MonosSign in

Privacy Policy

Effective Date: August 27, 2026

Service: Monos, a product operated by Formed Goods LLC, a Washington limited liability company

Privacy contact: hello@runmonos.com

1. Who We Are, and What This Policy Covers

Monos is a product of Formed Goods LLC, a Washington limited liability company ("Formed Goods," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and protect information in connection with the Monos website and software service (together, the "Service").

"Monos" is the software. Formed Goods LLC is the company behind it, and the legal person responsible under this Policy.

It covers two different relationships, and the difference decides who you should contact:

  • Account Data — information about you as a person who is invited to, registers for, or uses the Service: your name, email address, avatar, sign-in method, and login and usage activity. Formed Goods LLC is the controller of Account Data, and this Policy describes our own practices.
  • Customer Data — the operational information a business enters into its Workspace: materials, formulas, suppliers, costs, batches, orders, documents, and, where applicable, personal information about that business's own customers and contacts. For personal information within Customer Data, Formed Goods LLC acts only as a processor / service provider on the Workspace's instructions. Our obligations there are governed by a Data Processing Addendum, available on request to hello@runmonos.com. If you are a customer of a business that uses Monos and you have a question about the information it holds about you, please contact that business directly.

2. What We Collect

2.1 Account and Workspace Administration Information

What: your name, email address, avatar image, the sign-in method on your account, workspace names, workspace membership and roles, and the invitation record that let you create an account. Source: you, and the person who invited you. Purpose: to create and secure your account, to place you in the right workspace, and to contact you about the Service. Shared with: our hosting and database providers (Section 4), and our transactional email provider when we send you an invitation. Retained: while your account exists — see Section 6.

2.2 Customer Data Entered Into a Workspace

What: materials, suppliers, formulas and formula versions, products, manufacturing batches and their records, inventory, locations, costs, purchase orders, expenses, tasks, notes, and standard operating procedures. Source: you and your workspace members, and any integration you connect. Purpose: to provide the Service to that workspace. Shared with: our hosting and database providers; an AI provider when a workspace member invokes an AI Feature on it. Retained: while the workspace exists — see Section 6.

2.3 Your Own Customers' Contact and Order Information

What: names, email addresses, phone numbers, order history and order values, and anything else a workspace member records in a free-text field about a contact. Source: entered by workspace members, or synced from a connected sales channel. Purpose: to provide the Service to that workspace. We are a processor for this category. Shared with: the same providers as Section 2.2. Retained: while the workspace exists, or until the workspace deletes the record.

2.4 Uploaded Documents and Images

What: files a workspace member uploads — certificates of analysis, invoices, formula sheets, product and batch photographs, screenshots attached to a bug report. Source: you. Purpose: to store them against the record you attached them to, and — when you ask for it — to read them with an AI Feature. Shared with: our storage provider; an AI provider when you invoke a reading or transcription feature on the file. Retained: until deleted from the workspace — see Section 6.

2.5 AI Prompts, Attachments, Context and Output

What: the question you ask, the records you attach to it, the workspace data the Service retrieves to answer it, and the model's response. We also record, per request, the workspace, the person who made it, the feature, the model, and the token counts. Source: you, and your workspace's own records. Purpose: to produce the answer, to keep your conversation history, to detect abuse, and to understand what the Service costs to run. These records are an internal cost instrument; nothing in them is billed to you. Shared with: the AI provider serving the request (Section 4.2). Retained: a conversation stays in your workspace until you delete it, and it goes when the workspace goes; the per-request usage counts are kept as operating records.

2.6 Integration Data

What: whatever the service you connect returns under the permissions you grant — for example orders, products and customers from a sales channel; calendar events; advertising performance figures, public comments on advertisements, and aggregate audience distributions; email campaign names and send dates; product reviews including the reviewer's name and email address where the review platform supplies them. Source: the third-party service, at your direction. Purpose: to display and use that information within your workspace. Shared with: our hosting and database providers. Retained: while the workspace exists, or until you disconnect the integration and ask us to remove what it brought in.

2.7 Technical, Security and Server-Log Information

What: IP address, browser and device information, requested URLs, timestamps and response status, collected by our hosting provider as ordinary server logs; and error reports from our error-monitoring provider, which record the page, the browser, and the fault. Source: collected automatically. Purpose: to operate and secure the Service, to detect and diagnose faults, and to detect abuse. Shared with: our hosting provider and our error-monitoring provider. Our error monitoring is configured not to transmit request bodies, cookies, signed-in user identities, IP addresses, or session recordings. Retained: by those providers on their own schedules — see Section 6.

2.8 Support, Feedback and Suggestions

What: messages you send us, bug reports, feature requests, ingredient suggestions, and anything you attach to them. Source: you. Purpose: to answer you and to improve the Service. Note: feature requests and ingredient suggestions are posted to a shared board that every workspace can see and vote on. Do not put confidential information in one. Bug reports are not shared — they are visible only to their author and to us, because that is where people paste their own data. Retained: as operating records.

