Privacy Policy
Last updated October 6, 2026Monstream is operated by Fairmath. This policy explains what we collect when you use Monstream on the web or in our apps, why we collect it, who helps us process it, and what you can do about it. If anything here is unclear, write to [email protected].
The short version
- We collect what we need to run your account and deliver your streams — nothing for advertising.
- We do not sell your data, and we do not use third-party analytics or tracking.
- The only cookie we set is the one that keeps you signed in.
- You can ask us to delete your account and everything tied to it at any time.
What we collect
- Account details: your email address, display name, handle, and — if you add them — a short bio, a website and your time zone. If you sign up with a password, we store only a one-way hash of it. If you sign in with Google, we receive your email address, name and a Google account identifier.
- Streams you create: their rules — what to look for, what to skip, sources and schedules — and whether each stream is private or public.
- How you use streams: which streams you follow and how you want results delivered (in the app, by email, by push), which results you have read, and the marks you leave on items: saved, relevant, not relevant or hidden.
- Delivery records: which emails we sent you and whether they went out, and — if you turn push on — the push subscription your browser or device gives us.
- Technical data: standard server logs (such as IP address, request times and errors) kept for security and troubleshooting.
What streams find
The results a stream delivers are public material — papers, articles, posts, releases and job listings — found on the open web and in public feeds and APIs. We store them so we can show them to the people who follow the stream. They are not about you.
How we use it
- To run your account, sign you in and keep it secure.
- To run your streams and the ones you follow, and to deliver their results in the app, by email and by push.
- To tune results for you: items you mark as not relevant are hidden from your own feed.
- To send messages about your account, such as confirming your email address or resetting your password.
- To keep Monstream working and safe: fixing errors, preventing abuse, and enforcing our Terms.
We do not use your data for advertising and we do not sell it.
Who processes it for us
We use a small number of service providers, each only for the job listed:
- Railway — hosting for the app and its servers.
- MongoDB Atlas — the database where accounts, streams and results are stored.
- MailerSend — sending emails: results, confirmations and password resets.
- OpenRouter and the AI model providers it routes to — reading what streams find, judging it against a stream’s rules, and writing summaries. They receive a stream’s rules and the public material it found. When you describe a new stream in your own words, that description is sent too. Your email address and account details are not.
- Exa — searching the web on behalf of streams. It receives search queries built from a stream’s rules.
- Google — if you choose to sign in with Google.
- Cloudflare — the domain name and network in front of the site.
- Your browser’s or device’s push service (such as Apple, Google or Mozilla) — if you turn push on, notices travel through it.
What others can see
- Your profile — display name, handle, bio, website — and your public streams are visible to anyone.
- Private streams are visible only to you.
- Which streams you follow, what you read and how you mark items are not shown to other people. Stream authors see how many people follow a stream, not who.
Cookies
We set one cookie of our own, monstream_session, which keeps you signed in. It lasts up to 30 days and cannot be read by scripts on the page. We use Google Analytics to understand how the site is used — which pages are visited and how people find us; it sets its own cookies (_gaand similar). We use no advertising cookies. Your browser may also remember small preferences locally.
How long we keep it
- Account data, streams and your marks — for as long as your account exists.
- In-app notifications — 90 days.
- Server logs — kept briefly for security and troubleshooting.
- When you delete your account, we delete your personal data within 30 days, except where we must keep something by law.
Your choices and rights
- Edit your profile at any time in Settings.
- Turn email or push off for any stream on that stream’s page, or stop emails from a single stream with the link at the bottom of every email.
- Ask for a copy of your data, a correction, or deletion of your account by writing to [email protected] from the address on your account.
Depending on where you live, you may have further rights under laws such as the GDPR or the CCPA. We honour them; write to us to use them.
Security
Data travels over encrypted connections. Passwords are stored as one-way hashes. Keys to the services we use are stored encrypted. No system is perfectly secure, but we work to protect what you trust us with and will tell you if something goes wrong that affects you.
Children
Monstream is not meant for children under 13, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it.
Changes
If we change this policy in a way that matters, we will say so in the app or by email before the change takes effect. The date at the top shows the latest version.
Contact
Questions or requests: [email protected].