MATILLY LEGAL
Privacy Policy
How Matilly collects, uses, discloses and protects personal data.
This Privacy Policy explains how SILICADRIVE PTE. LTD., UEN 202628389C (“Matilly,” “we,” “us,” or “our”) collects, uses, discloses and protects personal data when you use matilly.com and the Services described in the Terms of Service.
Matilly is the organisation or controller responsible for the personal data described here, except where we process data solely on behalf of a business customer under a separate data-processing agreement.
1. Personal data we collect
Account and identity data
Your name, email address, profile image, account identifiers, authentication records, plan and account settings. If you sign in with Google, Google provides the information you authorise it to share.
User Content
Prompts, conversations, uploaded documents, images, audio, video, code, generated output, source selections, tool instructions and feedback. User Content may contain personal data about you or others. Do not submit sensitive or third-party data unless you are authorised and the Services are appropriate for it.
Billing data
Plan, transaction, invoice, tax, billing-country and subscription information. Stripe or another payment provider processes payment credentials. We generally receive limited payment details, such as card brand, last four digits, status and transaction identifiers, rather than the complete card number.
Device, usage and log data
IP address, browser and device type, operating system, language, timestamps, pages and features used, request identifiers, model or service selected, approximate location derived from IP, performance, diagnostic, security and fraud signals.
Communications and support data
Messages, attachments and contact details you provide when seeking help, reporting a problem, completing a survey or communicating with us.
Data from integrations and public sources
When you direct the Services to connect to another service or retrieve public information, we receive the data needed to perform that request. The third party controls what it shares and its own privacy terms also apply.
Cookies and browser storage
We use cookies, local storage and similar technologies as described in the Cookie Policy.
We do not intentionally seek sensitive data such as government identifiers, financial credentials, health records, precise location, biometric templates, political or religious beliefs, or information about children. Avoid placing such data in prompts or files unless Matilly has expressly approved that use.
2. How we use personal data
We use personal data to:
- create and authenticate accounts;
- provide chat, image, video, file, voice, code and connected features;
- generate and deliver output and preserve conversation history you request;
- process subscriptions, invoices, cancellations and support;
- personalise settings and maintain continuity across sessions;
- monitor reliability, measure performance and troubleshoot errors;
- protect accounts, detect fraud, prevent abuse and enforce our terms;
- comply with law and respond to valid legal requests;
- communicate operational, security, billing and policy updates;
- develop and improve features using feedback, testing and aggregated or de-identified metrics; and
- send marketing only where permitted and provide an opt-out.
We do not use private prompts, private files or private outputs to train general-purpose AI models unless you separately and expressly opt in. We may process them to provide and secure the Services. We may also use feedback and aggregated or de-identified operational information that cannot reasonably identify you to evaluate and improve the Services.
3. Legal bases for processing
Where laws such as the GDPR or UK GDPR require a legal basis, we rely on:
- Contract: to create your account, provide requested features and process payment;
- Legitimate interests: to secure, maintain, analyse and improve the Services, prevent abuse and operate our business, where those interests are not overridden by your rights;
- Consent: for optional technologies, certain marketing, optional integrations and any use that law requires you to approve; and
- Legal obligation: to comply with tax, accounting, sanctions, court and regulatory requirements.
You may withdraw consent at any time, without affecting processing already carried out. Some data is necessary to provide the Services; if it is not supplied, a feature may not work.
4. How we disclose personal data
We may disclose data:
- to infrastructure, hosting, security, support, communications and AI service providers acting for us;
- to Google for authentication and connected features you choose;
- to Stripe and financial partners for billing, fraud prevention and payment processing;
- to Cloudflare for secure delivery, DNS, traffic protection and tunnelling;
- to third parties when you direct a tool, integration, share or export;
- to professional advisers, auditors, insurers and potential transaction parties under confidentiality obligations;
- to authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud or enforce agreements; and
- as part of a merger, financing, reorganisation or sale, with appropriate safeguards.
We do not sell personal data for money. Matilly does not currently use personal data for cross-context behavioural advertising. If that changes, we will update this policy and provide any consent or opt-out rights required by law before enabling that use.
5. International transfers
Matilly and its providers may process data outside your country. Where required, we use contractual, organisational and technical safeguards intended to provide a comparable level of protection, such as recognised transfer clauses and transfer-risk assessments. Contact [email protected] for information about applicable safeguards.
6. Retention
We keep personal data only as long as reasonably necessary for the purposes described in this policy, including providing the Services, account security, fraud prevention, dispute resolution and legal compliance.
Account information is ordinarily kept while your account is active. Conversations and files are kept until you delete them, close your account, or they are no longer needed to provide the Services. Security, diagnostic and support records are kept for a period proportionate to their operational or legal purpose. Billing and tax records are kept for the period required by applicable law. Deleted data may remain in encrypted backups until the relevant backup cycle expires.
Retention may be extended for security incidents, fraud prevention, legal holds, disputes or mandatory recordkeeping. We may retain aggregated or irreversibly de-identified information. You may ask about retention applicable to your account by contacting [email protected].
7. Security
We use administrative, technical and physical safeguards designed to protect personal data, including access controls, encryption where appropriate, logging, backups and service isolation. No system is completely secure. Protect your account, use secure devices and notify [email protected] immediately if you suspect misuse.
8. Your choices and rights
Depending on where you live, you may have rights to:
- know or access the personal data we hold about you;
- correct inaccurate data;
- delete data;
- receive a portable copy;
- object to or restrict certain processing;
- withdraw consent;
- opt out of marketing and certain targeted advertising;
- appeal a rights-request decision; and
- complain to your local data-protection authority.
You can manage some information in the product. For other requests, email [email protected]. We may verify your identity and may decline or limit a request where law permits. Authorised agents must provide proof of authority.
Singapore users may request access to and correction of personal data and may withdraw consent subject to the Personal Data Protection Act 2012. Matilly's Data Protection Officer is available at [email protected].
9. Cookies and communications
See the Cookie Policy for information about cookies and browser storage. You can unsubscribe from marketing emails through the message link, while still receiving essential account, security and billing notices.
10. Children
The Services are not directed to children under 13 or under the minimum age required in their country, and we do not knowingly collect their personal data. If you believe a child has provided data contrary to this policy, contact [email protected] so we can investigate and take appropriate action.
11. Third-party links and services
Third-party websites, integrations and services have their own privacy practices. Review them before sharing information. This policy does not govern a third party's independent processing.
12. Changes to this policy
We may update this policy to reflect changes in law or the Services. We will update the effective date and provide additional notice where required. Material changes apply prospectively.
13. Contact and complaints
SILICADRIVE PTE. LTD. (UEN 202628389C)
163 Kallang Way, #04-18
Mapletree Hi-Tech Park @ Kallang Way
Singapore 349256
Data Protection Officer
Privacy: [email protected]
You may also contact the Personal Data Protection Commission of Singapore or the competent authority where you live.