Privacy Policy
Last updated: June 8, 2026 · Compliant with the LGPD (Brazilian General Data Protection Law — Law 13.709/18) and the EU GDPR (Regulation (EU) 2016/679)
This is a courtesy translation. In case of any conflict, the Portuguese version prevails.
1. What we collect
Account data (in our central platform database, Postgres):
- Email address (via Clerk)
- Billing information (managed by Stripe — we do not store card numbers)
- Provisioning metadata (agent slug, Fly IDs, status)
- Third-party API keys you register (stored encrypted with AES-256)
- Administrative action log (audit log)
Agent usage data(in your container’s isolated volume):
- Telegram conversation history
- Agent persistent memory (MEMORY.md, daily notes)
- Personal settings (persona, crons, skills)
- Files you send to the agent
Important: agent usage data never enters the central database. It resides exclusively in your container’s Fly volume, encrypted at rest.
2. How we use your data
- Operating the platform (authentication, billing, agent provisioning)
- Support (responding to your emails when you ask for help)
- Aggregate metrics (number of users, churn, MRR) — no individual identification
We do not sell your data. We do not use it to train our own models. We do not share it with partners for marketing purposes.
3. Third parties that process data
- Clerk (authentication) — email and login data
- Stripe (billing) — payment data, managed under PCI-DSS standards
- Neon (Postgres database) — platform metadata
- Fly.io(containers) — runtime and your agent’s volume data
- Anthropic / OpenAI / Groq / FAL.ai — when your agent calls these models, the content is processed by the respective providers under their own policies. You are the controller of that relationship (your API key, your account with them).
4. Your rights (LGPD)
You may, at any time:
- Access the data we hold about you — via the dashboard or by emailing us
- Exportyour data — the full export (memory, conversation history, file library, images and skills) is available directly from the dashboard (Personality & memory tab,
.tar.gz) - Correct your data (email, persona, etc.) directly in the dashboard
- Delete your account and all data — the dashboard button destroys your container and removes all rows from the central database (LGPD: right to erasure)
5. Users in the European Union (GDPR)
If you are located in the European Economic Area (EEA), the processing of your data is also governed by the General Data Protection Regulation — GDPR (Regulation (EU) 2016/679). In that context we act as the data controller for platform data, and you are entitled to the safeguards below.
5.1. Legal basis for processing (GDPR Art. 6)
- Performance of a contract: processing account and provisioning data is necessary to provide the service you signed up for (creating, operating, and billing your agent).
- Legitimate interests: platform security, fraud/abuse prevention, aggregate metrics, and service improvement — always balanced against your rights and freedoms.
- Consent: where applicable (e.g., optional communications), obtained freely and specifically, and withdrawable at any time.
- Legal obligation: retention of tax and accounting records required by law.
5.2. Your rights under the GDPR
You may, at any time, exercise the rights to:
- Access the personal data we process about you;
- Rectification of inaccurate or outdated data;
- Erasure(the “right to be forgotten”), where no legal basis requires us to retain it;
- Data portability — receiving your data in a structured, machine-readable format;
- Restriction of processing in certain circumstances;
- Objection to processing based on legitimate interests;
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise any of these rights, contact our Data Protection Officer (section 8). We respond within the timeframes set by the GDPR (generally within 30 days).
5.3. International data transfers
Your data may be processed outside the EEA — for example, by infrastructure and service providers such as Vercel, Fly.io, Neon, Clerk, and Stripe, whose servers may be located in the United States or other countries. In such cases, we rely on appropriate safeguards, such as the Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure a level of protection equivalent to that of the EEA.
5.4. Lodging a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Data Protection Authority) in your EEA country if you believe the processing of your data infringes the GDPR.
6. Security
- API keys and tokens encrypted with AES-256-GCM in the database
- Container volume with encryption at rest
- Dashboard access via OAuth (Clerk) — no passwords stored by us
- All communications over HTTPS
- Daily volume backup with 30-day retention
- Audit log for all administrative actions
In the event of a security incident involving your data, you will be notified within 72 hours, as required by the LGPD.
7. Retention
We retain personal data only for as long as necessary for the purposes described in this policy or as required by law:
- Active account: data retained for as long as the account exists
- Canceled account: agent data preserved for 30 days (reactivation window), then destroyed
- Account data (email, platform IDs): deleted within 30 days after permanent account closure, unless a legal obligation applies
- Billing records (invoices): retained for 5 years under Brazilian tax obligations
- Audit log: retained indefinitely for system integrity
8. Data Protection Officer (DPO)
Our Data Protection Officer (DPO), the point of contact for both the LGPD and the GDPR, is Paulo Augusto Minari — contact@myndo.io
See also Terms of Use.