Modly

LEGAL

Privacy Policy

Last updated

This Privacy Policy describes how Code Particle, Inc., a California corporation with a business address of 10000 Washington Blvd, Fl. 6, Suite 7127, Culver City, CA 90232, doing business as Modly ("Modly," "we," "us"), collects, uses, shares, and protects personal information when you use the Modly service, website, applications, browser extension, and any related APIs or integrations we make available (collectively, the "Service").

This Privacy Policy is incorporated into our Terms of Use by reference. Capitalized terms not defined here have the meanings given in the Terms of Use.

In short. Modly's business is helping organizations answer questions from knowledge they already own. We collect what we need to run the Service, we don't sell your personal information, we don't use your Customer Content to train AI models, and we don't share your Customer Content for advertising.

1. Our Role: Controller and Processor

Modly acts in two different capacities, depending on the data:

  • As a controller, we decide how and why we process personal information for our own operational purposes: account creation, authentication, billing, service delivery, security, and Modly's website analytics.
  • As a processor, we handle personal information contained in Customer Content — the content you or your organization submit, upload, connect, or generate through the Service — on your behalf and on your instructions. If you are using the Service on behalf of an organization, that organization is the controller of Customer Content and is responsible for the lawful basis on which it is processed.

Where we act as a processor, our processing is governed by our Terms of Use and, where applicable, a separate Data Processing Agreement between us and your organization. Organizational customers may request a Data Processing Agreement by contacting legal@modly.one.

2. Personal Information We Collect

We collect the following categories of personal information. These map to the "categories of personal information" defined by California Consumer Privacy Act (Cal. Civ. Code § 1798.140):

2.1 Information you provide directly

  • Identifiers: name, email address, organization name, account username.
  • Authentication information: hashed credentials (via Amazon Cognito — we never store plaintext passwords) and multi-factor authentication data.
  • Payment information: billing name and address, and card metadata (last four digits, expiry, brand). Full card numbers are handled directly by Stripe and are never stored by Modly.
  • Support and correspondence: the content of any messages you send us at `legal@modly.one`, `privacy@modly.one`, or through in-product support.
  • Marketing and waitlist: email address, name, and organization if you sign up for the waitlist, request a demo, or subscribe to marketing communications.

2.2 Information generated when you use the Service

  • Customer Content: files you upload, prompts you submit, content indexed from connected third-party sources (for example, Slack, Jira, Confluence, GitHub, Google Drive, Salesforce, Bitbucket), and AI outputs generated in response to your prompts. Customer Content may include personal information about you, your colleagues, or third parties. We process Customer Content only to provide the Service to you and your organization.
  • Usage and query metadata: which user asked a question, when, cost/token counts, latency, error rates, and Channel used. This metadata does not include the content of the query.
  • Security and audit logs: authentication events, IP addresses, User-Agent strings, session identifiers, and organization/user identifiers associated with security-relevant events.
  • Device and technical information: browser type and version, operating system, screen size, referrer URL, and cookie identifiers.

2.3 Information collected automatically

  • Cookies and similar technologies: as described in Section 8.
  • Analytics data: page views and interaction data on the Modly website, collected via Google Analytics 4 only after you consent (or where we treat you as opted-in based on your jurisdiction — see Section 8).

2.4 Information from third-party sources

  • Third-party identity providers: if you sign in with Google, we receive basic profile information (name, email) from Google.
  • Connected data sources: when you or your Admin connects a third-party source (Slack, Jira, etc.), we access, index, and retrieve content and metadata from that source using your credentials, and only content that the querying user is already permitted to see.
  • Payment provider (Stripe): transaction status, invoice history, and dispute information related to your subscription.

Sources. The categories of sources from which we collect personal information are: (a) directly from you or an administrator of your organization; (b) automatically as you use the Service; (c) from third-party services and identity providers you or your organization connects to the Service; and (d) from our service providers (for example, Stripe).

3. How We Use Personal Information

We use personal information for the following purposes. For users in the EU/UK/EEA, the lawful basis under the GDPR/UK GDPR is indicated in brackets.

