⚠ DRAFT — NOT YET LAWYER-REVIEWED. Every [BRACKETED] item must be filled in before this is published. Google, Microsoft and Dropbox all read this document during OAuth app verification; inaccuracies here can fail a review and re-queue you for weeks. See the checklist at the end.
Monokrew is operated by [LEGAL ENTITY NAME], a Delaware corporation with its registered office at [REGISTERED ADDRESS].
In this policy, "we", "us" and "Monokrew" mean [LEGAL ENTITY NAME]. "You" means the person using the service. "Workspace" means the account your organisation uses, created on first sign-in.
Contact for privacy matters: [PRIVACY EMAIL, e.g. privacy@monokrew.com]
Monokrew is a platform where AI agents build, deploy and operate software on your behalf. To do that, the service:
That last point matters more than anything else in this document. When you connect a service to Monokrew, you are granting agents access to data in that service. Sections 4 and 6 set out exactly what that means.
Account and identity. When you sign in through an identity provider (Google, Microsoft, GitHub, GitLab, Discord, Apple), we receive your name, email address, and a provider account identifier. We never receive or store your password.
Workspace information. Your organisation name, members, roles, and settings.
Content you create. Project descriptions, prompts, instructions, uploaded files, generated code, workflow definitions, and messages you send through the service.
Payment information. Handled by our payment processor. We receive billing contact details, plan, and transaction records. We do not receive or store full card numbers.
Only after you explicitly authorise a connection, and only within the scope you approve:
| Service type | What we access |
|---|---|
| Cloud storage (Google Drive, OneDrive, SharePoint, Box, Dropbox, S3, Google Cloud Storage, WebDAV, SFTP) | Files and folders within the scope you grant — read, and write where you enable it |
| Source control (GitHub, GitLab) | Repository contents you connect, commit history, and the ability to push where you enable it |
| Messaging (WhatsApp, Slack, Discord, Teams, SMS, Telegram) | Messages sent to or from the channels you connect |
We store the access and refresh tokens for these connections, encrypted. We do not use these connections for any purpose other than carrying out the tasks you or your agents initiate.
This section describes something most privacy policies do not have to, and it should be read carefully.
Your content is sent to AI model providers. To build and operate software for you, we send prompts, project descriptions, code, and relevant file contents to third-party AI providers listed in section 7. This is how the service functions.
Your content is not used to train models. We contract with our AI providers on terms that prohibit using your content to train their models, and we do not train models on your content ourselves.
Agents act autonomously within the permissions you grant. Once you authorise a workflow or a connection, agents may read, write, create, modify and delete data within that scope without asking again each time. You control the scope; within it, agents act on your behalf.
Agent output can be wrong. Generated code, generated content and agent-taken actions may contain errors. You are responsible for reviewing output before relying on it. This is a privacy document, so the full position on that is in the Terms of Use.
| Purpose | Basis (where GDPR applies) |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Executing tasks and workflows you initiate | Performance of a contract |
| Billing and account management | Performance of a contract |
| Security, abuse prevention, fraud detection | Legitimate interests |
| Improving reliability and diagnosing faults | Legitimate interests |
| Service announcements and essential notices | Performance of a contract |
| Marketing communications | Consent — you can withdraw at any time |
| Meeting legal obligations | Legal obligation |
We do not sell your personal information. We do not share it for cross-context behavioural advertising.
We share information with:
Sub-processors — the vendors listed in section 7, only as needed to run the service.
Services you connect — when an agent acts in your Google Drive or pushes to your GitHub, information necessarily flows to that service. That flow is governed by your agreement with them, not this policy.
Members of your workspace — content in a workspace is visible to its members according to the roles you set. Your workspace owner and administrators can access workspace content.
Legal and safety — where required by law, or to protect rights, safety or property. We will notify you of a legal demand unless legally prohibited.
Business transfer — in a merger, acquisition or asset sale, subject to this policy continuing to apply.
⚠ THIS LIST MUST BE ACCURATE AND COMPLETE BEFORE PUBLICATION. Verify every entry against what is actually deployed. An incomplete sub-processor list is both a compliance problem and something enterprise customers will audit.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting, compute, storage | [REGIONS] |
| [DATABASE PROVIDER] | Application databases | [REGIONS] |
| [AI PROVIDER(S)] | Model inference for agent operation | [REGIONS] |
| [PAYMENT PROCESSOR] | Payments and billing | [REGIONS] |
| [EMAIL PROVIDER] | Transactional email | [REGIONS] |
| [ERROR MONITORING] | Error and performance monitoring | [REGIONS] |
We maintain a current list at [SUB-PROCESSOR PAGE URL] and will give notice of changes as described there.
We are based in the United States and process information there. If you are in the European Economic Area, the United Kingdom or Switzerland, transfers are made under [Standard Contractual Clauses / UK IDTA / other mechanism].
| Category | Retention |
|---|---|
| Account and workspace | While your workspace is active |
| Content, projects, code | While your workspace is active, then [N] days after deletion |
| Connection tokens | Until you disconnect or the workspace closes, then deleted |
| Application databases | While the application exists, then [N] days |
| Execution and audit records | [N] months |
| Technical logs | [N] days |
| Billing records | As required by law, typically [N] years |
On workspace deletion we delete or de-identify your information within [N] days, except where retention is legally required.
We protect information with encryption in transit and at rest, encrypted storage for credentials and tokens, access controls and least-privilege internal access, tenant isolation between workspaces, and audit logging of sensitive operations.
Your responsibilities matter too. The security of your identity provider account determines the security of your Monokrew workspace — we never see your password, so we cannot protect an account whose provider credentials are compromised. Grant connections the narrowest scope that works, and disconnect services you no longer use.
No system is perfectly secure. If a breach affects your information we will notify you and any regulator as required by law.
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to processing of your information, withdraw consent, and not be discriminated against for exercising these rights.
Exercise any of them at [PRIVACY EMAIL]. We respond within the period the law requires, typically 30 days. We may need to verify your identity first.
If your organisation controls your workspace, direct requests to them — we act on their instructions for workspace content, and will refer you to them.
California residents. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. Categories collected, purposes and disclosures are in sections 3, 5 and 6.
EEA and UK residents. You may complain to your local supervisory authority. [DPO / EU REPRESENTATIVE, if required]
We use cookies and local storage for authentication and session management, remembering preferences such as theme, and understanding service usage.
[STATE WHETHER YOU USE ANALYTICS OR ADVERTISING COOKIES. If you use analytics, name the provider and describe the opt-out. If you use none, say so — it is a genuine advantage and worth stating.]
Monokrew is not for anyone under 18. We do not knowingly collect information from children. If we learn we have, we delete it.
We will post changes here and update the date above. For material changes we will give notice by email or in-product at least [N] days before they take effect.
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[PRIVACY EMAIL]
Three things make this riskier than a standard SaaS policy: