Security

What happens to the data your team puts into Mongo Chat: who receives it, how long it is kept, and the controls you have over it.

Where your data is stored
Your workspace's conversations, files and settings are stored with our cloud hosting provider.
Who receives it
To answer a request, its text and the files it refers to are sent through our gateway to the provider of the model you chose. Web searches go to a search provider, and payments to our payment processors. The privacy policy describes each kind of provider we use.
How long it is kept
Your content stays until you or your workspace delete it. Temporary chats are deleted after 30 days. Deleting an account removes its conversations, files, projects and memories; usage records and the audit trail stay with the organisation, with the person's name removed.
Encryption in transit
The site, the app and the API are served only over HTTPS, so what you send is encrypted on its way to us.
Separation between organisations
Each organisation's data is kept separate. A person signed in to one workspace cannot see another workspace's conversations, files or settings.
Admin controls
Administrators invite and remove people, decide who else is an administrator, see usage by person and by model, and set spending budgets with alerts. Which models and features a workspace has follows its plan, and can be tailored on Enterprise.
Audit log
Administrative actions (changes to people, roles, settings and billing) are written to an audit log administrators can read.
Export and deletion
Every person can export all of their data from Settings, and delete their account.
Payments
Card and QR payments are handled by our payment processors. We never see or store card numbers.

Who we share data with

Found a security issue? Tell us through the contact page. Machine-readable details are in security.txt.

Try it with your team.

Setting up takes a minute.