Privacy Policy
Summary. Muhkoo is built to know as little about you as possible. Your account uses zero-knowledge authentication, so we never receive or store your password. Some of your data is encrypted on your device with keys our servers do not hold: your direct messages and, by default, your key/value records. Other content, including uploaded files, messages in channels, and database records, is encrypted in transit and at rest, and our systems can access it in order to run the service, so it is protected by access controls. The limits of this design, including what changes if you sign in with Google or a recovery email, are explained in Encryption & access to content. This policy explains what we process and how.
1Scope & who we are
This Privacy Policy explains how Muhkoo Inc. (“Muhkoo,” “we,” “us”) collects, uses, and shares information when you visit muhkoo.com, use the Muhkoo platform, SDK, developer portal, and hosted applications, or otherwise interact with our services (together, the “Services”).
Muhkoo is a developer platform. Where you use an application built by a developer on Muhkoo, that developer is the controller of the personal data you provide to their app; see Developers & end users below.
2Information we collect
Account & identity
Muhkoo authentication is zero-knowledge. When you create an account we store a username, a cryptographic commitment derived on your device, and your account’s public keys. We never receive or store your password. We store only values derived from it on your device, which are designed so that your password cannot be read from them. For each sign-in or recovery method you set up (password, passkey, recovery phrase, recovery email, Google sign-in, or a paired device), we store an encrypted copy of your account key together with what that method needs in order to work: for a recovery email, your full email address; for Google sign-in, your Google account identifier; for a passkey, a credential identifier. We never store your recovery phrase. How these copies are protected is explained in Encryption & access to content.
Your content
We store and process the content you send or keep through Muhkoo: messages, key/value records, files, and database records. Some of it is encrypted on your device before it reaches us and some is not; Encryption & access to content sets out which, and what we can access. We also process the operational metadata required to route and deliver content (for example, timestamps, message and shard sizes, content-addressed hashes, the names of key/value records, and delivery status).
Developer account & usage
If you register as a developer, we process your app configuration (names, slugs, allowed origins, redirect URIs), API key metadata, and usage metrics (such as request counts, storage bytes, message counts, and AI inference units) that we use to operate and bill your account.
Billing
Payments are processed by Stripe. We receive billing status, subscription and plan information, and limited transaction metadata. We do not store your full card number or bank details; those are handled by Stripe under its own privacy policy.
Website & communications
On our marketing website we use analytics (see Cookies & analytics). If you join a waitlist or contact us, we collect the email address and any details you provide in order to respond and, where you have opted in, to send you product updates.
Technical & log data
Like most online services, our infrastructure automatically records technical data such as IP address, approximate location, device and browser type, and request logs. This is used for security, abuse prevention, debugging, and reliability.
3Encryption & access to content
All content is encrypted in transit and at rest. Beyond that, what Muhkoo can access depends on the kind of content and on how you sign in:
- Content encrypted with keys our servers do not hold. Direct messages are end-to-end encrypted: our servers relay them in encrypted form and do not store them. Key/value records are, by default, encrypted on your device with a key derived from your account key, and so are your Muhkoo filesystem (folder and file names, and the keys to the files in it) and messages in spaces whose group key is shared only among their members. The names of key/value records are not encrypted.
- Content our systems can access. Files uploaded through an app’s file storage are encrypted on your device before upload, but the keys needed to read them are stored by our service so that you can share them with the people and apps you choose. Messages in channels, and in spaces that members join through an invite link, are encrypted on your device with a group key that our service also holds so that it can admit new members and run features such as AI agents. Real-time publish/subscribe messages and signals such as typing indicators, database records, and key/value records an app stores without encryption are relayed or stored as the app sends them. Files deployed to app hosting are stored unencrypted and served publicly. This category also includes any content you or an app send to a feature that runs on our servers, such as an AI agent, AI assistant, or serverless function.
We protect content our systems can access with encryption at rest and access controls. Our systems process it automatically to deliver it and to run the features you or an app’s developer enable. Our personnel access it only as needed to operate, secure, and support the Services, to prevent abuse and enforce our Terms, to comply with law or respond to valid legal requests, to protect the rights, safety, and property of Muhkoo, our users, or the public, or as the app’s developer instructs.
How your account key is protected
Your account key unlocks the content in the first category above. We store it on our servers only in encrypted form, once for each sign-in or recovery method you set up. If you use a password, passkey, recovery phrase, or paired device, that copy is protected by a secret only you or your device holds; as with any password, a weak one could still be guessed, so choose a strong password or use a passkey. Google sign-in and recovery email are more convenient, but less secure than those zero-knowledge methods. For them, the copy is protected by keys that Muhkoo holds, which is what lets you sign in or recover your account without remembering a secret. It also means that, for an account with either method turned on, Muhkoo could technically recover your account key and read the content in the first category. For the strongest protection, use only a password, passkey, or recovery phrase.
