Privacy and Security
This page explains where MIDAS processes your data, where it stores the data, and what communication it has with external servers. It also summarizes the terms of use and the browser requirements.
Where data is processed
Loading, computation, and rendering of data all take place inside the browser. MIDAS has no server that receives and processes data. CSV parsing, fitting statistical models, and drawing graphs are executed by MIDAS's own program, which runs inside the browser. Column type detection and conversion, SQL, and reading and writing the Parquet-format row data inside MDS files are executed by DuckDB1, which also runs inside the browser.
The MIDAS Provider cannot access your data. The data exists only inside your browser and is never sent to the Provider's servers. Article 4 of the Privacy Policy states this as well.
Where data is stored
Everything MIDAS stores goes into the storage area that the browser reserves for the site app.midas-app.org. MIDAS uses four kinds of browser storage, each holding the following.
| Storage | Contents |
|---|---|
| OPFS (Origin Private File System) | The datasets, reports, and analysis results of projects saved to the browser, temporary files written during saving and exporting, and a copy of the most recently exported MDS file |
| IndexedDB | The project list, records of recently opened files, file references for Reload Dataset, signing keys and registered public keys, logs, and the error history |
| localStorage | Settings and the time at which files for offline use finished downloading |
| Cache Storage | Application files, DuckDB and its extensions, and sample data that the browser keeps for offline use |
Saved projects disappear without your action only when the browser evicts them for lack of space. When you save a project, MIDAS asks the browser to exclude the stored data from eviction. If the browser grants the request, the data is not evicted from then on.
MIDAS deletes the temporary files and the export copy in OPFS without any action on your part. It deletes the temporary files as soon as the save or export finishes. The next time you open MIDAS, it deletes any temporary files left behind by a tab that was closed in the middle of writing. It deletes the copy of the most recently exported MDS file when you start the next export in the same tab, or when you open MIDAS after closing that tab.
There are three ways to delete stored data yourself: deleting a project in the Storage Management screen, running Full Application Reset, and clearing the site data for app.midas-app.org in the browser settings. The last two delete all data. For deleting projects and checking storage usage, see Storage Management.
When the browser denies access to OPFS, projects cannot be saved, loaded, or exported to an MDS file. In some browsers this happens in private browsing. MIDAS detects this state at startup and shows a warning on the home screen. Analysis itself still works.
MIDAS writes a record of operations and errors to IndexedDB for troubleshooting and never sends it outside the browser. You can export this record as a file from the Logs tab of Help > Settings.... An exported log may contain information about the data you were working with, such as the SQL statements you ran.
External communication
The only external communication MIDAS starts on its own, without your action, is of two kinds: downloading the files that run the application, and sending usage events. Communication caused by your actions includes importing from a URL and clicking links.
Downloading the files that run the application consists of downloading the application files, DuckDB and its extensions2, and sample data from app.midas-app.org. None of this carries your data.
Usage events are events MIDAS sends to app.midas-app.org to improve the application. There is no setting to turn this off. MIDAS sends only the following three kinds of events, the application version, and, for error events, a word naming the error type.
- The home screen was shown
- The project screen was shown
- An unhandled JavaScript error occurred
The transmitted content contains none of your data. MIDAS does not send dataset contents, file names, column names, or the names of features you used. The word naming the error type is chosen from a fixed list written into the MIDAS program. The list contains words such as TypeError and RangeError; an error whose type is not in the list is replaced with a word meaning "other error", and a thrown value that is not an error object is replaced with the name of its type. The error message text is never sent. As a result, the strings MIDAS sends are limited to a finite set of words decided in advance, and there is no way for your data to slip in.
The receiving server adds the country or region and a string identifying the browser (the User-Agent) and records the event on the infrastructure of Cloudflare, Inc., which the Provider uses for delivery. This infrastructure keeps the records for at most six months and then deletes them automatically. For the list of information collected, see Article 3 of the Privacy Policy.
Importing from a URL is subject to the same restrictions whichever path it takes. The main paths are three: Open from URL on the home screen, the URL tab of Data > Import Data..., and Reload Dataset for a dataset imported from a URL. Only HTTPS URLs can be fetched. If the server responds with a redirect to another URL, MIDAS does not follow it and cancels the import. Connections to cloud service metadata endpoints3 are always rejected. MIDAS waits at most 30 seconds for a response. MIDAS asks for confirmation before continuing with MDS or CSV files larger than 10 MB. You can change this threshold on the Import tab of Help > Settings....
