Skip to content

Legal

Privacy Policy

Last updated: 30 April 2026Modeus services

How information moves through the Modeus workspace, including user inputs, connected tools, model providers, and product memory.

Reading guide

The product-specific questions to check first.

This guide helps you navigate the policy. It does not replace the legal text below.

InputsWhat Modeus may collectPrompts, files, connected data, and activity MemoryHow information may support the serviceDelivery, retrieval, security, and product operations ProvidersWhen information may be sharedConfigured AI providers and service operators LifecycleHow long information may remainRetention, deletion, and product-specific controls
On this page Scope 1. Information we collect 2. How we use information 3. How we share information 4. Retention 5. Your choices 6. Cookies 7. Other services 8. Security 9. International transfers 10. Children 11. Changes 12. Contact 13. Regional notices

The legal entity operating Modeus (“Modeus”, “we”, “us”, or “our”) provides AI-enabled software, web applications, connected tools, browser and desktop features, and related services (collectively, the “Service”). This Privacy Policy describes how we process personal information collected through the Service.

For content safety and prohibited uses, review the applicable Modeus safety and usage policies. If you use the Service through an organization, published application, team workspace, or API customer, that organization may control some of the information and its privacy notice may also apply.

Publication note: this Modeus-branded policy is adapted from the privacy text supplied for the website. The operating entity, data-protection officer, addresses, processors, product behavior, retention periods, international transfer mechanisms, and contact emails must be verified against the deployed system and reviewed by qualified privacy counsel before publication.

Notice to European users: see Notice to European users for additional information for people in the European Economic Area and United Kingdom (“Europe”).

1. Your Activity and Information You Provide

1.1 Information you provide

Depending on how you interact with the Service, you may provide:

  • Contact data, such as name, salutation, email address, telephone number, professional title, company, and billing or mailing address.
  • Profile data, such as username, password, teams, workspace role, preferences, and information added to an account profile.
  • Communications data, including messages and attachments exchanged with support, through the Service, or through social media.
  • Transactional data, including plan, subscription type, transaction history, invoices, and information needed to complete a purchase.
  • Marketing data, such as communication preferences and engagement with campaigns.
  • Inputs, prompts, and user-generated content, including messages, comments, questions, code, photos, images, audio, voice clips, music, video, files, third-party account instructions, and other material you submit, generate, transmit, or make available, together with associated metadata.
  • Derived data created to provide features such as image transformation, avatars, audio processing, or voice functionality. Some laws may classify certain derived measurements as biometric data even where we do not use them to identify a unique person.
  • Payment data collected directly by payment processors such as Stripe or an app-store billing provider.
  • Published-experience end-user data, such as an email address or credentials when a site or application built with Modeus uses an authentication feature. We may process this on behalf of the owner.
  • Other data described when it is collected or used as otherwise explained in this Policy.

Do not provide sensitive personal information unless a feature expressly supports it and you are authorized to do so. Sensitive information may include government identifiers, financial account numbers, credentials, health data, biometric or genetic information, political or religious beliefs, union membership, sexual orientation, criminal history, or similar data.

1.2 Third-party sources

We may combine information you provide with information obtained from:

  • Public sources, including public records, websites, research databases, and social networks.
  • Third-party AI providers that process inputs, generate outputs, perform moderation, or return technical and usage information.
  • Service providers helping us operate, secure, analyze, support, or promote the Service.
  • Login and linked services, such as Google, Apple, identity providers, or services you ask Modeus to connect to. Information depends on the permissions and settings you choose.
  • Sources you direct us to use, including Connectors that access an authorized external data source, application, or account solely to carry out your instructions. Connector behavior, storage, and provider-policy requirements must be documented for each deployed integration.

1.3 Automatic data collection

We, our service providers, and business partners may automatically log:

  • Device data, such as operating system, manufacturer and model, browser, screen resolution, memory and disk information, CPU usage, device type, IP address, unique identifiers, language, carrier, network type, and approximate location.
  • Online activity data, such as pages viewed, time spent, referring page, navigation paths, actions, access times, session duration, crashes, and performance diagnostics.
  • Communication-interaction data, such as whether an email or message was opened, forwarded, or acted upon.
  • Sandbox or execution data when Modeus performs tasks in an isolated environment, including uploaded and generated files, shell commands and output, generated or supplied code, tool activity, and execution logs needed for delivery, security, replay, or debugging.
  • Browser Operator data when you enable a browser extension or local browser connector, including authorized page content, clicks, scrolling, form input, navigation, local session context, and actions performed on your behalf. We should not collect your raw login password through this feature. You can revoke access by disabling the connector or uninstalling the extension.

