← Back to Munshi

Privacy Policy

Last updated: September 4, 2026

This Privacy Policy explains what data Munshi ("we", "us") collects, why, and what rights you have. It applies to the Munshi app and website. We have tried to keep it plain: we collect what we need to run the Service, we protect it, and we do not sell it.

Munshi is operated by Dojo Labs LLC, a Wyoming limited liability company with its registered address at 30 N Gould St STE 52615, Sheridan, WY 82801, United States. Dojo Labs LLC is the data controller for the personal data described in this policy.

1. Information we collect

  • Account information: your name, email address, and a securely hashed password. We never store your password in plain text.
  • Workspace content: the company profile, strategy, prompts, and the content generated for and by you.
  • Connected‑service credentials: if you connect a social account (YouTube, LinkedIn, Instagram, Facebook, Threads, TikTok, Pinterest, Bluesky, X) or a publishing destination (WordPress, Ghost, Sanity, Webflow, Framer), we store the tokens needed to publish on your behalf. These are encrypted at rest.
  • Social platform data: content and performance information we retrieve from the accounts you connect. See section 5.
  • Payment information: handled by our payment processor (Paddle). We receive your subscription status but never see or store your full card number.
  • Usage and technical data: basic logs, IP address, the essential session cookie, and the analytics described in section 6.

2. How we use your information

We use your data to provide the Service: to authenticate you, generate and store your content, publish approved items to your connected channels, enforce plan limits, process billing, provide support, keep the Service secure, and comply with the law.

3. AI processing

To generate content, the relevant inputs are sent to our AI provider (OpenRouter, which routes to the underlying model) using our own, server‑side keys. Your content and inputs are not used to train AI models, and they are not sold or shared for advertising. Data retrieved from connected social platforms is never sent to an AI provider for training.

4. How we share your information (subprocessors)

We share data only with service providers who help us run Munshi, under contract and only as needed:

  • OpenRouter: AI content generation.
  • Outstand: social publishing infrastructure. When you connect a social account or publish a post, the content, media, and access tokens for that account are handled by Outstand on our behalf.
  • Paddle: subscription billing and payments.
  • Cloudflare: hosting, content delivery, and network security.
  • Resend: transactional email (sign-in codes, account and support messages).
  • Sentry: error monitoring. When something in Munshi crashes, Sentry receives the technical details of the failure: the error, the code path, and the release. It does not receive your content.
  • ClickUp and Discord: our support and alerting tools. When you file a bug report from inside Munshi, the report (your email address, what you wrote, the page you were on, and the screenshot if you attached one) is filed as a ticket in ClickUp and posted to a private Discord channel our team reads. A new signup also posts the account email address to that private Discord, and operational alerts about the Service go there too.
  • Backblaze B2: offsite storage for our nightly database backups, which contain a copy of workspace data. Backups are kept for 30 days and then deleted.
  • Channels you connect: we send your approved content to the publishing platforms you choose, at your direction.

We do not sell your personal data.

5. Social platform data

When you connect a social account, you authorise Munshi to act on that account on your behalf. We retrieve only what the Service needs: the identity of the connected account (so we can show you which account is connected), the posts Munshi publishes for you, and aggregate performance figures for those posts and that account.

We show this information only to members of your own workspace. We do not combine it with data from other customers, use it for advertising or ad targeting, use it to build or enrich profiles, or use it to train AI models. You can disconnect any account at any time from the Integrations page, which deletes the stored tokens for that account.

YouTube API Services

Munshi's YouTube features use YouTube API Services. By connecting a YouTube channel to Munshi you agree to be bound by the YouTube Terms of Service, and the information Google receives and processes is handled in accordance with the Google Privacy Policy.

What Munshi accesses through YouTube API Services, and why:

  • Uploading videos to your channel: when you publish or schedule a video in Munshi, we upload it to the channel you connected, using the title, description and thumbnail you entered and approved. We do not alter what you wrote, and we never publish anything you have not explicitly sent or scheduled.
  • Reading your channel and video information: we read the connected channel's identity so we can show you which channel is linked, and public statistics for the videos on it (such as view, like and comment counts) so we can report how your content performed.

We do not download, cache, or store copies of YouTube audiovisual content. We do not access other people's YouTube data, and Munshi has no comment, subscriber, or messaging surface.

You can revoke Munshi's access to your Google account at any time via the Google security settings page at https://security.google.com/settings/security/permissions, or by disconnecting the channel inside Munshi. Revoking access stops all further use and causes the stored tokens to be deleted.

Questions or complaints about how Munshi handles your YouTube data can be sent to support@munshi.social.

Facebook Pages, Instagram and Threads

Munshi's Facebook, Instagram and Threads features use Meta's APIs. When you connect a Facebook Page, an Instagram professional account, or a Threads profile, you do so as someone who administers it, and you authorise Munshi to act on it on your behalf. Information Meta receives and processes is handled in accordance with the Meta Privacy Policy.

What Munshi accesses through Meta's APIs, and why:

  • Publishing to your Page, account or profile: when you approve or schedule a post in Munshi, we publish it to the destination you connected, exactly as you wrote it. This includes posts, photos, videos, Reels and Stories. We never publish anything you have not explicitly sent or scheduled.
  • Reading which accounts you administer: we read the list of Pages and accounts you manage so you can choose which one to connect, and the identity of the connected one so we can show you which is linked.
  • Reading performance figures: we read aggregate figures for the connected Page or account and for its posts (such as reach, view, like, comment and share counts) so we can report how your content performed.
  • Reading and answering comments: we read the comments left on the posts Munshi published for you, and show them in your workspace so you can reply from Munshi. A reply is published only when a member of your workspace writes and sends it.
  • Removing your own content: where the platform allows it, we can delete a post or a comment that Munshi published for you, at your request.

