Privacy Policy

How Molecule.dev collects, uses, and retains your data.

Last updated: August 1, 2026

In summary: we collect only what we need to run Molecule.dev. That means the contact details you choose to give us, plus first-party usage and operational analytics tied to your account so we can keep the service running and improve it. We do not use third-party advertising or behavioral-tracking networks, and we never sell or rent your information.

Molecule.dev is operated by Molecule Dev, Inc., a Delaware corporation ("Molecule", "we", "us"), which is the data controller for the personal data described in this policy. We value the privacy of our users. This Privacy Policy describes the information we collect and record and how we use it.

If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us.

This Privacy Policy applies to your use of Molecule.dev and the information you share with, or that is collected by, the service. It is not applicable to information collected offline or via channels other than this service.

Consent

By using Molecule.dev, you consent to this Privacy Policy and agree to its terms.

Information we collect

Providing personal contact information is optional — it is up to you. The personal information you are asked to provide, and the reasons why, are made clear to you at the point we ask for it.

If you contact us directly, we may receive additional information about you such as your name, email address, the contents of your message and any attachments, and any other information you choose to provide.

When you register for an account, we may ask for contact information including your name and email address.

Analytics & product usage

Molecule.dev records first-party product and operational analytics so that we can operate the service, debug problems, enforce usage limits, and improve the product. These events are stored on our own infrastructure and, when you are signed in, are keyed to your account (user id) so we can attribute usage and act on the data.

Examples of what we record include: account sign-ups and sign-ins, feature and page usage, when usage or rate limits are reached, payment and plan changes, and error and reliability events.

We do not embed third-party advertising SDKs or cross-site tracking networks, we do not build advertising profiles, and we do not sell, rent, or share this analytics data with third parties for their own purposes. Where a feature requires a sub-processor to function (for example an AI provider that fulfils a request, or a payment processor), only the data needed for that request is sent to it; such providers act on our behalf and are not permitted to use your data for their own marketing.

How we use your information

If you choose to provide your personal information, it may be used for the following:

  • Operating, securing, and improving the service
  • Personalization within the application
  • Communicating with you, including for customer service, service updates, and (where you have not opted out) product information
  • Sending you transactional emails
  • Preventing fraud and abuse

Log Files

The API follows standard logging procedures. The information logged includes internet protocol (IP) addresses, browser types (user agents), date and time stamps, and referring/exit pages. The purpose of this information is debugging, security, and keeping the service running.

Cookies

The application uses a single browser cookie to securely keep you logged in for requests made to the API.

We do not use third-party advertising cookies, and we do not allow third-party cookies or scripts for cross-site tracking.

Data retention

We keep personal data only as long as we need it. In particular:

  • Analytics events: raw, account-keyed analytics events are retained for approximately 90 days, after which they are aggregated into anonymous daily statistics and the underlying raw events are deleted. (The retention window is configurable; see our operational documentation.)
  • Your projects and conversations: retained for as long as your account is active, until you delete the project or your account.
  • Account deletion: when you delete your account we remove your projects, conversations, and associated analytics events, and we destroy the related sandboxes and databases. Some records may be retained where required for legal, accounting, or fraud-prevention purposes.

GDPR & your data protection rights

Every user is entitled to the following:

The right to access & portability – You can request and download a copy of your personal data, including a machine-readable export of your projects, conversations, and account data.

The right to rectification – You can request that we correct information you believe is inaccurate or complete information you believe is incomplete.

The right to erasure – You can delete your account, which erases your personal data as described under "Data retention" above.

The right to restrict processing – You can request that we restrict the processing of your personal data.

The right to object to processing – You can object to our processing of your personal data.

If you make a request, we have one month to respond. To exercise any of these rights, use the data export and account-deletion controls in your account, or contact us.

Your applications' users

Apps you build and deploy with Molecule.dev may collect personal data from their own users. For that data, you are the controller and we act as your processor: we host and process it on your behalf and do not use it for our own purposes. That processing is governed by our Data Processing Addendum. You are responsible for your app's own privacy practices and disclosures to its users.

Sub-processors

We use a small set of service providers to run Molecule.dev: the AI model providers that process your requests, our payment processor (Stripe), and cloud infrastructure providers for hosting, storage, and email delivery. Each processes data only as needed to provide its service to us and is bound by data-protection obligations. Only the data needed to fulfill a given AI request is sent to the provider that fulfills it.

Each AI model processes requests in a specific region, shown next to the model in the model picker. Some models default to providers in the United States; others — including the default DeepSeek models — default to their native region in China, and a few (for example the latest Kimi models) are offered only from China. Requests to a China-region model send that request's prompt and related code to a provider in China. Where a model offers more than one region, you can change it in the picker — the flag shown on each model is the region that will process it. Depending on the model and region, requests may be processed in the United States or other countries, including outside the European Economic Area.

International data transfers

We are a US company and process data in the United States (and in other locations where our infrastructure providers operate). Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

Security

We protect your data with industry-standard measures, including encryption in transit, isolated per-project execution environments and databases, and access controls limiting internal access to those who need it. No method of transmission or storage is 100% secure, but we work to protect your information and will notify affected users of a data breach as required by applicable law.

US state privacy rights

If you live in California or another US state with a comprehensive privacy law, you have rights to access, correct, delete, and port your personal information, corresponding to the rights described above. We do not sell your personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of. We will not discriminate against you for exercising your rights.

Children's Information

Molecule.dev does not knowingly collect Personally Identifiable Information from children under the age of 13. If you believe your child provided this kind of information, please contact us immediately and we will make our best efforts to promptly remove it from our records.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and, for material changes, notify you through the Service. Continued use of Molecule.dev after changes take effect means the updated policy applies.

Contact

Questions about this policy or your data? Contact Molecule Dev, Inc. through the support options in the app or on our website.