Montr AI – Privacy Policy
Last Updated: December 11, 2025
Montr AI (“Montr”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy (“Policy”) describes how we collect, use, disclose, and safeguard your personal information when you access or use our website at https://montr.io (the “Site”), mobile applications, APIs, and AI-powered services for generating content such as text, images, code, and other outputs (collectively, the “Services”). The Services are provided by Montr, with its principal place of business at Office 3, AMUIF, AMU, Aligarh, U.P., India – 202001.
By using the Services, creating an account, or providing personal information, you consent to the practices described in this Policy. If you do not agree, please do not use the Services. This Policy is incorporated into our Terms and Conditions (the “Terms”). We encourage you to review this Policy periodically, as it may be updated.
Scope of This Policy: This Policy applies to personal data we collect through the Services. It does not apply to third-party websites, services, or applications that we do not control, even if linked from our Site. For users in specific regions (e.g., EU/UK under GDPR, California under CCPA), additional rights may apply as outlined below.
Global Users: The Services are available worldwide, but data processing complies with applicable laws, including India’s Digital Personal Data Protection Act, 2023 (DPDP Act), GDPR, CCPA, and others. You are responsible for ensuring your use complies with local privacy laws. We may restrict access in certain jurisdictions due to legal requirements.
1. Personal Information We Collect
We collect personal information to provide, improve, and secure the Services. “Personal Information” means any data that identifies or relates to you as an individual (e.g., name, email). Over the past 12 months, we have collected the following categories:
1.1 Information You Provide Directly
- Account and Profile Data: Name, email address, username, password, billing details (e.g., payment card info via processors like Stripe, PayPal, Razorpay, etc.), and preferences when you register, subscribe, or update your account.
- User Content and Inputs: Prompts, text, images, video, files, or data you upload or submit for AI generation (“Inputs”).
- Generated Outputs: AI-produced content based on your Inputs (“Outputs”), which may include metadata tied to your account.
- Communications: Inquiries, feedback, support requests, or survey responses sent via email, chat, or forms.
- Marketing Preferences: Opt-in choices for newsletters or promotions.
1.2 Information Collected Automatically
- Device and Usage Data: IP address, device type, operating system, browser, unique device identifiers, mobile carrier, and crash reports.
- Analytics Data: Pages viewed, time spent, interactions (e.g., clicks, searches), referral sources, and session duration via tools like Google Analytics.
- Location Data: Approximate location derived from IP address (not precise GPS unless you enable it).
- Cookies and Tracking Technologies: See Section 7 for details.
1.3 Information from Third Parties
- Payment Processors: Transaction data (e.g., Stripe or PayPal or Razorpay) for billing.
- Social Logins: If you sign in via Google, Apple, or similar, we receive basic profile info (e.g., email, name) as permitted by their policies.
- Partners and Public Sources: Aggregated demographic data (e.g., job title, location) from analytics providers or public profiles to enhance personalization.
We do not collect sensitive personal information (e.g., health, biometric, or political data) unless voluntarily provided in Inputs, in which case you are responsible for compliance.
AI-Specific Collection: Inputs and Outputs are processed by our generative AI models. We may retain anonymized versions for debugging and aggregated insights, but specific personal data in Outputs is tied to your account only.
2. How We Use Your Personal Information
We use Personal Information for legitimate business purposes, including:
2.1 Providing and Improving Services
- Account management, authentication, and personalization (e.g., saving preferences, generating Outputs).
- Processing subscriptions, payments, and usage limits (e.g., credits, API calls).
- Responding to support requests and troubleshooting issues.
- Analyzing usage to improve AI models, features, and user experience (e.g., aggregated analytics for trend identification).
2.2 Communications and Marketing
- Sending transactional emails (e.g., billing confirmations, password resets).
- Marketing communications (e.g., newsletters, promotions) if you opt in; you can unsubscribe anytime.
- Interest-based advertising via partners, subject to opt-out.
2.3 Security and Compliance
- Fraud prevention, security monitoring, and debugging.
- Complying with legal obligations (e.g., responding to subpoenas, tax reporting).
- Protecting rights, property, or safety (e.g., enforcing Terms, resolving disputes).
2.4 Research and Development
- Creating anonymized, aggregated datasets for AI training and product development (opt-out available in account settings).
- No use of your specific Inputs/Outputs for training third-party models without consent.
We process data based on your consent, contract necessity, legitimate interests (e.g., Service improvement), or legal requirements. For AI Outputs, we do not guarantee uniqueness or accuracy; review them before use.
3. How We Disclose Your Personal Information
We do not sell your Personal Information (as defined under CCPA/CPRA). Disclosures are limited to:
3.1 Service Providers
- Vendors for hosting (e.g., AWS, Oracle, GCP, etc.), payments (e.g., Stripe, PayPal, Razorpay, etc.), analytics (e.g., Google), email (e.g., SendGrid, Zoho, Brevo, etc.), and support tools. They are bound by confidentiality and process data only as instructed.