Munshi does not read your private messages, and has no inbox or direct message surface. We do not use Meta data for advertising or ad targeting, we do not combine it with data from other customers, we do not use it to build or enrich profiles of any person, and we do not use it to train AI models. Comment authors' names and comment text are shown only to members of your own workspace, and only for posts Munshi published.

You can revoke Munshi's access at any time by disconnecting the account in Munshi, or from Facebook Settings under Business integrations. Disconnecting deletes the stored tokens and the platform data we had cached for that account. See Delete your data for step by step instructions.

LinkedIn Pages

When you connect a LinkedIn Company Page, you do so as an administrator of that Page, and you authorise Munshi to act on it on your behalf. What Munshi accesses, and why:

  • Publishing to your Page: when you approve or schedule a post in Munshi, we publish it to the Page you connected, exactly as you wrote it. We never publish anything you have not explicitly sent or scheduled.
  • Reading your Page's performance: we read the connected Page's identity so we can show you which Page is linked, and aggregate performance figures for its posts (such as impression, reaction, comment and share counts) so we can report how your content performed.

Munshi does not display, store, or export any LinkedIn member's profile data, and does not display the content of members' comments. Comment and reaction figures are shown only as aggregate counts. We do not use LinkedIn data for advertising, sales, recruiting, lead generation, CRM enrichment, audience building, or ad targeting; we do not combine it with other data to build or enrich profiles; and we do not operate a social‑feed surface.

Retention for LinkedIn data is capped below our general limits: Page administration and reporting figures are kept for at most one year, your Page's own posts and their metadata for at most six months, and member profile data is not stored at all. Disconnecting the Page in Munshi deletes the stored tokens and its retained data. You can also revoke Munshi's access from your LinkedIn settings at any time.

6. Cookies and analytics

Signing in sets one essential cookie: an HTTP‑only, secure session cookie that keeps you signed in. The Service cannot work without it.

We also use two analytics tools to see how people find Munshi and where they get stuck. Neither loads until you allow it. On your first visit to munshi.social a banner asks whether we may use analytics; until you choose Accept analytics, no script from either tool is loaded and no analytics cookie is set. Choosing Essential only keeps them off. Neither is used for advertising. We do not sell what they collect, and we do not use it to follow you around other companies' websites.

  • Google Analytics 4, on both munshi.social and app.munshi.social. It sets first‑party cookies (_ga, _ga_*) to count visits and to measure which pages and features get used. We send it page addresses and product events, such as a signup or a plan being chosen. We never send it your name, your email address, or anything you have written in Munshi. The only identifier attached is a random workspace ID that means nothing outside our own database. Google acts as our processor and its handling is covered by the Google privacy policy.
  • Microsoft Clarity, on our marketing website only. It is not loaded inside the app, and it is never loaded on the checkout page. It sets cookies (_clck, _clsk) and records a session replay of how visitors move through the public pages, including mouse movement, clicks and scrolling, so we can see which parts of the site confuse people. Its handling is covered by the Microsoft privacy statement.

Your choice is stored in your browser, not on our servers, and you can change it at any time: reopen the analytics choice. Clearing this site's data in your browser also resets it, and any browser setting or extension that blocks analytics scripts blocks both tools. Nothing in Munshi stops working if you decline.

7. Data retention

We keep your data for as long as your workspace is active, and for a limited period afterward as needed for security, legal, and accounting purposes. When you delete your workspace, we delete its data (see your rights below).

Data retrieved from connected social platforms is handled in two ways. Performance figures for your posts and accounts are kept for as long as the account stays connected, so you can see how your content performed over time. Everything else we retrieve from a platform (a post's title, its description, the connected account's name and picture) is refreshed rather than accumulated: we keep only the latest copy. All of it is deleted when you disconnect the account or delete your workspace.

8. Security

We take security seriously: passwords are hashed, connected‑service credentials are encrypted at rest, sessions use secure, HTTP‑only cookies, and each workspace's data is strictly isolated from every other workspace. No system is perfectly secure, but we work to protect your data and to limit what any single failure could expose.

9. Your rights

Depending on where you live (including under GDPR and CCPA), you have rights to access, correct, export, and delete your personal data, and to object to or restrict certain processing. Munshi supports this directly:

  • Disconnect: you can disconnect any connected social account yourself, at any time, from Settings and then Integrations. This deletes the stored tokens and the platform data we had cached for that account.
  • Export: email us and we will send you a full export of your workspace data.
  • Delete: a workspace owner can have the workspace and all of its data permanently deleted. Because the action is permanent and affects every member of the workspace, we confirm the request with the owner before we run it.

Full instructions are on Delete your data. You can also email info@munshi.social to exercise any of these rights, and we will action the request within 30 days.

10. International transfers

Our providers may process data in countries other than yours. Where we transfer personal data internationally, we rely on appropriate safeguards as required by applicable law.

11. Children

Munshi is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children.

12. Changes

We may update this policy as the Service evolves. If we make a material change we will take reasonable steps to notify you, and we will update the date at the top of this page.

13. Contact

Questions about your privacy? Email info@munshi.social.