Skip to content

Privacy policy

Last updated August 14, 2026

This policy covers the monkeyllm.com website and the client portal it hosts. It does not cover software you self-host: a Station running on your own infrastructure sends us nothing, ever.

Who is responsible

MonkeyLLM is an open-source project published by its copyright holder, who is also the controller of the data described here. Questions and requests go to [email protected] and are answered by a person.

What we collect

Contact and enterprise forms: the name, email address, company, role, team size and message you type. We use them to answer you and to keep a record of the conversation.

Client portal: your email address, the company inferred from its domain, the company details you fill in, and the meetings, service orders and invoices attached to your account.

Analytics: first-party, anonymous page views. We store the path visited, the language, the referring page, UTM parameters when present, and a random visitor identifier generated in your browser. No cookie is set for analytics, no cross-site identifier is used, and no profile is built. If your browser sends a Do Not Track signal, nothing is sent at all.

What we deliberately do not collect

No third-party trackers and no advertising pixels run on this site.

We do not collect the content of your forests, your documents, your queries or your agents’ activity. Those live on infrastructure you control and never reach us.

Cookies

Two cookies exist, both strictly necessary, and both set only after you request a magic link: portal_token, an httpOnly session token used to authenticate you with our API, and portal_user, a readable cookie holding your id, email and name so the interface can greet you correctly.

Your light or dark theme preference is stored in your browser’s localStorage, not in a cookie, and is never sent to us.

Processors we use

Stripe processes payments. Card details are entered on Stripe’s own checkout and never reach our servers; we store only the identifiers Stripe returns.

Resend delivers transactional email: magic links and lead notifications.

Our servers are operated by the project, and access is restricted to its maintainers.

How long we keep it

Leads and portal records are kept while the commercial relationship is active and afterwards for as long as tax and contractual obligations require.

Analytics events are kept for reporting and are not linked to an identified person.

Your rights

You can ask for access to your data, its correction, a copy of it, or its deletion, and you can withdraw consent at any time. Write to [email protected]; we answer every request from a human.

Changes

Material changes to this policy are published on this page, with the date at the top updated accordingly.