3.2 Business Partners and Affiliates
- Limited sharing with affiliates for operational purposes.
- Third-party integrations (e.g., Google Drive API for file uploads), where data is governed by their policies.
3.3 Legal and Business Transfers
- As required by law (e.g., court orders, government requests).
- In mergers, acquisitions, or asset sales, where data transfers with notice.
3.4 Aggregated or De-Identified Data
- Anonymized data (e.g., usage statistics) shared for research or marketing, without identifying individuals.
AI-Specific Disclosures: Outputs may incorporate third-party data sources; we exclude your data from such external training. No sharing of Inputs/Outputs for unrelated purposes.
4. Your Rights and Choices
You have control over your Personal Information. Depending on your location, you may exercise:
- Access: Request a copy of your data.
- Correction: Update inaccurate information via account settings.
- Deletion: Request removal (subject to legal retention; e.g., billing records).
- Opt-Out: Unsubscribe from marketing; opt-out of data for AI training in settings.
- Portability: Receive data in a structured format.
- Restriction/Objection: Limit processing for certain purposes (e.g., marketing).
To exercise rights, email hi@montr.io with your name, email, and request details. We respond within 45 days (extendable). For CCPA sales/opt-out signals, we do not sell data but honor requests. Authorized agents must provide proof.
Global Rights:
- EU/UK (GDPR): Rights include withdrawal of consent; data protection officer contact via email. Transfers use Standard Contractual Clauses (SCCs).
- California (CCPA/CPRA): Rights to know, delete, and opt-out of sharing. No discrimination for exercising rights. Non-discrimination for sensitive data.
- India (DPDP Act): Consent-based processing; grievance officer at hi@montr.io.
- Other Regions: Similar rights under local laws (e.g., Brazil’s LGPD).
We verify requests to prevent unauthorized access. Appeals: If unsatisfied, contact us; we may escalate to regulators.
5. Data Security
We implement reasonable administrative, technical, and physical safeguards (e.g., encryption, access controls, firewalls, regular audits) to protect Personal Information from loss, misuse, or unauthorized access. However, no system is fully secure, and we cannot guarantee absolute security. You must protect your login credentials and report breaches promptly. In case of a data incident, we notify affected users and authorities as required by law.
6. Data Retention
We retain Personal Information only as long as necessary for the purposes described, considering factors like usage, legal obligations, and disputes:
- Account data: While active, plus 1 year post-deletion for backups.
- Inputs/Outputs: Until deletion request or account termination; anonymized versions indefinitely for improvements.
- Billing data: 7 years for tax compliance.
- Logs: 90 days for security.
Deleted data is removed from active systems but may persist in backups. For Google integrations, data is deleted within 120 days of revocation.
7. Tracking Tools and Opt-Out
We use Cookies (small text files) and similar technologies (e.g., pixels, beacons, local storage) for functionality, analytics, and advertising:
- Essential: For login, security, and core features (cannot opt out).
- Functional: Preferences and personalization.
- Analytics/Performance: Usage stats (e.g., Google Analytics – opt-out via Google’s tool).
- Advertising: Interest-based ads; opt-out via device settings or Network Advertising Initiative.
We do not respond to “Do Not Track” signals. Manage via browser settings (e.g., delete Cookies) or our Cookie banner. Third-party tools like Privacy Badger can help. Session replay may be used for UX improvements with anonymization.
8. International Data Transfers
Data is processed in India and may be transferred to the US, EU, or other countries via providers (e.g., AWS, Google, Oracle). For EU/UK transfers, we use adequacy decisions, SCCs, or Binding Corporate Rules. Transfers comply with local laws; you consent by using global Services.
9. Children’s Privacy
The Services are not intended for children under 18 (or 13 in the US under COPPA, or the age of majority in your jurisdiction). We do not knowingly collect Personal Information from children. If we discover such data, we delete it promptly. Parents/guardians: Contact hi@montr.io to review, delete, or stop collection. We do not condition participation on excess data from children.
10. Changes to This Privacy Policy
We may update this Policy to reflect changes in our practices, technology, or laws. We will notify you of material changes via email, Site notice, or in-Service alerts, with the new effective date. Continued use after changes constitutes acceptance. Minor updates do not require notice.
11. Data Processing Agreement
If you are a Controller under GDPR or similar laws and you upload personal data to Montr AI for processing (e.g., names, photos, customer lists in your prompts), the Data Processing Agreement applies automatically and is incorporated into this Privacy Policy by reference.
12. Contact Us
For questions, rights requests, or concerns about this Policy:
- Email: hi@montr.io
- Postal Address: Montr, Office 3, AMUIF, AMU, Aligarh, U.P., India – 202001
- Grievance Officer: hi@montr.io


