Legal
Privacy Policy
Effective and last updated July 31, 2026
Monolith is a business decision-support platform operated by Mark Shapiro ("Monolith," "we," "us," or "our"). This Policy explains how information is collected, used, disclosed, and protected when authorized users access Monolith.
1. Information we collect
Depending on the features used, we may collect:
- Account and organization information: name, username, email address, role, company, permissions, account preferences, and onboarding status.
- Business and relationship information: companies, contacts, relationships, meetings, communications, notes, clients, prospects, and associated records entered by users or imported by an authorized organization.
- Opportunity and decision information: procurement opportunities, searches, screening results, verdicts, assessments, actions, institutional knowledge, investment cases, diligence materials, financial assumptions, and decisions.
- Documents and AI content: uploaded files, pasted text, source links, extracted text and facts, prompts assembled by the service, model responses, citations, reviews, and user corrections.
- Public-source information: records from sources such as SAM.gov, USAspending, SBIR/STTR, SEC EDGAR, USPTO, company websites, and other reviewed public sources.
- Technical and security information: IP address, browser and device information, session and security events, audit history, feature usage, errors, request timing, and authentication records. For authenticated activity, routine logs may include an internal user ID, role, active organization ID, page or endpoint path, request method, response status, duration, and timestamp. Passwords are stored as one-way hashes, not as readable passwords.
2. Activity logging
Monolith records successful sign-ins and sign-outs, security events, changes to business records, aggregate daily usage, and limited request metadata. We use these records to secure accounts, enforce organization access, provide administrators with audit history, investigate errors, and improve reliability. Routine request logs are designed not to contain passwords, form bodies, uploaded document contents, business-record text, or AI prompts and responses. Information submitted to a feature may still be stored as an authorized business record or AI evidence item as described elsewhere in this Policy.
3. How we use information
We use information to operate and secure Monolith; authenticate users; enforce organization and role permissions; provide CRM, opportunity, assessment, memory, and fund-intelligence workflows; extract and organize evidence; generate user-requested AI analysis; maintain audit history; diagnose errors and performance; improve the service; communicate about accounts or security; and comply with legal obligations.
4. AI processing
When an authorized user invokes an AI feature, relevant prompts, records, and document text may be sent through OpenRouter to the selected model provider. Routine navigation, rules-based scoring, CRM operations, and searches do not require premium AI processing. AI output can be incomplete or incorrect and must be reviewed before use. Do not upload information your organization is not authorized to process or disclose.
5. How information is disclosed
We may disclose information to service providers that help operate Monolith, including Render for application hosting, Supabase and PostgreSQL infrastructure for data storage, OpenRouter and selected model providers for user-requested AI processing, and Google Fonts for web typography. These providers process information under their own terms and privacy practices. We may also disclose information when required by law, to protect rights or safety, to investigate misuse, or as part of a merger, financing, acquisition, or transfer of the service.
We do not sell personal information or share it for cross-context behavioral advertising.
6. Organization-controlled data
Much of the information in Monolith is business data controlled by the organization that invited the user. That organization determines which records its users may enter and access. Requests concerning organization-controlled data may be referred to the relevant organization administrator.
7. Cookies and similar technology
Monolith uses essential cookies and browser storage for secure sessions, cross-site request-forgery protection, display preferences, and tutorial progress. If “Keep me signed in” is selected, the secure session can remain active for up to 30 days unless the user signs out or the session is revoked. We do not use advertising cookies or cross-site behavioral tracking. Because we do not track users for advertising across unrelated sites, Monolith does not respond differently to browser "Do Not Track" signals.
8. Retention
We retain information while an account or organization is active and as reasonably needed to provide the service, preserve authorized audit history, secure and troubleshoot the platform, maintain backups, resolve disputes, and meet legal obligations. Operational request logs are retained according to the hosting and security log cycle; daily usage aggregates and audit events may be retained longer for account administration, security, and record integrity. Retention can vary by record type and organization instructions. Information may remain in backups until the applicable backup cycle completes.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, tenant and role restrictions, secure sessions, password hashing, audit logging, encrypted network connections in hosted environments, and restricted credentials. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
10. Your choices and requests
Authorized users may review and correct many records in Monolith. To request access, correction, deletion, or an export of personal information, or to ask a privacy question, contact Info@jmshapiro.com. We may need to verify identity and authority before acting. Some information may be retained where required for security, audit integrity, legal obligations, or another permitted purpose.
11. California notice
California residents may request information about the categories of personal information collected and disclosed, and may request access, correction, or deletion where applicable. The categories described in Section 1 are collected for the business purposes in Sections 2 and 3 and may be disclosed to the service-provider categories in Section 5. Monolith does not sell personal information or share it for cross-context behavioral advertising.
12. Children and international access
Monolith is a business service for users age 18 or older and is not directed to children. The service is operated from the United States. Users outside the United States understand that information may be processed in the United States and other locations used by our service providers.
13. Changes to this Policy
We may update this Policy as Monolith changes. We will post the revised version here with a new effective date and provide additional notice when a material change requires it.
14. Contact
Privacy questions and requests: Info@jmshapiro.com.