PRIVACY
Privacy Policy
What we collect, why, where it goes, and how to get it deleted.
Private beta notice. This policy describes Monroe’s current data-handling posture for private beta customers. Final general-availability terms will be reviewed with counsel before broader launch.
What we collect
Account information
When you sign up, we collect your name, work email, the workspace you connect (Slack workspace ID, Teams tenant ID), and billing information processed by Stripe (we never store your full card number).
Workspace data
Monroe accesses the third-party data you authorize via OAuth: for example, messages from a Slack channel you grant access to, files in a specific Google Drive folder, issues in a GitHub repository. We access only what each run requires.
Usage data
We log run records (who triggered each run, where, when, and credits used) for billing and audit. Server-level logs are retained 30 days; run records are retained for the life of your account.
How we use it
- To run Monroe: fulfilling your prompts and producing the work you asked for.
- To bill you: metering credits, processing invoices via Stripe.
- To support you: diagnosing issues you report, with explicit consent for run-level access.
- To improve the product: aggregated, de-identified metrics only.
What we don’t do
- We do not use your workspace data to train foundation models.
- We do not sell your data.
- We do not share your data with third parties except subprocessors required to deliver the Service (listed below).
Subprocessors
- Amazon Web Services: compute, storage, and networking, in our AWS account.
- AWS managed AI services: managed AI execution in our AWS account.
- Clerk: identity, SSO, and session management.
- Stripe: billing and payment processing.
- Vercel: marketing site hosting and edge CDN.
- Vanta: SOC 2 evidence collection.
This list mirrors the sub-processor table published at getmonroe.com/security, which is the canonical source.
Security
Data is encrypted in transit, and production storage is designed for encryption at rest. Connector scopes are least-privilege by default. Enterprise customers can review key management and isolation options during security review. See our security overview for details.
Your rights
You can request an export of your run history and deletion of your account at any time by writing to privacy@getmonroe.com. EU and UK residents have additional rights under GDPR, including access, rectification, erasure, and portability. To exercise any right, write to privacy@getmonroe.com.
Children
Monroe is not directed at children under 16. We do not knowingly collect data from children.
Contact
privacy@getmonroe.com reaches a human.