Privacy Policy

Last Updated: August 28, 2026

Solid Technologies AG (“Company”) operates Mono (the “Service”) and is committed to protecting and respecting your privacy. This Privacy Policy describes how Mono collects, uses, and shares your personal data. It also explains your choices and rights regarding your personal data.

If you use Mono as a business customer and Mono processes personal data on your behalf, the Data Processing Agreement (DPA) explains the processor terms that apply.

1. Data Controller and DPO Contact

Data Controller: Solid Technologies AG
Data Protection Officer (DPO): Jonas Kamber, jonas@mono.chat

If you have any questions, concerns, or requests regarding your personal data, please contact the DPO at the email address above.

2. Data Mono Collects

  1. Account Information: When you register, Mono may collect your email address and other information you voluntarily provide.
  2. Subscription and Billing Data: Subscription tier, billing country, tax status, and limited payment details. Payment processing is performed by third-party processors; Mono does not store full credit card numbers.
  3. User-Generated Content and Prompts: Inputs (e.g., prompts, files, images) and configuration settings you submit to use models, and the resulting outputs you choose to store with Mono.
  4. Usage Data and Logs: IP address, device and browser information, pages viewed, model selections, timestamps, feature interactions, diagnostics, and predefined product events. During the current service test, PostHog data is collected only after a logged-out visitor grants optional analytics consent or while a user is logged in. Eligible session replays mask form and input values, but rendered visible page content may be recorded. When PostHog tracking is active, Mono may associate selected product events with an account identifier and limited profile properties such as name, email address, language, and subscription plan.
  5. Cookies and Similar Technologies: Mono uses cookies, local storage, pixels, and similar technologies (see the Cookie Policy).

3. How Mono Uses Your Data

Mono uses personal data to:

  1. Provide and Operate the Service: Authenticate you; route prompts to selected models; deliver outputs; apply usage limits; and provide customer support.
  2. Billing and Account Management: Process payments, taxes, promotions, and subscription changes.
  3. Service Quality, Safety, and Performance: Monitor usage, enforce fair-use and security controls, prevent abuse and fraud, and improve functionality.
  4. Analytics and Development: Analyze usage patterns to improve and develop features.
  5. Communications: Send administrative messages, service updates, and responses to inquiries.
  6. Legal Compliance: Comply with legal and regulatory requirements and protect Mono's rights.

4. Lawful Bases for Processing

Depending on your jurisdiction, Mono processes personal data under one or more of the following bases:

  1. Consent: For optional PostHog tracking before login. PostHog is activated for a logged-out visitor only after analytics consent is granted.
  2. Contract Performance: To provide the Service under the Terms of Service.
  3. Legitimate Interests: To secure, test, and improve the Service, including product analytics and the temporary use of session replay for logged-in users and consenting visitors, prevent fraud, and communicate with you, where these interests are not overridden by your rights.
  4. Legal Obligation: Where processing is necessary to comply with applicable law.

5. Data Sharing and Transfers

  1. Third-Party Model Providers: To deliver model outputs, your prompts, outputs, and related metadata may be sent to third-party model providers. Those providers process data under their own terms and privacy policies. Inputs and outputs are not used to train providers' models unless the interface clearly discloses that the selected provider may use data for training and you explicitly agree before continuing.
  2. Infrastructure and Hosting: Mono uses third-party infrastructure (including Firebase/Google) which may process and store data on behalf of Mono.
  3. Payment Processors: Mono shares necessary billing information with payment processors for subscription payments and taxes.
  4. Analytics and Attribution: Mono uses PostHog Cloud EU to test and improve the Service. PostHog is initialized only after a logged-out visitor grants analytics consent or while a user is logged in. Certain logged-in users may be excluded from session replay under Mono's recording rules. When replay is active, it records page structure, rendered visible text, element attributes, and interaction sequences; form and input values are masked, and console-log, network-payload, and canvas capture are disabled. Because rendered visible text is not masked, readable page content displayed in the Service—including submitted prompts, model outputs, account details, and other text—may be sent to PostHog. Uploaded file contents are not intentionally captured unless rendered visibly on the page. Active PostHog tracking may also send predefined product events, a user or device identifier, and—after login—limited account properties such as name, email address, language, and subscription plan. Autocapture, automatic page views, automatic exception capture, and performance capture remain disabled. SparkLoop affiliate conversions are confirmed server side after a successful checkout when a SparkLoop referral was captured.
  5. Legal and Safety: Mono may disclose data to comply with law, enforce agreements, or protect rights, property, or safety.
  6. Business Transfers: In a merger, acquisition, or asset sale, personal data may be transferred as part of the transaction.

