What this policy covers
This policy explains how the information you give us is stored, who can reach it, how long we keep it, and what you can ask us to do with it. It sits alongside the Privacy Policy, which explains what we collect and why.
Legal
How your information is stored, who can reach it, how long we keep it, and what you can ask us to do with it.
This policy explains how the information you give us is stored, who can reach it, how long we keep it, and what you can ask us to do with it. It sits alongside the Privacy Policy, which explains what we collect and why.
Your account, plans, saved answers, tool inputs and purchase records are held in a managed cloud database. Traffic between your browser and that database is encrypted in transit, and the stored data is encrypted at rest by the hosting provider.
Records are scoped to your account. Under normal operation, one member's account cannot read another member's data — the database enforces that rule, not just the app.
You can always see and edit your own data from your account pages.
A small number of administrators hold privileged credentials needed to operate the platform, investigate a support request or fix a fault. Those credentials can technically reach stored records, including account identity details. We use them only for operating, support and security purposes.
Aggregate, non-identifying figures are used for analytics and reporting. Individual goals, plans and financial figures are not shown in those reports.
Our hosting, payment and email providers process data on our behalf under their own terms, and their systems keep operational logs and backups.
When you ask Monet a question, your message and the context of the page you are on are sent to an external AI provider so an answer can be generated. Do not paste account numbers, passwords, government identifiers or other sensitive identifiers into the assistant.
The database is backed up by the hosting provider on a rolling schedule, so a deleted record may persist in a backup for a limited period before it ages out.
We keep account and content data for as long as your account is open. Records we are required to retain — such as purchase and receipt records, and signed policy agreements — are kept for the period required by law and for our own legal records, even after an account is closed.
Access rules are enforced at the database level, privileged keys are held server-side only and never shipped to your browser, and payment card details are handled entirely by our payment provider — we never see or store your card number.
No system is perfectly secure. If a breach affects your data, we will notify affected members and take the steps required of us.
You can ask for a copy of the data held about you, ask us to correct it, or ask us to close your account and delete your data, subject to the records we must legally keep. Requests are made through the contact details published on this site.
Read this with the Privacy Policy and the Content Protection Policy.