Skip to main content

MyntriqOS Privacy Policy

Last Updated: 19 June 2026

Applies to: MyntriqOS platform (distinct from the Myntriq website privacy policy at `/legal/privacy`)

Company: Myntriq Pte Ltd (UEN 202537571M), Singapore

Contact: hello@myntriq.io


Introduction

This Privacy Policy describes how Myntriq Pte Ltd ("Myntriq", "we", "us", "our") collects, processes, and protects information when you or your organisation uses the MyntriqOS platform.

This policy applies to the MyntriqOS platform — the authenticated dashboard, AI agents, governance tools, and APIs available to registered customers. It is separate from the website privacy policy that applies to visitors of `www.myntriq.io`.

By using MyntriqOS, you accept this policy on behalf of yourself and your organisation.


1. Two Types of Data Controller

It is important to understand who controls different categories of data in MyntriqOS:

Myntriq as Data Controller — for data Myntriq collects to operate its business: account information, billing, authentication credentials, platform usage analytics, and platform communications.

Customer as Data Controller, Myntriq as Data Processor — for data the customer enters into MyntriqOS: customer content (conversations, knowledge base documents, business data, agent configurations, and any personal data of the customer's own users or third parties that the customer uploads or processes through the platform). For this data, the customer is the Data Controller and Myntriq processes it only to provide the platform services. The Data Processing Addendum governs this relationship.


2. Information Myntriq Collects

2.1 Account and Organisation Information

When a customer organisation is onboarded to MyntriqOS, Myntriq collects:

  • Organisation name and unique identifier
  • Administrator email address and profile information
  • User email addresses and profile information for each added user
  • Role assignments (admin, member, viewer)
  • Organisation settings and preferences

This information is collected to create and manage the customer's platform account and is processed under Myntriq's legitimate interest in providing the contracted service.

2.2 Authentication Data

Myntriq uses Supabase Auth to manage authentication. When users sign in, Myntriq collects:

  • Authentication method (Google OAuth or email/password)
  • Session identifiers (stored as httpOnly cookies; not accessible to JavaScript)
  • Sign-in timestamps and authentication history
  • Device and browser information for session management

Authentication data is retained for the duration of the account plus 12 months following account termination, except where longer retention is required by law.

2.3 Platform Usage Data

Myntriq collects platform usage data to operate the service, enforce usage limits, generate billing data, and improve platform performance. This includes:

  • Feature interactions (pages visited, features used, agents configured)
  • AI model usage metrics: model invoked, token counts, estimated cost, outcome
  • API request logs: endpoint, timestamp, response time, status code
  • Error and diagnostic logs

Usage data is associated with the organisation and user identifier, not retained as individually profiled records.

2.4 Customer Content

Customer content is data that the customer and its users enter into MyntriqOS. This includes:

  • Conversations: Messages and responses exchanged with AI agents
  • Prompts: Instructions and context submitted to AI models
  • Knowledge base documents: Files, text, and data uploaded to train or inform agents
  • Business data: Data entered into business modules (CRM contacts, HR records, financial figures, campaign data) where applicable modules are in use
  • Agent configurations: Instructions, personas, and workflow settings defined for AI agents

Customer content is processed by Myntriq solely to provide the platform services. Myntriq does not use customer content to train its own AI models. Myntriq does not sell, share, or use customer content for purposes outside the contracted service.

2.5 Audit Log Data

MyntriqOS maintains an audit log of all actions taken by users and agents within the platform. Audit log entries contain:

  • User or agent identifier
  • Timestamp
  • Action type and description
  • Outcome (success/failure)
  • AI model used and cost (for agent actions)

Audit logs are available to organisation administrators through the Governance Dashboard. They are retained for a minimum of 24 months.


3. How Myntriq Uses Information

Myntriq uses the information described above for the following purposes:

PurposeData UsedLegal Basis
Providing and operating MyntriqOSAccount data, authentication data, customer content, usage dataContract performance
Authentication and session managementAuthentication dataContract performance
Billing and subscription managementUsage data, account dataContract performance
Platform support and troubleshootingUsage data, error logs, customer content (where shared with support)Contract performance / Legitimate interest
Security monitoring and incident detectionUsage data, authentication data, audit logsLegitimate interest
Platform improvement (aggregate/anonymised)Anonymised usage metricsLegitimate interest
Legal complianceAs required by applicable lawLegal obligation

Myntriq does not use customer content for advertising, model training, or any purpose outside the contracted service.


4. AI Model Processing

MyntriqOS routes AI inference requests through third-party model providers. When a user or agent submits a prompt, that prompt — together with any context from the conversation history or knowledge base — is sent to the selected AI model provider for processing.

