Legal

Privacy Policy

Last updated September 3, 2026

Procurement and data-handling questions

The questions security and procurement reviewers send us most often. For the full control detail, see our security overview.

How does Monroya handle client data?
We store the minimum needed to run scans: your account profile, the prompts you confirm, the AI provider responses those prompts return, and the citations we extract from them. We do not ask for or store CRM, revenue, or source-of-truth analytics data, and we do not sell or share customer data.
Is the scan data anonymized?
Scan results are tied to your account so you can see historical movement over time, so they are identifiable to you. The queries we send to AI providers carry no account identity, no scan history, and no other customer's data - to the provider they look like any other API call.
Is client data used to train AI models?
No. Your tracked prompts, scans, opportunities, and drafted assets are never used to train AI models, for advertising, or to build profiles. We do not send private content to AI providers.
Where is data stored, and is it encrypted?
Data is stored in US regions in a managed Postgres database behind a serverless edge runtime. All traffic uses TLS 1.2 or higher, and backups are encrypted at rest and tested on a rotating schedule.
Who are your subprocessors?
Resend for transactional email, Stripe for payments (card data never touches our infrastructure), OpenAI, Anthropic, Google, and Perplexity at scan time only, and an error monitoring service scrubbed of personal data. We notify customers at least 30 days before adding or replacing a subprocessor that processes customer data.
How long is data retained, and how do we delete it?
Active accounts retain scans and drafts so you can see historical movement. On account deletion we hard-delete records within 30 days, and encrypted backup snapshots are purged on the next rotation (30 days or less). Trial accounts that never convert are purged 90 days after the trial ends.
What access does Monroya take on connected analytics accounts?
None today. Monroya does not currently offer a customer-facing connection to Google Analytics 4, Google Search Console, or Bing Webmaster Tools, and we hold no credentials for customer analytics accounts. If we launch that connection, access will be read-only and limited to aggregated session, conversion, click, impression, and citation counts - never user-level or individually identifiable records - and we will update this policy and give the subprocessor notice described above before it is enabled.
Do you offer a Data Processing Agreement (DPA)?
Yes. A GDPR DPA is available on request for paying customers. SOC 2 Type II controls are implemented but the audit is not yet complete, and we do not publish certification badges we have not earned. Email support@monroya.ai for procurement paperwork.

Need more detail for a vendor review? Read the security overview or email support@monroya.ai.