The legal entity operating Modeus (“Modeus”, “we”, “us”, or “our”) provides AI-enabled software, web applications, connected tools, browser and desktop features, and related services (collectively, the “Service”). This Privacy Policy describes how we process personal information collected through the Service.
For content safety and prohibited uses, review the applicable Modeus safety and usage policies. If you use the Service through an organization, published application, team workspace, or API customer, that organization may control some of the information and its privacy notice may also apply.
Notice to European users: see Notice to European users for additional information for people in the European Economic Area and United Kingdom (“Europe”).
1. Your Activity and Information You Provide
1.1 Information you provide
Depending on how you interact with the Service, you may provide:
- Contact data, such as name, salutation, email address, telephone number, professional title, company, and billing or mailing address.
- Profile data, such as username, password, teams, workspace role, preferences, and information added to an account profile.
- Communications data, including messages and attachments exchanged with support, through the Service, or through social media.
- Transactional data, including plan, subscription type, transaction history, invoices, and information needed to complete a purchase.
- Marketing data, such as communication preferences and engagement with campaigns.
- Inputs, prompts, and user-generated content, including messages, comments, questions, code, photos, images, audio, voice clips, music, video, files, third-party account instructions, and other material you submit, generate, transmit, or make available, together with associated metadata.
- Derived data created to provide features such as image transformation, avatars, audio processing, or voice functionality. Some laws may classify certain derived measurements as biometric data even where we do not use them to identify a unique person.
- Payment data collected directly by payment processors such as Stripe or an app-store billing provider.
- Published-experience end-user data, such as an email address or credentials when a site or application built with Modeus uses an authentication feature. We may process this on behalf of the owner.
- Other data described when it is collected or used as otherwise explained in this Policy.
Do not provide sensitive personal information unless a feature expressly supports it and you are authorized to do so. Sensitive information may include government identifiers, financial account numbers, credentials, health data, biometric or genetic information, political or religious beliefs, union membership, sexual orientation, criminal history, or similar data.
1.2 Third-party sources
We may combine information you provide with information obtained from:
- Public sources, including public records, websites, research databases, and social networks.
- Third-party AI providers that process inputs, generate outputs, perform moderation, or return technical and usage information.
- Service providers helping us operate, secure, analyze, support, or promote the Service.
- Login and linked services, such as Google, Apple, identity providers, or services you ask Modeus to connect to. Information depends on the permissions and settings you choose.
- Sources you direct us to use, including Connectors that access an authorized external data source, application, or account solely to carry out your instructions. Connector behavior, storage, and provider-policy requirements must be documented for each deployed integration.
1.3 Automatic data collection
We, our service providers, and business partners may automatically log:
- Device data, such as operating system, manufacturer and model, browser, screen resolution, memory and disk information, CPU usage, device type, IP address, unique identifiers, language, carrier, network type, and approximate location.
- Online activity data, such as pages viewed, time spent, referring page, navigation paths, actions, access times, session duration, crashes, and performance diagnostics.
- Communication-interaction data, such as whether an email or message was opened, forwarded, or acted upon.
- Sandbox or execution data when Modeus performs tasks in an isolated environment, including uploaded and generated files, shell commands and output, generated or supplied code, tool activity, and execution logs needed for delivery, security, replay, or debugging.
- Browser Operator data when you enable a browser extension or local browser connector, including authorized page content, clicks, scrolling, form input, navigation, local session context, and actions performed on your behalf. We should not collect your raw login password through this feature. You can revoke access by disabling the connector or uninstalling the extension.
1.4 End users and team members
Where Modeus processes personal information for an owner of a published site or application, an API customer, or a team-plan owner, that customer determines the purposes and means of processing and acts as controller; Modeus acts as processor or service provider under the customer’s instructions and contract. Team owners or authorized administrators may have access to team-workspace activity, content, usage, and administrative information as disclosed when a user joins the team.
