Trust
Security and privacy
What is stored, what leaves Modloom, and how builds are isolated.
This page summarizes how your code and data are handled. The Privacy Policy and Terms are the authoritative documents, and they win if anything here differs.
Your projects are private#
Projects belong to a workspace and are visible only to it. Another user asking for your project gets "not found". Your source, history, attachments and built jars are kept in private storage with no public links. Downloads use short-lived private links.
How builds are isolated#
Your code is built in an isolated sandbox, and Modloom never runs generated code on its own web, API or worker servers. Sandboxes have limited CPU, memory and time, and they hold no Modloom credentials.
A sandbox is isolated from Modloom's systems, but a plugin you download runs on your server with the permissions you give it. Review code you did not write before you run it.
What is sent to AI providers#
To do its work the agent sends your prompts, project files and attachments to the model provider you picked, through a model gateway. Modloom asks providers not to retain or train on this data, but each provider has its own terms, and those apply too. The Privacy Policy lists the services involved.
Do not put secrets such as passwords, tokens or private keys in prompts, files or attachments.
Abuse screening#
Prompts are screened by an automated check. Modloom stores a flag and a score when something is flagged, not the prompt itself. Repeated flags can lead to an automatic ban.
Analytics and cookies#
Modloom uses privacy-friendly product analytics (hosted in the EU) for page views and key events, linked to your name and email. It does not include prompts or file contents, and there is no session recording.
Cookies in use:
- a session cookie, valid for up to seven days,
- a draft cookie that holds a brief you typed before signing in, for 24 hours,
- your theme preference,
- an analytics identifier.
Retention#
- Account, workspace and project data are kept until you delete them.
- Expired sessions, codes and drafts are removed automatically.
- Backups keep deleted data for a limited time.
- Invoices are kept for as long as tax law requires.
- Code already pushed to your GitHub repositories stays there.
For access, correction or deletion requests, follow the contact details in the Privacy Policy.
Your responsibilities#
You must be 16 or older to use Modloom. You are responsible for the content you submit and for reviewing generated code before you run it.