Opening Monarch.
Opening Monarch.
Privacy
Last updated: July 12, 2026
Operator:Monarch LLC, a New York limited liability company ("Monarch," "we," "our," "us").
This Privacy Policy describes how Monarch handles personal data when you use our service at flymonarch.ai (the "Service"). It covers four audiences: Customers (organizations and individuals paying for a Monarch tenant), End Users (people invited to a Monarch tenant by a Customer), Recipients (people who receive an email or one-pager sent through Monarch), and Visitors (people who browse flymonarch.ai without an account). The Service is offered to US-based customers during the public beta.
If you have questions, email privacy@flymonarch.ai.
Account and Tenant Data. Name, work email, and the organization name provided at signup; authentication credentials (password hash, OAuth tokens, MFA setup if used); tenant configuration including brand profile, voice profile, settings, and sender physical address; and billing data including name, billing email, and a payment method handle from Stripe. Monarch does not store full card details; Stripe handles all card data.
End User Data. Name, work email, role, and join date; authentication credentials including OAuth tokens for Gmail, HubSpot, Salesforce, and any other authorized provider; activity logs (captures created, drafts generated, emails sent, settings changed); and voice profile audio samples if the End User opts in.
Capture, transcript, draft, and send data. Audio recording or text note, the transcript generated by our transcription subprocessor, the draft email generated by our drafting subprocessor, one-pager content and rendered PDF if used, the sent email content, send time, message ID, and delivery status, and replies, bounces, opens, clicks, and complaints associated with the send.
Recipient Data. Name, work email, phone, title, company, LinkedIn URL, and other professional context the End User provides or that the enrichment cascade returns; enrichment data from Apollo, Hunter, Clay, or other configured enrichment providers; the conversation history Monarch has tracked between the Tenant and the Recipient; and engagement data such as whether the Recipient opened or clicked Monarch-sent email (if tracking is enabled). We treat enrichment data about Recipients as personal data subject to the same protections as account data.
Visitor Data. IP address (briefly retained for security and analytics), user agent and basic device info, pages visited and timestamps, referral source (UTM parameters, referrer header), and cookie consent state.
We process personal data to deliver the Service (capture, transcribe, enrich, draft, send, and log), to operate billing through Stripe, to maintain security (detect abuse, prevent fraud, investigate incidents), to communicate (product updates, transactional email, support, and legal notices), and to improve the Service through aggregate usage analytics. We do not use Customer Data to train foundation models offered to other customers. Where GDPR applies, our legal bases are contract (to deliver the Service), legitimate interests (security, fraud prevention, abuse investigation, aggregate analytics), consent (non-essential cookies and marketing email where required), and legal obligation (tax records, court orders, lawful requests).
Cookies. We use strictly necessary cookies (authentication, security, basic site function), functional cookies (remembering preferences), and analytics cookies (aggregate site usage). Affiliate attribution may be captured from referral links and retained in first-party browser storage for up to 30 days so a signup can be credited after the visitor returns. Cookie consent is presented via a banner on first visit, and you can change your choices at any time at flymonarch.ai/cookies.
Email tracking.Monarch-sent emails may include open-tracking pixels and click-tracking link rewrites, and one-pagers may collect view analytics; tracking is configured by the Customer. When tracking is on, every Monarch-sent email includes a footer disclosure, and a Recipient who replies "no-track" is recorded in a no-tracking flag so future sends skip the tracking pixel and use plain links.
We share personal data only in these ways. We use a small set of subprocessors to deliver the Service, listed at flymonarch.ai/dpa, each bound by data-protection terms equivalent to ours. When a Customer authorizes an integration (Gmail, HubSpot, Salesforce, Apollo, etc.), Monarch exchanges data with that provider as needed to deliver the Service, and the provider's own privacy policy governs that provider's handling. Monarch-sent emails contain data the End User authored and optionally a one-pager; Recipients see only what the End User chose to send. We may disclose personal data to comply with applicable law, court orders, subpoenas, or lawful requests, or to protect rights, property, or safety, and where permitted we will notify affected Customers before disclosure. In a merger, acquisition, or asset sale, personal data may transfer to the acquiring entity subject to the protections of this Privacy Policy or a successor policy with equivalent protections.