2. How We Use Your Information
We may use personal information for the following purposes or as described when collected.
2.1 Service delivery and operations
- provide, maintain, and operate the Service;
- transmit inputs to configured AI providers and receive outputs needed to fulfill requests;
- establish, maintain, and authenticate accounts and profiles;
- enable security, fraud prevention, abuse detection, and account recovery;
- manage team collaboration, roles, permissions, session synchronization, and shared resource usage;
- operate authentication, analytics, hosting, and support for published experiences at the owner’s direction;
- send service announcements, updates, security alerts, support responses, and administrative messages;
- support events, early-access programs, and contests in which you choose to participate;
- run asynchronous, scheduled, or background tasks and retain logs required for replay, debugging, and proof of execution; and
- coordinate parallel agents for large tasks under the same data-protection controls that apply to the primary task.
2.2 Personalization
We may use information to understand interests and preferences, personalize the Service and related communications, remember choices, and adapt the workspace to your selected settings.
2.3 Service improvement and analytics
We may analyze use of the Service, identify popular or underused features, diagnose performance, understand navigation, improve accessibility and reliability, evaluate model or tool behavior, and develop new products. Optional analytics cookies are used only where permitted and, when required, with consent.
2.4 Marketing and advertising
We may send direct marketing where permitted and personalize it based on your interests. You can opt out at any time. Where law permits and consent is obtained when required, online identifiers may be used to show relevant promotions, measure performance, and build or refine audiences.
2.5 Compliance and protection
We may use information to comply with law, lawful requests, and legal process; protect rights, privacy, safety, and property; audit compliance; enforce contracts and policies; and prevent, identify, investigate, or deter fraud, cyberattacks, identity theft, harmful behavior, abuse, and other illegal or unethical activity.
2.6 Corporate events
Information may be evaluated or transferred in connection with a prospective or completed financing, investment, merger, acquisition, restructuring, sale, insolvency, bankruptcy, or transfer of assets.
2.7 Aggregated, de-identified, and anonymized data
We may create data that no longer reasonably identifies an individual and use or share it for lawful business purposes, including Service analysis, reliability, security, research, model evaluation, and business promotion. We will not attempt to re-identify data treated as de-identified except to test whether our de-identification measures work or as permitted by law.
2.8 Processor services
When a customer uses Modeus to process end-user or team-member personal information, we process it under the customer’s documented instructions and applicable data-processing agreement to host the experience, execute requests, administer the team workspace, and provide related support.
2.9 Further uses
If we want to use personal information for a materially different purpose that is not compatible with the original purpose, we will provide notice and request consent where required.
4. Retention
We generally retain personal information for as long as needed to provide the Service, fulfill the purposes described in this Policy, meet legal, accounting, and reporting obligations, establish or defend claims, prevent fraud, resolve disputes, and enforce agreements.
We consider the amount, nature, and sensitivity of the information; the risk from unauthorized use or disclosure; the purpose of processing; whether the purpose can be achieved another way; contractual commitments; and applicable law. When information is no longer needed, we delete, anonymize, or isolate it according to our retention program and backup lifecycle.
4.1 Team-related information
Retention for team-session content and team usage records may also be set by the team owner or administrator under organizational policy and law.
4.2 Sandbox environments
Task sandboxes may be ephemeral and may reset. The supplied policy text describes retention of up to seven days after last activity for free plans and up to fourteen days for paid plans. Those periods must be confirmed against the deployed Modeus infrastructure before publication.
4.3 End-user information
Information processed for a published-experience owner or API customer is retained under that customer’s instructions. Team members seeking deletion of team-workspace information should first contact their team owner or administrator. If a request concerns data Modeus independently controls, such as account billing or security information, the individual may contact Modeus directly.
5. Your Choices
5.1 Access or update information
If you have an account, you may review and update certain information in account settings.
5.2 Opt out of communications
You may opt out of marketing email using the unsubscribe instructions in the message or by contacting us. You may continue to receive service, security, transactional, and other non-marketing communications.
