Privacy Policy

Last updated: August 15, 2026

This Privacy Policy describes how Mogplex Inc. ("Mogplex", "we", "us") collects, uses, and shares personal data when you use the hosted Mogplex service at mogplex.com, including the web app, CLI, MCP server, and integrations. It does not apply to self-hosted deployments of the open-source software — those are operated by whoever runs them.

1. Data we collect

  • Account data: your name and email address; a hash of your password if you sign up with one; and, if you sign in through single sign-on or an identity provider (GitHub, Google, or Microsoft), your avatar and profile from that provider plus the OAuth tokens needed to act on connected accounts within the scopes you approve
  • Content you provide: prompts, agent conversations, agent and automation configurations, and the repository content agents access at your direction
  • Usage records: per-request metering for billing and observability — model used, token counts, duration, tool-call metadata, and sandbox runtime
  • Team data: team membership, roles, and an audit log of team actions (with credentials and prompt contents redacted)
  • Billing data: plan, balance, and transaction history. Payment card details go directly to Stripe; we never store them
  • Device and log data: IP address, browser or client user agent, and session records used for authentication and security
  • Integration data: if you connect Slack, workspace and event data needed to run agents from Slack; tool execution results are kept briefly to deduplicate Slack retries

2. How we use it

We use this data to:

  • Authenticate you and operate the Service
  • Run agents against your repositories and sandboxes as you direct
  • Meter usage and bill you accurately
  • Secure the Service and prevent fraud and abuse
  • Debug problems and improve reliability
  • Communicate with you about your account and the Service
  • Comply with law

We do not use your code, prompts, or conversations to train AI models, and we do not sell your personal data.

3. AI model providers

When you run an agent, your prompts and relevant repository content are sent through an AI gateway to the model provider you select (such as Anthropic or OpenAI). Those providers process that data under their own terms and privacy policies. If you bring your own gateway or provider key, your direct agreement with that provider governs its processing.

4. Service providers

We share data with subprocessors only as needed to run the Service:

  • Vercel: application hosting, sandbox compute, AI gateway, and privacy-friendly analytics
  • Neon: our Postgres database, where your account and content data live
  • Stripe: payments, as merchant of record for the Service
  • Resend: transactional email (sign-in, invites, billing notices)
  • Trigger.dev: background job execution
  • Sentry: error tracking
  • Cloudflare: CLI release distribution
  • GitHub and Slack: when you connect them, governed by their own privacy policies

Beyond these providers, we disclose personal data only with your direction, when required by law, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to your data).

5. Teams

If you use Mogplex as part of a team, the team's owners and admins can see your membership, role, usage and cost attribution, and entries you generate in the team audit log.

6. Cookies and analytics

We use cookies for authentication and session management, and aggregate analytics to understand how the Service is used. A consent manager on our public pages lets you accept or decline non-essential categories; in regions that require opt-in consent (such as the EU) nothing non-essential runs until you agree, and California residents can opt out.

7. Data retention

We keep your data while your account exists. Sandbox environments are ephemeral and destroyed when they stop. Slack tool execution records are deleted automatically after 24 hours. Billing and audit records may be retained longer where the law requires it. When your account is deleted, associated content is deleted from our production database.

8. Your rights

You may request access to, correction of, export of, or deletion of your personal data at any time by contacting us. You can revoke Mogplex's access from your GitHub, Google, Microsoft, or Slack settings, and revoke personal access tokens and CLI sessions from your Mogplex settings. Depending on where you live (including the EU/EEA, UK, and certain US states), you may have additional statutory rights, which we will honor. We will not discriminate against you for exercising them.

9. International transfers

Mogplex is operated from the United States, and your data is processed there and in the regions where our subprocessors operate. Where required, we rely on appropriate safeguards for cross-border transfers.

10. Security

We encrypt data in transit, isolate agent execution in sandboxed environments, enforce row-level security on database access, and scope OAuth tokens to the permissions you approve. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

11. Children

The Service is not directed to anyone under 18, and we do not knowingly collect personal data from children. If we learn we have collected data from a child, we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. For material changes we will give notice — on this page, by email, or in the product — before the changes take effect.

13. Contact

Questions or requests about your data? Email support@mogplex.com or open an issue on our GitHub repository.