← Back to Monika AI
1. Introduction
Monika AI ("we," "us," or "the Service") is an AI companion chatbot powered by Google Gemini. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the choices you have regarding your information.
By creating an account or using Monika AI, you acknowledge that you have read and understand this Privacy Policy.
2. Data We Collect
We collect the following categories of personal data:
- Account identifiers — Your email address (for email/Google Sign-In login) or phone number (for phone/SMS login). If you sign in with Google, we also receive your Google profile name.
- Chat messages — The text content of every message you send and every response Monika generates, stored per-conversation in our database.
- Memories (facts) — Short preference or profile facts extracted from your conversations (e.g., "User likes coffee"), used to personalize responses across sessions.
- User settings — Preferences you configure such as personality mode, response length, language, theme, voice, and notification preferences.
- Device and session information — Browser name, operating system, a cryptographic hash of your IP address, and a hash of your User-Agent string. These are stored per login session to let you review and revoke active devices.
- Attachments metadata — File name, MIME type, size, and kind (image/PDF/text) for files you attach to messages. Raw file data is transmitted to the AI provider for analysis but is not persistently stored in our database.
- Reminders — Reminder text, scheduled time, recurrence, and delivery status for reminders you create.
- Usage metrics — Daily counts of messages sent, images processed, and estimated token usage, aggregated per user per day.
3. How We Use Your Data
- Providing the Service — Your messages and memories are sent to the Google Gemini API to generate Monika's responses. Conversation history (up to 16 recent messages) and up to 20 stored memories are included as context in each request.
- Authentication — Your email or phone number is used to verify your identity via Google Sign-In, Firebase Phone Authentication, or our email OTP system.
- Session management — Device and session data lets you see which browsers are signed in and revoke access from unrecognized devices.
- Personalization — Your settings and memories customize Monika's behavior, language, personality, and response style.
- Notifications — If you enable browser notifications, we use Web Push to deliver reminders you've scheduled.
- Security and abuse prevention — We log rate-limit events and authentication failures in an audit log (retained for 180 days) to detect and prevent abuse.
4. Third-Party Services
We integrate with the following third-party services:
- Google Gemini / Google GenAI — Your messages, conversation history, memories, and attachment content are sent to the Gemini API for response generation. Google's Gemini API Terms and Google Privacy Policy apply to this processing.
- Google Sign-In (GSI) — If you log in with Google, your email and profile name are provided by Google's Identity Services. Google's own privacy policy governs how Google handles your credentials.
- Firebase Authentication — If you log in with a phone number, Firebase Phone Authentication and reCAPTCHA are used to verify your identity. Firebase Privacy applies.
- SMTP Email Service (Brevo) — For email OTP codes, welcome emails, and login alert notifications, we use an SMTP relay service. Your email address and the message content are transmitted through this service.
5. Cookies, Local Storage, and Session Data
We use the following browser-side storage:
- Session cookie (
__Host-monika_refresh or monika_refresh) — An HTTP-only, secure cookie containing a cryptographically random refresh token. This keeps you signed in across page loads and is rotated on every session refresh.
- CSRF cookie (
_csrfSecret) — An HTTP-only cookie used for cross-site request forgery protection on all state-changing requests.
- localStorage keys —
monika_session_hint (boolean flag for fast session detection), monika_theme (your selected theme), monika_current_conversation (last active conversation ID), and monika_draft (unsent message draft). These contain no sensitive personal data.
We do not use third-party tracking cookies or advertising cookies.
6. Data Retention
- Chat messages and conversations — Retained indefinitely until you delete individual conversations or your entire account.
- Memories — Retained indefinitely, capped at the 100 most recent per user. You can delete individual memories or clear all memories from the Memory settings tab.
- Sessions — Expire after the configured session TTL (default: 365 days) or when you manually revoke them.
- OTP codes — Automatically expire and are deleted after 5 minutes.
- Audit events — Automatically deleted after 180 days.
- Usage metrics — Retained indefinitely in aggregate form (daily counts only, no message content).
7. Your Rights
You have the following rights over your data:
- Export — You can export any conversation as a TXT, Markdown, or PDF file using the toolbar buttons in the chat interface.
- Delete conversations — You can delete individual conversations from the sidebar, or clear all chat history from the sidebar footer.
- Delete memories — You can remove individual memories or clear all stored memories from Settings → Memory.
- Revoke sessions — You can log out individual devices or all other devices from Settings → Devices.
- Delete your account — You can permanently delete your account and all associated data (messages, conversations, memories, sessions, reminders, push subscriptions, settings, and usage data) from Settings → Privacy → "Delete my account and all data." This action is irreversible.
If you need assistance exercising your rights, contact us at tagadearpit@gmail.com.
8. Data Security
We implement the following security measures:
- All connections are encrypted via HTTPS/TLS.
- Refresh tokens are hashed before storage; raw tokens are never persisted.
- OTP codes are cryptographically hashed (HMAC-SHA256) before storage.
- IP addresses are hashed and never stored in plain text.
- CSRF double-submit token protection on all state-changing requests.
- Content Security Policy (CSP) headers restrict script and resource loading.
- Rate limiting on authentication and API endpoints to prevent brute-force attacks.
9. Children's Privacy
Monika AI is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by requiring re-acceptance of the updated policy upon your next login. The "Last updated" date at the top of this page indicates when the policy was last revised.
11. Contact
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
tagadearpit@gmail.com