Privacy Policy
Effective date: July 27, 2026 Last updated: July 27, 2026
This Privacy Policy describes how MicroAI LLC, a Wyoming limited liability company ("MicroAI", "we", "us"), operator of the Organ platform (the "Service"), collects, uses, and shares personal data. MicroAI is the data controller for personal data processed under this policy. For business data your organization submits to the Service, your organization is the controller and MicroAI acts as a processor on its behalf.
Contact: qipsagi@gmail.com · MicroAI LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA
1. Data We Collect
Account data. Name, email address, password (stored as a salted hash), profile image, and organization membership and role.
OAuth data. If you sign in or connect accounts via GitHub, GitLab, or Google, we receive and store OAuth tokens and provider account identifiers needed to operate the connection.
Connected resources and credentials. Credentials you choose to store so Agents can act on your behalf — for example repository access tokens, API keys, email account credentials, hosting, domain, and database credentials. These are encrypted at rest (AES-256-GCM), scoped to your tenant, and are not returned to the browser. Access to stored credentials is logged (accessor, action, IP address, timestamp).
Venture and business data. Content you or your Agents create in the Service: venture descriptions, goals, tasks, decisions, observations, generated content and assets, agent activity logs, and any performance figures recorded on a venture record (including legacy records created before the Service stopped offering performance tracking).
Billing data. Subscription plan, billing status, and Stripe customer and subscription identifiers. Payment card details are collected and processed by Stripe, not by us.
Waitlist data. Email, name, answers to qualification questions, referrer, user agent, UTM parameters, and a hashed (not raw) IP address.
Usage and device data. Product analytics events (via Mixpanel), error and diagnostic reports (via Sentry, with PII scrubbing applied before transmission), log data, and cookies described in Section 6.
2. How We Use Data
- Provide, operate, and secure the Service, including running Agents you configure and storing credentials you provide.
- Process payments and manage subscriptions, credits, and metered usage.
- Communicate with you about the Service (transactional email, escalations and approvals, waitlist status).
- Monitor, debug, and improve the Service (analytics, error tracking, performance).
- Enforce our Terms, prevent abuse, and comply with law.
We do not sell personal data. We do not use Your Content or credentials to train machine-learning models. Prompts and content sent to third-party model providers are governed by those providers' API terms (see Section 4).
3. Legal Bases (EEA/UK Users)
Where the GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (providing the Service); legitimate interests (security, analytics, service improvement, fraud prevention); consent (where required, e.g. non-essential cookies and marketing); and legal obligation (tax, accounting, lawful requests).
4. Sharing and Subprocessors
We share personal data only with service providers who process it on our instructions, with parties you direct us to share it with (e.g. the third-party services you connect), or as required by law. Current categories of subprocessors:
| Provider | Purpose |
|---|---|
| Amazon Web Services (AWS) | Hosting, container runtime, asset storage |
| Anthropic / OpenAI / OpenRouter | AI model inference (prompts and relevant context are sent to the provider serving your configured model; with BYOK, under your own provider agreement) |
| Stripe | Payments and billing |
| Mixpanel | Product analytics |
| Sentry | Error monitoring (PII-scrubbed) |
| Resend | Transactional email |
| Slack | Notifications you configure |
| GitHub / GitLab / platform-hosted repositories, Linear, X (Twitter) | Services you connect; data flows to them at your direction |
We may disclose data to comply with law, enforce our Terms, protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required).
5. International Transfers
We are based in the United States and process data there. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or the recipient's participation in a recognized adequacy framework.
6. Cookies and Analytics
We use: (a) strictly necessary cookies — authentication/session cookies and functional preferences (e.g. selected venture, locale); and (b) analytics — Mixpanel events and identifiers used to understand product usage. Where required by law (including the EEA/UK), non-essential cookies and analytics are used only with your consent, and you can withdraw consent at any time via the cookie settings in the Service. You can also control cookies through your browser.
7. Retention
We retain personal data for as long as your account is active and as needed for the purposes above. After account termination, Your Content is available for export for at least 30 days and then deleted or anonymized, except where retention is required for legal, tax, security, or dispute purposes. Credential access logs and billing records are retained per our legal obligations. Waitlist data is retained until you sign up, ask us to delete it, or 24 months after collection, whichever comes first.
8. Security
We use technical and organizational measures including encryption of stored credentials (AES-256-GCM), tenant isolation, access logging, transport encryption (TLS), and scoped, short-lived credential provisioning to agent containers. No method of transmission or storage is completely secure; we cannot guarantee absolute security. We will notify you and regulators of personal-data breaches as required by law.
9. Your Rights
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. EEA/UK users may lodge a complaint with their supervisory authority. To exercise rights, contact qipsagi@gmail.com; we will verify your identity and respond within the time required by law. We do not discriminate against you for exercising privacy rights.
10. Children
The Service is not directed to anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Changes
We may update this policy. Material changes will be notified via the Service or email before taking effect. The "Last updated" date reflects the latest revision.