⚠ DRAFT — These documents are not yet reviewed by counsel.
Effective only when this banner is removed.
Privacy Policy
Effective: June 12, 2026 · Inoni LLC · v1.0-draft
1. What we collect
- Account info: email, name, tenant slug, billing identifier.
- Content you send us: emails you send to / CC / forward
to Murphy, files you upload, prompts you write.
- Generated content: Service-produced drafts, replies,
deliverables. Each is tagged with a license ID (mLIC-...) for provenance.
- Operational telemetry: request logs, latency, error rates,
LLM token counts per tenant for billing.
- Payment data: we do not store your card number; Stripe
handles card data. For crypto we store the NOWPayments invoice ID and
confirmation hash.
2. How we use it
- To deliver the Service (process your requests, produce outputs).
- To bill you correctly (token usage, tier, add-ons).
- To improve quality (anonymized aggregate analytics; see Section 4).
- To enforce our Terms and protect against abuse.
3. Who we share it with
- Payment processors: Stripe (cards) and NOWPayments (crypto).
- LLM providers: when you submit a prompt, the prompt may
be routed to a third-party LLM provider for processing. We use providers
with no-retention agreements (Together AI, DeepInfra, Anthropic).
- Validators (if you opt in): when you request a validator
attestation, the content you ask to validate is shared with the relevant
domain-expert validator in our network.
- Service vendors: infrastructure providers (Hetzner) bound
by data-processing agreements.
We do not sell your data. We do not use your content to train models.
4. Anonymized aggregate analytics
Inoni LLC may use de-identified, aggregated metrics (e.g. "median reply
length per industry") to improve the Service and produce industry reports.
Aggregated data cannot be reconnected to your identity.
5. Data retention
- Account & billing records: 7 years (tax compliance).
- Generated artifacts and license records: indefinite (license
verification is a permanent public record).
- Prompts & raw content: 90 days for active accounts, 30 days after
account closure.
- Operational logs: 90 days.
6. Your rights
You may request access, correction, export, or deletion of your data by
emailing legal@murphy.systems. Where law requires (GDPR,
CCPA), we respond within 30 days. Note that license records (Section 5) are
not deletable because they serve a public-interest verification function.
7. Security
We use TLS in transit, encrypted-at-rest databases on infrastructure
providers with SOC 2 compliance, key rotation, and role-based access. No
system is perfectly secure; we report material breaches per applicable law.
8. International transfers
Our infrastructure is in Germany and the United States. By using the
Service you consent to your data being processed in these jurisdictions.
For EU/UK users we rely on Standard Contractual Clauses where applicable.
9. Children
The Service is not for users under 16. We do not knowingly collect
data from children.
10. Changes
We will notify you by email at least 30 days before material changes
take effect.
11. Contact
Privacy questions: legal@murphy.systems