Privacy Policy

Last updated: July 5, 2026 | GDPR-aligned · EU AI Act-ready

Privacy That Others Can't Match

ChatGPT memory is unavailable in the EU due to GDPR concerns. Ask Mojo was built for privacy from day one.

E2E Encryption

Optional zero-knowledge encryption. We literally can't read your data.

  • AES-256-GCM encryption
  • PBKDF2 (600K iterations)
  • 24-word recovery phrase

Local AI Option

Run AI completely offline. Zero data leaves your machine.

  • Ollama & LM Studio support
  • 100% offline capable
  • No cloud dependency

Data Portability

Export everything in one click. Standard formats, no lock-in.

  • Markdown & JSON export
  • Works with Obsidian, Notion
  • Complete data archive

Full GDPR Compliance

EU-based data controller with all 7 user rights.

  • 30-day deletion guarantee
  • Data access requests
  • Right to be forgotten
ChatGPT's EU Problem: ChatGPT memory features are not available in the EU, UK, Iceland, Liechtenstein, Norway, and Switzerland due to GDPR compliance issues. Ask Mojo works everywhere.

1. Information We Collect

We collect information you provide directly to us when you create an account, use our services, or communicate with us. This includes:

  • Account information (email, name)
  • Content you create (documents, skills, conversations)
  • Usage data (how you interact with our service)
  • OAuth connections (with your explicit consent)

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process your requests and transactions
  • Send you technical notices and updates
  • Respond to your comments and questions
  • Analyze usage patterns to improve user experience

3. AI Processing

Ask Mojo uses Claude (Anthropic) — specifically the claude-haiku model for the Mojo assistant — to process your conversations and execute magik workflows.

How it works:

  • Your messages are sent to Anthropic's API in real-time for processing
  • Conversation history (last 10 turns) is included for context coherence
  • Anthropic does not train AI models on your data
  • We operate under Anthropic's Data Processing Agreement (DPA), which governs sub-processor obligations under GDPR Art. 28
  • Per EU AI Act Article 50(1) (chatbot disclosure), Mojo already discloses at the start of every interaction that it is an AI system, not a human
  • AI-generated content marking (Art. 50(2)): AI-generated images hosted by AskMojo are embedded with machine-readable provenance metadata (IPTC Digital Source Type: trainedAlgorithmicMedia + EXIF) at upload time, and AI-generated text shown publicly (outputs, feed, blog posts authored by Mojo) carries a visible “AI-generated” label. Cryptographically signed C2PA manifests are on our roadmap as tooling matures.
  • High-risk use restrictions: creating or publishing magik intended for automated decisions in EU AI Act Annex III high-risk contexts (e.g. recruitment, credit scoring, biometric categorization) is prohibited on the Service — see Terms of Service § 6.1.

Data transfer: Anthropic processes data in the United States under Standard Contractual Clauses (SCCs) as part of our DPA. We do not currently offer EU-only Anthropic processing (would require AWS Bedrock Frankfurt setup, planned for Enterprise tier if requested).

Learn more: Anthropic Privacy Policy

3.1 Mojo Conversations — Storage & Retention

When you chat with Mojo, your messages are:

  • Sent to Anthropic (sub-processor) which runs the model claude-haiku-4-5-20251001
  • Stored in our database — encrypted at disk level by Supabase (AES-256), but not column-encrypted, meaning Ask Mojo team members can access conversation content for support purposes
  • Retained for 24 months then automatically deleted
  • Never used for training — Anthropic's DPA (Art. 28) explicitly prohibits model training on user data

You can delete all your conversations at any time in Settings > Privacy.

4. Data Storage and Security

Standard Mode (Default)

By default, your data is stored securely on our servers with industry-standard protection:

  • Data encrypted in transit (HTTPS/TLS 1.3)
  • Data encrypted at rest in our PostgreSQL database
  • OAuth tokens encrypted using AES-256-GCM
  • Access from any device seamlessly
  • We can assist with support and data recovery

Who can access your data: You, and Ask Mojo team members for support purposes. This is similar to services like Google Docs, Notion, or Dropbox.