1.4 End users and team members

Where Modeus processes personal information for an owner of a published site or application, an API customer, or a team-plan owner, that customer determines the purposes and means of processing and acts as controller; Modeus acts as processor or service provider under the customer’s instructions and contract. Team owners or authorized administrators may have access to team-workspace activity, content, usage, and administrative information as disclosed when a user joins the team.

2. How We Use Your Information

We may use personal information for the following purposes or as described when collected.

2.1 Service delivery and operations

  • provide, maintain, and operate the Service;
  • transmit inputs to configured AI providers and receive outputs needed to fulfill requests;
  • establish, maintain, and authenticate accounts and profiles;
  • enable security, fraud prevention, abuse detection, and account recovery;
  • manage team collaboration, roles, permissions, session synchronization, and shared resource usage;
  • operate authentication, analytics, hosting, and support for published experiences at the owner’s direction;
  • send service announcements, updates, security alerts, support responses, and administrative messages;
  • support events, early-access programs, and contests in which you choose to participate;
  • run asynchronous, scheduled, or background tasks and retain logs required for replay, debugging, and proof of execution; and
  • coordinate parallel agents for large tasks under the same data-protection controls that apply to the primary task.

2.2 Personalization

We may use information to understand interests and preferences, personalize the Service and related communications, remember choices, and adapt the workspace to your selected settings.

2.3 Service improvement and analytics

We may analyze use of the Service, identify popular or underused features, diagnose performance, understand navigation, improve accessibility and reliability, evaluate model or tool behavior, and develop new products. Optional analytics cookies are used only where permitted and, when required, with consent.

2.4 Marketing and advertising

We may send direct marketing where permitted and personalize it based on your interests. You can opt out at any time. Where law permits and consent is obtained when required, online identifiers may be used to show relevant promotions, measure performance, and build or refine audiences.

2.5 Compliance and protection

We may use information to comply with law, lawful requests, and legal process; protect rights, privacy, safety, and property; audit compliance; enforce contracts and policies; and prevent, identify, investigate, or deter fraud, cyberattacks, identity theft, harmful behavior, abuse, and other illegal or unethical activity.

2.6 Corporate events

Information may be evaluated or transferred in connection with a prospective or completed financing, investment, merger, acquisition, restructuring, sale, insolvency, bankruptcy, or transfer of assets.

2.7 Aggregated, de-identified, and anonymized data

We may create data that no longer reasonably identifies an individual and use or share it for lawful business purposes, including Service analysis, reliability, security, research, model evaluation, and business promotion. We will not attempt to re-identify data treated as de-identified except to test whether our de-identification measures work or as permitted by law.

2.8 Processor services

When a customer uses Modeus to process end-user or team-member personal information, we process it under the customer’s documented instructions and applicable data-processing agreement to host the experience, execute requests, administer the team workspace, and provide related support.

2.9 Further uses

If we want to use personal information for a materially different purpose that is not compatible with the original purpose, we will provide notice and request consent where required.

3. How We Share Your Information

We may share personal information with the following parties, subject to contracts and law where required:

  • Corporate affiliates, including a parent, subsidiary, or affiliated entity.
  • Service providers supporting hosting, infrastructure, security, information technology, email, customer support, research, analytics, accessibility, and marketing.
  • Third-party AI providers powering chat, reasoning, multimodal generation, moderation, embedding, search, data analysis, or recommendations.
  • Payment processors such as Stripe or app-store billing providers, which process payment-card or purchase information under their own privacy terms.
  • Marketing and measurement partners helping promote and measure the Service, where allowed and subject to opt-out rights.
  • Third parties you designate or authorize us to contact, connect, or share with.
  • Published-experience owners and API customers when you interact with a site, application, or workflow they operate.
  • Linked services where you sign in through or connect an external account; their use is governed by their privacy policy and your settings.
  • Professional advisers, including lawyers, auditors, accountants, bankers, and insurers.
  • Authorities and other parties where we believe disclosure is necessary for compliance, legal process, safety, rights enforcement, or protection.
  • Business transferees in connection with an actual or prospective investment, financing, sale, merger, acquisition, insolvency, or similar transaction.

3.1 Other users and the public

Content you choose to publish or share may be visible to other users or the public. Others may collect, copy, cache, index, screenshot, or redistribute it, and we cannot control their use after disclosure.

In a team workspace, a team owner may be able to access team-session data, task steps, content, usage, exports, and materials created during team sessions. Administrators may receive a more limited set of administrative and usage information depending on their role. The exact permissions must be disclosed in-product before a member joins or contributes team data.

4. Retention

We generally retain personal information for as long as needed to provide the Service, fulfill the purposes described in this Policy, meet legal, accounting, and reporting obligations, establish or defend claims, prevent fraud, resolve disputes, and enforce agreements.