2.9 Cookies, Authentication and Browser Storage

Covered in Section 10.

3. How We Use Information

  • To provide, operate, and maintain the Service, including workspace isolation, formula versioning, inventory calculation, and reporting.
  • To create accounts, authenticate sign-in, and send invitations.
  • To provide AI Features, by transmitting the relevant content to the AI provider serving the request and returning its output to you.
  • To respond to support requests and to act on bug reports and feature requests.
  • To monitor, secure, and troubleshoot the Service, including detecting abuse and unauthorized access, and to measure how much AI usage a workspace generates so we understand what the Service costs to run.
  • To comply with legal obligations.

We do not sell Account Data or Customer Data. We do not use one workspace's Customer Data to populate, train, or improve another workspace's account, or to train a foundation model. We do not use Customer Data for Formed, the skincare business Formed Goods LLC also operates — see Section 5.3 of the Terms of Service, which states that boundary as a contractual commitment rather than a policy statement.

We do not currently send marketing or product-announcement email. The only messages the Service itself sends are workspace invitations; your account may also receive sign-in, confirmation and password-reset messages from our authentication provider. If we introduce announcement email, it will carry an unsubscribe link.

4. Who Receives Information

4.1 Infrastructure and Operations

These providers process information on our instructions in order to run the Service:

  • Supabase — managed PostgreSQL database, file storage for uploaded documents and images, and authentication. Holds Account Data and Customer Data.
  • Vercel — application hosting, serverless execution, and content delivery. Application code runs in Vercel's US East region. Generates server logs.
  • Resend — transactional email. Receives the name and email address of a person being invited, and the message text. It does not receive Customer Data.
  • Sentry — error monitoring, active on deployments where it is configured. Receives technical fault information. It is configured to exclude request bodies, cookies, user identities, IP addresses and session recordings; URLs it records may contain workspace identifiers.
  • Google — where you sign in with a Google account, Google acts as your identity provider. We receive your email address and whether Google has verified it. We do not receive your Google password.

4.2 AI Model Providers

  • Anthropic (Claude) — processes content submitted to AI Features, including the reading and transcription of uploaded documents and images.
  • OpenAI — processes content submitted to the text-based assistant, where a workspace has selected OpenAI as its provider.

AI Features are part of the Service, and using one sends the relevant content to a model provider. They run on model access Formed Goods LLC contracts for, so nothing is required from you to enable them; a workspace may instead supply its own API key and choose which provider to use. Either way, content leaves our systems for the provider serving the request only when you invoke a feature that needs it — we do not send your records to a model provider in the background. Each provider handles what it receives under its own commercial or API terms, together with our configuration with that provider. We identify the providers here so you can read those terms; we do not make an independent representation about their training or retention practices.

4.3 Integrations You Choose to Connect

If you connect Shopify, Google Calendar, Meta or Instagram, Klaviyo, or Judge.me, information flows to and from that service according to the permissions you grant. Those are the integrations that exist today; anything the application shows as planned is not built and connects to nothing. Each provider's own privacy practices govern its handling of the data, and we encourage you to review them.

4.4 Legal and Business Transfers

We may disclose information where required by law, subpoena, or legal process; to protect the rights, property, or safety of Formed Goods LLC, our users, or others; or in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections.

4.5 What We Ask of Them

Our infrastructure and AI providers are engaged under their standard terms, which include confidentiality and data-protection commitments. We have not separately negotiated bespoke data-protection agreements with each of them.

5. Security

Our security practices, limited to what is actually in place:

  • Encrypted transmission (TLS) between your browser and the Service.
  • Credentials you store for third-party integrations, and the API keys you store for AI providers, are encrypted with AES-256-GCM before they are written to the database, using a key held in the application environment and never in the database itself. This is an additional layer over the encryption at rest described below, applied specifically to the secrets you connect.
  • Encryption at rest (AES-256) for all data stored in the Service.
  • Workspace isolation enforced in the database by PostgreSQL row-level-security policies rather than by application code alone, and exercised by an automated isolation test suite that runs in continuous integration on every proposed change and on every change to the main branch.
  • Internal access limited to the people who need it to build, operate, or support the Service.

We do not maintain physical infrastructure of our own, and we do not currently hold an independent security certification.

No method of transmission or storage is completely secure. If we become aware of a security incident affecting your information, we will notify you as required by applicable law and, where a Data Processing Addendum is in place with your business, on the timeline it sets.