End-to-End Encryption Mode (Optional)

For maximum privacy, you can enable end-to-end encryption (E2E):

  • Client-side encryption: Your data is encrypted in your browser using AES-256-GCM before being sent to our servers
  • Zero-knowledge storage: We store only encrypted data. The founder, developers, and support team cannot read your content
  • 24-word recovery phrase: You control the encryption key via a BIP39-style recovery phrase. This is your responsibility to store safely
  • Device setup required: Each device needs your recovery phrase imported to decrypt your content
  • No recovery possible: If you lose your recovery phrase, your data cannot be recovered by anyone—including us

Technical Specifications

  • Encryption Algorithm: AES-256-GCM (via Web Crypto API)
  • Key Derivation: PBKDF2 with 600,000 iterations
  • Salt: Unique per encryption operation
  • IV: Random 12-byte initialization vector per encryption
  • Recovery Phrase: 24 words (BIP39-style, 256-bit entropy)
  • Performance: <100ms decryption overhead (~50ms for 50 documents)

Important: E2E Trust Model

With E2E encryption enabled, your data is decrypted in your browser and sent to Anthropic's Claude AI for processing. This means:

  • You trust Anthropic (Claude AI) to process your data securely
  • You don't need to trust Ask Mojo's founder or team with your encrypted content
  • Claude processes your data according to Anthropic's privacy policy
  • This trust model is the same as using Claude directly (ChatGPT, Claude Desktop, etc.)

Recommendation: Most users are happy with Standard Mode. Use E2E encryption if you're handling highly sensitive personal information and want zero-knowledge storage.

5. Local AI Mode (Complete Privacy)

For users who require absolute privacy, Ask Mojo supports running AI entirely on your local machine using Ollama or LM Studio. This is the ultimate privacy option, no data ever leaves your computer.

How Local AI Works

  • Ollama: Open-source local AI runtime supporting Llama, Mistral, Mixtral, and other models
  • LM Studio: Desktop app for running local language models with OpenAI-compatible API
  • Your hardware: AI runs on your GPU/CPU, requires a reasonably powerful computer
  • 100% offline: No internet connection required after initial model download

Local AI Privacy Guarantees

  • Zero data transmission: Your prompts, documents, and responses never leave your machine
  • No cloud dependency: Works completely offline, no API keys, no cloud accounts
  • No trust required: You don't need to trust Ask Mojo, Anthropic, or any third party
  • Complete control: You choose which models to run and can audit everything locally

Supported Models

Local AI mode supports various open-source models optimized for different use cases:

  • Llama 3.2 (3B, 7B): Meta's latest models, excellent general performance
  • Mistral 7B: Fast and efficient for most tasks
  • Mixtral 8x7B: Mixture-of-experts model for complex reasoning
  • DeepSeek Coder: Optimized for code-related tasks
  • Gemma 2: Google's open models with strong performance

Trade-offs vs Cloud AI

  • Pros: Complete privacy, no API costs, works offline, no rate limits
  • Cons: Requires powerful hardware (8GB+ GPU recommended), slower than cloud, smaller context windows
  • Best for: Sensitive data, air-gapped environments, privacy-conscious users, developers

Fallback option: If local AI is unavailable (e.g., Ollama not running), Ask Mojo can automatically fall back to Claude (cloud) with your permission. You control this behavior in Settings.

6. Third-Party Services and Data Sharing

6.1 OAuth Integrations

When you connect third-party services (Gmail, Slack, GitHub, etc.), we use Composio to manage OAuth connections. Your credentials are stored securely by Composio and never exposed to us.

6.2 MCP Servers (Model Context Protocol)

Ask Mojo.ai allows you to connect to third-party MCP servers. Important:

  • Third-Party Responsibility: MCP servers are developed and operated by third parties. We do not control, verify, or monitor them.
  • Data Sharing: When you connect an MCP server, you grant it access to your data according to its permissions. The MCP server operator becomes a data processor.
  • Your Privacy Choices: Review each MCP server's privacy policy and permissions before connecting. You can disconnect any MCP server at any time.
  • Our Liability: Ask Mojo.ai is not responsible for how third-party MCP servers handle, store, or use your data. Any data breach, misuse, or privacy violation by an MCP server is the responsibility of that server's operator.

6.3 Community Skills

Skills created by community members may process your data differently than official Ask Mojo skills. You are responsible for reviewing and understanding what data each skill accesses and how it uses that data.

6.4 Data Processors We Use

We work with the following trusted third-party processors:

  • Anthropic (Claude AI): AI processing. DPA incorporated into Anthropic's Commercial Terms (DPA version effective Feb 24, 2025), including Standard Contractual Clauses (Modules 2 & 3 + UK and Swiss addenda) for EU–US transfers. Anthropic may not train models on Customer Content (Commercial Terms §B, effective Jun 17, 2025). Privacy Policy
  • Clerk: Authentication. DPA included in terms. Privacy Policy
  • Composio: OAuth integrations - Privacy Policy
  • Stripe: Payment processing. Standard Contractual Clauses + EU–US Data Privacy Framework. Privacy Policy
  • Vercel: Hosting and infrastructure. DPA included in terms. Privacy Policy
  • Supabase: Database hosting. DPA in place, EU region primary. Privacy Policy
  • PostHog: Product analytics. DPA in place, EU region. Privacy Policy
  • Plausible: Privacy-friendly website analytics (cookie-free, EU-hosted). DPA in place. Privacy Policy
  • Loops.so: Email communications - Privacy Policy
  • WaveSpeed: AI image generation - Privacy Policy
  • Twilio: Voice workflows (optional) - Privacy Policy

