01Introduction and scope
This Policy covers your use of the Services: visiting our websites, creating and using an account, building, previewing, testing and publishing Apps, buying a plan or a domain, and contacting us.
It does not cover data that people submit to Apps built by our users. The person or organisation that built an App is responsible for the data that App collects and how it is used, as described in Apps you build and their users.
We handle Personal Information in line with the Australian Privacy Act 1988 and the Australian Privacy Principles and, where they apply to you, the EU and UK General Data Protection Regulation, and applicable US state privacy laws.
02Definitions
“Personal Information” means information about an identified or reasonably identifiable person, such as your name, email address, payment details, IP address, device and browser identifiers, and usage records that relate to you. Where a law that applies to you uses a different term, such as “personal data” under the GDPR, we mean whatever that law covers.
“App” means anything you build or publish with MonstarX: a website, web app, online store, internal tool or other software project.
“Customer Content” means what you submit to or create with the Services: prompts and chat messages, attached files, code, project files, versions, feature plans, settings, and generated output. Customer Content may contain Personal Information. It does not include Your Users’ Data.
“Your Users’ Data” means Personal Information that people who use your Apps give to those Apps, or that your Apps collect about them: for example, your App’s user accounts, form submissions, orders, and the records in your App’s database and file storage. It does not include people you invite to view your projects, who are covered by the rest of this Policy.
“Usage Data” means information about how the Services are accessed and used, such as requests, the AI models used and their cost, build, test and publish events, logs and diagnostic information. Where Usage Data relates to an identifiable person, it is Personal Information and we protect it as such.
03Personal Information we collect
Information you provide. Account details (your name, email address, and how you sign in: a password, which we store only as a salted hash, or a sign-in provider such as GitHub or Google, from which we receive your name, email address and profile picture). Customer Content. Billing details you give our payment processor (we never see or store full card numbers). The details you provide when you buy a domain. Your communications with us.
Information collected automatically. Usage Data, your IP address, browser and operating system type, session identifiers, and records of the emails we send you. We use cookies and similar technologies only as described in Cookies and similar technologies.
Information from integrations you enable. If you connect another service to MonstarX or to an App (for example, a code repository, a productivity suite, a payment account or a database), we receive the data that service makes available under the permissions you grant, and we store the access tokens or keys it needs. We access only what the integration you enabled requires. Keys and tokens are encrypted before they are stored and are never shown back to you or sent to your browser.
Information from other sources. Payment status and fraud signals from our payment processor, and technical signals from the providers that protect the Services.
04How we use Personal Information
- Provide the Services: operate your account; build, preview, test, scan, publish and host your Apps; save your projects to the services you connect; and register and serve domains.
- Protect and secure: detect, prevent and investigate fraud, abuse, security incidents and breaches of our Terms of Service, and apply rate limits.
- Payments and usage: process payments, and measure usage against your plan’s allowances.
- Communicate: send you service messages about your account, subscription, domains and projects, and answer your questions. We don’t send marketing emails without your permission.
- Improve: analyse Usage Data to improve the performance, reliability and quality of the Services.
- Comply with law: meet legal, tax and regulatory obligations, and establish, exercise or defend legal claims.
We use automated systems to detect fraud, abuse and security risks. If an automated decision significantly affects you, such as an account suspension, you can ask for a person to review it by writing to support@monstarx.com.
05AI processing and model training
To answer a request, MonstarX sends your message, the files you attach and the relevant parts of your project to one or more third-party AI model providers. The same applies to the AI features in your Apps. These providers process the content to return a response. Some may keep it for a limited time to detect abuse.
We don’t train AI models on your content. We don’t use Customer Content, Your Users’ Data or your account details to train AI models, and we don’t allow others to do so on our behalf.
AI output can be wrong. Please review what MonstarX builds before you rely on it (see our Terms of Service).
08Apps you build and their users
Your Users’ Data belongs to your App. You decide what your App collects and why, so you are responsible for it: under the GDPR, you are the controller and we are your processor. We store and process Your Users’ Data only to run your App on your instructions, and we don’t use it for any other purpose.
You are responsible for your App’s privacy notice, any consents your App needs, and answering requests from your App’s users.
If you used an App someone built with MonstarX, the person or organisation that built it decides what data it collects and why. Please send your privacy requests to them; their own privacy notice should say how to reach them. If you contact us, we will refer you to them and help them respond where we can.
09Domains you buy through MonstarX
If you buy a domain through MonstarX, the contact details needed to register it are shared with the registrar and the registry that operate it and, where ICANN’s rules require, with ICANN and a data escrow provider. Where a domain ending allows it, personal contact details are hidden from public lookups.