5.3 Images and tracking technologies
Browsers and email clients may let you block remote images or similar technologies. Blocking them can affect message formatting and measurement.
5.4 Targeted advertising and privacy signals
Where applicable, account settings and a “Your Privacy Choices” control may allow you to opt out of sharing or processing for targeted advertising. Depending on your location, we may treat a valid Global Privacy Control (“GPC”) signal as an opt-out request for the browser receiving the signal. Other “do not track” signals may not be recognized where no common standard applies.
5.5 Declining to provide information
Some information is required to provide an account, perform a task, process payment, or meet legal obligations. If you decline to provide required information, the relevant Service may be unavailable.
5.6 Linked platforms and Connectors
You can use provider settings to limit or revoke linked-account access. Revocation does not erase information already lawfully received. You can manage or remove Modeus Connectors and disable Browser Operator through the relevant settings or by uninstalling the extension.
5.7 Delete content or close an account
You may delete supported content through the Service and request account closure through the account or official support channel. Some information may be retained where required for law, security, fraud prevention, dispute resolution, or legitimate backup cycles.
5.8 Team privacy controls
Team settings may let members manage sharing of non-collaborative content. Certain aggregate usage or task-progress information may remain visible to owners or administrators as needed to operate the team.
7. Other Sites and Services
The Service may link to third-party websites, applications, and online services, and Modeus content may appear within services we do not operate. A link or integration is not an endorsement or representation of affiliation. We do not control third parties and are not responsible for their acts, omissions, security, or privacy practices. Review the privacy policies of services you use.
8. Security
We use technical, organizational, and physical safeguards designed to protect personal information, including access controls and procedures intended to preserve confidentiality, integrity, and availability. No internet, email, storage, or transmission system can be guaranteed completely secure. Use the Service at your discretion and do not submit credentials or sensitive information outside supported, authorized features.
If you believe your account or information is at risk, use the verified security or support channel immediately and avoid sending secrets in an unencrypted support message.
9. International Data Transfers
Modeus and its service providers may operate in multiple countries. Personal information may be transferred to or processed in the United States, Singapore, or other locations where privacy laws differ from those where you live.
Where required, we use recognized transfer mechanisms such as adequacy decisions, approved standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard. In limited cases, a statutory derogation may apply. European users should review the additional information in the regional notice below.
10. Children
The Service is not intended for anyone under 18. If you are a parent or guardian and believe we collected a child’s personal information contrary to law, contact us. If we learn that prohibited information was collected, we will take steps required by applicable law to delete it.
11. Changes to This Privacy Policy
We may update this Policy. We will revise the “Last updated” date and publish the new version. For material changes, we may provide additional notice or request consent where law requires. Changes apply when stated in the updated Policy.
Owners of published experiences, API customers, and team owners may separately update their privacy practices. Where Modeus acts as their processor, processing may change under their documented instructions and applicable agreement.
12. How to Contact Us and Our Data Protection Officer
Privacy requests and questions should be sent to the verified privacy contact for the legal entity operating Modeus. The proposed address privacy@modeus.ai must be configured, monitored, and confirmed before publication.
The identity, postal address, and contact information of the controller and any appointed Data Protection Officer must be inserted here before this Policy is relied upon.
13. Addendum and Regional Notices
13.1 Notice to European users
Scope. This notice applies to people in the United Kingdom and European Economic Area. References to personal information include “personal data” under the General Data Protection Regulation and UK GDPR (“GDPR”).
Controller and processor. The verified legal entity operating Modeus is the controller for individual-account, billing, security, support, and direct relationship processing. For data processed solely for a published-experience owner, API customer, or team owner, that customer is controller and Modeus is processor. Team members should normally direct workspace-related data requests to their team owner first.
Representatives and DPO. Any required EU or UK representative and the appointed DPO must be identified with current contact information before the Service is offered in those territories.
