Scope and roles#
This policy applies globally to individual users, companies, and other organizations when information is processed through MEGA, including account, organization, profile, repository, billing, support, security, and service activity information. In this policy, "MEGA" means the service and the team responsible for operating it. For this information, MEGA generally acts as a controller. When MEGA processes Customer Personal Data only on an organization's documented instructions, MEGA acts as a processor under the Data Processing Addendum.
This policy does not control how an independent third party uses information after you intentionally direct MEGA to that party, publish information publicly, or follow a link to an external service. Review the third party's notice before using that integration.
Information we process#
Account and organization information may include a handle, display name, email or identity-provider identifier, profile fields, organization membership and roles, authentication methods, preferences, and support communications. MEGA does not need your full payment-card number because payment details are handled by the checkout provider.
Content and service information may include repository files and metadata, models, datasets, Space or MCP configuration, discussions, comments, prompts or inputs sent to a selected feature, job and inference metadata, access settings, revision history, and records of actions you take.
Technical and security information may include IP address, device and browser information, request time and route, response status and duration, session and authentication events, rate-limit events, audit records, error details, and security signals. Billing information may include plan, usage, transaction identifiers, invoices, refund or dispute status, and the billing contact supplied to the payment provider.
TensorPlayChat information#
When you use TensorPlayChat, MEGA may process prompts, conversation messages, uploaded attachments, conversation titles, model and feature selections, favorites, feedback and reports, sharing choices, and information about search or connected-tool activity. This information is used to provide conversation continuity, synchronize your saved history, deliver requested model and tool results, support sharing controls, prevent abuse, and diagnose failures.
If you enable a model provider, web search, MCP server, or other connected tool, the information reasonably needed to perform that request may be sent to the selected service. A connected service may process that information under its own terms and privacy notice. Review the service and its permissions before enabling it, especially when a conversation contains personal, confidential, or regulated information.
Saved conversations are private to the signed-in account by default. When you create a public share link, the selected conversation content becomes available to people who have that link for up to 14 days. Recipients may copy or redistribute what they can view. Revoking a share link, its 14-day expiry, or deletion of the underlying conversation prevents later access through that link but cannot remove copies already made by a recipient.
If you enable Memory, MEGA processes the preferences, project context, profile details, or standing instructions you or an enabled tool choose to save. Memory can be reviewed, edited, disabled, searched for relevant context, or removed through Chat settings and authorized MEGA tools. Saved Memory records are not included in public Chat shares. Current instructions and higher-priority safety rules continue to take precedence over saved Memory.
Sources of information#
MEGA receives information directly from you; from an organization administrator; automatically from your browser, device, API, CLI, Git, or other service interaction; from identity and payment providers; and from integrations you authorize. MEGA may also receive public repository or research metadata from public sources when providing discovery features.
Purposes and legal bases#
MEGA processes information to create and secure accounts; provide repositories, storage, compute, inference, billing, support, and community features; carry out your requests; maintain auditability; prevent abuse and fraud; diagnose failures; improve reliability; communicate service or policy changes; and comply with legal obligations.
Where the GDPR or similar law applies, the legal basis depends on the activity:
- performance of a contract for requested service and billing;
- legitimate interests for security, fraud prevention, service reliability, and proportionate product improvement;
- consent for optional analytics or communications that require it; and
- legal obligation for tax, accounting, sanctions, regulatory, and valid legal-process requirements.
You may object to processing based on legitimate interests, subject to applicable exceptions.
Public content and visibility#
Information in a public profile, repository, discussion, Space, MCP listing, article, or other public surface is intended to be visible to visitors and may be indexed by search services. It can include your handle, display name, public profile fields, repository metadata and files, documentation, comments, and revision history.
Set visibility carefully and do not place secrets, credentials, confidential information, or unnecessary personal data in public content. Changing visibility or deleting content does not remove copies that other people lawfully made while it was public.
Analytics, advertising, cookies, and local storage#
MEGA uses essential first-party storage for authentication, security, and interface preferences. MEGA also uses limited first-party measurements to operate and improve the service. These necessary functions do not depend on optional analytics consent.
With your prior permission, MEGA loads Google Analytics, provided by Google LLC, and Better Stack real-user monitoring, provided by Better Stack, Inc., on eligible public pages to understand acquisition, navigation, performance, interaction patterns, frontend errors, and sampled session replays. Google Analytics receives coarse route categories and allowlisted campaign fields. Better Stack is isolated from account, organization-settings, private, and preview documents; MEGA does not identify signed-in users to Better Stack, disables cross-subdomain cookies, strips URL queries from captured error requests, and blocks input controls from replay. Review the Google Privacy Policy and Better Stack Privacy Policy for provider details.
With separate prior advertising permission, approved publisher networks may automatically fill clearly labelled advertising slots. Google AdSense can participate alongside MEGA Sponsored inventory as an equal-priority eligible source; no source receives a guaranteed or paid priority through this pool. The selected network receives the ordinary browser and advertising-request data needed to decide whether it can fill the slot. MEGA does not load an external advertising network when you deny advertising.
