Data we collect
An access request can include your name, email address, role context, profile URL, intended use, preferred setup language, and request note. Approved setup flows can also contain questionnaire answers, CV files or links, and the source notes created from that material.
Private chat use can create conversation messages and operational records needed to run, protect, and review the service.
How we use it
FluxonLab uses submitted data to review access, run the guided setup, create the requested assistant, answer through approved source material, deliver service emails, investigate failures, and limit abuse.
Mono AI extracts bounded text from TXT files in the production Worker. PDF, DOCX, RTF, and image files are stored without in-process document parsing or OCR, so their contents are not added automatically to assistant sources; include important facts in the CV notes.
AI output can be wrong or incomplete. Profile owners and readers should verify important claims directly before making a hiring or business decision.
Service providers
Mono AI uses configured hosting and database providers to run the service. The configured AI provider receives the profile sources and conversation context needed to answer a chat. If an administrator deliberately starts a behavior review, the AI provider can also receive bounded conversation excerpts after common email, URL, token, and phone patterns are removed. This pattern filter is not a guarantee that every sensitive detail will be detected.
Resend can process email delivery data. Cloudflare Turnstile can process browser, network, and challenge data to help prevent abuse. When Google Drive storage is configured, it stores uploaded CV files; otherwise they remain in Mono AI's private database storage. Each provider applies its own security and retention practices.
Optional browser telemetry
Browser telemetry is disabled by default, and the current production relay discards browser telemetry instead of forwarding it to an observability service. A future release must explicitly enable and disclose that relay before forwarding a redacted page path, event or error name, short error message, language, viewport size, or timing data. The client omits the page referrer and removes private link credentials from reported paths. Do not rely on those safeguards as a reason to publish a private link.
Private links are bearer links
Anyone who receives a current setup, chat, approval, or CV file link may be able to open the resource. Treat each link like a private document. Do not post it publicly, forward it without permission, or place it in systems that expose full URLs.
Access, archiving, and erasure
Archiving an assistant closes it for live use. Archiving alone does not promise immediate deletion of every related record. Erasure is a separate administrator action and can also begin with a request from the profile owner.
Mono AI does not publish a fixed automatic deletion period on this page. To ask for access, correction, link revocation, or erasure, email hello@monoai.link.
What you should avoid submitting
Do not upload passwords, private keys, financial account details, medical records, or another person's confidential material. Submit only content you have the right to use for this purpose.