Privacy Policy
Effective Date: February 5, 2026
Last Updated: February 5, 2026
GazeFi AI LLC ("Company," "we," "us," or "our") operates MOLT at agent.molt.direct (the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Account Data
- Email Address: Required for authentication and communication
- Name: Optional, for personalization
- Profile Image: Optional, if provided via OAuth
Bot Configuration Data
- Bot Names & Settings: Names and configurations for your deployed bots
- AI Model Selection: Your choice of Claude, GPT, or Gemini models
- Channel Tokens: API credentials for Telegram, Discord, or WhatsApp (encrypted at rest)
- Custom Configurations: Any custom settings or prompts you provide
Subscription Data
- Stripe Customer ID: Unique identifier for billing
- Subscription Status: Active, canceled, or payment status
- Billing Period: Current subscription dates
Note: We do not store credit card numbers. All payment data is handled by Stripe.
Usage Data
- Bot Activity: Message counts and status logs
- Deployment Logs: Server creation and status events
- Session Data: Authentication tokens and session identifiers
Technical Data
- IP Address: For rate limiting and security
- Device Information: Browser type, operating system (via standard headers)
2. How We Use Information
We use collected information to:
- Provide the Service: Deploy and manage your AI agents
- Authenticate Users: Secure access via email OTP verification
- Process Payments: Handle subscription billing through Stripe
- Send Communications: Transactional emails (OTP codes, deployment confirmations)
- Monitor Performance: Track bot health and usage metrics
- Improve the Service: Analyze usage patterns to enhance features
- Ensure Security: Detect and prevent fraud, abuse, or unauthorized access
3. AI Processing & Transparency
MOLT facilitates AI-powered bot deployment. Here's how we handle AI-related data:
🤖 AI Data Handling
- • Your Prompts: Stored securely and never shared between users
- • Bot Messages: Processed by your selected AI provider (Anthropic, OpenAI, or Google)
- • No Training: Your data is not used to train AI models without explicit consent
- • Model Providers: Subject to their respective privacy policies
AI Providers
- Anthropic (Claude): Privacy Policy
- OpenAI (GPT): Privacy Policy
- Google (Gemini): Privacy Policy
4. Data Sharing & Third Parties
We share data with the following service providers (sub-processors):
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Email, payment info |
| Database Provider | Database hosting | All stored data |
| Cloud Infrastructure Provider | Server infrastructure | Bot runtime data |
| Email Delivery Provider | Email delivery | Email address, name |
| Security Infrastructure Provider | Rate limiting & abuse prevention | IP address (hashed) |
| Application Hosting Provider | Application hosting | Request logs |
We may also disclose information:
- To comply with legal obligations or valid legal processes
- To protect and defend our rights and property
- To prevent fraud or security threats
- With your consent or at your direction
5. Data Retention
- Account Data: Retained while your account is active, plus 30 days after deletion
- Session Tokens: 30 days from creation
- Verification Codes: 10 minutes (auto-deleted after use)
- Bot Configurations: Retained while subscription is active
- Deployment Logs: 90 days for troubleshooting purposes
- Payment Records: As required by law (typically 7 years)
6. Security Measures
We implement industry-standard security measures:
- Encryption in Transit: All connections secured via TLS/HTTPS
- Encryption at Rest: Sensitive data encrypted in our database
- Session Security: Secure, HTTP-only cookies with CSRF protection
- Rate Limiting: Protection against brute-force attacks
- Access Controls: Role-based access to production systems
No system is 100% secure. If you discover a vulnerability, please contact us at contact@molt.direct.
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and associated data
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
To exercise these rights, contact us at contact@molt.direct or use our Contact Form.
8. Analytics & Cookies
We use analytics tools to understand how users interact with the Service and to improve user experience:
- Product Analytics: We use privacy-focused analytics to track page views, feature usage, and user flows. Data is anonymized and not sold to third parties
- Essential Cookies: We use cookies strictly necessary for authentication, session management, and security (e.g., CSRF tokens)
- No Advertising Cookies: We do not use third-party advertising or tracking cookies
- Opt-Out: You may disable analytics tracking through your browser settings or by contacting us
9. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you
- Right to Delete: You may request deletion of your personal information, subject to legal exceptions
- Right to Opt-Out: We do not sell personal information. If this changes, we will provide a "Do Not Sell My Personal Information" link
- Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
To exercise your CCPA rights, contact us at contact@molt.direct with the subject line "CCPA Request."
10. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland:
- Legal Basis: We process your data based on: (a) your consent, (b) the necessity to perform a contract with you, (c) our legitimate business interests, or (d) compliance with legal obligations
- Additional Rights: In addition to the rights listed in Section 7, you have the right to lodge a complaint with your local supervisory authority
- Data Protection Officer: For GDPR-specific inquiries, contact us at contact@molt.direct with the subject line "GDPR Request"
- Data Transfer Safeguards: Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission
11. Data Processing Agreement (DPA)
For enterprise customers or organizations that require a Data Processing Agreement to comply with GDPR or other data protection regulations, we offer a DPA upon request. Contact us at contact@molt.direct with the subject line "DPA Request" to initiate the process.
12. International Transfers
Your data may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses where applicable.
13. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or by posting a prominent notice on the Service. Continued use after changes take effect constitutes acceptance of the revised policy.
15. Contact Information
GazeFi AI LLC
254 Chapman Rd Ste 208
Newark, DE 19702, USA
Phone: +1 (408) 548-1121
Email: contact@molt.direct
Support: Contact Form