LEGAL
PRIVACY

Privacy Notice

What personal data Muninn collects, why, who else handles it, how long it is kept, and what you can do about it. Muninn is built so that we collect as little as we can and can read less than you might expect. This page says where that stops being true.

Last updated 14 September 2026

01

Who we are

This notice covers Muninn (the web app, API, MCP server and published pages at munn.is, muninn.bizat.co and their subdomains) and the company website at bizat.co.

They are run by Biz-Automation Co., Ltd., trading as Biz Automation, a company registered in Thailand under registration number 0105554085465, with its registered office at 20 Soi Phattanavet 7, Sukhumvit 71 Road, Vadhana, Bangkok 10110, Thailand. We are the controller of the personal data we collect about users of our product and site.

For anything about privacy, email [email protected] or write to us at the address above.

02

What we collect, and why

DataWhy we use itLegal basis
Account: email address, password (stored only as a salted PBKDF2 hash), verification status, account creation date.To create and secure your account, sign you in, and send the emails the service needs (verification, password reset).Contract
Your content: memories, tags, projects, skills, bundles, tasks, tables, artifacts, settings.To provide the service: store it, make it searchable by meaning, return it to you and the AI tools you connect.Contract
Credentials: API keys, recovery code material, session and sign-in tokens, authorisations you grant to AI clients over MCP.To let you and your connected tools access your account.Contract
Connections you choose: a Google Drive authorisation (limited to files Muninn creates) and, if you connect GitHub, the GitHub App installation identifier.To mirror your data into storage you own, only if you connect it.Contract
Teams and sharing: team names, members, the email address of someone you invite, your email shown in that invitation, and a public handle if you claim one.To share memories with a team and publish pages under your handle.Contract
Subscription and payments: plan, status, renewal date, the subscription, customer and transaction identifiers Paddle gives us, and a record of each payment event (amount, currency and outcome). We never receive your card details.To give paid accounts their paid features.Contract; legal obligation (accounting)
Technical data: IP address, request logs (time, address, path, status), browser type.To keep the service running and secure: rate limits, abuse and fraud prevention, debugging.Legitimate interests (keeping the service available and safe for all users)
Website analytics on bizat.co: pages viewed, clicks and scrolling, device and approximate location.To understand which pages are useful and improve the site.Consent
Messages: emails you send us.To answer you.Legitimate interests (responding to people who contact us)

We do not collect your name, and we do not sell personal data or use your content to train AI models. We do not build a profile of you from your content.

03

What we can and cannot read

Memory text, previews, settings, artifact titles, the tag dictionary and your Drive authorisation are encrypted at rest with AES-256-GCM, under a key that only your own credentials unlock. There is no master key that opens every account. The details are on the encryption page.

Some things are not protected that way, and you should know which:

  • Stored readable: your email address, tag names, project names, table titles and field names, team names, bundle node names, task status and dates, and timestamps.
  • Published artifacts are stored as a readable copy, because anyone with the link can open them.
  • While a mirror is connected, the server holds a separately protected copy of your key so scheduled pushes can run while you are away. Disconnecting the last mirror deletes it.
  • While a request is processed, your text exists unencrypted in memory, because computing the search embedding needs it. It is not written down unencrypted.
04

Who else handles your data

We use these service providers to run Muninn. Each processes data only to provide its service to us.

  • Cloudflare, Inc. (United States, global network): hosting, databases, search index, AI embedding computation, and request logs.
  • Resend (United States): sending account and team invitation emails.
  • Paddle (Paddle.com Market Limited, United Kingdom, and Paddle.com Inc., United States): our Merchant of Record. Paddle sells the paid plan to you, takes payment, manages the subscription, handles tax and invoicing, and processes refunds. Paddle collects your payment details and billing information directly and is an independent controller of that data under its own privacy notice.
  • Google LLC: Google Drive, only if you connect a Drive mirror. Google Analytics on bizat.co, and web fonts loaded by our pages.
  • GitHub, Inc.: only if you connect a GitHub mirror.
  • Microsoft Corporation: Microsoft Clarity analytics on bizat.co.
  • jsDelivr and cdnjs: public code libraries loaded by some app pages. They receive your IP address as any web request does.