6. International Data Transfers

Core Mono customer data is hosted in Frankfurt, Germany. PostHog analytics data is sent to PostHog Cloud EU, hosted in Frankfurt. PostHog Inc. and its affiliates or subprocessors may nevertheless process limited data from other countries as described in PostHog's contractual privacy terms. Other providers, including model providers, may also process data outside Switzerland or the EEA. Where required by law, Mono uses appropriate safeguards such as adequacy decisions, the Swiss-U.S. or EU-U.S. Data Privacy Framework for certified recipients, and Standard Contractual Clauses (SCCs).

7. Data Retention

Mono retains personal data only as long as necessary for the purposes described in this Policy, to comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and use. PostHog browser identifiers may remain for up to 365 days unless browser storage is cleared. Session recordings are retained for up to 30 days. PostHog product events are subject to the retention setting configured by Mono and are deleted or de-identified when no longer necessary. When a valid deletion request applies, Mono also initiates deletion of the corresponding PostHog person and event data.

8. Your Rights

Depending on your location, you may have rights such as:

  • Access, Rectification, and Erasure
  • Restriction or Objection to Processing
  • Data Portability
  • Withdraw Consent (where processing relies on consent)

Residents of the EEA/UK and other jurisdictions with similar laws, and residents of certain U.S. states, may have additional rights as required by law. To exercise rights, contact the DPO at jonas@mono.chat. You may also have the right to lodge a complaint with a supervisory authority.

9. Security Measures

Mono implements technical and organizational measures designed to protect personal data against unauthorized access, loss, or alteration. However, no method of transmission or storage is completely secure, and Mono cannot guarantee absolute security.

10. Children's Privacy

The Service is not directed to individuals under 18, and Mono does not knowingly collect personal data from them. If you believe a minor has provided personal data to Mono, please contact Mono so the data can be deleted.

11. Third-Party Model Outputs and Provider Terms

Ownership, licensing, reuse, and restrictions for model outputs may depend on the relevant third-party model provider. You are responsible for reviewing and complying with those providers' terms before using or distributing outputs. Possible use of inputs or outputs for provider training is clearly disclosed in the interface and requires your explicit agreement before continuing.

12. Cookies and Consent Management

Mono presents a cookie settings overlay before PostHog is activated for a logged-out visitor. You can accept or reject optional analytics. Rejecting or withdrawing analytics consent prevents or stops PostHog tracking while you are logged out. While you are logged in, PostHog tracking may remain active independently of the public-site analytics choice. Necessary storage remains active because it is required for the Service to function and to remember your consent choice.

You can reopen and change your cookie settings at any time using the Cookie settings link on the Cookie Policy page. Changes apply going forward and may affect analytics-related insights.

13. Do-Not-Track and Global Privacy Control

Mono does not currently respond to browser “Do-Not-Track” signals or Global Privacy Control (GPC) signals, except where required by law.

14. Changes to This Privacy Policy

Mono may update this Privacy Policy from time to time. If Mono makes material changes, Mono will update the “Last Updated” date above and post the revised policy. Continued use of the Service after changes become effective constitutes acceptance.

15. Contact

If you have questions, concerns, or requests about this Privacy Policy, please contact the Data Protection Officer:

Jonas Kamber, jonas@mono.chat