Legal bases for processing
Depending on the activity, we rely on consent, performance of a contract, compliance with law, or legitimate interests that are not overridden by your rights.
| Purpose | Information | Legal basis |
|---|---|---|
| Service delivery and operations | Contact, profile, communications, transactions, inputs, content, connected-service, device, and payment-related data | Contractual necessity; compliance with law where applicable |
| Security and abuse prevention | Contact, device, activity, network, location, account, and relevant content data | Legitimate interests in securing the Service; compliance with law |
| Personalization | Profile, preferences, activity, and feature-use data | Legitimate interests; consent for optional storage where required |
| Analytics and improvement | Profile, device, activity, approximate location, inputs, outputs, derived, and connected-service data | Legitimate interests; consent for optional cookies where required |
| Direct marketing | Contact, profile, communications, transactions, and marketing preferences | Legitimate interests or consent; opt-out available |
| Advertising measurement | Contact identifiers, device data, and online activity | Consent where required |
| Compliance and protection | Information relevant to the legal, safety, fraud, or rights issue | Compliance with law; legitimate interests |
| Aggregated research and development | Relevant data transformed to remove or reduce identifiability | Legitimate interests in improving and securing the Service |
| Further compatible uses | Information relevant to the new purpose | Original legal basis if compatible; otherwise consent or another lawful basis |
Your European rights
Subject to conditions and exceptions in law, you may request:
- Access to information about processing and a copy of your personal data.
- Correction of inaccurate or incomplete data.
- Deletion where there is no lawful reason to continue processing.
- Portability of certain data in a machine-readable format.
- Restriction of processing in specified circumstances.
- Objection to processing based on legitimate interests and to direct marketing.
- Withdrawal of consent at any time where processing relies on consent, without affecting prior lawful processing.
We may ask for information needed to verify identity and authority. If a request is denied in whole or part, we will explain why, subject to legal restrictions. You may complain to the data-protection authority where you live or work. UK users may contact the Information Commissioner’s Office at ico.org.uk/make-a-complaint.
Transfers outside Europe
We may transfer information to countries subject to an adequacy decision. For other destinations, we may use approved standard clauses or another lawful safeguard. In limited circumstances, a legal derogation may apply. You may request information about the safeguard used for a relevant transfer.
13.2 Notice to California users
This section applies where processing is subject to the California Consumer Privacy Act, as amended (“CCPA”). We may disclose personal information to service providers or contractors under agreements restricting their use.
California residents may have rights to know, access, correct, delete, and receive information about personal information collected, used, disclosed, sold, or shared; to opt out of sale or sharing and certain targeted advertising; to limit use of sensitive personal information where applicable; and not to receive discriminatory treatment for exercising privacy rights.
Where Modeus uses identifiers for cross-context behavioral advertising, a “Your Privacy Choices” setting and qualifying GPC signal should be honored as required. The website must not claim such a control works until it is technically connected to the deployed advertising and consent systems.
13.3 Notice to South Korea users
Where Korea’s Personal Information Protection Act applies, the legal entity operating Modeus must identify its Personal Information Protection Officer and make required disclosures. Cross-border hosting, storage, support, and security transfers must use a permitted basis, include required notice or consent, and be supervised under applicable law.
13.4 Notice to Japan users
Where Japan’s Act on the Protection of Personal Information applies, the verified Modeus operating entity is the personal-information handling business operator for processing covered by this Policy. Required disclosures about joint use, foreign transfers, security measures, and requests must be supplied in Japanese where applicable.
13.5 Notice to Singapore users
Where Singapore’s Personal Data Protection Act 2012 (“PDPA”) applies, the verified operating entity is responsible for collection, use, and disclosure as described in this Policy. It must appoint and publish a Data Protection Officer contact, notify the Personal Data Protection Commission and affected individuals of notifiable breaches within required timeframes, and ensure comparable protection for transfers outside Singapore.