Your data never
reaches us.
mploi is self-hosted software. It runs on infrastructure you control, and the conversations, documents and connected-account data it works with stay there. This page explains the narrow set of data mploi.ai itself handles, and for how long.
Last updated 6 August 2026
The short version
Three sentences, then the detail.
mploi Server runs on your infrastructure. Your chats, uploaded documents, agent activity and the data your agents read from connected accounts are stored on your own servers, under your own administration. We have no access to them and receive no copy.
We never see your connected-account content. When you connect a third-party account such as Confluence, Jira, GitHub or Azure, your agent reads that data directly from the provider to your server. Pages, issues, repositories, messages and files never pass through mploi.ai.
The one thing that briefly touches us is the sign-in handoff — described in full below. It is held for at most 60 seconds, can be collected exactly once, and is deleted the moment your server collects it.
What your own server stores
Listed for completeness, because a privacy policy that only covered our side would be telling you half the story. All of this lives in your database, on your infrastructure, governed by your retention and backup policies — not ours.
Accounts. Usernames, email addresses, group memberships, and either a password hash or the identity your SSO provider asserts. Passwords are never stored in a recoverable form.
Conversations and agent work. Chat messages, agent responses, tool calls and their results, uploaded documents, saved memories and scheduled jobs.
Connected-account credentials. Access and refresh tokens for services you connect, stored encrypted at rest and scoped to the individual user who authorized them. One person's connected accounts are never usable by another user, and disconnecting deletes the stored tokens.
Activity logs. Sign-ins, configuration changes, agent runs and individual tool invocations, retained for as long as your administrators choose.
Your administrators can delete any of it at any time. Because the software is self-hosted, deletion is immediate and complete — there is no vendor-side copy to also erase.
The sign-in handoff
The only point at which mploi.ai touches anything of yours, in full detail.
Connecting a third-party account uses OAuth. Providers require
a fixed, pre-registered address to return the user to after
sign-in — which is a problem for self-hosted software, because
every customer's server has a different hostname that no
provider knows about. mploi.ai operates a small relay at
www.mploi.ai/oauth so that customers do not each
have to register their own application with every provider.
What passes through it: the access and refresh token the provider issues, and the display name and email address on the account you signed in with, so your server can label the connection. That is all.
What does not: your Confluence pages, Jira issues, repositories, mail, files, cloud resources or any other content. The relay performs the token exchange and nothing else. It never calls a content API, and your agent's later requests go directly from your server to the provider without involving us.
How long we hold it: the token bundle is written to a single-use record with a 60-second lifetime. Your server collects it immediately, and collection deletes it. A record that is never collected is purged automatically once the 60 seconds elapse. Expired records are also swept on every subsequent operation.
How it is protected: every exchange between your server and the relay is signed and timestamped, so a request cannot be forged or replayed. The one-time identifier used to collect a bundle is unguessable, works exactly once, and carries no token itself — a browser intercepting it after your server has collected the bundle gets nothing.
We do not log token values, and we do not retain a record of which accounts were connected after the handoff completes.
This website
If you contact us or request a demo through this site, we receive the name, email address, organization and message you submit, and use them to reply to you and to follow up about mploi. We do not sell that information or share it with third parties for their own marketing.
Our web server keeps standard access logs — IP address, page requested, timestamp, browser user agent — for operational and security purposes.
Your rights, and who to ask
For anything held inside a deployed mploi instance, the organization running that instance is the data controller. Requests to access, correct, export or delete that data go to that organization's administrators, who can act on them directly — we cannot, because we have no copy and no access.
For data this website holds — a contact form submission, for instance — or for any question about this policy, write to info@mploi.ai and we will respond within 30 days.
We will post any material change to this policy on this page and update the date at the top.
Questions about
how we handle data?
Our team is happy to walk your privacy and compliance leadership through the details.
Talk to Our Team