Current model providers:

ProviderModelProcessing Location
OpenAIGPT-4oUnited States
AnthropicClaudeUnited States
OpenRouter (Meta Llama)Llama 3.3United States

All model inference requests are routed through Myntriq's LiteLLM service. Customers do not interact with model providers directly.

What model providers receive: The prompt text, system instructions, and conversation context required to generate a response. Model providers do not receive account identifiers, billing information, or other platform metadata.

Model training: OpenAI and Anthropic do not use data submitted through their commercial APIs to train their models, under the terms of their enterprise API agreements. Myntriq does not use customer prompts or responses to train its own AI models.

Cross-border transfers: AI inference requests are processed in the United States. Customers who submit personal data of Singapore residents or EU/EEA individuals as part of prompts should be aware of this transfer and should apply appropriate safeguards (such as pseudonymisation or data minimisation) when submitting personal data to AI agents.


5. Subprocessors

Myntriq uses the following third-party subprocessors to deliver MyntriqOS:

SubprocessorPurposeLocation
Google Cloud PlatformCompute, secrets, container registrySingapore
SupabaseDatabase, authentication, storageSingapore
OpenAIAI model inference (GPT-4o)United States
AnthropicAI model inference (Claude)United States
OpenRouterAI model inference (Llama 3.3)United States

The complete and current Subprocessor List, including DPA availability for each subprocessor, is maintained at the Myntriq Trust Centre.


6. Data Retention

Myntriq retains platform data in accordance with the following schedule:

Data CategoryRetention Period
Account and organisation dataDuration of account + 12 months
User profilesDuration of account + 12 months
Conversation historyDuration of account + 12 months
Knowledge base documentsDuration of account; deleted within 30 days of account termination
Audit logs24 months minimum
AI usage metrics24 months
Authentication session tokensSession-scoped; cleared on sign-out
Error and diagnostic logs90 days

Following account termination, Myntriq will delete or anonymise customer data within 30 days, unless longer retention is required by law or by the terms of the Data Processing Addendum.

Customers may request early deletion of specific data categories by contacting hello@myntriq.io.


7. Security

Myntriq implements technical and organisational security measures appropriate to the risks associated with processing customer data. These are described in detail in the Myntriq Security Overview.

Key controls include:

  • AES-256 encryption at rest for all customer data in the database
  • TLS encryption in transit for all connections
  • Row-level security (RLS) enforcing strict tenant isolation at the database layer
  • Secrets management via Google Cloud Secret Manager
  • Role-based access control within organisations
  • Immutable audit logging of all user and agent actions

In the event of a personal data breach affecting customer data, Myntriq will notify affected customers in accordance with the incident response process described in the Security Overview.


8. International Data Transfers

MyntriqOS's primary data store and compute infrastructure are hosted in Singapore. However, AI model inference requests are processed by OpenAI, Anthropic, and OpenRouter in the United States.

Where customer data — including personal data of Singapore residents — is transferred outside Singapore for AI model processing, Myntriq relies on:

  • The commercial API terms of model providers, which include data processing commitments
  • Data minimisation: prompts should contain only the information necessary for the task; personal data should be anonymised or pseudonymised where possible

Customers in regulated sectors or with explicit data residency requirements should contact hello@myntriq.io to discuss available configuration options.


9. Customer Rights

Customers (as Data Controllers for their own data) may exercise the following rights with respect to data Myntriq holds about the customer organisation and its users:

Access — request a copy of the personal data Myntriq holds about the organisation's users.

Correction — request correction of inaccurate personal data.

Deletion — request deletion of personal data. Myntriq will comply within 30 days except where retention is required by law or legitimate business interest.

Data portability — request export of conversation history, knowledge base content, and agent configurations in a portable format (where technically feasible).

Objection — object to processing based on Myntriq's legitimate interest.

To exercise any of these rights, contact hello@myntriq.io. Myntriq will respond within 30 days.

Rights of individual users within a customer organisation: individual users who wish to exercise data subject rights should contact their organisation's administrator in the first instance, as the customer is the Data Controller for user data entered into the platform.


10. Children's Data

MyntriqOS is a business platform intended for use by organisations and their employees. It is not directed at individuals under 18 years of age. Myntriq does not knowingly collect personal data from minors.

If a customer uploads or processes personal data of minors through MyntriqOS, the customer is responsible for ensuring they have the appropriate legal basis and parental or guardian consent to do so.


11. Changes to This Policy

Myntriq may update this Privacy Policy from time to time. Material changes will be communicated to customers through the platform or by email at least 14 days before taking effect.

The effective date at the top of this document will reflect the date of the most recent update.


12. Contact

For privacy enquiries, data subject rights requests, or to report a data protection concern, contact:

Myntriq Pte Ltd

Data Protection

hello@myntriq.io

Singapore

Myntriq's Data Protection Officer can be reached at hello@myntriq.io marked "Attn: Data Protection".