Optional analytics and advertising scripts do not load merely because you continue browsing. The first layer offers equally direct reject and accept actions, plus controls for each purpose, and the site remains available if you reject or make no choice. MEGA remembers either decision for 6 months, configures Google Analytics first-party cookies not to renew beyond that period, samples ordinary Better Stack replay sessions at 10 percent while retaining replay on captured errors, and asks again after expiry.
MEGA does not intentionally send account identifiers, access tokens, prompts, payment details, or private repository content as fields to optional analytics or advertising providers. You can withdraw either permission through the floating Cookie settings control. Withdrawal disables future scripts for that purpose; analytics withdrawal also removes accessible first-party Google Analytics and Better Stack cookies. MEGA treats Global Privacy Control or Do Not Track as denial of both optional purposes.
Sharing and service providers#
MEGA does not sell personal information. MEGA shares information only when needed to provide a requested feature, process payment, secure and support the service, comply with law, complete a business reorganization subject to appropriate safeguards, or protect rights and safety.
Core application delivery, database, object storage, security, and related cloud functions use Cloudflare. See the Cloudflare Privacy Policy and Cloudflare Data Processing Addendum. Waffo Pancake handles hosted checkout, subscription, invoice, refund, and payment-dispute information. Optional Google or GitHub identity providers receive information when you choose them. Google Analytics and Better Stack receive the limited public-page analytics described above only after permission. Google AdSense may receive the advertising-request data described above only after advertising permission. Cal.com receives the details you choose to provide when you open the support-booking flow; see the Cal.com Privacy Policy.
User-selected compute, inference, storage, DOI, Space, or other integrations may receive the content and identifiers needed to perform the request. The applicable interface or documentation identifies the provider where practical. Organization administrators can also access information governed by their organization and may control retention, membership, and feature settings.
International transfers#
MEGA and its providers may process information in more than one country. Where law requires a transfer mechanism, MEGA relies on safeguards such as adequacy decisions, contractual protections, or the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate. The destination can also depend on a compute, inference, storage, or other provider you select.
Retention and deletion#
MEGA retains information only for as long as reasonably needed for the purposes described here. Retention depends on account status, repository visibility and history, the feature used, security and audit needs, contractual commitments, backup and cache cycles, dispute preservation, and tax or legal obligations.
You can update profile information and manage repository visibility through MEGA controls. Where deletion is available, production data is removed or de-identified through the applicable workflow; limited copies may remain temporarily in protected backups, caches, fraud-prevention records, or legal holds and are not used for unrelated purposes. Public revision history or copies held by others may remain where deletion is not technically or legally available.
TensorPlayChat conversations and their attachments remain available with the account until you delete them or another applicable retention rule requires removal. Favorites are saved as independent snapshots and remain until you remove them. Public access through a share link ends when you revoke the link, 14 days after it is created, or delete the underlying content, subject to copies already made by recipients and the limited retention described above.
Disabling Memory stops it from being used for new Chat context but does not itself remove saved Memory records. Forgetting an item or clearing Memory removes the selected Memory record; text that already appears in a conversation follows that conversation's separate retention and deletion controls. Permanent account deletion also removes account Memory through the account-deletion workflow, subject to the limited backup, cache, fraud-prevention, and legal-hold retention described above.
Your rights and choices#
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of personal information; object to certain processing; withdraw consent; or appeal a privacy decision. Withdrawal does not affect processing already carried out lawfully. MEGA may verify your identity and authority before completing a request.
Use account and repository settings for available self-service controls, Cookie settings for optional analytics, or the Contact control in the footer for another privacy request. Identify the right you want to exercise and the relevant account or organization. MEGA will respond within the period required by applicable law. EU and EEA residents may also complain to their local supervisory authority listed by the European Data Protection Board.
Security and incidents#
MEGA uses administrative, technical, and organizational safeguards designed for the risk, including encrypted transport, access controls, scoped authorization, credential protection, audit and security records, rate limiting, isolation controls, and incident response. No internet service can guarantee absolute security.
If a personal-data incident requires notice under applicable law, MEGA will notify affected controllers, users, or authorities as required and provide available information about the nature, likely effects, and mitigation. You should protect credentials, review visibility, keep appropriate backups, and promptly report suspected compromise.
Children#
MEGA is not directed to children who cannot legally consent to use the service in their location. MEGA does not knowingly collect personal information from a child in violation of applicable law. A parent or guardian who believes a child supplied information unlawfully should use the Contact control in the footer so MEGA can investigate and take appropriate action.
Contact and complaints#
Use the Contact control in the site footer for privacy questions, rights requests, complaints, or data-protection notices. Provide the account or organization involved and a concise description of the request. Do not include passwords, private keys, access tokens, or full payment-card details.
Policy updates#
MEGA may update this Privacy Policy when processing practices, providers, features, or legal requirements change. The current version and effective date appear on this page. For material changes, MEGA will provide reasonable notice through the service or account contact information when practicable.

