Legal
Privacy Policy
What we collect, who else touches it, how long we keep it, and how to get it back or have it erased. Written to be specific rather than reassuring.
Last updated
1.Who is responsible
[your full legal name], an individual trading as MMNTM from [your business address], is the controller of the personal data described here. For privacy questions or to exercise any right below, write to dream3rsounds@gmail.com and we will reply within 30 days.
2.What we collect
Because you have an account: your name, email address, and profile picture if you sign in with GitHub or Google. If you use a password, we store a hash of it, never the password. We store session records so you stay signed in, and OAuth tokens encrypted at rest.
Because you build things: your projects and their files, the prompts you write, MMNTM’s replies and the record of what it did, and the saved versions of your work. Environment variables you add are encrypted at rest with AES-256-GCM and are only ever decrypted into the sandbox that runs your app.
Because we meter and bill: a record of each run with its token counts, cost and credits, your plan, your credit balance and the ledger behind it, and your Stripe customer identifier. We never see or store your card details — those go directly to Stripe.
Because servers keep logs: ordinary technical logs including IP address, browser user agent, and the requests you made, kept for a short period for security and debugging.
We do not collect special-category data, and we ask you not to put it into projects. MMNTM is not intended for children under 13.
3.Why we use it, and our legal basis
- To run the service — building, previewing, exporting and publishing your projects. Basis: performance of our contract with you.
- To meter and charge — credits, invoices, receipts, and preventing abuse of free credit. Basis: contract, and our legitimate interest in being paid.
- To keep it secure — rate limits, abuse detection, incident investigation. Basis: legitimate interest in a service that is not abused.
- To contact you — sign-in, verification, password resets, team invitations, and notices about changes that affect you. Basis: contract. We do not send marketing email without asking.
- To meet legal duties — tax and accounting records. Basis: legal obligation.
4.Who else processes it
We use a small number of providers to run the service. Each acts on our instructions under a data processing agreement, and receives only what its job needs.
| Provider | What it receives | Where |
|---|---|---|
| Our AI model provider | Prompts, the files MMNTM reads or writes during a run, and its replies | United States |
| Render | Application hosting and the Postgres database holding everything below | Singapore |
| Stripe | Name, email, and payment details you enter directly with them | United States and Ireland |
| E2B (when hosted sandboxes are enabled) | Project files, while a sandbox is running | United States |
| Resend (when email is enabled) | Your email address and the text of account emails | United States |
| GitHub and Google (only if you use them) | Sign-in identity; GitHub also receives the code you choose to push | United States |
We will name the current model provider on request. Where a provider is outside your country, transfers rely on standard contractual clauses or an equivalent safeguard. We will publish notice here before adding a processor that handles project content.
6.How long we keep it
- Projects, versions and conversations — until you archive or delete them, or your account is closed.
- Sandboxes — recycled when idle; they are working space, not storage.
- Billing and ledger records — kept as long as tax and accounting law requires, typically several years, even after an account closes.
- Technical logs — a short period, then discarded.
7.Your rights, and how to use them
You can ask for a copy of your data, correct it, have it deleted, restrict or object to how we use it, and withdraw consent where we relied on it. Depending on where you live, these come from the GDPR, Singapore’s PDPA or a similar law, and you may complain to your data protection authority.
You do not need to ask us for your work. Every plan can download a project as a zip or push it to GitHub at any time, which covers portability better than an export request would.
Account deletion is handled by a person rather than a button today: email dream3rsounds@gmail.com from your account address and we will erase your account, projects and content within 30 days, keeping only the billing records the law requires us to hold.
9.How we protect it
Traffic is encrypted in transit. Environment variables and stored OAuth tokens are encrypted at rest. Secrets are never placed in the AI model’s context, never written into the sandbox unless they are the public kind your app needs in the browser, and are stripped from the output of anything MMNTM runs. Exports are scanned for anything that looks like a key before they leave.
No system is perfect. If a breach affects your personal data we will tell you and the relevant authority without undue delay, and within 72 hours where the law requires it.
10.Changes
If we make a material change we will email account holders and update the date at the top of this page before it takes effect. The Terms of Service and Refund Policy sit alongside this document.
Questions about this page: dream3rsounds@gmail.com.