletions, validation verdicts, and the questions asked of MIA — each with the acting user and their IP. Plus the diagnostic counters needed to run and protect the service.
Who else receives it
These four, and nobody else. The list is the set of outbound requests the application actually makes, and a test compares it against the code on every commit.
- Railway — Hosting and managed PostgreSQL. Holds everything MIA stores. Always, for hosted use.
- National Weather Service (api.weather.gov) — A site's latitude and longitude. No maintenance data is sent. Only when weather intelligence is switched on for that site.
- U.S. Census Bureau geocoder (geocoding.geo.census.gov) — A site's street address, to turn it into coordinates once. Only when an address is saved for a site.
- OpenStreetMap Nominatim (nominatim.openstreetmap.org) — A site's town or place name, when the street lookup finds nothing. Only when an address is saved and the Census lookup does not match.
- Anthropic (api.anthropic.com) — Column headings and a small sample of cell values from a file being mapped — asset tags, part numbers, status words. No figure MIA publishes comes from it, and it is never sent a whole export. Only when the column proposer is switched on for this deployment AND that site has recorded its consent, which defaults to no and can be withdrawn at any time.
Weather intelligence is off for every site until somebody switches it on, and the address lookup runs only when an address is saved. No maintenance, parts or personnel record is sent outside MIA by any feature.
Getting your data back, and having it deleted
- Export. An owner or administrator can download everything MIA holds for a site, as JSON, from the Account page. It is read from the database schema itself, so it covers exactly what a deletion would remove.
- Delete a site. Removes the site and every record kept against it. It cannot be undone from the interface, so the export is offered first.
- Delete an organization. Removes it, every site under it, everybody's access to it, and every record kept against any of them.
- Close an account entirely. Email privacy@miareliability.com. During beta this is handled by a person rather than a button, because deleting your last organization would leave you signed in with nothing to open.
How long it is kept
Operational data is kept until you delete it or ask us to. Your conversation with MIA rolls over at 200 exchanges per person, per site. Sign-in attempt records and their IP addresses are cleared once they are 90 days old, along with spent password-reset requests and expired invitations; that sweep runs by itself and is not something anyone has to remember. The audit trail is kept for the life of the workspace, because months later it is the only thing that can tell you who changed what — deleting a site or an organization removes the records held against it, and the audit trail of the deletion itself survives it. Backups follow the hosting provider's retention and may hold a copy for a short period after deletion.
What not to load
Do not upload passwords or credentials, regulated health information, payment-card data, export-controlled material, or personal information unrelated to maintenance work. MIA is built for equipment records; nothing in it is designed to protect those categories.
Questions
Email privacy@miareliability.com.
Beta status. These are the terms MIA operates under today and they are accurate. They have not been reviewed by counsel and are not a compliance certification under GDPR, CCPA or any other framework. Approved legal terms will replace this notice before paid or broad external availability.