We may also share data with professional advisers (legal, accounting, audit), with a buyer if the business is sold (under the same protections), and with authorities where the law requires it or to protect the rights and safety of users or others.

05

International transfers

We are based in Thailand, and our providers process data in the United States, the United Kingdom and on Cloudflare's worldwide network, so your data will be handled outside your own country. Where data protection law requires it, including Thailand's Personal Data Protection Act and the EU and UK GDPR, we rely on appropriate safeguards such as the European Commission's standard contractual clauses in our providers' data processing terms, or an adequacy decision.

06

How long we keep it

  • Your account and content: for as long as your account exists. When you delete your account, it is deleted from our systems straight away. Deleting a single item deletes it straight away too.
  • Mirrors: copies in your own Google Drive are yours, and we do not delete them when you leave. When you delete a memory, its Drive copy is moved to your Drive trash, which Google empties after 30 days.
  • Sessions: 7 days. Email verification links last 24 hours and password reset links 1 hour.
  • Rate-limit records containing IP addresses: 1 hour.
  • Request logs: about 7 days.
  • Subscription and payment records: kept as the record of payments for tax and accounting, including after the account is deleted.
  • Published artifacts: until you unpublish them, they expire, or you delete them.
  • A public handle: when you delete your account, the handle is detached from you, and the name itself stays reserved so it is never given to someone else. Otherwise a stranger could take over links you shared.
  • Emails to us: until the conversation is finished, or sooner if you ask.

When we no longer need data, we delete it or make it anonymous.

07

Your rights

Depending on where you live, you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • correct it if it is wrong;
  • have it deleted;
  • restrict or object to how we use it, including anything we do on the basis of legitimate interests;
  • receive it in a portable format;
  • withdraw consent at any time, where we rely on consent, without affecting what happened before.

Much of this you can do yourself. Read, correct and delete anything in the app. Export your data from the app at any time, on every plan. Delete your whole account from the app settings.

For anything else, email [email protected] from your account's address. We reply within one month, or tell you within that month if we need longer, as the law allows. You can also complain to a data protection authority: in Thailand the Personal Data Protection Committee, in the EU the authority in your country, in the UK the Information Commissioner's Office.

08

Security

We protect personal data with technical and organisational measures appropriate to the risk. These include encryption at rest for your content, encryption in transit (HTTPS only), password hashing, per-user key separation, rate limiting, isolated origins for published pages so they cannot reach your session, and access to production systems limited to the people who run the service. No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant authorities as the law requires.

09

Cookies and local storage

NameWhereTypePurpose and duration
__Host-muninn_sessionMuninn appEssentialKeeps you signed in. 7 days.
__Host-muninn_lk_*Muninn published pagesEssentialRemembers that you unlocked a password-protected artifact. 7 days.
_ga, _ga_*bizat.coAnalyticsGoogle Analytics: counts visits and pages. Up to 2 years.
_clck, _clsk and relatedbizat.coAnalyticsMicrosoft Clarity: how pages are used (clicks, scrolling). Up to 1 year.

The site and the app also use your browser's local storage for preferences such as light or dark theme and panel layout. That data stays in your browser.

Essential cookies are needed for the service to work and are always on. Analytics cookies are set only if you choose Accept in the banner shown on your first visit to bizat.co. Nothing from Google Analytics or Microsoft Clarity loads before that. If your browser sends a Global Privacy Control signal, we treat it as a refusal and do not ask.

You can change your choice at any time with Cookie settings at the bottom of any page on bizat.co. Withdrawing consent deletes the analytics cookies from your browser. Your choice is remembered in your browser's local storage. The Muninn app itself sets no analytics cookies, and these legal pages load no analytics at all.

10

Children

Muninn is not for anyone under 16, and we do not knowingly collect data from children. If you think a child has given us personal data, contact us and we will delete it.

11

Changes to this notice

We will update this notice when our practices change. The date at the top shows the latest version. If a change materially affects you, we will tell you by email or in the app before it takes effect.

12

Contact

Biz-Automation Co., Ltd.
20 Soi Phattanavet 7,
Sukhumvit 71 Road, Vadhana, Bangkok 10110, Thailand
Privacy and data requests: [email protected]