Privacy Policy
Last updated August 13, 2026. This describes how Monoma actually operates today.
Who this covers
This policy applies to usemonoma.com and the Monoma application, operated by the Monoma team (“Monoma,” “we,” “us”). It covers visitors to our public site and organizations that connect their tools to Monoma.
Data we access
When your organization connects Jira, GitHub, Confluence, or another supported tool, you authenticate through that tool's own identity provider and grant Monoma access scoped to your own permissions in that tool — never a shared service account with broader access than you individually have.
Depending on which tools are connected, this can include tickets, pull requests, commits, comments, documents, and the people and workflow states associated with them, limited to what the authenticating user can already see.
How we use it
- To build and maintain the relationship graph between your tickets, PRs, docs, and people, so a question can be answered with correlated context instead of a single tool's isolated view.
- To answer questions you or your teammates ask, scoped to what each person can individually see.
- To draft proposed follow-up actions (status updates, comments, workflow transitions) — none of which is executed without your explicit approval.
- To maintain an audit log of what was proposed, approved, and executed, and by whom.
What we don't do
- We don't access anything beyond what the connecting user is individually permitted to see.
- We don't write to a connected tool without a human approving that specific change first.
- We don't sell the data you connect, or use it to train models for anyone outside your organization.
Infrastructure and subprocessors
We use third-party infrastructure and hosting providers to run the service. These providers process data solely on our behalf, to operate Monoma — not for their own independent purposes. A current list of subprocessors is available on request.
Data retention
We retain connected data for as long as your organization's account is active and the corresponding integration remains connected. If you disconnect an integration or close your account, we work with you to remove the associated data within a reasonable period. Audit logs are retained longer, since their purpose is to provide a durable record of what actions were taken.
Your requests
To access, correct, export, or delete data associated with your account, or to ask any question about how your data is handled, email founders@usemonoma.com. We respond to every request personally.
Security
Access is scoped per-user, not per-organization — Monoma never operates through a single shared credential with broad access on your team's behalf. Every proposed action requires explicit approval before it's executed, and every executed action is logged with who triggered it, what changed, and when.
Changes to this policy
We'll update the date at the top of this page when this policy changes, and post material changes here before they take effect.
Contact
Questions about this policy: founders@usemonoma.com.
This page is a working draft maintained by the Monoma team and describes our actual data practices as of the date above. It has not yet been reviewed by outside counsel — if you're evaluating Monoma as part of a formal security or compliance review, email us and we'll walk through specifics directly.
See it on your own tools.
Book a demo — your actual Jira and GitHub, not a slide deck.