Legal
Privacy Policy
Last updated 1 January 2026
Data we collect
Account details (name, email, avatar), business profile information you enter during onboarding, workspace activity records, and technical logs needed to operate and secure the service.
Tenant isolation
Every record is scoped to a workspace. Row-level security policies are enforced in the database, so one tenant can never read or write another tenant's data — even in the event of an application bug.
Your integration credentials
Moyan MBAS follows a bring-your-own-credentials model. Keys you connect for AI, messaging, payments or storage are held encrypted server-side, are never returned to the browser, and are used only to make requests on your behalf.
Audit logging
Sensitive actions — permission changes, integration updates, invitations, exports — are written to an immutable audit log scoped to your workspace and readable by your admins.
Retention and deletion
Workspace data is retained while your account is active. When a workspace is deleted, its records are removed from primary storage and expire from backups within 30 days.
Your rights
You can access, correct, export or delete your personal data at any time from account settings, or by contacting our team.
Questions about this policy? Contact us.