We do not sell personal dataas that term is defined under the CCPA or similar state laws, and Monarch does not "share" personal data for cross-context behavioral advertising.
Subprocessors (draft — under review). The list below names the third-party providers Monarch currently uses to deliver the Service. It is a best-effort summary being finalized with counsel; the authoritative, current list lives in our Data Processing Agreement. Some providers are only engaged when a Customer authorizes the relevant feature or integration, and the specific transcription or enrichment provider used may depend on configuration.
The Service runs on Google Cloud Platform in the United States (region us-central1). Enterprise customers may select a data residency region. The Service is offered to US-based customers during the beta. For any Customer or Recipient outside the United States, transfers to the U.S. are made under appropriate safeguards, including Standard Contractual Clauses where required, per our Data Processing Agreement.
Recipient rights (applies to anyone who receives a Monarch-sent email). Regardless of where you live, you may request access to the data we hold about you, request deletion (we will remove your data from all tenants that have records about you and ask each tenant's CRM to do the same), request correction of inaccurate data, unsubscribe via any unsubscribe link or by replying "unsubscribe" or "stop," and reply "no-track" to opt out of email and one-pager tracking. Submit requests by email to privacy@flymonarch.ai.
EU / UK rights (GDPR). If you are in the EU or UK, you also have the right to object to processing based on legitimate interests, to restrict processing in certain circumstances, to portability of your data, to withdraw consent at any time where processing is based on consent, and to lodge a complaint with your data protection authority. Monarch operates US-only during the public beta and has not appointed an EU Article 27 or UK representative; this section applies if and when Monarch offers the Service in the EU/UK.
California rights (CCPA / CPRA).If you are a California resident, you have the right to know what personal information we collect, use, and disclose and to whom; to delete personal information; to correct inaccurate personal information; to opt out of "sale" or "sharing" of personal information (we do not sell or share); to limit use of sensitive personal information (we do not collect sensitive personal information beyond what is necessary for the Service); and to non-discrimination for exercising your rights. To exercise these rights, email privacy@flymonarch.ai.
Other state privacy laws. For residents of Colorado, Connecticut, Utah, Virginia, and other states with similar privacy laws, the same request flow applies. To protect your data, we verify your identity before fulfilling rights requests. For Customers and End Users with a Monarch account, most rights are exercised in-app from the account security and tenant data-and-privacy screens.
Where retention is "tenant lifetime," data is purged 30 days after Tenant deletion, except for the categories above with explicit legal retention.
Deletion and the 30-day window.When a Tenant is deleted, the workspace is immediately deactivated and access is removed, and the data enters a 30-day grace period (a "soft delete"). During that window the deletion is reversible — an Owner can be restored with no data loss. After 30 days the data is permanently purged and cannot be recovered. The one exception is a legal hold: if data is under a legal hold (for example, to preserve records for a legal or regulatory matter), it is retained beyond the 30-day window and is not purged until the hold is released. The categories listed above with their own legal retention period (such as billing records and unsubscribe records) are also kept for that period.
We protect personal data using TLS in transit and AES-256 at rest, GCP-managed Cloud SQL with private VPC access, provider credentials stored only in GCP Secret Manager, tenant isolation at the data layer, audit logs for all administrative actions, background checks on personnel with production data access, and a defined incident response process. In the event of a personal data breach affecting your data, we will notify affected Customers and, where required, regulators, without undue delay and consistent with applicable law.
The Service is intended for business users and is not directed at children under 13 (under 16 in the EU). We do not knowingly collect personal data from children.
We may update this Privacy Policy. Material changes will be communicated by email to the Owner and by an in-product modal at next sign-in. The "Last updated" date at the top of this policy will be updated for any change.
Email privacy@flymonarch.ai. Postal: Monarch LLC, 418 Broadway STE N, Albany, NY 12207. No Data Protection Officer, EU Representative, or UK Representative is appointed during the US-only beta. For data subject requests, email privacy@flymonarch.ai so we can verify your identity and route to the right tenant(s). You can also email legal@flymonarch.ai.