Apps you sign in to
When you sign in to an app with your Muhkoo account, that app receives your account key on your device. It can then read your encrypted key/value records and Muhkoo filesystem, including data created in other apps, and act on your behalf. Only sign in to apps you trust. These protections also depend on the software running on your device, including the sign-in pages we serve.
Account recovery
If you lose your account credentials and every recovery method, we do not offer a way to restore your account or the content encrypted with your account key. If your only methods are a strong password, passkeys, or a recovery phrase, we have no technical means to do so. Please keep your recovery options up to date.
4How we use information
- Provide, maintain, secure, and improve the Services;
- Authenticate you and protect accounts;
- Route and deliver content and real-time messages;
- Run features an app’s developer enables, such as AI agents and serverless functions, which may process content, including with AI models, on the developer’s behalf. An AI agent keeps a transcript of its recent conversation in each space where it is enabled; deleting a message does not remove it from that transcript;
- Meter usage and process billing for developer accounts;
- Detect, prevent, and respond to fraud, abuse, and security incidents;
- Communicate with you about the Services, including service and security notices;
- With your consent, send product updates and marketing;
- Comply with legal obligations and enforce our terms.
5Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Services); legitimate interests (to secure, operate, and improve the Services, and to prevent abuse); consent (for marketing and non-essential cookies, which you can withdraw at any time); and legal obligation (to comply with applicable law).
6How we share information
We do not sell your personal information. We share limited information with:
- Service providers / sub-processors who help us run the Services, including payment processing (Stripe), marketing and waitlist email (SendGrid), CRM/waitlist (HubSpot), product analytics (Google Analytics), and our cloud infrastructure, edge-network, transactional email, and AI inference providers, which host and deliver the Services, send account and security emails, and run AI models on our behalf. The organizations that developed those AI models do not receive your content. These providers act on our instructions under contract.
- Legal & safety: where reasonably necessary to comply with law, respond to lawful requests, or protect the rights, safety, and property of Muhkoo, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
What we could disclose in response to a valid legal request depends on the kind of content (see Encryption & access to content). We do not store direct messages, and we cannot read them as they pass through our servers. Content our systems can access, such as uploaded files, messages in channels, and database records, could be subject to such a request, as could account and operational metadata. For accounts that use Google sign-in or a recovery email, content encrypted with the account key could also be subject to such a request, because we could technically recover that key.
7Data retention
We keep information for as long as your account is active and as needed to provide the Services, then for a limited period as required to comply with legal, tax, accounting, security, and dispute-resolution obligations. Content, including database records, is kept until you or the app deletes it. When messages or records are deleted we remove them promptly, although copies may remain in our infrastructure’s recovery systems for a limited period. Encrypted file data that is no longer referenced is permanently deleted after a one-year retention period. An AI agent’s transcript for a space is deleted when the agent is removed from that space. You may request deletion of your account as described below.
8Security
We use encryption in transit and at rest, zero-knowledge authentication, end-to-end encryption of direct messages, and access controls. No system is perfectly secure, but our architecture is designed to minimize the data that could ever be exposed. If we become aware of a breach affecting your personal data, we will notify you and regulators as required by law.
9Your rights & choices
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of “sale” or “sharing” (we do not sell or share personal information as those terms are defined). To exercise any right, contact us at privacy@muhkoo.com. We will not discriminate against you for exercising your rights. You can opt out of marketing emails at any time via the unsubscribe link.
10International transfers
We operate on a globally distributed edge network, so your information may be processed in countries other than your own. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
11Cookies & analytics
Our marketing website uses Google Analytics (GA4) to understand aggregate traffic and improve the site. These analytics may set cookies or similar identifiers. Essential cookies/local storage are used to run the Services (for example, to keep you signed in). You can control cookies through your browser settings; blocking some may affect functionality.
12Children
The Services are not directed to children under 13 (or the minimum age of digital consent in your jurisdiction), and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
13Developers & end users
Applications built on Muhkoo are operated by independent developers. When you use such an app, the developer is responsible for its own data practices and privacy notice, and Muhkoo processes the app’s content on the developer’s behalf and on the developer’s instructions. Muhkoo is independently responsible for the limited processing it carries out for its own purposes: securing the Services, preventing abuse, billing, and complying with law. An app you sign in to with your Muhkoo account receives your account key, as explained in Encryption & access to content. If you have a question about a specific app, please contact that app's developer. This policy governs Muhkoo's own website, platform, and developer services.
14Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after an update means you accept the revised policy.
15Contact us
Questions about this policy or your personal information? Contact:
Muhkoo Inc.Privacy: privacy@muhkoo.com
General: hello@muhkoo.com