Each processor listed above operates under a Data Processing Agreement covering GDPR Article 28 sub-processor obligations, with Standard Contractual Clauses or the EU–US Data Privacy Framework authorizing any transfer outside the EEA. Processor DPA terms and transfer mechanisms were last reviewed on July 2, 2026.

7. Data Export and Deletion

Data Portability

We believe in data self-sovereignty. Your content belongs to you, not us:

  • Standard formats: Everything is stored in Markdown and JSON—no proprietary formats
  • One-click export: Download all your data anytime from Settings
  • No lock-in: Use your exported data in other tools (Obsidian, Notion, etc.)
  • Complete archive: Export includes documents, conversations, skills, and knowledge items

Account Deletion

You can delete your account and all associated data at any time from Settings. Deletion is permanent and cannot be undone. Your data is removed from our servers within 30 days.

8. Your GDPR Rights (EU Residents)

If you are a resident of the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

8.1 Right to Access

You can request a copy of all personal data we hold about you. Export your data anytime from Settings → Export Data.

8.2 Right to Rectification

You can update your personal information at any time in your account settings. If you find inaccurate data, contact us at contact@askmojo.ai.

8.3 Right to Erasure ("Right to be Forgotten")

You can delete your account and all associated data at any time from Settings → Delete Account. Data is permanently removed from our servers within 30 days.

8.4 Right to Restriction of Processing

You can pause or limit how we process your data by:

  • Disconnecting OAuth integrations
  • Disconnecting MCP servers
  • Pausing or archiving skills
  • Enabling end-to-end encryption for zero-knowledge storage

8.5 Right to Data Portability

Export your data in standard formats (Markdown, JSON) that you can use with other services. No lock-in or proprietary formats.

8.6 Right to Object

You can object to processing of your data for:

  • Direct marketing: We don't send marketing emails without consent. You can unsubscribe from all communications at any time.
  • Analytics: We only collect usage analytics to improve the product. Contact us to opt out.

8.7 Right to Withdraw Consent

Where we process data based on your consent (e.g., OAuth integrations), you can withdraw consent at any time by disconnecting the integration.

8.8 Right to Lodge a Complaint

If you believe we are not handling your data properly, you have the right to lodge a complaint with your local data protection authority:

  • EU residents: Contact your national Data Protection Authority
  • UK residents: Information Commissioner's Office (ICO)
  • France residents: Commission Nationale de l'Informatique et des Libertés (CNIL)

9. Data Retention

We retain your data for as long as your account is active. When you delete your account:

  • Immediate: Your account is deactivated and data is inaccessible
  • Within 7 days: Personal data is anonymized or deleted
  • Within 30 days: All data is permanently removed from active databases
  • Backups: Backup data is purged within 90 days

Legal Retention: We may retain certain data longer if required by law (e.g., financial records for tax purposes, 7 years).

10. International Data Transfers

Data Controller: Mix Web Management SARL (France, SIREN 517 939 112)

Your data may be processed in:

  • European Union: Primary data storage via Supabase EU, PostHog EU (analytics)
  • United States: Third-party processors (Anthropic, Clerk, Stripe, Vercel, Loops.so, Twilio, WaveSpeed) under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where certified

Specifically for Anthropic: conversations are processed in US-East region by default. SCCs in our Anthropic DPA legally authorize this transfer per GDPR Articles 44–50. EU-only Anthropic processing is not currently offered for AskMojo (would require AWS Bedrock Frankfurt setup — available on request for Enterprise customers).

All international transfers comply with GDPR Article 44-50 requirements.

11. Children's Privacy

Ask Mojo.ai is not intended for users under 16 years old. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, please contact us immediately at contact@askmojo.ai and we will delete it.

