Data Protection & Privacy Standards

Privacy Policy

Effective Date: August 15, 2026• Version 2.4. At Moven AI, we build zero-overhead safety infrastructure for autonomous AI agents with an uncompromising commitment to data privacy, zero model training, and strict customer ownership.

1.Privacy Overview & Scope

This Privacy Policy explains how Moven AI Inc. ("Moven", "we", "us") collects, processes, and safeguards information when you use our website (moven.dev), the Moven Developer Studio, SDK libraries, and API telemetry ingestion endpoints.

Zero Model Training Guarantee

We NEVER use your agent prompts, code, or data to train AI models.

Your agent prompts, reasoning steps, tool arguments, database outputs, and memory checkpoints are processed strictly for real-time circuit breaker evaluation and telemetry rendering. They are never retained or transferred for generative AI model fine-tuning or training datasets.

3. Information We Collect

A. Account & Identity Data

Name, email address, organization name, authentication credentials (OAuth Google/GitHub tokens), and billing identifiers.

B. Agent Telemetry & Trace Events

Tool execution signatures, recursion depth counts, token spend metrics, latency timestamps, tripped circuit breaker heuristics, and error stack traces transmitted by the Moven SDK.

C. Optional Step Checkpoints

When Ctrl+Z Step Rewind is enabled, lightweight execution snapshots are captured to allow time-travel prompt editing and replay.

4. How We Use Your Information

  • Evaluate in-memory loop interception rules in <1ms.
  • Render interactive Flame Graphs, DAGs, and Step Rewind timeline viewers in your private console.
  • Generate automated AST Self-Healing GitHub pull requests when requested by your team.
  • Dispatch Slack and email notifications when a circuit breaker halts a runaway turn.
  • Maintain platform security, mitigate fraud, and enforce API rate limits.

5.Security & Encryption Standards

All data in transit is encrypted using TLS 1.3 with modern cipher suites. Data at rest is encrypted using AES-256.

All database queries and telemetry access are strictly isolated by tenant organizations using PostgreSQL Row Level Security (RLS) policies.

6. Third-Party Subprocessors

Moven engages reputable third-party infrastructure providers that maintain strict SOC 2 Type II and ISO 27001 certifications:

Supabase / AWSPrimary cloud database, storage & auth
GitHub AppsSelf-healing pull request automation
Slack TechnologiesOptional tripwire incident webhooks
ResendTransactional alert emails & invites

7.GDPR & CCPA Rights

Depending on your location, you have the following rights regarding your personal data:

  • Right to Access: Request a complete export of your organization's telemetry and account records.
  • Right to Rectification: Modify and update inaccurate profile information.
  • Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of your account and trace logs.
  • Right to Restrict Processing: Pause trace ingestion and telemetry collection at any time.

8.Data Retention & Auto-Purge

Trace logs and execution checkpoints are retained according to your workspace tier (default: 30 days for Developer tiers, up to 365 days for Enterprise tiers). Customers may configure custom data retention windows directly in Project Settings.

9. Data Protection Contact

To exercise your privacy rights or submit a Data Processing Addendum (DPA), contact:

Moven AI Inc. • Data Protection Officer

Privacy Inquiries: privacy@moven.dev

Security Office: security@moven.dev

Website: https://moven.dev