Legal
Privacy policy
How Mongeflow collects, uses, protects, and retains personal data — and the rights available to you.
Last updated: 2 August 2026
Who we are
Mongeflow is operated by LEXINTELI LLC, a limited liability company registered in the State of Wyoming, United States ("we", "us"). For personal data processed through the service, LEXINTELI LLC acts as the data controller for account and billing data, and as a processor for personal data contained in customer content.
What we collect, and where it comes from
Account data: name, email address, and authentication identifiers, collected when you sign up (via our authentication provider). Organization data: workspace names, membership, and roles. Customer content: the briefs you write, files you upload, and the decisions, scenarios, and reports the service produces from them. Billing data: subscription and transaction records, handled by our payment processor acting as merchant of record — we do not store card numbers. Usage data: first-party product events and service logs. Support data: messages you send us.
Data comes from you, from your organization's administrators, and from your use of the service. We do not buy personal data from third parties.
Why we process it (purposes and legal bases)
To provide and secure the service (performance of contract); to operate, improve, and protect the service, and to understand how it is used (legitimate interests); to bill and to meet legal obligations (legal obligation); and, where required, on the basis of consent. We do not sell personal data, and we do not use it for third-party advertising.
Customer decision data and uploaded files
Customer content is processed only to provide the service, on your instructions. It is isolated per organization at the database layer. Brief text is processed server-side by an AI text-processing subprocessor to structure your decision; customer content is not used to train AI models — ours or any provider's.
Retention and deletion
Account and customer content are retained while your account is active. On account termination or verified deletion request, data is deleted within a reasonable period, except where retention is required by law (for example, billing records) or for the establishment or defense of legal claims.
Subprocessors and cookies
The service providers that process data on our behalf are listed on the subprocessors page. Cookie use is described in the cookie policy.
International transfers
The service is operated from the United States, and some providers process data in the United States or the European Union. Where data protection law requires transfer safeguards, we rely on appropriate mechanisms such as standard contractual clauses, as described in our data processing addendum.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent (GDPR and comparable laws). Residents of certain US states have similar rights, including the right to know and to delete; we do not sell personal data, so no opt-out of sale is needed.
To exercise a right, contact us via the contact page. You may also lodge a complaint with your supervisory authority.
Security and incidents
Data is encrypted in transit, organization isolation is enforced at the database layer, access is role-based, and administrative actions are logged. If a personal data breach affects you, we will notify you and the competent authorities as required by applicable law.
Data processing addendum
Customers who need a GDPR processor agreement can put our data processing addendum in place via the contact page.
Changes and contact
We update this policy as the service evolves and revise the date above when we do. Questions: contact LEXINTELI LLC via the contact page, by mail at 8 The Green #13599, Dover, DE 19901, United States, or by phone at +1 302 620 2550.