1. Who we are
MUGEN 無限 (“MUGEN”, “we”, “us”) provides an AI business control tower: a workspace where you deploy AI agents that plan, dispatch and act across your tools — chat, voice, media generation, CRM, email, knowledge and more — under spend caps, authority scopes and human approval gates that you control. This policy explains what data we process, why, and the controls you have over it.
Questions about this policy can be sent to support@osmugen.com.
2. What we collect
Account data
When you create a workspace we collect your name, email address and the industry you select. If you sign in with Google, we receive the profile information you authorize (name and email) from Google.
Workspace data
- Your keys (“BYOK”): API keys you choose to connect (LLM providers, media providers, email, CRM). Keys are encrypted with AES-256-GCM under a per-tenant key before storage; we never store plaintext secrets and never display a stored key again.
- Generated media: images and videos you create in the Media Studio are stored in per-tenant object storage and can be deleted by you at any time.
- Knowledge & memory: documents and notes you import, and memory rows produced by voice or chat sessions, so your agents can reuse context.
- Activity & audit: dispatch records, spend ledger entries and audit rows that power your dashboard’s stats, approvals and audit view.
Usage data
Aggregate request counts and latency metrics used to enforce your spend caps and rate quotas. We do not sell your data and do not train models on your workspace content.
3. Google Drive and Dropbox access
When you connect Google Drive, we request the narrow drive.file scope. This grants access only to files you explicitly create or open through MUGEN — we cannot see, list, modify or delete the rest of your Drive. Exported media and knowledge bundles are written into a dedicated MUGEN/ folder you own.
- Offline access: we request offline access so exports can be uploaded on your behalf without you being signed in. The access and refresh tokens are stored in your encrypted per-tenant vault and never leave our systems in plaintext.
- Revocation: you can disconnect at any time from the Integrations page; the tokens are deleted from your vault. You can also revoke access directly in your Google Account or Dropbox security settings.
- Dropbox: the same model applies — a scoped app connection that writes only to the MUGEN/ app folder.
4. How we store and protect data
- Encryption in transit (TLS) and at rest.
- Secrets encrypted with AES-256-GCM + HKDF per-tenant keys; the vault master key is never shipped in code or committed to repositories.
- Multi-tenant isolation: your data is scoped to your workspace at every layer (session-derived tenant only — we never trust a client-supplied tenant header).
- PostgreSQL for structured data and per-tenant object storage (MinIO) for media bytes.
- SSRF-hardened connectors and fail-closed authorization on every non-public route.
5. Sharing and third parties
We do not sell or rent personal data. We share data only with the providers you explicitly connect to (the platform you gave us a key or OAuth grant for) and the infrastructure vendors that host the service. Where we engage processors, they act only on our instructions and under confidentiality obligations.
6. Retention and deletion
You can delete individual assets (media, knowledge items, memories) at any time. Settings → Workspace Data provides a full workspace export and a permanent delete that removes your rows and media from our systems (with credential redaction on export). Ledger and audit rows are retained to the extent required to operate billing and safety gates, then deleted with your workspace.
7. Your rights
Depending on your jurisdiction (including the GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict processing. To exercise them, contact support@osmugen.com — we respond within 30 days.
8. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the console and the “last updated” date above will advance. Continued use of the service after changes constitutes acceptance.