Malloy Studio Privacy Policy
Version 2.0 | Effective date: September 16, 2026
Malloy Labs (“Malloy,” “we,” “us,” or “our”) provides Malloy Studio, including our websites, creator portal, application programming interfaces, and tools made available through ChatGPT and other Model Context Protocol (“MCP”) clients (together, the “Service”).
This policy explains what data we collect, why we use it, who receives it, how long we keep it, and the choices available to you. It applies when you use the Service directly or connect your Malloy account to a supported AI assistant.
1. Data we collect
Account and profile data
We collect your email address, name, password hash when you use password sign-in, social sign-in provider and account identifier when you use Google sign-in, organization and role information, account creation date, subscription status, plan, and credit or storage balances.
Content and files you provide
We collect animation prompts and revisions, answers you give during planning, aspect ratio and generation-style selections, editable template values, brand guidelines, and images, logos, GIFs, SVGs, or reference images you choose to upload. File data includes the file name, media type, size, storage key, and upload date. Please do not provide payment-card data, health information, government identifiers, passwords, API keys, authentication codes, or other sensitive information in prompts or uploads.
Generated content and activity
We store generated animation code, templates, preview data, editable parameters, exported video settings and files, generation and export status, errors, timestamps, and usage of generation and export credits. This lets you resume, edit, preview, save, and export your work.
ChatGPT and MCP connection data
When you connect Malloy to ChatGPT or another MCP client, we receive your Malloy account identifier and only the tool inputs that the client sends to Malloy. Depending on the tool you use, those inputs can include a prompt, aspect ratio, generation style, Malloy session, template, export or asset identifiers, editable template values, export settings, a file name, media type and size, or an asset search term. We also process OAuth client information, authorized scopes, token hashes, token issue and expiry times, and revocation status to secure the connection. We do not request or retrieve your full ChatGPT conversation history.
Malloy tool responses may return job status and errors; Malloy session, template, export or asset identifiers; template names, dimensions, duration, creation time and editable parameters; asset names, types, sizes and upload dates; plan and credit information; temporary upload fields; and time-limited preview, asset or export URLs. The connected AI service processes the inputs and outputs under its own terms and privacy policy.
Payments and commercial data
Our payment providers process your payment-card and billing details. Malloy receives transaction identifiers, customer and subscription identifiers, plan, payment status, billing dates, country or tax information where needed, and cancellation feedback. We do not receive or store full payment-card numbers.
Device, usage, and diagnostics data
We collect IP address, browser and device information, referring URL, pages viewed, clicks and feature interactions, cookie or device identifiers, approximate location derived from IP address, request and event times, performance data, and application errors. Our product analytics may associate usage with your email address, account, plan, and subscription state. Server observability may include request headers, request paths, tool calls, network calls, and error details. Do not place secrets in URLs, prompts, or file names.
Communications and support
We collect messages, attachments, contact details, and related account information when you contact support, use our in-product messenger, join a mailing list, respond to a survey, or otherwise communicate with us.
2. How we use data
- Provide, authenticate, secure, and operate the Service.
- Generate, revise, preview, save, and export motion graphics at your request.
- Provide asset storage, account history, plan entitlements, usage limits, and billing.
- Connect your Malloy account to ChatGPT or another MCP client and carry out the specific Malloy tool calls you authorize.
- Diagnose errors, prevent abuse, enforce rate and credit limits, and protect users and the Service.
- Analyze feature use, improve performance and usability, measure marketing, and understand which features lead to successful use of the product.
- Send transactional messages, provide support, and send marketing communications where permitted. You may unsubscribe from marketing messages at any time.
- Comply with law, enforce our agreements, and establish or defend legal claims.
We do not use your prompts, uploaded assets, private templates, or exported videos to train models for other Malloy customers. We do not sell personal data for money.
3. How AI generation works
To generate or revise an animation, Malloy sends the prompt and any reference or selected asset needed for that request to an AI provider. Depending on the generation method and availability, that provider may be Google (including Google Vertex AI or Google AI services) or OpenAI. Providers return generated text, code, images, or related results to Malloy. We send only the content needed to perform the requested generation. Provider handling is also governed by the provider's applicable service terms and privacy commitments.
Connecting Malloy to ChatGPT does not give Malloy access to all of your chats. ChatGPT decides what explicit tool input to send when a Malloy tool is called. ChatGPT and OpenAI may separately process your conversation, tool inputs, and tool outputs under OpenAI's own terms and privacy policy.
4. Who receives data
We disclose data only as needed for the purposes described above. The categories of recipients are:
- AI providers: OpenAI and Google receive prompts and any necessary reference images or assets to generate or revise content.
- Connected AI clients: OpenAI/ChatGPT or another MCP client receives the Malloy tool outputs described above when you connect and use that client.
- Infrastructure and storage providers: providers that host the website, application, databases, queues, logs, files, content delivery, rendering, and email, including Amazon Web Services, CloudFront, Vercel, Logfire, Redis infrastructure, and Resend.
