Privacy notice
What we collect, why, where it’s kept, for how long, who helps us, and your rights. Everyone gets the same rights, whatever state you live in.
The short version
- We collect what it takes to run packs for you: your account, what you send to runs, their results, and receipts.
- Your inputs, files and results stay in your account. Creators never see them.
- Packs improve from de-identified patterns in how runs go, never from your files, inputs or results. Nobody may re-identify you.
- We don’t sell your personal data or share it for ads, and we don’t train AI models on it.
- Everything is stored in the US, with a short list of US-hosted service providers.
- Export, deletion, “what we hold” and stopping learning are free and open to everyone.
Who we are and what this covers
This notice explains how Modpack, Inc. (“Modpack”, “we”) handles personal data. It’s the Privacy Policy you agree to when you connect Modpack. It covers modpack.md, the Modpack connection in your AI agent, our emails, and every pack you run.
Modpack is a US-only beta for people 18 or older. We process and store data in the United States.
Your agent’s maker, such as Anthropic for Claude, handles your chats under its own privacy policy. Modpack receives only what your agent sends to a run, never your other chats or memory.
Pack creators don’t receive your personal data (section 06).
What we collect
We sort data into classes. Where it’s stored, who can reach it and how long we keep it follow the class.
We don’t ask for sensitive personal data, and our Terms ask you not to put it into runs. We don’t collect precise location, and we don’t buy data about you.
Why we use it
We don’t use your data for advertising, and we don’t send marketing email unless you ask for it.
Learning from runs, and de-identification
Packs improve automatically from how runs go. The contribution license in the Terms covers the rights; this is what it means for your data.
Where it happens
Evidence is derived inside your account’s boundary. When an AI model helps classify it, that call runs for your account under our commercial agreements with US-hosted AI providers. It isn’t public learning.
What can leave your account
Only de-identified, minimized evidence: outcomes, error and failure types, timings, resource use, which checks passed, which fix worked, and general patterns. Never your files, inputs or results, data from your connected accounts, credentials, raw logs, or anything that identifies you or another person.
How
Fixed fields instead of free text, rounded values, synthetic test cases instead of your inputs, checks that no text from your inputs slips through, and a minimum of 5 accounts behind any metric. Dates in metrics are rounded to the week and never come with file names or which runs a fix came from. Anything unclear is held back and deleted after 7 days.
Who it reaches
The learning audience: the pack’s creator, who sees totals across 5 or more people (below that, “not enough data yet”), and the Modpack network, as improved pack versions everyone can use.
Our commitment
We keep de-identified information in de-identified form and don’t attempt to re-identify it. Everyone who receives it, including creators and other users, is bound by contract not to re-identify it either.
Stopping
Stop anytime in Settings. New evidence stops being eligible at once, and your packs pause, because learning is part of how managed packs work. Export, files, receipts and every right in section 09 keep working. What was already built into released versions stays there; it was never linked to you.
Changes
We ask for your fresh agreement before using your runs for learning in a materially different way. A change never applies to runs from before you agreed.
No selling, no ads, no AI training
We don’t sell personal data
We don’t sell your personal data, and we don’t “share” it for cross-context behavioral advertising, in the sense California law uses.
No ad trackers
There are no advertising or social media trackers on Modpack.
No AI training on your data
We don’t train foundation models or any other AI models on your data, and our AI providers’ commercial terms don’t let them train on it. Learning improves packs, meaning their code, instructions and checks, not AI models.
Opt-out signals
Because we don’t sell or share, there’s nothing to opt out of. We still honor Global Privacy Control signals as an opt-out request.
Where your data is stored
In the United States. Our databases and files are in Google Cloud’s us-east4 region (Virginia), and packs run in Vercel sandboxes in iad1 (Washington, D.C. area). During the beta we use only US-hosted providers, and we don’t transfer personal data outside the US. A provider whose region we’re still confirming isn’t used for your data until we have.
How long we keep it
Your rights and choices
These rights are for everyone, whatever state you live in. Most take one click in your account.
See what we hold
“What we hold” in Settings lists the data in your account, your consent records and where each is kept.
Export
Download everything as one signed bundle from Export. It’s free and works with a $0 balance, with paused packs and with no agent connected. We email you when it’s ready.
Delete
Delete your account from Settings, confirmed with a passkey or by signing in again. You can cancel for 24 hours. Your data is deleted within 7 days and backups expire within 30 days. Receipts stay as the law requires.
Stop learning from your runs
From Settings. Your packs pause; export and your other rights keep working.
Correct
Change your name and email in Settings, or ask us to fix anything else.
Disconnect
Revoke an agent or a connected account anytime in Connections.
Email choices
Turn off optional email in Settings. Email about your runs, money and security stays on while your account is open.
Asking us
Email privacy@modpack.md. We confirm it’s you by asking you to sign in, and answer within 30 days, or 45 at most if we tell you why we need longer.
Someone acting for you
An authorized agent can ask for you with your signed permission. We still confirm your identity with you.
If we say no
Reply to our answer to appeal. A different person reviews it and answers within 45 days. If you’re still unhappy, you can contact your state attorney general.
No penalty
We don’t charge you more or treat you worse for using these rights. Stopping learning pauses managed runs because learning is part of how they work; everything else, including export, keeps working.
Children
Modpack is for adults. You must be 18 or older, and everyone confirms it when they connect. Nothing on Modpack is aimed at children. If we learn an account belongs to someone under 18, we close it and delete its data. If you think a child has an account, email privacy@modpack.md.
How we protect it
- Every run gets a fresh sandbox of its own, deleted after the run. Pack code never runs on your computer.
- Sandboxes reach only the sites a pack declared, through our network proxy, and hold no secrets. Every connection is logged.
- Tokens for accounts you connect stay in our vault and are added only at the network edge. Packs never see them.
- Only signed pack versions run, and the signature is checked before each run.
- Data is encrypted in transit and at rest.
- Staff access is limited, needs strong sign-in and is logged.
No system is perfectly secure. If a breach affects your personal data, we tell you within 30 days and tell regulators as the law requires.
Report a security issue to security@modpack.md; we reply within 1 business day. More on the Security page.
If you publish packs
Public by design
Your handle, profile, packs, prices, versions and pack evidence are public.
Payouts
Stripe collects your legal name, address, date of birth, bank details and tax ID through Stripe Connect Express. We receive whether its checks passed, your payout status and what we need to file your 1099-MISC, and keep tax records as the law requires.
What you see about people who run your packs
Totals across 5 or more people, and question text without names. Never their identity, inputs, results or files.
Counter-notices
If you send a copyright counter-notice, we forward your name, address, phone number and statement to the person who sent the notice, as the law requires.
Changes to this notice
We post every version here with its date. Before a material change applies, we tell you by email and in your account, and ask for your agreement. A change to how we use your runs for learning always needs your fresh agreement and never applies to runs from before you agreed.
Contact
Privacy questions and requests
Security issues
Legal
Postal address
Modpack, Inc., [postal address to be added]