MIDAS warns you when you newly import from a URL that is not in the trusted URL list. The list is under Trusted URLs on the Security tab of Help > Settings... and contains https://midas-app.org/ and its subpaths by default. Re-fetching with Reload Dataset does not show this warning. When you enable Block connections to untrusted domains on the same Security tab, imports from URLs outside the list, including Reload Dataset, are rejected instead of warned about.
Clicking a link produced by a column's link display or a Markdown link in the report body does not tell the destination site the URL of the MIDAS page. MIDAS opens these links in a new tab and marks them so that the browser does not send the URL that normally indicates where the visitor came from (the Referer). For the conditions under which links can be clicked, and for the warning shown where links are disabled, see Managing Signing Keys.
MIDAS restricts the destinations of communication from the page with a Content Security Policy (CSP). A CSP is a mechanism by which a page declares its allowed destinations to the browser, and the browser rejects everything else. By default, destinations are limited to URLs starting with https://. When you enable Block connections to untrusted domains, MIDAS tightens the CSP further, limiting destinations to app.midas-app.org and the sites in the trusted URL list. MIDAS sets the CSP only when the page loads, so a change to this setting takes effect only after you reload the page.
SQL queries, including SQL contained in MDS files, cannot read external URLs. MIDAS applies a separate CSP to the part that runs DuckDB, limiting its destinations to app.midas-app.org alone. In addition, MIDAS disables the DuckDB setting that downloads extensions from outside automatically.
Through the CSP, MIDAS also refuses to be embedded in pages on other sites. Only app.midas-app.org itself and pages on midas-app.org can embed it. This prevents a third-party site from overlaying an invisible MIDAS on its own page and making you operate MIDAS without noticing.
Cloudflare, on the delivery path, processes and retains request information including IP addresses. The Provider accesses this information only when necessary for security and does not use it for behavioral tracking or profiling. For how Cloudflare handles the information it retains, see Articles 3 and 5 of the Privacy Policy.
License and terms of use
The conditions for using MIDAS are set by the Terms of Service, and the Japanese version of the terms is the authoritative text. MIDAS is free of charge, and the terms permit use for any purpose, including commercial use. However, MIDAS is not open source software: the terms prohibit serving all or part of MIDAS from your own server and prohibit modifying MIDAS. The governing law is the law of Japan.
The Provider does not guarantee the operation or results of MIDAS. MIDAS is a beta version, and features may be added, changed, or removed without notice. The Provider also does not guarantee the accuracy, completeness, or reliability of results, and is not liable for damages arising from use, except in cases of willful misconduct or gross negligence.
The licenses of the open source software and sample data bundled with MIDAS are listed on the Third-Party Licenses page. Some of the sample data was created by third parties, and the source and author of each are shown on that page as well.
Browser requirements
MIDAS requires four browser features: WebAssembly, Web Workers, IndexedDB, and the Web Crypto API. WebAssembly and Web Workers run DuckDB, IndexedDB stores signing keys and other items, and the Web Crypto API signs and verifies MDS files. Saving and loading projects and exporting MDS files additionally require OPFS, and offline use requires Service Workers.
Two features are unavailable in some browsers. The ability of Reload Dataset to remember the file you reloaded so that you can reload it next time without choosing it again depends on the File System Access API and works in Chrome and Edge. For how this feature behaves, see Table Menu. Installing MIDAS as an application is also limited to certain browsers. For the current support, see PWA and Offline Use.
The Provider runs its browser-driven automated tests only on Chromium. Chromium is the browser that Chrome and Edge are built on. Behavior in Firefox and Safari is not verified continuously.
MIDAS assumes a desktop-sized display and does not target the screen widths of smartphones or tablets.
See also
- Storage Management - Reviewing and deleting saved projects, checking storage usage
- MDS Files - Project file structure and digital signatures
- Managing Signing Keys - Generating and backing up keys, registering others' public keys
- PWA and Offline Use - Installing as an application and using offline
Footnotes
-
DuckDB is a SQL engine. MIDAS uses DuckDB-WASM, the version that runs inside the browser. ↩
-
When initializing DuckDB, MIDAS loads the ICU, JSON, and Parquet extensions. MIDAS uses the ICU extension for handling timestamps with time zones, the JSON extension for parsing the structure of SQL statements, and the Parquet extension for reading and writing the row data inside MDS files. None of the three ships inside DuckDB itself, so MIDAS serves them from
app.midas-app.org. ↩ -
Metadata endpoints are addresses such as
169.254.169.254that are visible only from virtual machines in the cloud and return that machine's credentials. This restriction prevents attacks that make a browser running in the cloud read such an address. ↩
Also available as a Markdown file.