  • To provide the Service. Creating and maintaining your account; authenticating you; enabling connections to third-party sources; processing prompts; generating and returning cited answers; running channels (Slack, Telegram, Discord, browser extension). *[Contract, Art. 6(1)(b).]*
  • To bill you and manage subscriptions. Processing payments through Stripe; sending invoices; enforcing auto-renewal, free-trial reminders, and renewal reminders required by California Business and Professions Code Section 17602; recovering unpaid amounts. *[Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c).]*
  • To secure the Service. Detecting and responding to unauthorized access, abuse, fraud, and service disruption; maintaining audit logs; responding to security incidents. *[Legitimate interests, Art. 6(1)(f) — securing the Service for all users; legal obligation where applicable.]*
  • To communicate with you. Sending transactional emails (confirmation, security, billing, product notices) and — with your consent — marketing emails and product updates. *[Contract; legitimate interests; consent for marketing, Art. 6(1)(a).]*
  • To improve the Service (aggregate only). Generating anonymized, aggregated statistics from usage patterns to improve reliability, performance, and features. We do not use Customer Content to train, fine-tune, or otherwise improve AI models — Modly's own, third-party, or self-hosted. See Section 5. *[Legitimate interests, Art. 6(1)(f).]*
  • To comply with law. Responding to lawful requests from courts, government agencies, and law enforcement; complying with tax, accounting, and other legal obligations. *[Legal obligation, Art. 6(1)(c).]*

We do not use personal information for automated decision-making that produces legal or similarly significant effects on you.

4. How We Share Personal Information

We share personal information with the following categories of recipients:

  • Our subprocessors (Section 6), acting on our instructions to help us provide the Service.
  • Your organization, if you are using the Service under an organizational account: your administrators can access account, usage, and Customer Content associated with your use of the Service.
  • Third-party sources you connect, limited to what is technically required to authenticate and retrieve content on your behalf.
  • AI providers used to answer your queries — see Section 5.
  • Successors in interest in the event of a merger, acquisition, reorganization, or sale of all or substantially all of our assets, subject to this Privacy Policy or a materially equivalent successor policy.
  • Law enforcement, courts, and regulators where required by law or where we believe in good faith it is necessary to protect our rights, the safety of users, or the security of the Service.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). If this changes, we will update this Privacy Policy and provide the opt-out mechanism required by California law.

We do not currently use marketing or advertising cookies or pixels. If we add them in the future, we will update this Privacy Policy and, where required by law, obtain your fresh consent before they load.

5. AI Providers and Customer Content

Modly's own systems — including our servers, data stores, employees, contractors, observability tools, logging pipelines, and internal support workflows — do not use Customer Content to train, fine-tune, or otherwise improve any AI model.

Default AI provider routing. For default AI models provided through the Service, Modly routes Customer Content only through AI providers whose published API terms disable training on customer inputs, and only via zero-retention or opt-out endpoints where offered. The current list of AI providers used for default routing is included in the subprocessor table in Section 6 below. When we add or remove a default AI provider, we update the subprocessor table and the "Last Updated" date at the top of this Privacy Policy. If a provider changes its terms in a way that conflicts with Modly's routing commitment, we remove that provider from default routing until the issue is resolved or a compliant alternative is in place.

BYOK and BYOM. If you configure a bring-your-own-key ("BYOK") or bring-your-own-model ("BYOM") integration, you select the third-party provider or self-hosted system, you agree to that provider's terms, and that provider handles your Customer Content according to your agreement with them. Modly is not a party to that relationship and makes no representations about the third party's practices.

6. Subprocessors

We use the following subprocessors to help us provide the Service. We select subprocessors that offer appropriate confidentiality, security, and data-protection commitments, and we engage them under terms consistent with our obligations under this Privacy Policy where required by applicable law.