- Payment and subscription providers: Stripe and, where offered, PayPal or other checkout providers process purchases, subscriptions, refunds, tax, and fraud signals.
- Analytics, advertising, and referral providers: PostHog, Google Analytics and Google Tag Manager, Microsoft Clarity, Meta, and FirstPromoter receive device, usage, account, conversion, or referral data according to the features that are enabled.
- Communications and support providers: Intercom, Resend, and Kit (formerly ConvertKit) receive contact and message data needed to provide support and email communications.
- Authentication providers: Google receives sign-in requests when you choose Google sign-in.
- Legal and corporate recipients: advisers, authorities, courts, or a buyer, investor, or successor may receive data when reasonably necessary for legal compliance, safety, a corporate transaction, or the protection of rights.
These providers may process data in countries other than yours. Their own privacy policies apply when they act as independent controllers of your data.
5. Retention
We keep data only for the periods below or for the shorter period required by law. Where a period is described as “account lifetime,” we keep the data while your account is open so that you can continue to access your work.
| Data | Retention period |
|---|---|
| Account, profile, prompts, generation sessions, saved templates, editable parameters, and library assets | For the account lifetime, until you delete an available item, or until your verified deletion request is completed. |
| Temporary style-reference uploads | Automatically expire within a few days and are not added to your asset library. |
| Rendered export files | 7 days. A download URL expires within 24 hours and may be replaced with another time-limited URL during that period. |
| MCP credentials and temporary connection data | Access tokens: 1 hour; preview tokens: 4 hours; refresh tokens: 30 days unless revoked sooner; dynamic client registrations: 90 days. We store refresh-token hashes rather than usable refresh tokens. |
| Security, application, and diagnostic logs | Normally up to 90 days. Logs tied to a security incident or legal obligation may be kept longer until the matter is closed. |
| Website and product analytics | Up to 24 months in Malloy-controlled analytics projects, subject to any shorter period selected in the relevant provider. |
| Support and business communications | Up to 24 months after the conversation closes, unless needed for an active account issue or legal claim. |
| Billing and transaction records | Up to 7 years after the transaction or as otherwise required by tax, accounting, and payment laws. |
After a verified account-deletion request, we delete or de-identify account content from active systems within 30 days unless retention is required for fraud prevention, security, payment disputes, tax, accounting, or another legal obligation. Residual encrypted backups are overwritten on their normal cycle, generally within an additional 30 days. Our providers may keep limited records under their own legal obligations and retention schedules.
6. Your choices and controls
- Access and correction: review and update available profile and project information in the Service, or contact us for help.
- Delete content: delete library assets where the Service provides a delete control, or ask us to delete other account content.
- Disconnect AI clients: disconnect Malloy from the connected client or contact us to revoke all active Malloy MCP refresh tokens. Revocation takes effect for an existing access token within no more than one hour.
- Delete your account or obtain a copy of data: email us from the address associated with your account. We may need to verify your identity before completing the request.
- Marketing: use the unsubscribe link in a marketing email. We may still send transactional or security messages.
- Cookies and advertising: use browser settings to block or clear cookies and use the controls offered by Google and Meta. Blocking cookies may affect sign-in, referrals, preferences, or other Service features.
Depending on where you live, you may also have rights to object, restrict processing, withdraw consent, or complain to your local data protection authority. To exercise a right, email support@malloy.sg. We will not discriminate against you for making a privacy request.
7. Cookies and similar technologies
Malloy and the analytics, advertising, support, and referral providers listed above use cookies, local storage, pixels, and similar technologies. These technologies keep you signed in, remember settings, attribute referrals, measure use and conversions, diagnose problems, and support advertising. They may collect page URLs, IP address, browser information, identifiers, and interaction events. Your browser and the relevant provider controls let you limit these technologies; some are necessary for authentication and security.
8. Security
We use administrative, technical, and organizational safeguards designed to protect data, including encryption in transit, encryption at rest for supported storage, access controls, account-scoped authorization, signed and time-limited file URLs, hashed passwords and MCP refresh tokens, and monitoring. No service can guarantee absolute security. Keep your credentials private and tell us promptly if you believe your account has been compromised.
9. International transfers
Malloy is based in Singapore, and we and our providers process data in Singapore, the United States, and other countries where we or they operate. Those countries may have different data-protection laws. Where required, we use appropriate contractual or legal safeguards for international transfers.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided data to us, contact us so we can delete it. Users who are not old enough to consent under local law should use the Service only with authorization from a parent or guardian.
11. Changes to this policy
We may update this policy as the Service or law changes. We will post the revised policy here and update the effective date. If a change materially affects how we use personal data, we will provide additional notice where required.
12. Contact us
For privacy questions, requests, or complaints, contact Malloy Labs at support@malloy.sg and use the subject line “Privacy Request.”