Legal

Privacy Policy

Last updated 3 September 2026

What we collect, where it is kept, what leaves for a model provider, and what you can do about any of it.

Written in plain language by the team that built the product, and describing only mechanisms the product actually has. It has not yet been reviewed by outside counsel; if that matters for your procurement, say so and we will tell you where the review stands.

1.What we hold

Account data: your email, workspace name, membership and role, and billing records. Payment card details are held by Stripe, not by us — we store an identifier and the last four digits.

Workspace content: the documents, spreadsheets, decks, PDFs, mail, calendar entries and meeting transcripts you put in, plus what the agent derives from them — long-term memory, the knowledge graph, and citations back to the source.

Operational records: conversations with the agent, the tools it called and their arguments, every proposal and your decision on it, and model usage for billing. The audit chain is signed, which means it can be verified and not quietly edited.

Secrets you store are encrypted and write-only: the API can return a name and the last four characters, never the value, and the model never sees one — {{secret:NAME}} is substituted at the moment a tool is dispatched and scrubbed from the result.

2.Where it lives, and where it is processed

Persistent data — conversations, memory, the knowledge graph, documents, encrypted secrets — is stored in Zurich, Switzerland.

Inference is processed in the EU, and on the Swiss track it runs on open-weight models hosted in Switzerland. Which track a workspace uses is a setting you control.

That split is the honest statement of the arrangement: stored in Switzerland, processed in the EU. We do not claim a certification we have not earned.

3.What model providers see — read this one

To answer a turn we send the model the material that turn needs: your message, the retrieved sources, the tool definitions and the results. That is how the agent works, and there is no version of it where the provider sees nothing.

We do not currently have a zero-retention agreement with the upstream model providers. We ask you to assume prompts may be retained by them under their own policies and retention periods. If a provider offers a no-retention arrangement we can rely on, we will say so here and name it.

Incognito mode means WE write nothing durable — no conversation, no message, no memory, no trace on our side. It does not and cannot control what happens on someone else’s infrastructure, and this page will not pretend otherwise.

Providers are not permitted by us to train on your content, and we do not train on it either.

4.Keeping workspaces apart

Every row of workspace data carries a tenant identifier and is isolated by Postgres row-level security, so a query from one workspace cannot reach another’s rows even if the application layer is wrong.

Sub-agents and connected tools inherit that boundary. A tool connection belongs to the workspace that created it.

5.Your rights over it

Export: your files are downloadable in the formats you put them in, at any time, without asking us.

Deletion: you can delete a document, a conversation or the whole workspace. Deleting a document also retires the knowledge-graph facts that were sourced from it, so the agent stops asserting them.

Access and correction: ask and we will tell you what we hold about you, and fix what is wrong.

If you are in the EU, EEA, UK or Switzerland you have the rights their data-protection law gives you, including complaining to your supervisory authority.

6.Who else is involved

Supabase (Postgres, Zurich) for the database. Cloudflare for the application and file storage. Fly.io for the agent runtime. Stripe for payments. Resend for email. Model providers as described above.

Each is used for the purpose named and nothing else.

7.How long we keep it

Workspace content: until you delete it, or for 30 days after the workspace closes.

Audit and billing records: kept as long as the law requires, because their point is that they cannot be quietly removed.

Contact: hello@monopea.com.

The mechanisms behind these claims are described in Security, and the agreement itself is in the Terms of Service.