mumo Privacy Policy

mumo is operated by Sourced LLC, a Florida limited liability company ("mumo," "we," "us"). This Privacy Policy explains what information we collect when you use mumo.chat, our API, and our MCP server (together, the "Service"), how we use it, who receives it, and the controls you have.

Effective date: September 28, 2026

1. At a glance

  • Your questions go to the AI providers you choose — plus, for a few platform features, a provider we select (Section 5.2). That is how the Service works. We are selective about those providers (Section 8) and publish the full list, what each receives, and how we verified its commitments at mumo.chat/legal/providers.
  • We separate your data into categories and treat them differently. Account information follows different rules than conversations. The table below is the summary; the sections after it are the detail.
  • We never sell your account information. No advertising, no data brokers, no profiling for marketing.
  • If you create an account, you get two data-use choices, both changeable at any time. Platform Improvement lets mumo use your sessions to evaluate and improve the product. It is a mumo-only program: nothing used under it is licensed, sold, or handed to a third party for that party's own use. Dataset Contribution lets mumo include model-generated material from your sessions in redacted research datasets we license to AI labs and researchers. You are asked about both when you sign up, with nothing pre-selected for Dataset Contribution. Guest sessions may be used for Platform Improvement but are always excluded from Dataset Contribution. Section 6 describes exactly what each does.
  • Sessions you created before August 29, 2026 are permanently excluded from any licensed dataset. No exceptions, no later change can reach them.
  • Your prompts and attachment files are never directly included in any licensed dataset. Model answers can repeat details from your questions or attachments, so contributed model-generated material may still contain information that originated there.
  • Sharing or publishing a session is separate from your data choices. A share link makes the session accessible to anyone with the link; publishing makes it public. Neither changes whether the session is eligible for Platform Improvement or Dataset Contribution (Section 7).

Summary matrix

CategoryExamplesRetainedUsed to improve mumoIn licensed datasets
Account & billingemail, auth identity, plan, payment metadata, spend recordslife of account + legal tailnonever
Operationaltimestamps, token counts, model/latency stats, request IDs, error codeswith the session (DB), except guest-limit records (§4); ≤30 days (provider logs)yes (reliability, planning)never
Conversational — your prompts and attachment fileswhat you write and uploaduntil you delete (§5.4)prompts per Platform Improvement; attachment files never directlynever directly
Conversational — model-generated materialmodel answers, model-to-model reactions, models' self-reported confidencewith the sessionper Platform Improvementper Dataset Contribution, redacted
Derived session structuresclaim maps, takeaways, titleswith the sessioninherits the sessioninherits the session, redacted
Aggregate statisticscounts and shares with no session content or session linkageindefinitelyyesmay be published or licensed
Shared or published contentsessions you make accessible through a share link or public URLuntil you revoke access, unpublish, or deleteper Platform Improvementper Dataset Contribution

2. The categories, defined

Account & billing data identifies you as a customer: your email address, authentication identity (including SSO identifiers), display name if you set one, subscription and entitlement state, payment metadata, and our per-call spend records. Full card numbers are handled solely by our payment processor and never touch our servers.

Operational data describes how the Service ran, not what was said: request timestamps, token counts, model and endpoint identifiers, effort levels, latency, HTTP status, request IDs, and error codes. We define operational data as not containing the substance of your conversations, and we engineer our logging, analytics, and error handling to keep it that way.

Conversational data is the substance of your sessions. It has two parts with different rules:

  • Your prompts and attachments — what you write and upload. These may contain personal data about you or others if you choose to include it.
  • Model-generated material — the answers models write, the reactions models write about each other's answers (a quoted sentence from a peer plus a short comment), and models' self-reported confidence (each model's own list of the claims in its answer it considers load-bearing, with a score before and after seeing its peers). Model-generated material is written by the models, not by you — but it is written in response to your prompts and attachments and can repeat facts from them.

Derived session structures are artifacts our systems generate from conversational data: claim maps, takeaways, and session titles. Because they are built from — and can reveal — the substance of your sessions, we classify and protect them as conversational data and they inherit the choices in force for the session they came from. They are never treated as operational data.

Aggregate statistics are counts and shares computed across many sessions with no session content and no link back to any session or account — for example, which models are chosen most often, how often a single-model chat is escalated to a panel, or how a model's reactions distribute across the five reaction types. Section 4.1 states the rules they follow.

Published content is a session you have affirmatively chosen to publish to a public URL. Publication is governed by Section 7.

3. Account & billing data

We collect account and billing data when you create an account, subscribe, or contact support. We use it to authenticate you, provide and bill the Service, communicate with you about your account, and meet legal and tax obligations. We share it only with the service providers that operate these functions (Section 9), and we retain it for the life of your account plus the period required for tax and legal records. Account and billing data is never used to improve models, never included in any dataset, and never sold.