6. How Long We Keep Information

  • Account Data — while your account exists. Deleting an account removes its profile, workspace membership, invitation record and login.
  • Customer Data in a workspace — while the workspace exists. Deleting a workspace permanently removes its records from our active database; the application counts what will be destroyed and requires the workspace's name to be typed back before it proceeds.
  • After termination — Customer Data remains available for export for 30 days, as described in Section 13 of the Terms of Service, and may then be deleted from active systems.
  • Uploaded documents and images — until deleted from the workspace.
  • AI conversations and their output — until deleted from the workspace. Per-request usage counts are kept as operating records.
  • Support messages, bug reports and feature requests — kept as operating records.
  • Records we must keep — we may retain limited information for longer where required for legal, tax, security or dispute-resolution purposes.

Server logs, error reports and database backups are held for the standard retention periods our infrastructure providers apply to them, after which they age out. Deleted records may persist in backups until those backups age out.

7. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing.

Send any request to hello@runmonos.com. There is no self-service privacy control in the application, with these exceptions, which you can use yourself today:

  • You can correct your own name and avatar in your account settings.
  • You can export your workspace's records as CSV files from within the application.
  • A workspace owner who belongs to more than one workspace can permanently delete a workspace.

A few things worth knowing before you write to us:

  • We may need to verify your identity, or your authority to act for a business, before we can act on a request.
  • If your request concerns information a Monos customer controls — for example, your order record in a maker's workspace — it should generally go to that business, which decides what happens to it. We will assist that business as required under any Data Processing Addendum in place with it.
  • Rights differ by jurisdiction and are subject to exceptions. Describing a right here does not mean every privacy law applies to Formed Goods LLC, or that a given right is available to you.

We will respond within the timeframe applicable law requires.

8. California Residents

If the California Consumer Privacy Act, as amended, applies to a given interaction, the following describes our practices. This description does not concede that Formed Goods LLC meets the statute's applicability thresholds.

  • Categories collected: identifiers (name, email address, IP address); commercial information (order and purchase records within a workspace); internet or network activity (server logs, error reports); and the contents of documents and messages you provide. Sections 2.1 to 2.8 describe each in detail.
  • Sources: you; your workspace members; the person who invited you; third-party services you connect; and automatic collection by our hosting and error-monitoring providers.
  • Business purposes: providing and securing the Service, authentication, support, fault diagnosis, abuse prevention, enforcing usage limits, and legal compliance.
  • Categories of recipients: the infrastructure, email, error-monitoring, identity and AI providers listed in Section 4, and the integrations you choose to connect.
  • Sale or sharing: we do not sell personal information, and we do not share it for cross-context behavioral advertising. We run no advertising technology and no third-party analytics on the Service — see Section 10.
  • Sensitive personal information: we do not ask for it, our Terms of Service prohibit uploading it about identifiable individuals, and we do not use it to infer characteristics.
  • Submitting a request, and appealing: email hello@runmonos.com. If we decline a request, you may appeal by replying to our response and asking for the decision to be reviewed.
  • Non-discrimination: we will not deny you the Service, or provide a different level of service, because you exercised a privacy right.

9. Where Your Information Is, and Who the Service Is For

The Service is offered to businesses in the United States during the private beta, and is hosted and operated from the United States. It is not currently marketed to, or offered to, businesses or individuals in the European Economic Area, the United Kingdom, or Switzerland. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.

Our application code runs in our hosting provider's US East region, and our database and file storage are provided by a US-based managed host.

We do not offer the Service in the EEA, the United Kingdom or Switzerland, and this Policy does not describe rights or transfer mechanisms under the laws of those jurisdictions. This section will be updated before the Service is offered there.

10. Cookies and Browser Storage

We use strictly necessary cookies only — the authentication cookies that keep you signed in, and two cookies that record which workspace you are working in. We do not use advertising cookies, cross-site tracking pixels, or third-party product-analytics cookies.

The application also stores display preferences in your browser's local storage — your light or dark theme, sidebar width, saved table layouts, pinned pages, recent searches, and which notifications you have already seen. That data stays on your device and is not transmitted to us as an identifier.

11. Children

The Service is intended for business use by people aged 18 or older, which matches the eligibility requirement in Section 3 of our Terms of Service. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal information, contact hello@runmonos.com and we will delete it.

12. Changes to This Policy

We may update this Policy. Ordinary clarifications — better wording, corrections, a re-organized section — take effect when published, and the Effective Date above is updated. For material changes, including a change in the categories of information we collect, the purposes we use it for, or the categories of recipients, we will provide notice appropriate to the change and as required by applicable law before it takes effect.

13. Contact Us

Questions or requests regarding this Policy may be directed to hello@runmonos.com, which is the address for all privacy correspondence.

Formed Goods LLC is a Washington limited liability company whose registered office is 522 W Riverside Ave, Ste N, Spokane, WA 99201, United States. That address identifies the entity; it is not an operating or correspondence address, and a request sent there will take longer to reach us than email.

Terms of ServicePrivacy Policy

Monos, operated by Formed Goods LLC · hello@runmonos.com