Боварӣ ва ҳуқуқ

Privacy Policy

This policy explains what personal data Milly Lab collects, why it is processed, who else receives it, and how you control it. It applies to the Milly Lab web application, the Milly Lab iOS and Android apps, and the Milly Lab API. It is for anyone who uses Milly Lab or is considering it.

Ин ҳуҷҷат лоиҳаи баррасинашуда буда, дар интизори баррасии ҳуқуқист. Қиматҳое, ки бо «дар интизорӣ» қайд шудаанд, ҳанӯз ниҳоӣ карда мешаванд ва матн метавонад тағйир ёбад.

#Who we are

Milly Lab is operated by дар интизорӣ, registered in дар интизорӣ, with a registered address at дар интизорӣ.

For data-protection purposes the operator is the controller of the personal data described in this policy.

Data-protection contact: дар интизорӣ


#The short version

  • Milly Lab is an AI workspace. What you type into it is sent to third-party AI model providers so they can produce a response. Those providers are listed in the Subprocessor List.
  • If you connect a GitHub repository or Google Drive, Milly Lab can read files from it, and the contents of those files are also sent to AI model providers as context.
  • Milly Lab never writes to your repository or Drive on its own. Proposed changes are held aside and are written only when you press Apply.
  • Milly Lab does not sell personal data and does not use your content to train its own models.

#What data Milly Lab collects

Data you provide when you create an account

DataSourceWhy it is processed
Email addressYou, or your Google account if you sign in with GoogleAccount identity, sign-in, transactional email, account recovery
PasswordYou (stored only as a one-way hash, never in readable form)Authentication
Display nameYou, or your Google accountShowing who you are in the interface and to teammates
Profile picture URLYour Google account, if you sign in with GoogleDisplay only
Interface languageYouShowing the interface in your language
Field of work ("sphere")You, optionalOptional profile detail; not required to use Milly Lab

Content you submit to the service

Everything you send to Milly Lab in order to get a result:

  • Chat messages and conversation history, including the model used for each message.
  • Prompts for image, video, 3D and document generation, and the files those prompts produce.
  • Files you upload as attachments.
  • Voice recordings you make using voice input, which are converted to text.
  • Swarm Mind briefs, the intermediate work produced by each model, and the final deliverables.
  • Anything you write in Spaces, Teams, or a Council discussion.

Files from a connected workspace

This is described in full in "Connected workspaces" below, because it is the most sensitive category of data Milly Lab handles.

Billing and plan data

DataWhy it is processed
Your plan, subscription status and billing periodDetermining what you have access to
Prepaid balance and transaction historyMetering usage against your balance
Usage records — model used, tokens in, tokens out, cost, and whether it was charged to your plan allowance or your balance, linked to the conversationBilling accuracy, showing you your own usage, and fraud prevention

Milly Lab does not currently process card numbers, bank details or any payment instrument, because no payment gateway is connected yet. If a payment provider is added, this policy and the Subprocessor List will be updated before it takes effect.

Data collected automatically

  • Authentication tokens. After you sign in, your browser holds an access token (valid 60 minutes) and a refresh token (valid 30 days) in browser local storage. These identify you on every request.
  • A short-lived connection cookie. When you connect GitHub or Google Drive, Milly Lab sets a single-use cookie named connect_nonce, scoped to /api/connectors, marked HttpOnly and Secure. Its only purpose is to confirm that the account being connected is being connected by the same browser that started the request. It is consumed and discarded immediately afterwards. Milly Lab does not use advertising or tracking cookies.
  • Operational logs. Server logs recording requests, errors and timing.
  • IP address. Received by the hosting provider as an unavoidable part of serving a request.

Data Milly Lab does not collect

Milly Lab does not ask for and does not want government identifiers, health data, or financial account numbers. Do not put them into prompts. Content in prompts is transmitted to third-party model providers, and Milly Lab cannot retrieve it from them once sent.


#Connected workspaces — read this section carefully

Milly Lab can connect to a GitHub account or Google Drive so that Swarm Mind runs can read your files and propose changes to them. This gives Milly Lab access to material that is usually private, so the following is stated precisely.

What Milly Lab can read

GitHub. Milly Lab requests the OAuth scope repo.

This is important: repo is GitHub's scope for full read and write access to repository content. It is not limited to the single repository you pick inside Milly Lab. Once you grant it, the access token GitHub issues is technically capable of reading and writing every repository your GitHub account can access, including private ones and those belonging to organisations you are a member of.

Milly Lab restricts itself to the repository you select for a session, and rejects file paths that try to escape it. That is a restriction imposed by Milly Lab's own code, not a limit enforced by GitHub.

Google Drive. Milly Lab requests the OAuth scope https://www.googleapis.com/auth/drive.file. This scope is limited by Google: it grants access only to files that you specifically open with Milly Lab and files that Milly Lab itself creates. Milly Lab cannot see the rest of your Drive.

What Milly Lab does with those files

  1. During a Swarm Mind run, models can list directories and read file contents from the connected workspace.
  2. The contents of files that are read are sent to third-party AI model providers as context, in the same way your typed prompts are. If your repository contains secrets, credentials, personal data about other people, or material you are contractually forbidden to disclose, do not connect it. Review what is in a repository before connecting it.
  3. Read volume is capped — roughly 48 KB per file read and 300 entries per directory listing — so large files are truncated rather than transmitted in full. This is a performance and cost measure, not a privacy guarantee.

What Milly Lab does when it wants to change a file

Nothing is written to your repository or Drive during a run. Every proposed create, edit or delete is held in a staging area attached to that session. You see the complete list of proposed changes in a review panel.

