Skip to content

1. Account and organization data

We store information required for authentication and workspace operation, such as name, email, Google identifier when used and organization membership. Passwords are stored as derived values, not plain text.

The browser stores the authenticated session token locally. Strictly functional cookies remember the selected interface language and whether the cookie notice was acknowledged. MuriOps currently does not use advertising or behavioral analytics cookies.

2. Projects and results

We store registered URLs, settings, discovered pages, scores, findings, technical evidence and generated results. This data supports history, run comparisons and remediation plans.

Do not place secrets in names, descriptions or URLs. An analysis may observe content publicly exposed by the analyzed website.

3. AI providers

When you configure Claude, OpenAI or Gemini, relevant parts of findings, descriptions or plans are sent to the selected provider for processing. That provider's terms and policies also apply.

Without your own configured key, MuriOps does not silently use a shared key: responses fall back to deterministic mode.

4. Integration credentials

AI keys and third-party integration credentials are encrypted before database storage and decrypted only for the requested operation. MuriOps-generated bridge tokens are access credentials stored for exact lookup; protect and regenerate them if exposed. Always use minimum-scope credentials and revoke third-party access at the source when disconnecting a service.

5. Sharing and retention

We do not sell personal data. Data may be processed by essential hosting, database, authentication and user-selected provider services only as needed to deliver the product.

Projects, analyses and blueprints can be deleted in their respective areas. An authenticated user can download an account data copy or permanently delete the account under Settings. Some records may be retained only when required by law, to exercise legal rights or to prevent fraud and abuse.

6. Your data rights

Subject to applicable law, you may request confirmation of processing, access, correction, portability, anonymization, blocking or deletion of eligible data, information about sharing, and review of consent choices.

Account export deliberately excludes passwords, credential material, AI keys, bridge tokens and webhook secrets. These secrets are never included in download links or query parameters.

7. Contact

Privacy requests can be sent to .privacidade@muriops.com.br