Privacy and data handling
Version 1, 2026-09-25. Changes to this page are listed at the end.
This page covers the Magnetite product: the magnet command-line tool and
editor, the dashboard where seats are managed, and this documentation site. The
company website has its own policy, and who we
are in full is in the Impressum.
The short version: your models, your source and your generated code never leave your machine. What we hold about you is:
- an email address;
- the machines your seat is active on;
- a record of administrative actions that holds ids and not people.
You can download all of it and delete all of it yourself, from the dashboard, at any time.
Who is responsible
Section titled “Who is responsible”Astra Labs GmbH
Buergermeister-Miehle Straße 65
86199 Augsburg, Germany
info@astralabs.de
Astra Labs GmbH is responsible for the processing described on this page. Where you use Magnetite through your employer, your employer decides who holds a seat and can remove yours; a request about your data can go to either of us, and we answer the ones sent to us.
What we hold, why, and for how long
Section titled “What we hold, why, and for how long”| Data | Why | Legal basis | Kept until | Where |
|---|---|---|---|---|
| Sign-in account: email address, name if you give one, how you sign in, sessions, organization membership | to sign you in to the dashboard | performance of the contract (Art. 6(1)(b) GDPR); for a customer’s employees, our legitimate interest in providing the licensed service (Art. 6(1)(f)) | you delete your account, or ask us to | identity provider, United States |
| Seat: the email address it was granted to, your organization’s name, the identity provider’s ids for you and your organization | to license the software to a named person, which is what a seat is | the same | the seat is removed, you delete your data, or your organization is erased (see Retention) | licensing service, United States |
| Machine: a fingerprint, a name, the operating system, when it was activated | to hold a seat to its two machines, and to let you tell them apart | the same | you deactivate or remove the machine, or the seat goes | licensing service, United States |
| Organization: its name and the identity provider’s id for it; what it bought and when | to know who the customer is and what they are entitled to | performance of the contract | the organization is erased | our database, European Union |
| Audit log: what was granted, revoked, issued or removed, by which user id, and when | to be able to account for every administrative action, to the customer and to ourselves | legitimate interest in the security and accountability of license administration (Art. 6(1)(f)) | kept; your user id is removed from it when you are erased | our database, European Union |
| Request logs: IP address, time, path and status of requests to the dashboard and this site | to operate and secure the services | legitimate interest in operating a secure service (Art. 6(1)(f)) | the hosting provider’s log retention for our plan; we keep no copy | hosting provider, European Union |
The machine fingerprint is a SHA-256 digest of the identifier your
operating system already has for the installation (/etc/machine-id, the
platform UUID, MachineGuid). The identifier itself is never sent. The digest
is unsalted and stays the same for the life of the installation, so it tells
your machine apart from every other: we treat it as your personal data, not as
anonymous.
The machine name is the platform and the first six characters of that
fingerprint (macos-3f9a1c), unless you choose one with
magnet license activate --name. Your hostname is never sent. A machine
activated before this default existed carries the hostname it was given then,
until you remove it.
The audit log records ids and never a person. It holds no email address and no machine name, and the database refuses one. While your seat exists its id leads to your address at the licensing service; once it is gone, it leads nowhere.
What we never receive
Section titled “What we never receive”Your models, source files, generated code, project names and build output
stay on your machine. magnet has no telemetry, no crash reporting and no
analytics, and neither do the editor, the dashboard or this site. The
security statement lists every network connection magnet
makes and exactly what each one carries.
On your own machine
Section titled “On your own machine”magnet license activate writes two files under ~/.magnet, readable by you
alone: the seat’s key, and a signed license file that contains your email address
and organization. They are yours and we cannot reach them.
magnet license deactivate removes both, and the machine from your seat.
magnet license status prints your address and fingerprint to the terminal,
so they can end up in a CI log you keep.
Who else receives it
Section titled “Who else receives it”Three kinds of provider process this data on our behalf, each under a data processing agreement, and nobody else receives it. We sell none of it and use none of it for advertising.
| Role | Provider | What it receives | Where |
|---|---|---|---|
| identity provider | Clerk | your sign-in account | United States |
| licensing service | Keygen | your seat and your machines | United States |
| hosting provider | Railway | our database, and the request logs of the services | European Union (the Netherlands) |
The rest of this page calls each by what it does.
Transfers outside the European Union
Section titled “Transfers outside the European Union”The dashboard, its database and this site run in the European Union. The identity provider and the licensing service are in the United States, so your sign-in account, your seat and your machines are held there.
Those transfers rest on the safeguards the GDPR provides for them: an adequacy decision where the provider is certified under the EU–US Data Privacy Framework, and the European Commission’s standard contractual clauses otherwise, as set out in our agreement with each provider. Ask us for a copy.
Retention
Section titled “Retention”Nothing here expires on its own, so this is what ends it:
- You delete your data from the dashboard, which removes every seat and machine of yours in every organization, and then your sign-in account.
- Your administrator removes you. Remove deletes your seat, its machines and your address. Revoke does not: a revoked seat stays on the roster with your address so that it can be handed back, until somebody removes it.
- We erase a customer’s organization (every seat, machine and address, and the names in its audit trail) ninety days after a term ends without renewal, or sooner when the customer asks.
If we ever restore a backup, the erasures made since it was taken are carried out again before the restored data is used.
Your rights
Section titled “Your rights”| Right | How to use it |
|---|---|
| Access and portability (Art. 15, 20) | Your data → Download, at the foot of every dashboard page: everything we and the licensing service hold about you, as a JSON file |
| Erasure (Art. 17) | Your data → Delete, in the same place; or ask your administrator to remove you; or write to us |
| Rectification (Art. 16) | your name and address are changed in the dashboard’s account menu; a seat granted to the wrong address is removed and granted again |
| Restriction and objection (Art. 18, 21) | write to us |
| Complaint (Art. 77) | to a supervisory authority; ours is the Bayerisches Landesamt für Datenschutzaufsicht, Ansbach |
Write to info@astralabs.de. We answer within one month, and we may ask you to show that the address is yours before we act on it. If you cannot sign in, we carry out an export or an erasure for you, and the record it leaves carries a reference number and not your name.
An export includes the audit entries that concern you: what you did, and what was done to your seat. It does not say who did the second kind, because that is somebody else’s data.
Deleting your data does not reach two things. The license file on your own
machine contains your details until it expires or you run magnet license deactivate.
Audit entries stay, without you in them: that a seat was granted is kept, and
that it was you who granted it is not.
Cookies
Section titled “Cookies”The dashboard sets the cookies that keep you signed in, which the service cannot work without, and nothing else: no analytics, no advertising, no third-party trackers. This site sets none, and its fonts are served from the site itself.
Automated decisions
Section titled “Automated decisions”None: there is no profiling, and no decision about you is made by a machine.
Changes to this page
Section titled “Changes to this page”- Version 1, 2026-09-25. First published version.