A change reaches your real repository or Drive only when you press Apply. At that point you choose where it goes — the default branch, a new branch, or a newly created repository. If you discard the changes, or simply never apply them, nothing is written.

When applying to GitHub, Milly Lab checks that the file has not changed since it was read. If a teammate has committed to that file in the meantime, that file is reported as a conflict and left alone rather than overwritten.

Tokens, and what happens when you disconnect

The access and refresh tokens issued by GitHub and Google are stored in the Milly Lab database. They are encrypted at rest with Fernet symmetric encryption, using a key held in the server environment and not in the database. In production the application refuses to start unless this encryption key is configured, so encryption at rest does not depend on deployment configuration.

Disconnecting a workspace in Milly Lab removes the stored connection and its token.

Disconnecting in Milly Lab does not by itself revoke the authorisation on the provider's side. To revoke it completely:

  • GitHub — Settings → Applications → Authorized OAuth Apps → Milly Lab → Revoke.
  • Google — myaccount.google.com/permissions → Milly Lab → Remove access.

You should do this as well as disconnecting inside Milly Lab if you want the grant fully withdrawn.


PurposeLegal basis
Creating and running your accountPerformance of a contract
Sending your prompts and files to AI providers to produce the result you asked forPerformance of a contract
Metering usage and billingPerformance of a contract
Transactional email — verification, password reset, team invitationsPerformance of a contract
Keeping the service secure, preventing abuse and fraudLegitimate interests
Aggregate product analyticsLegitimate interests
Meeting legal and accounting obligationsLegal obligation
Marketing email, if any is sentConsent

Milly Lab does not carry out automated decision-making that produces legal or similarly significant effects about you.


#Who else receives your data

Milly Lab relies on third parties to operate. Each one receives only what it needs. The authoritative, maintained list — including processing locations and links to each provider's terms — is the Subprocessor List, which forms part of this policy.

In summary:

ProviderWhat it receives
Anthropic, OpenAI, Google, DeepSeek, xAIPrompts, conversation history, attachments and connected-workspace file contents, for the model you chose
fal.ai, Runway, MeshyImage, video and 3D generation prompts and any reference media
OpenAI (speech-to-text)Voice recordings made with voice input
TavilySearch queries, when web search is used for a message
E2BCode executed in the sandbox, when a run uses it
Cloudflare R2Generated and uploaded files
ResendYour email address and the contents of transactional email
RailwayHosting — all application data passes through it
GitHub, GoogleOnly where you have connected a workspace

Different model providers apply different data-retention and training policies to what they receive.

Milly Lab does not sell personal data and does not share it with advertisers.

Milly Lab may disclose data where legally required, or to establish or defend legal claims.


#Where data is processed

Milly Lab's application and database are hosted on Railway in дар интизорӣ. The AI providers above process data in the regions described in the Subprocessor List, which for most of them includes the United States.

If you are in the UK, EU, or another jurisdiction restricting international transfers, your data will be transferred outside that jurisdiction as an inherent part of using Milly Lab.


#How long data is kept

Milly Lab does not yet apply automatic retention limits. The table below describes what actually happens today, rather than a policy that is not enforced.

CategoryCurrent behaviour
Account recordKept until the account is deleted
Conversations, messages, swarm sessions, generated assetsKept indefinitely — there is no automatic deletion. Deleting a conversation in the interface removes it.
Usage and billing recordsKept indefinitely at present
Session event logsKept indefinitely at present
Connected-workspace tokensKept until you disconnect
Server logsDetermined by the hosting provider
Data held by AI providers after Milly Lab sends itGoverned by each provider, not by Milly Lab. See the Subprocessor List.

#Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict processing, and complain to a regulator.

How to exercise them today

Email дар интизорӣ. Requests are answered within дар интизорӣ.

What the product currently supports — stated honestly

  • Deleting individual conversations — supported in the interface.
  • Deleting your account — the current "delete account" action deactivates the account by marking it inactive. It does not erase your conversations, messages, generated assets, usage records, or connected-workspace tokens. Deactivation does take effect immediately for access: every authenticated request re-checks the account's active status, so existing sessions stop working at once. To have the underlying data removed as well, contact the address in this policy.
  • Exporting your data — there is no self-service export yet. To receive a copy of your data, contact the address in this policy.

#Security

What Milly Lab actually does:

  • Traffic to Milly Lab is served over HTTPS.
  • Passwords are stored as one-way hashes, never in readable form.
  • Sessions can be revoked. Signing out and changing your password invalidate tokens issued earlier, so a stolen token stops working.
  • Connected-workspace tokens are encrypted at rest.
  • Each user's data is scoped to their own account, and requests are checked against the authenticated user.
  • Changes proposed to a connected workspace are staged and require your explicit approval, so a model cannot alter your repository on its own.

Milly Lab does not hold a SOC 2 report, an ISO 27001 certificate, or any other third-party security certification, and does not claim compliance with any security standard.

To report a vulnerability, email дар интизорӣ.

Milly Lab will notify you and any relevant regulator of a personal-data breach where required.


#Children

Milly Lab is not intended for children. You must be at least дар интизорӣ years old to use it. Milly Lab does not knowingly collect data from children below that age. If you believe a child has created an account, contact the address above and it will be removed.


#Changes to this policy

This policy may change as Milly Lab changes. The current version is always available at https://m-lab.app/docs/privacy-policy.

Material changes — in particular any change to what is sent to AI providers, or the addition of a payment provider — will be notified by email to the address on your account before they take effect. дар интизорӣ


#Contact

дар интизорӣ дар интизорӣ