10Our legal bases
Where the law requires a legal basis for using Personal Information, we rely on:
- Providing the Services: processing needed to give you the Services you signed up for, including billing and support.
- Legitimate interests: securing the Services, preventing fraud and abuse, improving the Services, and establishing, exercising or defending legal claims, in each case where our interests are not outweighed by your rights.
- Consent: for example, when you connect another service or agree to receive product news. You can withdraw consent at any time; this doesn’t affect processing that already took place.
- Legal obligations: bookkeeping, tax, and responding to lawful requests.
11International transfers
We are based in Australia. We and our service providers process Personal Information in several countries, including the United States and countries in the European Union, so your information may be transferred outside the country where you live.
When we disclose Personal Information overseas, we take reasonable steps to make sure it is protected as the Australian Privacy Principles require. Where the GDPR or UK GDPR applies, we use recognised transfer mechanisms such as the European Commission’s standard contractual clauses and the UK International Data Transfer Addendum.
12How long we keep it
We keep Personal Information only as long as we need it for the purposes in this Policy or as the law requires, then delete or de-identify it.
- Your account and Customer Content: while your account is open. When you delete a project, we delete its files, versions, database and published App. When you delete your account in Settings, we delete your account and projects straight away; after a verified deletion request, we do the same. We keep something longer only when the law requires us to.
- Your Users’ Data: while the App it belongs to exists, or until you delete it.
- Operational and security logs: as long as needed to run and secure the Services, and longer while we investigate an incident.
- Billing and tax records: for the periods accounting and tax laws require.
Backups are overwritten on their normal cycle.
13Information security
We protect Personal Information with technical and organisational measures appropriate to the risk, including encryption in transit and at rest, hashed passwords, encrypted storage of keys and access tokens, isolation of each App’s code and data, and access limited to staff who need it.
No system is perfectly secure. If a data breach is likely to cause serious harm, we will notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and any other regulator the law requires, within the required timeframes.
14Your privacy rights
You can see and change your account details in Settings, download a copy of your account data and delete your account (Settings → Data & privacy), export any project in full (Project settings → Export), delete projects, and disconnect integrations at any time.
You can also ask us to give you a copy of your Personal Information, including in a portable, machine-readable format; to correct it; or to delete it along with your account. You can object to or restrict certain processing, and withdraw any consent you have given. Write to support@monstarx.com. We may need to verify your identity first. We will respond within 30 days, or within the period your local law requires, and we will tell you if we need longer and why. We won’t treat you differently for exercising your rights.
If you are unhappy with how we handled your information, please tell us first so we can put it right. You can also complain to the Office of the Australian Information Commissioner or, in the EU, the UK or elsewhere, to your local data protection authority.
15Children
The Services are not intended for children under 16, and we don’t knowingly collect their Personal Information. If we learn that a child under 16 has created an account, we will close it and delete the associated Personal Information. If you believe a child has given us Personal Information, please contact us.
16United States state privacy disclosures
This section supplements the rest of the Policy for residents of US states with comprehensive privacy laws, including California. In the preceding 12 months we have collected the following categories of personal information and disclosed them for business purposes as shown:
| Category | Examples | Disclosed to |
|---|---|---|
| Identifiers | Examples:Name, email address, IP address, account ID | Disclosed to:Service providers; integrations you enable |
| Commercial information | Examples:Plan, purchases, domain orders | Disclosed to:Payment processor; service providers |
| Internet or network activity | Examples:Usage Data, sign-in events, logs | Disclosed to:Service providers |
| User content | Examples:Prompts, files, code and projects | Disclosed to:Service providers; AI model providers; integrations you enable |
| Sensitive personal information | Examples:Account sign-in credentials | Disclosed to:Service providers, only to authenticate you |
We don’t sell personal information or share it for cross-context behavioural advertising, and we don’t use sensitive personal information to infer characteristics about you. Depending on your state, you may have the right to know, access, correct and delete your personal information and to receive a portable copy. To exercise these rights, or to appeal a decision we made about a request, write to us as described in Your privacy rights. An authorised agent may make a request for you with proof of authorisation.
17Changes to this Policy
We will update this Policy as the Services change. The date at the top shows when it last changed. If we make a material change, one that reduces your rights or significantly expands how we use your Personal Information, we will give you at least 30 days’ notice by email or in the Services before it takes effect.
18Contact us
Questions, concerns or privacy requests: support@monstarx.com, or by post to Monstar Lab Pte Ltd, 9 Straits View, Marina One West Tower, #05-07, Singapore 018937. Monstar Lab Pte Ltd is the entity responsible for the Personal Information handled under this Policy (the “controller” where that term applies).