4. Operational data

We collect operational data automatically whenever the Service runs. We use it for metering, security and abuse prevention, capacity planning, debugging, and reliability. It applies on all plans regardless of your Section 6 choices, because the Service cannot be operated, secured, or billed without it. Operational records in our own database are kept with the session they describe and follow its deletion schedule (guest-limit records excepted, see below); server and database logs held by our hosting providers are kept for at most 30 days; product-analytics events contain no session content (all text and inputs are masked before they leave your browser). Operational data is never included in any licensed dataset and never sold.

Guest limits. To enforce guest limits we store a keyed hash of a random identifier kept in your browser, and a keyed hash of your IP network that is deleted within 48 hours. The browser identifier's hash is deleted once it has gone unused for 30 days. We use them only to enforce those limits — never for advertising — and we don't share them.

4.1 Aggregate statistics

We compute aggregate statistics across all sessions, including sessions whose Section 6 choices are off — your choices govern the content of your sessions, not whether they are counted. Aggregate statistics contain no session content and no link back to any session or account; they describe patterns across the user base rather than any individual. They may be published (for example, on our model profile pages) or licensed.

5. Conversational data

5.1 Collection and use

We collect conversational data when you run sessions. We use it to operate the Service: routing your prompts to the model providers you select, returning and displaying responses, generating derived session structures, maintaining your session history, and — where a session trips our safety systems (including when a model provider's safety system declines a request in that session) — investigating abuse. Uses beyond operating the Service are governed exclusively by your Section 6 choices.

5.2 Sending your questions to model providers

Running a session sends your conversational data to the providers serving the models in that session, and — when web search is on — sends search queries derived from your prompt to our search provider. This is inherent to what mumo does. Some platform features — web-search orchestration, per-round and per-session takeaways, and session titles — also send the relevant session content to providers even when their models are not on your selected panel. Those features, and the providers they send to, are listed in section 2 of mumo.chat/legal/providers. They introduce no recipients beyond the providers listed there. Section 8 states the standard every provider must meet and links the live list. We do not provide conversational data to any third-party model provider for that provider's own training use.

5.3 Attachments

Files you attach to a session are conversational data with one additional protection: the attachment files themselves are excluded from Platform Improvement and from every dataset on every plan, regardless of your choices. They are used only to run the session you attached them to.

Models can quote, summarize, or repeat information from an attachment in material they generate. If Platform Improvement is on, that model-generated material may be used by mumo under Section 6.1. If Dataset Contribution is on, that model-generated material may be eligible for a redacted research dataset under Section 6.2. The attachment file itself is never included.

5.4 Retention and deletion

Deleting a session and erasing it from our systems are two separate steps. Your sessions remain available to you until you delete them. Deleting a session removes it from your account immediately: it no longer appears in your history, and a deleted session is not used for Platform Improvement or Dataset Contribution — our eligibility check refuses any deleted session. The session's stored records remain in our systems until you ask us to erase them. To request erasure of specific sessions or your whole account, email privacy@mumo.chat and we will complete it within 30 days, including derived session structures. Database backups expire on a rolling 7-day schedule, so erased data is gone from backups within 7 days of erasure.

6. Your two choices

You are asked about both choices when you create an account, and you can change either at any time in Settings → Privacy. Changing either setting affects sessions created from then on; a later opt-in never makes an earlier ineligible session eligible for a new use. Turning Dataset Contribution off also withdraws your earlier contributed sessions from future dataset releases, as described in Section 6.2. Guest sessions may be used for Platform Improvement, including staff review and eligible public model-page excerpts, but are always excluded from Dataset Contribution. If you create an account, you can turn Platform Improvement off for sessions created from then on. Attachment files themselves are excluded from both. Neither choice affects aggregate statistics (Section 4.1).

6.1 Platform Improvement

Default: on. Available on every plan. When Platform Improvement is on, mumo may use your sessions — your prompts, model-generated material, and derived structures — to evaluate model quality, develop and test our prompts, routing, moderation, and product features, and measure how well mumo works. This may include review by mumo staff, and we may feature short quotes of model-generated material from eligible sessions on our public model pages after removing identifying details. Platform Improvement is mumo only — nothing used under it is licensed, sold, or handed to a third party for that party's own use. Turn it off and sessions created from then on are not used for improvement.

6.2 Dataset Contribution

Default: your choice at signup — nothing is pre-selected. When Dataset Contribution is on, mumo may include model-generated material from your sessions — model answers, model-to-model reactions, and models' self-reported confidence, together with derived structures built from them — in research datasets that we license to third parties such as AI labs and researchers.

What is never directly included: your prompts, your attachment files, your account information, and any session created before August 29, 2026 or while Dataset Contribution was off.

Before any release, we remove names, organizations, contact details, and similar identifying information from the material and review the remaining disclosure risk; we exclude records that cannot be made safe. We say "redacted," not "anonymized," deliberately: model answers can repeat details from your questions or attachments, and specific facts can identify a situation even after names are removed. If California law treats this licensing as a sale of personal information, Dataset Contribution being off is your opt-out (Section 15).

Every licensee is contractually bound not to attempt to re-identify anyone, not to resell or redistribute the material, to delete material we withdraw, and to submit to audit. We publicly commit that we will not attempt to re-identify redacted material.

