Sign up

Privacy Policy

Last updated: 22 August 2026

This Privacy Policy explains how MontiGate LLC (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you visit montigate.com, create an account, or use the Monti Browser desktop application and related services (together, the “Service”).

MontiGate LLC is the data controller for the personal data described here. Our payment provider, Paddle.com Market Ltd, acts as the Merchant of Record for every purchase and is an independent controller of the billing data it collects. We collect the minimum we need to run the Service, we do not sell personal data, and we do not use it for advertising.

1. Who we are and how to reach us

MontiGate LLC is a limited liability company registered in the United States, with its registered office at the address below.

MontiGate LLC
102 Gold Avenue Southwest

Albuquerque, NM 87102

United States

Email: info@montigate.com
Phone: +1 (737) 225-6131

Website: montigate.com

Use the email address above for any privacy question, data subject request, or complaint. We are a small team and answer privacy requests directly — there is no separate privacy office to route you through.

2. Scope of this policy

This policy covers the montigate.com website, the Monti Browser account and dashboard, the Monti Browser desktop application for macOS and Windows, and the API that the application uses. It does not cover third-party websites, services, or AI clients you connect to or reach through Monti, each of which has its own privacy policy.

By creating an account or using the Service you confirm that you have read this policy. Where we rely on your consent, you may withdraw it at any time as described below.

3. Personal data you give us

  • Account data — your email address and authentication credentials. Passwords are never stored in readable form; if you sign in with Google we receive your email address and basic profile identifiers from Google, not your Google password.
  • Organization data — the organization you belong to, your role in it, and your plan and entitlement settings, which the Service uses to enforce your session and concurrency limits.
  • Billing data — collected by Paddle at checkout (name, billing address, country, tax identifiers, and payment details). We never see or store your card number. Our own records hold only your plan, subscription status, subscription identifier, and current billing period end date.
  • Support data — the contents of emails and messages you send us, including anything you choose to attach.

4. Data collected automatically

  • Server and security logs — IP address, request time, requested path, user agent, and response status, generated by our hosting and CDN providers and used to operate the Service, investigate abuse, and diagnose faults.
  • API authentication records — when the desktop application calls our API we record which API token was used and when, so you can spot and revoke tokens you no longer recognise.
  • Application diagnostics — non-identifying information such as application version and operating system, sent with support and error reports.

We do not use advertising networks, behavioural tracking pixels, or cross-site trackers.

5. What we deliberately do not collect

Monti Browser is an automation browser. The browsing it performs happens on your own computer, and the data that browsing produces stays there:

  • We do not receive the pages you or your agents visit, their content, or your browsing history.
  • Browser session profiles, cookies, and any logins you store in the desktop application are held in that application’s encrypted local storage on your device.
  • Network routes and proxy credentials you configure, including anything you import from CSV, are stored locally and are not transmitted to us.
  • Prompts and results exchanged between Monti and your AI client run over a local MCP endpoint on your machine. Your AI provider’s own privacy policy governs anything you send to that provider.

What our servers hold for a paid account is deliberately small: your profile, your organization and membership, your entitlements, your subscription record, and the hashed API tokens described below.

6. How we use personal data, and our legal bases

  • To provide the Service — creating and authenticating your account, enforcing plan limits, and syncing your account across devices. Legal basis: performance of a contract.
  • To take and manage payments — processing subscriptions, renewals, cancellations, refunds, and applicable taxes through Paddle. Legal basis: performance of a contract and legal obligation.
  • To support you — answering questions and resolving problems you report. Legal basis: performance of a contract and legitimate interests.
  • To keep the Service secure — detecting, investigating, and preventing fraud, abuse, and unauthorised access. Legal basis: legitimate interests and legal obligation.
  • To improve the Service — aggregate, non-identifying analysis of how features are used. Legal basis: legitimate interests.
  • To send service messages — receipts, renewal and payment notices, security alerts, and material changes to this policy or our terms. Legal basis: performance of a contract and legal obligation.
  • To send optional product news — only where you have opted in. Legal basis: consent, withdrawable at any time.
  • To comply with law — meeting tax, accounting, and other statutory obligations, and responding to lawful requests. Legal basis: legal obligation.

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects for you.

7. Payments and Merchant of Record

Our order process is conducted by our online reseller Paddle.com Market Ltd. Paddle is the Merchant of Record for all our orders: Paddle handles the checkout, collects payment, calculates and remits applicable sales tax and VAT, and manages customer enquiries and returns relating to the transaction. Paddle, not MontiGate LLC, will appear on your card or bank statement.

Payment details are entered on Paddle’s systems and are processed under Paddle’s Privacy Policy and Buyer Terms. MontiGate LLC never receives your full card number, expiry date, or security code. When a subscription is created, changed, or cancelled, Paddle notifies us of the subscription identifier, its status, the plan purchased, and the billing period end date, and we record only those fields against your organization.

8. Who we share data with

We do not sell, rent, or trade personal data. We share it only with the service providers below, each of which acts on our instructions under a data processing agreement, except where noted:

  • Paddle.com Market Ltd (United Kingdom) — payments, tax, invoicing, and subscription management. Independent controller of the billing data it collects.
  • Supabase — authentication, database hosting for account, organization, entitlement, and subscription records.
  • Vercel — hosting and delivery of the website and API.
  • Cloudflare — content delivery, network security, and distribution of desktop application downloads.
  • Google — only if you choose Google sign-in, for the purpose of authenticating you.