  • Amazon Web Services (AWS) — Cloud compute (ECS), authentication (Cognito), primary database (RDS Postgres), file storage (S3). United States
  • DigitalOcean — Cloud infrastructure for AI orchestration and model serving. United States
  • RunPod — GPU compute for Modly-hosted AI models. United States
  • Vercel — Website and application hosting, content delivery. United States
  • Sanity — Content management for the Modly website. United States / global
  • Stripe — Payment processing and billing. United States
  • Gmail SMTP (Google) — Transactional email delivery. United States
  • Temporal — Workflow orchestration for data ingestion. United States
  • LiteLLM (self-hosted proxy) — Proxy layer for AI provider routing. Modly infrastructure
  • OpenAI — Default AI provider (zero-retention endpoints). United States
  • Anthropic — Default AI provider (zero-retention endpoints). United States
  • Google (Gemini API) — Default AI provider (opt-out endpoints). United States
  • Google Analytics 4 — Website analytics (post-consent only). United States
  • New Relic — Application performance monitoring. United States

To receive notifications when we add or remove a subprocessor, please contact privacy@modly.one.

7. International Data Transfers

Modly's infrastructure is currently located in the United States. If you access the Service from outside the United States, your personal information will be transferred to, stored, and processed in the United States and other countries where our subprocessors operate.

Where required by law, we rely on Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner's Office to lawfully transfer personal information from the EU/EEA and the United Kingdom to the United States. You may request a copy of the relevant transfer safeguards by contacting privacy@modly.one.

Modly does not currently target or actively offer the Service to individuals located in the EU/EEA. If we begin to do so, we will designate an EU representative under Article 27 of the GDPR before that offering begins and update this Privacy Policy.

8. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Service, remember your preferences, secure your session, and (with your consent) understand how the website is used.

Categories of cookies we use:

  • Strictly necessary — Session authentication, load balancing, security, storing your cookie-consent choice. No — required to operate the Service
  • Analytics — Google Analytics 4 to understand how our website is used. Yes
  • Performance monitoring — New Relic browser agent to measure page and application performance. Yes

We do not currently use marketing or advertising cookies. If we add them in the future, we will update this Privacy Policy and obtain your consent before they load where consent is required.

How consent works.

  • Users in the EU, EEA, United Kingdom, and Switzerland: non-essential cookies are blocked by default until you accept them through our cookie banner.
  • Users elsewhere: non-essential cookies may load by default, and you can reject or manage them through our cookie banner or your account settings.
  • Global Privacy Control (GPC): if your browser sends a GPC signal, we treat it as a request to opt out of non-essential cookies and similar tracking technologies, regardless of your location. For California residents, we also treat a GPC signal as an opt-out of "sale" and "sharing" of personal information as those terms are defined under the CCPA / CPRA.

You can manage your cookie preferences at any time through the cookie banner or by contacting privacy@modly.one. Rejecting non-essential cookies will not affect your ability to use the Service; some features (for example, remembering interface preferences) may be limited.

Cookie consent choices are retained for 12 months, after which the banner will re-appear.

9. Data Retention

We retain personal information only as long as we need it for the purposes described in this Privacy Policy or as required by applicable law. Specific retention periods:

  • Account data (name, email, org membership) — While your account is active, then deleted or anonymized within 30 days of account deletion
  • Billing and tax records7 years after the transaction (required by US tax law)
  • Customer Content — While your account is active, then deleted or anonymized within 60 days after account termination, subject to the exceptions in our Terms of Use
  • Query metadata (who asked what, when, cost — not content)13 months
  • Security and audit logs12 months
  • Support tickets and correspondence3 years
  • Marketing and waitlist emails — Until you unsubscribe; contact form submissions retained 2 years

We may retain personal information for longer where required by law, to enforce our Terms of Use, or to defend against legal claims. Backups are deleted or anonymized in the ordinary course.

10. Your Rights

Depending on where you live, you may have some or all of the following rights over your personal information:

  • Access: know what personal information we hold about you and receive a copy.
  • Correction: ask us to correct inaccurate or incomplete personal information.
  • Deletion (also called "right to be forgotten"): ask us to delete personal information we hold about you.
  • Portability: receive your personal information in a structured, commonly-used, machine-readable format.
  • Restriction of processing: ask us to pause processing while we address a concern.
  • Objection: object to processing based on legitimate interests, including direct marketing.
  • Withdraw consent: where our processing relies on your consent, you can withdraw it at any time without affecting processing that already occurred.
  • Opt out of "sale" or "sharing" of personal information (California and other US state laws) — although as noted in Section 4, we do not sell personal information and do not share it for cross-context behavioral advertising.
  • Right to non-discrimination: we will not discriminate against you for exercising any of these rights.
  • Right to lodge a complaint with your local supervisory authority — for EU/UK residents, this is your national Data Protection Authority.

