Боварӣ ва ҳуқуқ
Privacy Policy
This policy explains what personal data Milly Lab collects, why it is processed, who else receives it, and how you control it. It applies to the Milly Lab web application, the Milly Lab iOS and Android apps, and the Milly Lab API. It is for anyone who uses Milly Lab or is considering it.
#Who we are
Milly Lab is operated by дар интизорӣ, registered in
дар интизорӣ, with a registered address at
дар интизорӣ.
For data-protection purposes the operator is the controller of the personal data described in this policy.
Data-protection contact: дар интизорӣ
#The short version
- Milly Lab is an AI workspace. What you type into it is sent to third-party AI model providers so they can produce a response. Those providers are listed in the Subprocessor List.
- If you connect a GitHub repository or Google Drive, Milly Lab can read files from it, and the contents of those files are also sent to AI model providers as context.
- Milly Lab never writes to your repository or Drive on its own. Proposed changes are held aside and are written only when you press Apply.
- Milly Lab does not sell personal data and does not use your content to train its own models.
#What data Milly Lab collects
Data you provide when you create an account
| Data | Source | Why it is processed |
|---|---|---|
| Email address | You, or your Google account if you sign in with Google | Account identity, sign-in, transactional email, account recovery |
| Password | You (stored only as a one-way hash, never in readable form) | Authentication |
| Display name | You, or your Google account | Showing who you are in the interface and to teammates |
| Profile picture URL | Your Google account, if you sign in with Google | Display only |
| Interface language | You | Showing the interface in your language |
| Field of work ("sphere") | You, optional | Optional profile detail; not required to use Milly Lab |
Content you submit to the service
Everything you send to Milly Lab in order to get a result:
- Chat messages and conversation history, including the model used for each message.
- Prompts for image, video, 3D and document generation, and the files those prompts produce.
- Files you upload as attachments.
- Voice recordings you make using voice input, which are converted to text.
- Swarm Mind briefs, the intermediate work produced by each model, and the final deliverables.
- Anything you write in Spaces, Teams, or a Council discussion.
Files from a connected workspace
This is described in full in "Connected workspaces" below, because it is the most sensitive category of data Milly Lab handles.
Billing and plan data
| Data | Why it is processed |
|---|---|
| Your plan, subscription status and billing period | Determining what you have access to |
| Prepaid balance and transaction history | Metering usage against your balance |
| Usage records — model used, tokens in, tokens out, cost, and whether it was charged to your plan allowance or your balance, linked to the conversation | Billing accuracy, showing you your own usage, and fraud prevention |
Milly Lab does not currently process card numbers, bank details or any payment instrument, because no payment gateway is connected yet. If a payment provider is added, this policy and the Subprocessor List will be updated before it takes effect.
Data collected automatically
- Authentication tokens. After you sign in, your browser holds an access token (valid 60 minutes) and a refresh token (valid 30 days) in browser local storage. These identify you on every request.
- A short-lived connection cookie. When you connect GitHub or Google Drive, Milly Lab sets a
single-use cookie named
connect_nonce, scoped to/api/connectors, markedHttpOnlyandSecure. Its only purpose is to confirm that the account being connected is being connected by the same browser that started the request. It is consumed and discarded immediately afterwards. Milly Lab does not use advertising or tracking cookies. - Operational logs. Server logs recording requests, errors and timing.
- IP address. Received by the hosting provider as an unavoidable part of serving a request.
Data Milly Lab does not collect
Milly Lab does not ask for and does not want government identifiers, health data, or financial account numbers. Do not put them into prompts. Content in prompts is transmitted to third-party model providers, and Milly Lab cannot retrieve it from them once sent.
#Connected workspaces — read this section carefully
Milly Lab can connect to a GitHub account or Google Drive so that Swarm Mind runs can read your files and propose changes to them. This gives Milly Lab access to material that is usually private, so the following is stated precisely.
What Milly Lab can read
GitHub. Milly Lab requests the OAuth scope repo.
This is important:
repois GitHub's scope for full read and write access to repository content. It is not limited to the single repository you pick inside Milly Lab. Once you grant it, the access token GitHub issues is technically capable of reading and writing every repository your GitHub account can access, including private ones and those belonging to organisations you are a member of.Milly Lab restricts itself to the repository you select for a session, and rejects file paths that try to escape it. That is a restriction imposed by Milly Lab's own code, not a limit enforced by GitHub.
Google Drive. Milly Lab requests the OAuth scope
https://www.googleapis.com/auth/drive.file. This scope is limited by Google: it grants access
only to files that you specifically open with Milly Lab and files that Milly Lab itself creates. Milly Lab
cannot see the rest of your Drive.
What Milly Lab does with those files
- During a Swarm Mind run, models can list directories and read file contents from the connected workspace.
- The contents of files that are read are sent to third-party AI model providers as context, in the same way your typed prompts are. If your repository contains secrets, credentials, personal data about other people, or material you are contractually forbidden to disclose, do not connect it. Review what is in a repository before connecting it.
- Read volume is capped — roughly 48 KB per file read and 300 entries per directory listing — so large files are truncated rather than transmitted in full. This is a performance and cost measure, not a privacy guarantee.
What Milly Lab does when it wants to change a file
Nothing is written to your repository or Drive during a run. Every proposed create, edit or delete is held in a staging area attached to that session. You see the complete list of proposed changes in a review panel.
A change reaches your real repository or Drive only when you press Apply. At that point you choose where it goes — the default branch, a new branch, or a newly created repository. If you discard the changes, or simply never apply them, nothing is written.
