Skip to content

Privacy and data handling

Version 1, 2026-09-25. Changes to this page are listed at the end.

This page covers the Magnetite product: the magnet command-line tool and editor, the dashboard where seats are managed, and this documentation site. The company website has its own policy, and who we are in full is in the Impressum.

The short version: your models, your source and your generated code never leave your machine. What we hold about you is:

  • an email address;
  • the machines your seat is active on;
  • a record of administrative actions that holds ids and not people.

You can download all of it and delete all of it yourself, from the dashboard, at any time.

Astra Labs GmbH
Buergermeister-Miehle Straße 65
86199 Augsburg, Germany
info@astralabs.de

Astra Labs GmbH is responsible for the processing described on this page. Where you use Magnetite through your employer, your employer decides who holds a seat and can remove yours; a request about your data can go to either of us, and we answer the ones sent to us.

Data Why Legal basis Kept until Where
Sign-in account: email address, name if you give one, how you sign in, sessions, organization membership to sign you in to the dashboard performance of the contract (Art. 6(1)(b) GDPR); for a customer’s employees, our legitimate interest in providing the licensed service (Art. 6(1)(f)) you delete your account, or ask us to identity provider, United States
Seat: the email address it was granted to, your organization’s name, the identity provider’s ids for you and your organization to license the software to a named person, which is what a seat is the same the seat is removed, you delete your data, or your organization is erased (see Retention) licensing service, United States
Machine: a fingerprint, a name, the operating system, when it was activated to hold a seat to its two machines, and to let you tell them apart the same you deactivate or remove the machine, or the seat goes licensing service, United States
Organization: its name and the identity provider’s id for it; what it bought and when to know who the customer is and what they are entitled to performance of the contract the organization is erased our database, European Union
Audit log: what was granted, revoked, issued or removed, by which user id, and when to be able to account for every administrative action, to the customer and to ourselves legitimate interest in the security and accountability of license administration (Art. 6(1)(f)) kept; your user id is removed from it when you are erased our database, European Union
Request logs: IP address, time, path and status of requests to the dashboard and this site to operate and secure the services legitimate interest in operating a secure service (Art. 6(1)(f)) the hosting provider’s log retention for our plan; we keep no copy hosting provider, European Union

The machine fingerprint is a SHA-256 digest of the identifier your operating system already has for the installation (/etc/machine-id, the platform UUID, MachineGuid). The identifier itself is never sent. The digest is unsalted and stays the same for the life of the installation, so it tells your machine apart from every other: we treat it as your personal data, not as anonymous.

The machine name is the platform and the first six characters of that fingerprint (macos-3f9a1c), unless you choose one with magnet license activate --name. Your hostname is never sent. A machine activated before this default existed carries the hostname it was given then, until you remove it.

The audit log records ids and never a person. It holds no email address and no machine name, and the database refuses one. While your seat exists its id leads to your address at the licensing service; once it is gone, it leads nowhere.

Your models, source files, generated code, project names and build output stay on your machine. magnet has no telemetry, no crash reporting and no analytics, and neither do the editor, the dashboard or this site. The security statement lists every network connection magnet makes and exactly what each one carries.

magnet license activate writes two files under ~/.magnet, readable by you alone: the seat’s key, and a signed license file that contains your email address and organization. They are yours and we cannot reach them.

magnet license deactivate removes both, and the machine from your seat. magnet license status prints your address and fingerprint to the terminal, so they can end up in a CI log you keep.

Three kinds of provider process this data on our behalf, each under a data processing agreement, and nobody else receives it. We sell none of it and use none of it for advertising.

Role Provider What it receives Where
identity provider Clerk your sign-in account United States
licensing service Keygen your seat and your machines United States
hosting provider Railway our database, and the request logs of the services European Union (the Netherlands)

The rest of this page calls each by what it does.

The dashboard, its database and this site run in the European Union. The identity provider and the licensing service are in the United States, so your sign-in account, your seat and your machines are held there.

Those transfers rest on the safeguards the GDPR provides for them: an adequacy decision where the provider is certified under the EU–US Data Privacy Framework, and the European Commission’s standard contractual clauses otherwise, as set out in our agreement with each provider. Ask us for a copy.

Nothing here expires on its own, so this is what ends it:

  • You delete your data from the dashboard, which removes every seat and machine of yours in every organization, and then your sign-in account.
  • Your administrator removes you. Remove deletes your seat, its machines and your address. Revoke does not: a revoked seat stays on the roster with your address so that it can be handed back, until somebody removes it.
  • We erase a customer’s organization (every seat, machine and address, and the names in its audit trail) ninety days after a term ends without renewal, or sooner when the customer asks.

If we ever restore a backup, the erasures made since it was taken are carried out again before the restored data is used.

Right How to use it
Access and portability (Art. 15, 20) Your data → Download, at the foot of every dashboard page: everything we and the licensing service hold about you, as a JSON file
Erasure (Art. 17) Your data → Delete, in the same place; or ask your administrator to remove you; or write to us
Rectification (Art. 16) your name and address are changed in the dashboard’s account menu; a seat granted to the wrong address is removed and granted again
Restriction and objection (Art. 18, 21) write to us
Complaint (Art. 77) to a supervisory authority; ours is the Bayerisches Landesamt für Datenschutzaufsicht, Ansbach

Write to info@astralabs.de. We answer within one month, and we may ask you to show that the address is yours before we act on it. If you cannot sign in, we carry out an export or an erasure for you, and the record it leaves carries a reference number and not your name.

An export includes the audit entries that concern you: what you did, and what was done to your seat. It does not say who did the second kind, because that is somebody else’s data.

Deleting your data does not reach two things. The license file on your own machine contains your details until it expires or you run magnet license deactivate. Audit entries stay, without you in them: that a seat was granted is kept, and that it was you who granted it is not.

The dashboard sets the cookies that keep you signed in, which the service cannot work without, and nothing else: no analytics, no advertising, no third-party trackers. This site sets none, and its fonts are served from the site itself.

None: there is no profiling, and no decision about you is made by a machine.

  • Version 1, 2026-09-25. First published version.