How to exercise your rights. Send a written request to privacy@modly.one with your name, the email address associated with your account, and the right you wish to exercise.

Response timing depends on the law that applies to your request:

  • EU / EEA / United Kingdom (GDPR / UK GDPR): we will respond without undue delay, and in any event within one month of receipt of a verified request. Where the request is complex or you have made a number of requests, we may extend the response period by up to two additional months, and we will notify you of the extension and the reason within the initial one-month period.
  • California (CCPA / CPRA):
    • For verified requests to know, delete, or correct personal information, we will respond within 45 days of receipt. Where reasonably necessary, we may extend by up to 45 additional days, and we will notify you of the extension and the reason.
    • For requests to opt out of the "sale" or "sharing" of personal information, we will act as soon as feasibly possible, and in any event within 15 business days of receipt, consistent with California Privacy Protection Agency guidance.
  • Other jurisdictions: we will respond in the manner and time required by applicable law, and in any event within 30 days as our default commitment where no shorter statutory period applies.

To protect your personal information, we may need to verify your identity before we can respond. If we cannot verify your identity, we will explain what additional information we need and how you can provide it.

You may also authorize an agent to submit a request on your behalf; the agent must provide written authorization and, if requested, we may still verify your identity directly.

11. Automated Decision-Making

Modly generates AI answers to your questions using large language models. These outputs are informational; humans decide what to do with them. Modly does not make automated decisions about you that produce legal effects concerning you or that similarly significantly affect you within the meaning of GDPR Article 22.

12. Children's Privacy

The Service is intended for users 18 years of age or older. Modly does not knowingly collect personal information from anyone under 18. If you believe we have collected personal information from a person under 18, please contact privacy@modly.one and we will delete it.

13. Data Security

We implement technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, loss, or destruction. These include:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Password hashing via Amazon Cognito (we never store plaintext passwords).
  • Role-based access controls and the principle of least privilege for employee access to Customer Content.
  • Regular security monitoring, logging, and vulnerability management.
  • Contractual security obligations on subprocessors.

No security measure is perfect. If you believe your account has been compromised, contact privacy@modly.one immediately.

14. Data Breach Notification

If we become aware of a personal data breach — a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal information — our notification obligations depend on the law that applies.

Notice to supervisory authorities. Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, in accordance with Article 33 of the GDPR / UK GDPR. We will notify other regulators as required by other applicable laws (including US state breach-notification statutes).

Notice to affected users. Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, we will communicate the breach to the affected users without undue delay, in accordance with Article 34 of the GDPR / UK GDPR. Under other applicable laws, we will notify affected users in the manner and time required by law.

15. Do Not Sell or Share My Personal Information (California)

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), California residents have a right to opt out of the "sale" of their personal information and of the "sharing" of their personal information for cross-context behavioral advertising.

Modly does not sell personal information and does not share personal information for cross-context behavioral advertising. If this changes, we will update this Privacy Policy and provide a "Do Not Sell or Share My Personal Information" link and opt-out mechanism as required by law.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will post the updated version and change the "Last Updated" date at the top.

For material changes — including changes to the categories of personal information we collect, the purposes for which we use it, the categories of recipients, retention periods, or your rights — we will provide at least 30 days' notice by email to the address associated with your account (or, for organizational accounts, to the primary Admin) before the change takes effect.

Non-material updates take effect on posting. Your use of the Service after an update takes effect is subject to the updated Privacy Policy.

17. Contact Us

For questions about this Privacy Policy or to exercise your rights:

  • Email: privacy@modly.one
  • Postal mail: Code Particle, Inc., 10000 Washington Blvd, Fl. 6, Suite 7127, Culver City, CA 90232, Attention: Privacy

For questions about our Terms of Use or other legal matters, contact legal@modly.one.

Modly does not currently have a Data Protection Officer or an EU representative. We will designate an EU representative under Article 27 of the GDPR before actively offering the Service to individuals in the EU/EEA and update this Privacy Policy at that time.

Privacy Policy · Modly