Privacy Policy
- Last Updated:December 29, 2023
Overview
Megapodes is a self-hostable, AI-powered platform for building business systems. We are committed to protecting your privacy and giving you control over your data. This policy explains how we handle data across our self-hosted, Cloud, and Enterprise offerings.
Megapodes Technologies Pvt. Ltd. (update with exact registered legal name), a company incorporated under the laws of India, serving customers globally, is the data controller (and, under India’s DPDP Act, the data fiduciary) for megapodes.com and the services described in this policy.
Key takeaway: When you self-host Megapodes, your data never leaves your infrastructure. We have no access to your data, your models, or your applications.
Legal Frameworks
We serve customers globally and design our data-handling practices in alignment with the data protection laws that apply to them:
- India — Digital Personal Data Protection Act, 2023 (DPDP Act): As an Indian entity, we process personal data on lawful grounds with notice and consent where required, honor data principals’ rights to access, correction, and erasure, and maintain a grievance-redressal mechanism (see below).
- EU/UK — GDPR and UK GDPR: For personal data of EU and UK data subjects, we act as controller (for account data) or processor (for customer application data in Cloud), honor data-subject rights, and apply appropriate transfer safeguards.
- California — CCPA/CPRA: California residents have the rights to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell personal information.
Where a customer’s enterprise agreement or DPA imposes stricter obligations, those terms govern.
Self-Hosted (Licensed Deployment)
When you self-host Megapodes, all data — application metadata, user data, AI model interactions, knowledge base documents — resides on your own infrastructure. We do not collect, transmit, or have access to any of your data.
- No telemetry: The self-hosted version does not phone home or send analytics.
- No cloud LLM dependency: AI inference runs locally via Ollama on your GPU host.
- Your data, your rules: You are responsible for backups, encryption at rest, and access controls.
Cloud (Managed Hosting)
When you use our managed Cloud offering, we process and store your application data on our infrastructure. Here’s what we collect and how we use it:
- Account data: Name, email, and workspace settings for account management.
- Application data: All metadata, records, and configurations you create within your workspace.
- Usage data: Aggregate metrics (app count, user count, API calls) for billing and service management.
- AI interactions: Build session logs and AI Employee runs are stored for audit purposes within your workspace.
We do not:
- Sell or share your data with third parties.
- Use your data to train AI models.
- Access your application data without your explicit permission.
Subprocessors: The Cloud offering uses a small number of subprocessors for hosting, email delivery, and payment processing; a current list is available on request via privacy@megapodes.com.
Enterprise
Enterprise customers run on dedicated infrastructure (on-premise or private cloud). Data handling is governed by your enterprise agreement, including custom DPA, data residency requirements, and access controls.
International Data Transfers
How your data moves — or doesn’t — depends on your deployment model:
- Self-hosted: All data remains on customer infrastructure in the customer’s chosen jurisdiction. No personal data or application data is transferred to us, so no cross-border transfer to Megapodes occurs.
- Cloud: We offer data residency options so your workspace can be hosted in a region agreed with you. Where personal data of EU or UK data subjects is transferred internationally, we apply appropriate safeguards such as Standard Contractual Clauses (SCCs) and, where applicable, the UK Addendum, together with supplementary technical measures (encryption in transit and at rest).
- Enterprise: Residency and transfer terms are defined in your enterprise agreement and DPA.
Grievance Redressal (DPDP Act)
In accordance with India’s Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address questions, concerns, or complaints regarding the processing of personal data. Grievance Officer: contact privacy@megapodes.com. We acknowledge and respond to grievances within the timelines prescribed under applicable law.
Data Security
Megapodes is designed with security as a structural principle:
- PostgreSQL Row-Level Security (RLS): Forced on every tenant table.
- Envelope encryption: External data source credentials are encrypted with a per-source data key wrapped by a KMS-managed key, and never persisted in plaintext or logged.
- Argon2id: Password hashing resistant to GPU/ASIC attacks.
- Short-lived JWTs: Authentication tokens expire quickly.
- Audit logging: Every structural mutation is logged with full diff and approver.
- Fail-closed: If any security gate can’t be satisfied, the operation fails loudly.
Your Rights
Depending on your jurisdiction (DPDP Act, GDPR, CCPA, etc.), you may have the right to:
- Access your personal data.
- Request correction or deletion.
- Export your data (app portability feature).
- Object to processing.
- Withdraw consent.
To exercise these rights, contact us at privacy@megapodes.com.
Cookies
Our website uses minimal cookies for essential functionality. We do not use tracking cookies, advertising cookies, or third-party analytics. We use the following cookies:
- Session cookie: Required for authentication (Cloud users only).
- CSRF token: Required for form security.
Our website loads fonts from Google Fonts, which transmits your IP address to Google; self-hosted Megapodes deployments load no external resources.
Changes to This Policy
We may update this privacy policy from time to time. We will notify users of material changes via email or in-app notification. The “Last updated” date at the top of this page reflects the most recent revision.
Contact
Questions about privacy? Email privacy@megapodes.com or use our contact form.
The governed AI application platform. A local AI builds business systems as validated configuration, every change is human-approved, and it all runs on your infrastructure.