Overview
Monirum is an Amazon intelligence and operations workspace. To run your workspace — organising teams, tracking tasks, surfacing KPIs, sending invites, scraping public product data from Amazon — we collect and process information about you and your team.
This policy explains what we collect, why, who we share it with, and the choices you have. It applies to monirum.com and every Monirum product or surface that links to this document.
1. Who we are
Monirum is built and operated by the Monirum team. For privacy questions or data requests, send us a message via the Help Center and choose Security or privacy issue as the topic.
For data-protection purposes, we are the party responsible for the personal data described in this policy.
2. What we collect
2.1 Information you give us
- Account info — your name, email, password (stored hashed, never in plaintext), profile photo if you upload one, and your public user ID.
- Workspace content — workspace name and slug, teams you create, role labels, members you invite, tasks, KPIs, time logs, inbox conversations, files and images you attach.
- Support content — anything you send us when you write in.
2.2 Information we collect automatically
- Server logs — IP address, browser, operating system, pages visited, and timestamps. Recorded by our hosting and database providers.
- Session cookies — set by Supabase to keep you signed in. See Cookies & tracking.
- Workspace activity — a chronological log of joins, role changes, removals, and similar admin events. Visible to workspace admins.
2.3 Information we collect from third parties
- Public Amazon data — when you research or track an ASIN, we fetch public product listings (price, reviews, BSR, seller info) through an Amazon scraping provider. This data is about products, not about you.
- OAuth sign-in — if you sign in with Google or Microsoft, we receive the basic profile fields they release (name, email, picture). We never see your password with that provider.
3. How we use it
We use your data to:
- Run the service you signed up for — provision workspaces, deliver invites, log time, surface KPIs.
- Authenticate you and keep your account secure.
- Respond when you write in.
- Send essential service notices (sign-in emails, security alerts, downtime notices).
- Improve Monirum — debug issues from server logs, look at how features are used in aggregate, build better defaults.
- Comply with our legal obligations.
We do not use your workspace content (tasks, KPIs, files, conversations) to train AI models. When you use an AI feature inside Monirum, the prompt you choose to send is shared with Anthropic (our AI provider), and only for the time needed to return a response.
4. Legal basis (GDPR + PDPL)
If you're in a region that asks for a legal basis (EU/UK under GDPR, Saudi Arabia under PDPL, UAE under the UAE Data Protection Law), the bases we rely on are:
- Contract — to provide the service you signed up for.
- Legitimate interests — to keep the service safe, prevent abuse, debug, and improve product quality.
- Legal obligation — to keep tax records, respond to lawful requests, and meet other rules we have to follow.
- Consent — for anything optional (marketing emails, certain cookies). You can withdraw consent at any time.
5. How long we keep it
- While your account is active — for as long as you keep the workspace open.
- After you close your account — open Account → Delete account in the app and follow the instructions there. Self-serve deletion is being wired up; today, you can also send us a message via the Help Center and we'll close the account on your behalf. Closing your account removes your profile, signs you out of every device, and drops you from any workspace you're part of. Anything you've created inside a workspace stays with that workspace. Personal data tied to your account is deleted or anonymised within 30 days. Copies in our hosting provider's database backups roll off according to their backup retention window.
- Workspace activity log — kept for the lifetime of the workspace so admins can audit changes.
6. Your rights
Wherever you live, you can ask us to:
- Access — get a copy of the data we hold about you.
- Correct — fix anything that's wrong.
- Delete — remove your account and the personal data tied to it.
- Export — get a portable copy of your workspace data.
- Object or restrict — tell us to stop using your data for certain purposes.
- Withdraw consent — at any time, where we rely on it.
Send us a message via the Help Center— we'll respond within 30 days. If you're in the EU/UK you also have the right to lodge a complaint with your local data-protection authority.
8. International transfers
Some of the services we use to run Monirum process data outside your country (for example, calls to Anthropic's Claude API happen in the United States). When that happens, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- The provider's certification under recognised transfer frameworks.
- Your explicit consent, where neither of the above applies.
9. How we protect data
- All traffic is encrypted in transit (TLS 1.2+).
- Data at rest is encrypted by our infrastructure providers.
- Passwords are hashed with bcrypt — never stored in plaintext.
- Row-level security (RLS) in our database scopes every read and write to the workspace and user it belongs to.
- Production access is limited to a small number of authorised engineers and audited.
- If we ever detect a personal-data breach, we'll notify affected users and regulators within the timeframes required by law.
10. Children
Monirum isn't intended for anyone under 18. We don't knowingly collect personal data from children. If you believe a child has signed up, contact the Help Centerand we'll remove the account.
11. Changes to this policy
We may update this policy as the product changes or the law changes. When we do, we'll update the "Last updated" date at the top. For material changes we'll also email account owners and post an in-app notice. Continued use after a change means you accept the new policy.
12. Contact us
Privacy questions, deletion requests, or anything else — send us a message via the Help Center and choose Security or privacy issue as the topic. We aim to respond within 30 days.
Business customers who use Monirum to process personal data on behalf of their organisation can read the Data Processing Agreement. For matters of data protection between Monirum and a business customer, the DPA takes precedence over this Privacy Policy.