Turning Dataset Contribution off excludes sessions created from then on and removes your earlier contributed sessions from every future dataset release we make; we instruct existing licensees to delete retained copies under our agreements with them. It cannot recall copies already delivered, and it cannot remove information a licensee has already incorporated into a trained model or completed research.

7. Shared and published content

You can make a session accessible to others by creating a share link or publishing it. A share link can be viewed by anyone who has the link. Publishing creates a public URL and may also include the session in mumo's discovery surfaces. By sharing or publishing, you license mumo to host and display the session as necessary to provide that feature.

Sharing or publishing does not change whether that session may be used for Platform Improvement or Dataset Contribution. Dataset eligibility is determined by the Dataset Contribution setting in force when the session was created, subject to withdrawal if you later turn Dataset Contribution off. Revoking a supported share link or unpublishing removes mumo-hosted access through that link or public URL; copies made by others while the session was accessible are outside our control.

8. Where your questions go: model providers

We are selective about the providers we send inference to. We route only to (a) model developers serving their own models under API terms that prohibit training on submitted content, or (b) inference providers running open-weight models on their own infrastructure. We do not route through gateways, routers, or intermediaries, and we never send requests to the developer of an open-weight model. We re-check every provider's terms before any routing change.

For providers in category (a), the no-training commitment is a term of the provider's standard API agreement, which we accepted when we opened our account — binding on both parties, but their standard terms, not a negotiated contract. For providers in category (b), we rely on the provider's published data-handling statements. The live list at mumo.chat/legal/providers, generated from our routing configuration, shows every provider and the models you can select from it, what each receives, whether its commitment is a term of its API agreement or a stated policy, and when we last verified it.

Provider data-handling terms last verified: August 2026.

9. Other sharing

9.1 Service providers. We use service providers for the functions needed to operate mumo: hosting and edge delivery, database and authentication, product analytics (with all text and inputs masked before they leave your browser), web search (which receives search queries derived from your prompt when search is on), and payment processing once subscriptions launch. We provide information to them as needed for those functions. Providers may also generate and process technical or operational records as they deliver their services, subject to their applicable terms and policies. The current provider for each function, the data categories we intentionally send it, and relevant data-handling information are maintained at mumo.chat/legal/providers#subprocessors.

9.2 Legal and safety. We may disclose information to comply with law, enforce our Terms, or protect the rights, property, or safety of mumo, our users, or the public.

9.3 Business transfers. If Sourced LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. Any successor takes the data subject to the commitments of the policy version under which it was collected — including the Section 6 choices in force for each session and the permanent exclusion of pre-August 29, 2026 sessions from licensing. We will notify you before your information becomes subject to a materially different policy.

10. Security

Conversational data is encrypted in transit and at rest. Access to production systems follows least-privilege controls, with row-level security enforced at the database layer and audit logging on changes to your privacy choices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Retention summary

DataRetained
Conversational data & derived structuresuntil you delete; erased on request within 30 days; backups expire within 7 days
Attachmentswith the session; same schedule
Operational datadatabase records: with the session, except guest-limit records (IP-network hash: within 48 hours; browser-identifier hash: 30 days after last use); provider logs: at most 30 days
Aggregate statisticsindefinitely (no session content or linkage)
Account & billing records (incl. spend ledger)life of account + legal/tax retention period
Privacy-choice historyassociated with your account for the life of the account; after account deletion, disassociated from the account and retained with no fixed retention period
Support communications24 months
Published contentuntil unpublished

12. Your rights and requests

You can access and delete your sessions in the product and change both Section 6 choices in Settings → Privacy. For access, correction, erasure, or portability requests we haven't built self-serve, email privacy@mumo.chat and we will respond within 30 days. We will never discriminate against you for exercising your rights or for how you set your Section 6 choices.

13. Children

mumo is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn we have, we will delete it promptly.

14. International users

mumo is operated from the United States and is currently directed to users in the United States. Some service providers and inference providers may process information in other countries depending on the provider and infrastructure used. We do not currently operate a program specifically designed for users in the European Economic Area or United Kingdom. If you are located there and use the Service anyway, the rights-request path in Section 12 is available to you, and your Section 6 choices are honored as described.

15. California residents

If you are a California resident, you have the right to know what personal information we collect, to delete it, to correct it, and to opt out of its sale or sharing. The only use of your data that California law might treat as a sale is the licensing of redacted model-generated material from sessions with Dataset Contribution on (Section 6.2). Turning Dataset Contribution off — in Settings → Privacy, or by choosing No when asked — is your opt-out. We do not sell any other category of information, we do not share personal information for cross-context behavioral advertising, and we honor opt-out preference signals where required. We will not ask you to opt back in for at least twelve months after you opt out.

16. Changes to this policy

We version this policy. Material changes are announced in-product when they are published, and you will be asked to accept them before continuing to use the Service; where a grace period applies, you may continue using the Service until it ends. A later policy version does not make an earlier session eligible for a new use that was not permitted when the session was created. We maintain records sufficient to establish the privacy choices and policy version that applied to sessions.

17. Contact

Sourced LLC (d/b/a mumo) · privacy@mumo.chat