12. Analytics, Cookies & Tracking

We use essential cookies (authentication via Clerk, payments via Stripe, dev-gate) and, only with your prior consent, analytics cookies (PostHog). Our audience measurement (Plausible) is cookie-free and needs no consent. We do not use:

  • Advertising cookies
  • Third-party tracking cookies
  • Social media cookies

12.1 In-app analytics events

To understand how the service is used and improve your experience, we collect events in our internal analytics_events table:

  • Purpose: audience measurement, bug detection (web vitals), product improvement
  • Data collected: pages visited, UI actions (clicks, scrolls), web vitals (LCP, FID, CLS), front-end errors
  • No PII: only your internal UUID is associated with events — no email, name, or contact data
  • Retention: 12 rolling months
  • Opt-out: you can disable this at any time in Settings > Privacy
  • Sub-processor: none — stored directly on our Supabase EU instance

12.2 Third-party analytics tools

We use privacy-friendly analytics to understand how our product is used and improve it:

  • Plausible Analytics: Privacy-first, cookie-free website analytics. No personal data is collected. Fully GDPR compliant without consent banners. Data Policy
  • PostHog: Product analytics for understanding feature usage and improving the user experience. PostHog is EU-hosted and GDPR compliant. You can opt out of tracking in your account settings. Privacy Docs

You can disable cookies in your browser settings, but this may limit functionality.

12.3 Cookies we use

Under the CNIL / ePrivacy rules, non-essential cookies require your prior consent. We ask for it through a discreet banner the first time you visit, with equally weighted Accept and Decline options. Your choice is stored in a first-party cookie for 6 months, after which we ask again.

Cookie / toolCategoryPurposeConsent
Clerk session (__session, __client_uat)EssentialKeep you signed inNot required (exempt)
Stripe (__stripe_mid)EssentialPayment processing & fraud preventionNot required (exempt)
Dev-gate & consent choice (mojo_consent)EssentialAccess control on private previews · remember your cookie choiceNot required (exempt)
PlausibleAudience measurement (exempt)Aggregate, cookie-free website statistics — no personal dataNot required (cookieless)
PostHog EU (ph_*)AnalyticsProduct usage & funnel analysis (EU-hosted). Set for ~12 months.Required — only after you Accept

Withdraw your consent at any time via Manage cookies in the footer (this reopens the banner) — withdrawing is as easy as accepting. On decline or withdrawal, PostHog is never initialized and any existing ph_* cookies and local storage are purged. Signed-in users can also opt out permanently in Settings > Privacy — a server-side opt-out always overrides local consent.

13. Legal Basis for Processing (GDPR)

We process your data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide the Service (Art. 6(1)(b) GDPR)
  • Consent: OAuth integrations, MCP servers, optional features (Art. 6(1)(a) GDPR)
  • Legitimate Interests: Analytics, security, fraud prevention (Art. 6(1)(f) GDPR)
  • Legal Obligation: Tax records, compliance with law enforcement (Art. 6(1)(c) GDPR)

14. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by email or through the Service. Continued use after changes constitutes acceptance. You can view the change history by checking the "Last updated" date above.

15. White-Label Labs — Lab Owner as Data Controller

Ask Mojo.ai lets a user (a "Lab Owner") publish a branded lab and give their own end-users access to it. When personal data of a lab's end-users is processed through the Service, the data-protection roles differ from ordinary use of Ask Mojo.ai:

  • The Lab Owner is the data controller for their end-users' personal data. They decide what data their lab collects, why, and how it is used, and they are responsible toward their end-users under the GDPR (including providing a privacy notice and a lawful basis).
  • Ask Mojo.ai acts as a data processor for that data — we process a lab's end-user data only on behalf of, and on the documented instructions of, the Lab Owner, to run the infrastructure.
  • Our own processors become sub-processors in that chain. The providers listed in § 6.4 (Data Processors We Use) — Anthropic, Supabase, Clerk, and others — process a lab's end-user data as sub-processors under our existing DPAs, with Standard Contractual Clauses covering any transfer outside the EEA.

Processed on the Lab Owner's behalf: end-user data flowing through a white-label lab is handled for the purposes the Lab Owner sets, not for our own purposes. We do not sell it, and we do not use it to train AI models (Anthropic's DPA, GDPR Art. 28, prohibits training on this data).

Data Processing Agreement (DPA): a written DPA / sub-processor agreement reflecting the controller–processor relationship above is available on request for business (B2B) and enterprise Lab Owners. This is recommended where a lab handles significant volumes of end-user personal data or falls within scope of the EU AI Act. To request one, email contact@askmojo.ai with the subject "DPA request".

Lab Owners' responsibilities for the content, compliance, and protection of minors within their labs are set out in our Terms of Service § 22.

16. Contact Us & Data Protection Officer

For privacy questions, data requests, or GDPR-related inquiries, contact us at:

Email: contact@askmojo.ai
Subject Line: "Privacy Request" or "GDPR Request"

We will respond to all legitimate requests within 30 days as required by GDPR.