Privacy Policy
How MonkeysCode collects, uses, stores, and protects your information.
Data Controller: Colibricode Inc., Denver, Colorado, United States
1. Introduction & Scope
This Privacy Policy explains how Colibricode Inc. (“Colibricode,” “we,” “us,” or “our”), a Colorado corporation with its principal place of business in Denver, Colorado, collects, uses, discloses, and protects information in connection with MonkeysCode — our agentic coding IDE and AI service — including:
- The MonkeysCode website and marketing pages (monkeyscode.com)
- The MonkeysCode IDE, Terminal, and Troop applications
- Capuchin, MonkeysCode's own AI model, and any commercial AI models (Claude, Gemini, ChatGPT, or others) accessed through MonkeysCode
- The MonkeysCode account dashboard, billing portal, and related web applications
- Any other service that links to this Policy (collectively, the “Service”)
This Policy applies to all users of the Service worldwide, and includes disclosures specifically required under the EU/UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), the Colorado Privacy Act (“CPA”), and other applicable U.S. state privacy laws.
2. Who We Are
Data Controller: Colibricode Inc. (operating MonkeysCode)
Address: Denver, Colorado, USA
Privacy contact: privacy@monkeyscloud.com
3. Information We Collect
3.1 Information you provide directly
- Account information: name, email address, password (hashed), organization name, billing address.
- Payment information: processed by our payment processor, Stripe; Colibricode does not store full card numbers.
- Support communications: anything you send us via email, chat, or support tickets.
- Referral program data: your referral code, who you refer, and who refers you (see §3.4).
- Content you submit for AI processing: prompts, code, file context, and instructions you send to any model through MonkeysCode (see §3.3).
3.2 Information collected automatically
- Usage and telemetry data: feature usage, session duration, crash reports, performance metrics, agent-run metadata.
- Device and log data: IP address, browser type, operating system, device identifiers, timestamps, referring URLs.
- Cookies and similar technologies: see §12.
3.3 Code, prompts, and content submitted to AI models
How your content is handled depends on which model you use:
| Model path | What happens to your content |
|---|---|
| Capuchin (managed) | Processed on Colibricode's GCP infrastructure. Not used to train or improve Capuchin unless you explicitly opt in. |
| BYOK (your own API key) | Sent directly to the third-party provider using your credentials. Colibricode does not receive, store, or process this content. |
| Managed third-party access | Colibricode acts as an intermediary. Both this Policy and the provider's terms apply. |
| Local models | Your content never leaves your device. Colibricode has no access. |
| Self-hosted / remote models | Sent only to the endpoint you configure. Colibricode has no access. |
3.4 Referral program information
If you participate in the referral program, we collect the referral relationship, status of each referral, and the reward applied, in order to administer the program and prevent abuse.
4. How We Use Information
- Provide, operate, and maintain the Service, including routing requests to the model you select
- Process payments and manage subscriptions
- Provide customer support
- Monitor, secure, and troubleshoot the Service, including detecting fraud, abuse, and violations of our Terms
- Administer referral and promotional programs
- Improve Capuchin and the Service, only from opt-in signals (see §6)
- Comply with legal obligations, respond to lawful requests, and enforce our agreements
- Communicate with you about the Service, including security and billing notices
5. Legal Bases for Processing (EU/EEA/UK/Swiss Users)
- Performance of a contract — processing needed to provide the Service you've signed up for.
- Consent — for optional features such as opt-in model-improvement data collection, marketing communications, and non-essential cookies.
- Legitimate interests — for security monitoring, fraud/abuse prevention, and service improvement.
- Legal obligation — where we must retain or disclose information to comply with law.
6. AI Model Training & Opt-In Data Use
Colibricode's approach to improving Capuchin is opt-in only:
- Free, Pro, Pro+, Ultra, and Team plan users are asked to explicitly opt in before any usage data is used to improve Capuchin. The default is off.
- Enterprise, self-hosted, and air-gapped customers are never included.
- Where opt-in is given, we prioritize derived signals over raw source code and apply reasonable measures to minimize sensitive content.
- We do not use content submitted to third-party models to train any Colibricode model.
8. International Data Transfers
Colibricode is based in the United States, and Capuchin is served from U.S.-based cloud infrastructure. If you are located in the EEA, UK, or Switzerland, your information may be transferred to the United States. Where required, we rely on the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum) to safeguard such transfers.
9. Data Retention
- Account data: for the life of your account plus 90 days after closure, unless required longer by law.
- Billing records: as required by tax and accounting law (typically 7 years).
- Prompts/code sent to Capuchin: retained as needed to operate the Service, then deleted or anonymized.
- Signed agent-run records: retained as configured by your plan.
Enterprise and self-hosted customers may configure shorter or custom retention periods contractually.
10. Security
- Network protection: Google Cloud Armor (WAF, DDoS protection) at the network edge.
- Encryption: data encrypted in transit (TLS) and at rest.
- Access controls: least-privilege IAM for all internal systems; provider API credentials encrypted at rest.
- Audit logging: infrastructure and administrative actions are logged.
- Sandboxed execution: AI agent actions run in isolated sandboxes.
No system is perfectly secure. If we become aware of a data breach, we will notify you and applicable regulators as required by law. See our Security page for full detail.
11. Your Privacy Rights
11.1 GDPR rights (EEA, UK, Switzerland)
- Access the personal information we hold about you
- Rectify inaccurate or incomplete information
- Erase your information (“right to be forgotten”)
- Restrict or object to certain processing
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time
- Lodge a complaint with your local supervisory authority
11.2 California privacy rights (CCPA/CPRA)
- Know what personal information we collect, use, disclose, and sell or share
- Delete personal information we've collected from you
- Correct inaccurate personal information
- Opt out of the sale or sharing — Colibricode does not sell personal information
- Non-discrimination for exercising any of these rights
| Category | Collected? | Sold/Shared? |
|---|---|---|
| Identifiers (name, email, IP) | Yes | No |
| Customer records (billing info) | Yes | No |
| Commercial information (plan, purchases) | Yes | No |
| Internet/network activity (logs, telemetry) | Yes | No |
| Geolocation (approximate, from IP) | Yes | No |
| Professional info (organization name) | Yes | No |
| Sensitive personal info (account credentials) | Account credentials only | No |
11.3 Other U.S. state privacy rights
Residents of Colorado, Virginia, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights. Contact us at privacy@monkeyscloud.com to exercise these rights.
11.4 How to exercise your rights
Email privacy@monkeyscloud.com with your request and the state/country you're contacting us from.
13. Children's Privacy
The Service is not directed to children under 13 (or under 16 where required by applicable law), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@monkeyscloud.com and we will delete it.
14. Self-Hosted & Air-Gapped Deployments
For customers running MonkeysCode or Capuchin in a self-hosted or fully air-gapped configuration, Colibricode has no access to your code, prompts, or usage data — all processing occurs entirely within your own infrastructure. This Policy applies only to the limited license/identity data necessary to operate your deployment.
15. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified via the Service or by email before they take effect. The “Last updated” date at the top reflects the most recent revision.
16. Contact Us
Colibricode Inc.
Denver, Colorado, USA
Privacy inquiries: privacy@monkeyscloud.com
General inquiries: contact@monkeyscloud.com
This Privacy Policy is part of the MonkeysCode Terms of Service. See also our Security page.