When applying to GitHub, Milly Lab checks that the file has not changed since it was read. If a teammate has committed to that file in the meantime, that file is reported as a conflict and left alone rather than overwritten.
Tokens, and what happens when you disconnect
The access and refresh tokens issued by GitHub and Google are stored in the Milly Lab database. They are encrypted at rest with Fernet symmetric encryption, using a key held in the server environment and not in the database. In production the application refuses to start unless this encryption key is configured, so encryption at rest does not depend on deployment configuration.
Disconnecting a workspace in Milly Lab removes the stored connection and its token.
Disconnecting in Milly Lab does not by itself revoke the authorisation on the provider's side. To revoke it completely:
- GitHub — Settings → Applications → Authorized OAuth Apps → Milly Lab → Revoke.
- Google — myaccount.google.com/permissions → Milly Lab → Remove access.
You should do this as well as disconnecting inside Milly Lab if you want the grant fully withdrawn.
#Why Milly Lab processes your data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account | Performance of a contract |
| Sending your prompts and files to AI providers to produce the result you asked for | Performance of a contract |
| Metering usage and billing | Performance of a contract |
| Transactional email — verification, password reset, team invitations | Performance of a contract |
| Keeping the service secure, preventing abuse and fraud | Legitimate interests |
| Aggregate product analytics | Legitimate interests |
| Meeting legal and accounting obligations | Legal obligation |
| Marketing email, if any is sent | Consent |
Milly Lab does not carry out automated decision-making that produces legal or similarly significant effects about you.
#Who else receives your data
Milly Lab relies on third parties to operate. Each one receives only what it needs. The authoritative, maintained list — including processing locations and links to each provider's terms — is the Subprocessor List, which forms part of this policy.
In summary:
| Provider | What it receives |
|---|---|
| Anthropic, OpenAI, Google, DeepSeek, xAI | Prompts, conversation history, attachments and connected-workspace file contents, for the model you chose |
| fal.ai, Runway, Meshy | Image, video and 3D generation prompts and any reference media |
| OpenAI (speech-to-text) | Voice recordings made with voice input |
| Tavily | Search queries, when web search is used for a message |
| E2B | Code executed in the sandbox, when a run uses it |
| Cloudflare R2 | Generated and uploaded files |
| Resend | Your email address and the contents of transactional email |
| Railway | Hosting — all application data passes through it |
| GitHub, Google | Only where you have connected a workspace |
Different model providers apply different data-retention and training policies to what they receive.
Milly Lab does not sell personal data and does not share it with advertisers.
Milly Lab may disclose data where legally required, or to establish or defend legal claims.
#Where data is processed
Milly Lab's application and database are hosted on Railway in дар интизорӣ. The AI providers above process data in the regions
described in the Subprocessor List, which for most of them includes the United States.
If you are in the UK, EU, or another jurisdiction restricting international transfers, your data will be transferred outside that jurisdiction as an inherent part of using Milly Lab.
#How long data is kept
Milly Lab does not yet apply automatic retention limits. The table below describes what actually happens today, rather than a policy that is not enforced.
| Category | Current behaviour |
|---|---|
| Account record | Kept until the account is deleted |
| Conversations, messages, swarm sessions, generated assets | Kept indefinitely — there is no automatic deletion. Deleting a conversation in the interface removes it. |
| Usage and billing records | Kept indefinitely at present |
| Session event logs | Kept indefinitely at present |
| Connected-workspace tokens | Kept until you disconnect |
| Server logs | Determined by the hosting provider |
| Data held by AI providers after Milly Lab sends it | Governed by each provider, not by Milly Lab. See the Subprocessor List. |
#Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict processing, and complain to a regulator.
How to exercise them today
Email дар интизорӣ. Requests are answered within
дар интизорӣ.
What the product currently supports — stated honestly
- Deleting individual conversations — supported in the interface.
- Deleting your account — the current "delete account" action deactivates the account by marking it inactive. It does not erase your conversations, messages, generated assets, usage records, or connected-workspace tokens. Deactivation does take effect immediately for access: every authenticated request re-checks the account's active status, so existing sessions stop working at once. To have the underlying data removed as well, contact the address in this policy.
- Exporting your data — there is no self-service export yet. To receive a copy of your data, contact the address in this policy.
#Security
What Milly Lab actually does:
- Traffic to Milly Lab is served over HTTPS.
- Passwords are stored as one-way hashes, never in readable form.
- Sessions can be revoked. Signing out and changing your password invalidate tokens issued earlier, so a stolen token stops working.
- Connected-workspace tokens are encrypted at rest.
- Each user's data is scoped to their own account, and requests are checked against the authenticated user.
- Changes proposed to a connected workspace are staged and require your explicit approval, so a model cannot alter your repository on its own.
Milly Lab does not hold a SOC 2 report, an ISO 27001 certificate, or any other third-party security certification, and does not claim compliance with any security standard.
To report a vulnerability, email дар интизорӣ.
Milly Lab will notify you and any relevant regulator of a personal-data breach where required.
#Children
Milly Lab is not intended for children. You must be at least дар интизорӣ years old to use it. Milly Lab does not knowingly
collect data from children below that age. If you believe a child has created an account, contact
the address above and it will be removed.
#Changes to this policy
This policy may change as Milly Lab changes. The current version is always available at https://m-lab.app/docs/privacy-policy.
Material changes — in particular any change to what is sent to AI providers, or the addition of a
payment provider — will be notified by email to the address on your account before they take
effect. дар интизорӣ
#Contact
дар интизорӣ
дар интизорӣ