We may also disclose personal data where we are legally required to, to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of our users or the public. If MontiGate LLC is involved in a merger, acquisition, or sale of assets, personal data may transfer to the acquirer; we will notify you before your data becomes subject to a different privacy policy.

9. International transfers

Our providers operate data centres in the United States and the European Union, so your personal data may be transferred outside your country of residence, including outside the European Economic Area and the United Kingdom. Where that happens, the transfer is protected by an adequacy decision or by Standard Contractual Clauses (with the UK Addendum where applicable) in our agreements with those providers. You may request a copy of the relevant safeguards by emailing info@montigate.com.

10. Cookies and similar technologies

We use only the cookies and local storage the Service needs to function. These are strictly necessary and are not used for advertising or cross-site tracking:

  • Authentication cookies — set by Supabase to keep you signed in and to hand a web session to the desktop application. They expire when the session ends or when you sign out.
  • Security cookies — set by Cloudflare and Vercel to protect against abuse and to route requests correctly.
  • Checkout cookies — set by Paddle on its checkout pages, governed by Paddle’s own policy.

You can block or delete cookies in your browser settings, but the Service cannot keep you signed in without its authentication cookies.

11. How long we keep data

  • Account and organization records — for as long as your account is active, and deleted within 30 days of a verified deletion request.
  • Billing and tax records — retained for the period required by applicable tax and accounting law (generally up to seven years), even after account deletion. Paddle applies its own retention period to the records it holds as Merchant of Record.
  • Server and security logs — typically retained for up to 90 days by our hosting and CDN providers, unless a longer period is needed to investigate an incident.
  • Support correspondence — up to 24 months after the matter is closed.

Encrypted backups may hold residual copies for a short additional period before they are rotated out. Once a retention period ends, data is deleted or irreversibly anonymised.

12. Security

We apply technical and organisational measures appropriate to the risk. All traffic to the Service is encrypted with TLS. Data at rest with our hosting providers is encrypted. Passwords are stored only as salted hashes by our authentication provider. API tokens are stored as SHA-256 hashes together with a short display prefix — a token is shown to you exactly once at creation and cannot be recovered by us afterwards, only revoked and replaced. Access to production data is limited to the people who need it, and billing state can be written only by a signature-verified webhook from Paddle.

No method of transmission or storage is completely secure. Keep your credentials and API tokens confidential, and tell us immediately at info@montigate.com if you believe your account has been compromised.

13. Data breaches

If a personal data breach occurs, we will investigate promptly, take steps to contain and remedy it, and notify the competent supervisory authority within 72 hours where the law requires. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly by email without undue delay and explain what happened, what data was involved, and what you should do.

14. Your rights

Subject to your jurisdiction, you have the right to: access the personal data we hold about you; have inaccurate data corrected; request erasure; obtain restriction of processing; receive your data in a portable, machine-readable format and have it transmitted to another controller; object to processing based on our legitimate interests; and withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal.

To exercise any of these rights, email info@montigate.com from the address on your account. We respond within 30 days and will tell you if we need longer for a complex request. We do not charge for these requests unless they are manifestly unfounded or excessive, and we will never discriminate against you for making one. You may need to verify your identity before we act.

You can cancel a subscription at any time from your dashboard. Account deletion is handled on request — email info@montigate.com and we will erase your account and organization records, keeping only the billing and tax records we are legally required to retain.

15. Complaints

If you believe we have handled your personal data unlawfully, please contact us first at info@montigate.com so we can put it right. You also have the right to lodge a complaint with the data protection supervisory authority in your country of residence, place of work, or the place of the alleged infringement — in the EEA, your national data protection authority; in the UK, the Information Commissioner’s Office.

16. Residents of California and other US states

In the past twelve months we have collected the categories of personal information described in sections 3 and 4: identifiers, commercial information, and internet or network activity information. We collect them for the business purposes in section 6 and disclose them to the service providers in section 8.

We do not and will not sell or share personal information for cross-context behavioural advertising, and we do not process sensitive personal information for the purposes that would require a right to limit. If you are a resident of California, Colorado, Connecticut, Virginia, or another state with comparable law, you may request to know, correct, delete, or obtain a copy of your personal information, and you may appeal a refusal. Email info@montigate.com to make a request or an appeal; we will not discriminate against you for exercising these rights. An authorised agent may act for you with written proof of authority.

17. Children’s privacy

The Service is intended for business use and is not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction, to create an account. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email info@montigate.com and we will delete it promptly.

18. Marketing communications

We send transactional messages — receipts, renewal and payment notices, security alerts, and notice of material changes to this policy — for as long as you have an account, and these cannot be opted out of while your account is open. Optional product announcements are sent only with your consent and every one carries an unsubscribe link. Unsubscribing from those does not affect transactional messages.

19. Links to other resources

The Service links to, and can be driven to visit, websites and services we do not operate. We are not responsible for their content or privacy practices, and this policy does not apply to them. Review the privacy policy of any third-party site or AI provider before sending it your data.

20. Changes to this policy

We may update this policy to reflect changes in the Service or in the law. The “Last updated” date at the top always shows the current version. If a change materially affects how we handle your personal data, we will notify account holders by email or by an in-app notice before it takes effect. Continued use of the Service after a change takes effect means you accept the updated policy.

21. Contact

Questions, requests, or complaints about this policy or your personal data:

MontiGate LLC
102 Gold Avenue Southwest

Albuquerque, NM 87102

United States

Email: info@montigate.com
Phone: +1 (737) 225-6131