We consider the amount, nature, and sensitivity of the information; the risk from unauthorized use or disclosure; the purpose of processing; whether the purpose can be achieved another way; contractual commitments; and applicable law. When information is no longer needed, we delete, anonymize, or isolate it according to our retention program and backup lifecycle.

4.1 Team-related information

Retention for team-session content and team usage records may also be set by the team owner or administrator under organizational policy and law.

4.2 Sandbox environments

Task sandboxes may be ephemeral and may reset. The supplied policy text describes retention of up to seven days after last activity for free plans and up to fourteen days for paid plans. Those periods must be confirmed against the deployed Modeus infrastructure before publication.

4.3 End-user information

Information processed for a published-experience owner or API customer is retained under that customer’s instructions. Team members seeking deletion of team-workspace information should first contact their team owner or administrator. If a request concerns data Modeus independently controls, such as account billing or security information, the individual may contact Modeus directly.

5. Your Choices

5.1 Access or update information

If you have an account, you may review and update certain information in account settings.

5.2 Opt out of communications

You may opt out of marketing email using the unsubscribe instructions in the message or by contacting us. You may continue to receive service, security, transactional, and other non-marketing communications.

5.3 Images and tracking technologies

Browsers and email clients may let you block remote images or similar technologies. Blocking them can affect message formatting and measurement.

5.4 Targeted advertising and privacy signals

Where applicable, account settings and a “Your Privacy Choices” control may allow you to opt out of sharing or processing for targeted advertising. Depending on your location, we may treat a valid Global Privacy Control (“GPC”) signal as an opt-out request for the browser receiving the signal. Other “do not track” signals may not be recognized where no common standard applies.

5.5 Declining to provide information

Some information is required to provide an account, perform a task, process payment, or meet legal obligations. If you decline to provide required information, the relevant Service may be unavailable.

5.6 Linked platforms and Connectors

You can use provider settings to limit or revoke linked-account access. Revocation does not erase information already lawfully received. You can manage or remove Modeus Connectors and disable Browser Operator through the relevant settings or by uninstalling the extension.

5.7 Delete content or close an account

You may delete supported content through the Service and request account closure through the account or official support channel. Some information may be retained where required for law, security, fraud prevention, dispute resolution, or legitimate backup cycles.

5.8 Team privacy controls

Team settings may let members manage sharing of non-collaborative content. Certain aggregate usage or task-progress information may remain visible to owners or administrators as needed to operate the team.

6. Cookies and Similar Technologies

Some automatic collection is facilitated by cookies, local storage, pixels, software-development kits, and similar technologies. They may be used for strictly necessary functions, authentication, preferences, security, analytics, and marketing where permitted.

A separate Cookie Policy or consent manager should identify deployed cookies, their providers, purposes, durations, and controls. Optional cookies should not be represented as active until the website’s actual analytics and consent configuration has been verified.

7. Other Sites and Services

The Service may link to third-party websites, applications, and online services, and Modeus content may appear within services we do not operate. A link or integration is not an endorsement or representation of affiliation. We do not control third parties and are not responsible for their acts, omissions, security, or privacy practices. Review the privacy policies of services you use.

8. Security

We use technical, organizational, and physical safeguards designed to protect personal information, including access controls and procedures intended to preserve confidentiality, integrity, and availability. No internet, email, storage, or transmission system can be guaranteed completely secure. Use the Service at your discretion and do not submit credentials or sensitive information outside supported, authorized features.

If you believe your account or information is at risk, use the verified security or support channel immediately and avoid sending secrets in an unencrypted support message.

9. International Data Transfers

Modeus and its service providers may operate in multiple countries. Personal information may be transferred to or processed in the United States, Singapore, or other locations where privacy laws differ from those where you live.

Where required, we use recognized transfer mechanisms such as adequacy decisions, approved standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard. In limited cases, a statutory derogation may apply. European users should review the additional information in the regional notice below.

10. Children

The Service is not intended for anyone under 18. If you are a parent or guardian and believe we collected a child’s personal information contrary to law, contact us. If we learn that prohibited information was collected, we will take steps required by applicable law to delete it.

11. Changes to This Privacy Policy

We may update this Policy. We will revise the “Last updated” date and publish the new version. For material changes, we may provide additional notice or request consent where law requires. Changes apply when stated in the updated Policy.

Owners of published experiences, API customers, and team owners may separately update their privacy practices. Where Modeus acts as their processor, processing may change under their documented instructions and applicable agreement.

