modloom.

Last updated 4 October 2026

Privacy Policy

This policy explains what personal data Modloom collects when you use the website and service, why, who we share it with and what rights you have.

1. Who is responsible

The controller of your personal data is Jakub Krzyżanowski, an individual running an unregistered business activity in Poland. Contact for anything privacy-related: hello@modloom.dev.

2. What we collect and why

  • Account: your name, email address and profile image from GitHub or Discord, and the sign-in connection (tokens are stored encrypted). Used to run your account (contract).
  • Sessions and security: session tokens, IP address and browser user agent, rate-limit counters, and sign-in notices. Used to keep the service secure (legitimate interest).
  • Workspaces: workspace names, members and their roles, and the email addresses of people you invite.
  • Projects: your prompts, source files, attachments, agent history and checkpoints, Git bundles, build logs and built .jar files. Used to provide the service (contract).
  • Usage and billing: credits, build minutes and storage used, plan and subscription status, and the Stripe customer reference. Invoices and payment data are kept by Stripe.
  • Abuse screening: prompts are checked by an automated model for abuse. We store a flag with a confidence score when something is flagged, not the prompt itself. Repeated flags can lead to account suspension (legitimate interest in protecting the service).
  • Emails: a welcome email, plus usage-limit and new-sign-in notices that you can turn off in settings.
  • Product analytics: page views, page leaves, errors and key events (such as sign-up, starting a run, a finished build and hitting a limit), linked to your name and email. No prompts or file contents, no session recording and no advertising. Used to improve the product (legitimate interest).

We don't sell personal data and we don't use it for advertising or to train our own models.

3. Who we share data with

We use these service providers (processors) to run Modloom:

  • AI model providers via OpenRouter: receive your prompts, project files and attachments to generate responses. We request that providers don't retain or train on this data; each provider's own terms also apply.
  • Stripe: payments, subscriptions and invoices.
  • GitHub and Discord: sign-in. If you connect the GitHub App, we push your project code to the repositories you choose, with commits authored under your GitHub noreply address.
  • Cloudflare R2 and our hosting and database providers: store project files and run the service. Builds run in an isolated sandbox.
  • An email delivery provider: sends the emails above.
  • PostHog (EU region): product analytics, stored in the European Union and called through our own domain.

Product analytics stay in the EU. Some other providers are located outside the EU/EEA, mainly in the United States. Where that happens, transfers rely on the EU–US Data Privacy Framework or Standard Contractual Clauses. We may also disclose data where the law requires it.

4. Cookies and similar storage

  • Session cookie (essential): keeps you signed in, up to 7 days.
  • Draft cookie (essential): remembers a prompt you typed before signing in, for 24 hours.
  • Theme preference: your light or dark choice, stored in your browser.
  • Analytics identifier: PostHog sets an identifier in your browser so events can be tied to your account. Autocapture, session recording and heatmaps are off.

We don't use advertising cookies or third-party trackers. The footer loads a small status badge from status.modloom.dev.

5. How long we keep data

  • Account, workspace and project data: until you delete it, or the account.
  • Expired sessions, verification codes, rate-limit counters and draft prompts: removed automatically within minutes to hours of expiry.
  • Backups: deleted data can remain in backups for a limited time before they are overwritten.
  • Invoices and payment records: kept by us and Stripe as long as tax and accounting law requires (in Poland, generally 5 years).
  • Abuse flags: kept while needed to protect the service.

You can delete projects, attachments, GitHub connections and your whole account from the app, and export your data. Deleting your account removes your personal data and projects from our systems, and deletes or anonymises data held by our processors where we can, except what we must keep by law. Code already pushed to your own GitHub repositories stays there; remove it on GitHub.

6. Your rights

Under the GDPR you can ask for access to your data, correction, deletion, restriction, a portable copy, and you can object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time. Most of this you can do yourself in the app; for anything else email hello@modloom.dev and we will respond within one month.

You can also complain to the supervisory authority. In Poland that is the President of the Personal Data Protection Office (UODO), or the authority in your own EU country.

7. Security and children

We protect data with access controls, encryption of sign-in tokens, private storage, and isolated build sandboxes. No system is perfectly secure; we will notify you and the authorities where the law requires if a breach affects your data.

Modloom is not for people under 16, and we don't knowingly collect their data. If you think a child has an account, contact us and we will delete it.

8. Changes

We will update this policy when our practices change and show the new date above. For significant changes we will notify you in the app or by email. See also the Terms of Service.