Privacy Policy

Privacy Policy

Last updated 27 September 2026

We collect what we need to run monodrom and take payments, we use analytics and ad tracking only if you allow it, and we never sell your data. Details below. See also our Terms of Service.

1. Who is responsible

Ruleframe Limited (England and Wales) operates monodrom.ai and is the controller of your personal data. For anything about your data, email hello@ruleframe.io.

2. What we collect

  • Account data: your email address, and the name and profile picture from Google or Facebook if you sign in with them.
  • Your content: prompts, files you upload (such as reference images) and the images, video and audio generated for you.
  • Billing data: your plan, purchases, credit balance and Stripe customer ID. Stripe collects your card details; we never see your full card number.
  • Usage data: which pages and features you use and the generations you run (model, settings, credits spent, success or failure), linked to a random ID stored in your browser and, once you sign in, to your account. Our servers also log IP addresses and browser details for security.
  • Ad attribution (only if you accept): the ad click ID (such as Google's gclid), campaign tags and the referring page, so we can tell which ads lead to sign-ups and purchases.
  • Product analytics (only if you accept): how you move through the site, including recordings of on-screen interactions, with text you type (such as prompts) masked, so we can find what's confusing or broken.
  • Messages: emails you send us and the service emails we send you (receipts, account notices).

3. Why we use it, and our legal basis

PurposeLegal basis (UK GDPR)
Creating your account, running generations, storing your creations, taking payments, customer supportContract
Keeping the service secure, preventing fraud and abuse, checking content against our acceptable-use rulesLegitimate interests
Understanding how the product is used from our own usage events, to fix problems and improve itLegitimate interests
Ad attribution and conversion reporting to Google Ads; product analytics and session recordingsConsent (you can withdraw it at any time)
Keeping tax and accounting recordsLegal obligation

4. Who we share it with

We don't sell your personal data. We use these service providers, who process it on our behalf and under contract:

  • Google Cloud: hosting, file storage, sign-in (Firebase Authentication) and bot protection (reCAPTCHA).
  • MongoDB Atlas: our database.
  • Stripe: payments, invoices and fraud checks.
  • fal.ai and the model providers it connects to (such as Google, ByteDance, Black Forest Labs, Alibaba and xAI): they receive your prompt and attached files to generate your result.
  • ElevenLabs: voice generation, when you use voice tools.
  • Resend: sending service emails.
  • Google Ads (with consent): we report conversions using the ad click ID, the time and the value of a purchase. No email address or name is sent.
  • PostHog (with consent): product analytics and session recordings.

We may also disclose data where the law requires it, to protect people from harm, or as part of a sale or merger of our business.

5. International transfers

Some of these providers process data outside the UK, mainly in the United States. Where they do, we rely on the UK's adequacy regulations (including the UK-US data bridge for certified companies) or on approved contract terms such as the UK International Data Transfer Addendum.

6. How long we keep it

  • Account data: while your account is open, and deleted within 30 days of closing it.
  • Your creations: original files for the storage period of your plan (see pricing), small previews while your account is open; all deleted when you close your account.
  • Billing and tax records: 6 years, as UK law requires.
  • Usage events and analytics: up to 25 months. Security logs: up to 90 days.
  • Ad attribution data: up to 90 days after the ad click, or until you withdraw consent.

7. Your rights

You can ask us to access, correct, delete or export your personal data, or to restrict or object to how we use it. Email hello@ruleframe.io and we'll reply within one month. Where we rely on consent, you can withdraw it at any time: use Cookie preferences in your account settings.

If you're unhappy with how we handle your data, please tell us first. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.

8. Cookies and local storage

Essential (always on): a sign-in session cookie, your cookie choice, and a copy of an unsent prompt so it survives signing in.

Optional (only after you click Accept): ad attribution data kept in your browser, and PostHog analytics cookies. Declining is as easy as accepting, and you can change your mind at any time under Cookie preferences.

9. Children

monodrom is for people aged 18 and over. We don't knowingly collect data from children; if you believe a child has an account, tell us and we'll delete it.

10. Security

Data is encrypted in transit and at rest, access is limited to people who need it, and payments are handled by Stripe. No system is perfectly secure; if a breach affects you, we'll tell you and the regulator as the law requires.

11. Changes to this policy

If we change this policy in a way that matters, we'll update the date above and tell you by email or in the app before it applies.