Back to home

Privacy Policy

Version of August 11, 2026

This policy explains what data Monarch OS collects, why, how it is protected, and what rights you can exercise. It accurately reflects how the product actually works as of the date above and will be reviewed by a qualified lawyer before any large-scale commercial launch.

1. Data controller

Monarch OS is the controller for the data described in this policy. The full details of the publishing legal entity will be specified here before any large-scale commercial launch — see the note at the bottom of the page.

2. Data collected

Account data: first and last name, professional email address, password (encrypted), information about the customer business (name, legal form, address, industry).

Data provided by the Customer to its AI employees: the business's knowledge base, prospects, tasks, conversations with the Customer's end customers, and any content the Customer chooses to import through a connector it voluntarily activates (for example Gmail emails or WhatsApp Business messages).

Technical data: connection logs, audit trail of actions taken by AI employees (who proposed an action, who approved or rejected it, when it was executed) — kept for security, service reliability, and as proof of what was actually authorized.

Billing data: handled directly by Stripe (see "Sub-processors" below); Monarch OS never receives or stores full card details.

3. Purposes of processing

Providing the Service: enabling AI employees to carry out the tasks configured by the Customer, within the autonomy limits it has defined.

Ensuring account and Service security, preventing fraudulent use.

Managing the contractual relationship and billing.

Improving the Service, based on aggregated and anonymized measurements where possible.

4. Legal basis for processing

The processing described in this policy is based, depending on the case, on the performance of the contract entered into with the Customer (providing the Service), on compliance with legal obligations to which Monarch OS is subject (billing, accounting), on Monarch OS's legitimate interest (Service security, fraud prevention, Service improvement), or on the consent of the data subject where specifically required.

5. Isolation between customer businesses

Each customer business's data is technically isolated from every other customer business's data: no information (knowledge base, prospects, conversations, settings) is ever visible to or accessible by another customer organization, nor used to improve another organization's service. Each organization has its own rules and permissions, applied independently.

6. Sub-processors and data recipients

Monarch OS relies on a small number of technical providers, each with access only to the data strictly necessary for its function:

— Database hosting and authentication: Supabase.

— Payment processing and billing: Stripe.

— AI model providers used by AI employees to process requests: depending on the setting chosen by Monarch OS at the platform level or for the customer organization, this may be Anthropic, OpenAI, Google, Mistral, or a locally run model (Ollama) with no transmission to a third party. The Customer never chooses this provider directly — see AI_MODELS.md.

— Connectors voluntarily activated by the Customer: Google (Gmail, Google Calendar, Google Contacts) and Meta (WhatsApp Business) only receive and transmit data for organizations that have explicitly connected these tools, and only within the scope of the permissions granted at connection time.

Monarch OS selects its sub-processors based on sufficient data protection guarantees and governs each relationship through a contract compliant with applicable regulations, including the sub-processing clauses required under GDPR where it applies.

No data is sold to any third party, for any purpose.

7. International transfers

Some sub-processors mentioned above may process data outside the European Union. Details of the applicable safeguards (standard contractual clauses or equivalent) will be specified here before any large-scale commercial launch.

8. Retention period

Account and organization data is retained for the duration of the subscription. After termination, it is retained for a reasonable period allowing for possible reactivation, then deleted, unless a longer retention period is legally required (in particular for accounting and tax purposes).

The audit trail of AI employee actions is retained longer where this serves an evidentiary or security purpose, within limits that will be specified before any large-scale commercial launch.

9. Data security

Credentials for third-party tools (for example Gmail or WhatsApp Business access tokens) are encrypted and never accessible in plain text, including by Monarch OS's own teams.

Access to a customer organization's data is technically restricted to authorized members of that organization, enforced at the database level itself, not only at the interface level. Access to production systems by Monarch OS's own teams is itself limited to individuals whose role requires it, following the principle of least privilege.

Traffic between the Customer's browser and the Service is encrypted (HTTPS).

10. Data breach notification

In the event of a personal data breach likely to result in a risk to the rights and freedoms of the data subjects concerned, Monarch OS will notify the competent supervisory authority and, where applicable regulations require it, the data subjects themselves, within the timeframes set by that regulation.

11. Your rights

In accordance with applicable data protection regulations (including GDPR for users located in the European Union), you have the right to access, rectify, erase, restrict, object to, and port your personal data.

You may exercise these rights by contacting Monarch OS using the contact details listed on the website. A response will be provided as soon as possible.

You also have the right to lodge a complaint with the competent data protection supervisory authority (in France, the Commission Nationale de l'Informatique et des Libertés — CNIL) if you believe that the processing of your data does not comply with applicable regulations.

12. Cookies

Monarch OS only uses cookies strictly necessary for the Service to function (keeping you signed in). No advertising or third-party tracking cookies are used at this time.

13. Changes to this policy

This policy may evolve to reflect changes to the Service or to applicable regulations. Any substantial change results in a new, timestamped version, without ever erasing the record of an already-signed-up Customer's acceptance of an earlier version.

14. Contact

For any question about this policy or to exercise your rights, contact Monarch OS using the contact details listed on the website.

This document accurately reflects how Monarch OS actually works as of the date above. It will be reviewed and completed by a qualified lawyer before any large-scale commercial launch.