Security
What happens to the data your team puts into Mongo Chat: who receives it, how long it is kept, and the controls you have over it.
- Where your data is stored
- Your workspace's conversations, files and settings are stored with our cloud hosting provider.
- Who receives it
- To answer a request, its text and the files it refers to are sent through our gateway to the provider of the model you chose. Web searches go to a search provider, and payments to our payment processors. The privacy policy describes each kind of provider we use.
- How long it is kept
- Your content stays until you or your workspace delete it. Temporary chats are deleted after 30 days. Deleting an account removes its conversations, files, projects and memories; usage records and the audit trail stay with the organisation, with the person's name removed.
- Encryption in transit
- The site, the app and the API are served only over HTTPS, so what you send is encrypted on its way to us.
- Separation between organisations
- Each organisation's data is kept separate. A person signed in to one workspace cannot see another workspace's conversations, files or settings.
- Admin controls
- Administrators invite and remove people, decide who else is an administrator, see usage by person and by model, and set spending budgets with alerts. Which models and features a workspace has follows its plan, and can be tailored on Enterprise.
- Audit log
- Administrative actions (changes to people, roles, settings and billing) are written to an audit log administrators can read.
- Export and deletion
- Every person can export all of their data from Settings, and delete their account.
- Payments
- Card and QR payments are handled by our payment processors. We never see or store card numbers.
Found a security issue? Tell us through the contact page. Machine-readable details are in security.txt.