12. How to Contact Us and Our Data Protection Officer

Privacy requests and questions should be sent to the verified privacy contact for the legal entity operating Modeus. The proposed address privacy@modeus.ai must be configured, monitored, and confirmed before publication.

The identity, postal address, and contact information of the controller and any appointed Data Protection Officer must be inserted here before this Policy is relied upon.

13. Addendum and Regional Notices

13.1 Notice to European users

Scope. This notice applies to people in the United Kingdom and European Economic Area. References to personal information include “personal data” under the General Data Protection Regulation and UK GDPR (“GDPR”).

Controller and processor. The verified legal entity operating Modeus is the controller for individual-account, billing, security, support, and direct relationship processing. For data processed solely for a published-experience owner, API customer, or team owner, that customer is controller and Modeus is processor. Team members should normally direct workspace-related data requests to their team owner first.

Representatives and DPO. Any required EU or UK representative and the appointed DPO must be identified with current contact information before the Service is offered in those territories.

Legal bases for processing

Depending on the activity, we rely on consent, performance of a contract, compliance with law, or legitimate interests that are not overridden by your rights.

PurposeInformationLegal basis
Service delivery and operationsContact, profile, communications, transactions, inputs, content, connected-service, device, and payment-related dataContractual necessity; compliance with law where applicable
Security and abuse preventionContact, device, activity, network, location, account, and relevant content dataLegitimate interests in securing the Service; compliance with law
PersonalizationProfile, preferences, activity, and feature-use dataLegitimate interests; consent for optional storage where required
Analytics and improvementProfile, device, activity, approximate location, inputs, outputs, derived, and connected-service dataLegitimate interests; consent for optional cookies where required
Direct marketingContact, profile, communications, transactions, and marketing preferencesLegitimate interests or consent; opt-out available
Advertising measurementContact identifiers, device data, and online activityConsent where required
Compliance and protectionInformation relevant to the legal, safety, fraud, or rights issueCompliance with law; legitimate interests
Aggregated research and developmentRelevant data transformed to remove or reduce identifiabilityLegitimate interests in improving and securing the Service
Further compatible usesInformation relevant to the new purposeOriginal legal basis if compatible; otherwise consent or another lawful basis

Your European rights

Subject to conditions and exceptions in law, you may request:

  • Access to information about processing and a copy of your personal data.
  • Correction of inaccurate or incomplete data.
  • Deletion where there is no lawful reason to continue processing.
  • Portability of certain data in a machine-readable format.
  • Restriction of processing in specified circumstances.
  • Objection to processing based on legitimate interests and to direct marketing.
  • Withdrawal of consent at any time where processing relies on consent, without affecting prior lawful processing.

We may ask for information needed to verify identity and authority. If a request is denied in whole or part, we will explain why, subject to legal restrictions. You may complain to the data-protection authority where you live or work. UK users may contact the Information Commissioner’s Office at ico.org.uk/make-a-complaint.

Transfers outside Europe

We may transfer information to countries subject to an adequacy decision. For other destinations, we may use approved standard clauses or another lawful safeguard. In limited circumstances, a legal derogation may apply. You may request information about the safeguard used for a relevant transfer.

13.2 Notice to California users

This section applies where processing is subject to the California Consumer Privacy Act, as amended (“CCPA”). We may disclose personal information to service providers or contractors under agreements restricting their use.

California residents may have rights to know, access, correct, delete, and receive information about personal information collected, used, disclosed, sold, or shared; to opt out of sale or sharing and certain targeted advertising; to limit use of sensitive personal information where applicable; and not to receive discriminatory treatment for exercising privacy rights.

Where Modeus uses identifiers for cross-context behavioral advertising, a “Your Privacy Choices” setting and qualifying GPC signal should be honored as required. The website must not claim such a control works until it is technically connected to the deployed advertising and consent systems.

13.3 Notice to South Korea users

Where Korea’s Personal Information Protection Act applies, the legal entity operating Modeus must identify its Personal Information Protection Officer and make required disclosures. Cross-border hosting, storage, support, and security transfers must use a permitted basis, include required notice or consent, and be supervised under applicable law.

13.4 Notice to Japan users

Where Japan’s Act on the Protection of Personal Information applies, the verified Modeus operating entity is the personal-information handling business operator for processing covered by this Policy. Required disclosures about joint use, foreign transfers, security measures, and requests must be supplied in Japanese where applicable.

13.5 Notice to Singapore users

Where Singapore’s Personal Data Protection Act 2012 (“PDPA”) applies, the verified operating entity is responsible for collection, use, and disclosure as described in this Policy. It must appoint and publish a Data Protection Officer contact, notify the Personal Data Protection Commission and affected individuals of notifiable breaches within required timeframes, and ensure comparable protection for transfers outside Singapore.