Privacy Policy
Last updated: July 23, 2026
This Privacy Policy describes how Monostellar Limited (“we,” “us”) collects, uses, and shares data when you use browser-gateway cloud (the “Service”). Contact: [email protected]. For the purposes of GDPR and equivalent laws, Monostellar Limited is the data controller.
1. Data we collect
Account data. Email, display name, hashed password (email/password sign-in), profile image (OAuth sign-in), time zone. On signup a personal workspace is created for you.
Workspace data. Workspace name, member list, roles, billing address, and payment method reference (a token issued by our payment processor; we never see full card numbers).
Provider configuration. The endpoints and API keys you add so we can route sessions to them.
Session metadata. For each routed session we store the session identifier, provider used, start and end times, bytes in and out, message count, terminal state, and computed cost. We do not inspect or log the payload bytes of the browser automation traffic your client exchanges with the provider.
Replays (optional). If you enable session replay for a provider, we store CDP screencast frames for up to the retention window configured for your workspace (7 days by default).
Diagnostic data. Server logs, error traces, IP address of the connecting client, and browser user agent. Kept for up to 30 days for security and operational purposes.
2. Lawful basis (GDPR / UK GDPR)
We process personal data on the following bases:
- Performance of a contract for operating the Service you signed up for.
- Legitimate interest for security, fraud prevention, service improvement, and analytics.
- Legal obligation for tax, accounting, and required disclosures to regulators.
- Consent for optional marketing communications (withdrawable at any time).
3. How we use data
To operate and secure the Service, authenticate you, route sessions, bill for usage, prevent abuse, provide customer support, and improve the Service. We do not sell your data.
4. No training on your data
We do not use your session traffic, replays, workspace data, or any other content you send through the Service to train machine-learning models. Session payloads are relayed between your client and the browser provider you chose. We store only the metadata described in section 1.
5. Sub-processors
We use the following sub-processors to operate the Service:
- Cloudflare, Inc. Application hosting, database (D1), edge compute, CDN, DDoS protection.
- GitHub, Inc. OAuth sign-in provider when you sign in with GitHub.
- Google LLC. OAuth sign-in provider when you sign in with Google.
- Resend, Inc. Transactional email delivery (verification, password reset, invitations).
Each sub-processor is bound by a data processing agreement or equivalent. We review this list annually.
6. Data Processing Agreement
Enterprise and regulated customers may request a Data Processing Agreement (DPA). Email [email protected] with the subject line “DPA request”.
7. Data location and transfers
Our infrastructure runs on Cloudflare's global edge network. Data is processed in the region closest to you and replicated across Cloudflare's datacenter footprint for durability. Where transfers cross jurisdictional boundaries, they are governed by Cloudflare's Data Processing Addendum and the applicable Standard Contractual Clauses.
8. Retention
Account data: retained while your account is active, deleted 30 days after account closure. Session logs and replays: retained per your workspace's retention setting (default 7 days for replays). Payment records: retained for 6 years to satisfy Nigerian FIRS statutory retention. Diagnostic logs: 30 days.
9. Your rights
Under GDPR, UK GDPR, CCPA, and equivalent laws you have the right to access, correct, delete, or export your personal data, to restrict or object to processing, and to withdraw consent where processing is consent-based. To exercise any of these rights, email [email protected] from the address on your account. We respond within 30 days.
You may also lodge a complaint with your local data protection authority.
10. California residents (CCPA)
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act. California residents may exercise their access, deletion, and correction rights by contacting us at the address above.
11. Cookies
We use a small number of first-party cookies:
- bg_session. Authentication session token. HttpOnly, Secure, SameSite=Lax. Expires with the session.
- bg_workspace. Remembers the last active workspace. Not used for tracking.
We do not use third-party advertising cookies. We do not track you across other websites.
12. Security
Passwords are hashed using an industry-standard key derivation function. Provider credentials and API keys are stored in our Cloudflare D1 database, which encrypts data at rest at the storage layer. Data in transit is TLS-encrypted. Access to production data is restricted to a small set of Monostellar staff, audit-logged, and requires multi-factor authentication.
13. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If we learn we have, we will delete it.
14. Changes
We may update this Privacy Policy. Material changes will be communicated by email at least 14 days before they take effect. The date at the top of this page reflects the last update.
15. Contact
Monostellar Limited. Email [email protected].