Monroe

PRIVACY

Privacy Policy

What we collect, why, where it goes, and how to get it deleted.

Last updated · June 29, 2026

Private beta notice. This policy describes Monroe’s current data-handling posture for private beta customers. Final general-availability terms will be reviewed with counsel before broader launch.

What we collect

Account information

When you sign up, we collect your name, work email, the workspace you connect (Slack workspace ID, Teams tenant ID), and billing information processed by Stripe (we never store your full card number).

Workspace data

Monroe accesses the third-party data you authorize via OAuth: for example, messages from a Slack channel you grant access to, files in a specific Google Drive folder, issues in a GitHub repository. We access only what each run requires.

Usage data

We log run records (who triggered each run, where, when, and credits used) for billing and audit. Server-level logs are retained 30 days; run records are retained for the life of your account.

How we use it

What we don’t do

  • We do not use your workspace data to train foundation models.
  • We do not sell your data.
  • We do not share your data with third parties except subprocessors required to deliver the Service (listed below).

Subprocessors

  • Amazon Web Services: compute, storage, and networking, in our AWS account.
  • AWS managed AI services: managed AI execution in our AWS account.
  • Clerk: identity, SSO, and session management.
  • Stripe: billing and payment processing.
  • Vercel: marketing site hosting and edge CDN.
  • Vanta: SOC 2 evidence collection.

This list mirrors the sub-processor table published at getmonroe.com/security, which is the canonical source.

Security

Data is encrypted in transit, and production storage is designed for encryption at rest. Connector scopes are least-privilege by default. Enterprise customers can review key management and isolation options during security review. See our security overview for details.

Your rights

You can request an export of your run history and deletion of your account at any time by writing to privacy@getmonroe.com. EU and UK residents have additional rights under GDPR, including access, rectification, erasure, and portability. To exercise any right, write to privacy@getmonroe.com.

Children

Monroe is not directed at children under 16. We do not knowingly collect data from children.

Contact

privacy@getmonroe.com reaches a human.