Privacy Policy
Effective July 29, 2026 · Last updated July 29, 2026
This policy explains what Monogram Creative, LLC (“we”, “us”) does with personal information in Miliarium (the “Service”). It sits alongside the Terms of Use.
1. Two different roles
We handle two kinds of personal information, and the law treats them differently.
Your account. For information about you as our customer, we are the controller. We decide why and how it is used, and this policy tells you what we do.
Your customers. For information you enter about the people you work for, you are the controller and we are your processor. We act on your instructions, not our own. If one of your customers asks us to delete their information, we will point them to you, and tell you about the request.
2. What we collect
Account information. Your email address, business name, logo, accent colour, reply-to address, and your plan and subscription status.
Job information you enter. Your customer’s name and email address, the job title and type, start and delivery dates, the stages you define, and any note you write for display on the status page.
Activity records. A log of stage changes, date changes, and note changes on each job, plus a record of every notification email we send on your behalf and whether it was delivered.
Technical information. IP address, browser type, and timestamps in server logs, kept for security and debugging.
We do not ask for and do not want payment card numbers, government identifiers, health information, or other sensitive categories. Do not put them into the Service.
3. Why we use it, and on what legal basis
- To run the Service and provide what you signed up for — performance of our contract with you.
- To send sign-in links and service notices — performance of our contract.
- To send the notification emails you configure — performed as your processor, on your instructions.
- To keep the Service secure, investigate abuse, and prevent fraud — our legitimate interests.
- To meet tax, accounting, and other legal obligations — legal obligation.
We do not use your information or your customers’ information to train machine learning models, and we do not build advertising profiles.
4. We do not sell your information
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in California law. We have never done so.
5. Cookies
We set a cookie holding a random session identifier once you sign in, so the Service knows who you are. It is not used for tracking, advertising, or analytics, and it is strictly necessary for the Service to work, so no consent banner is required. Signing out deletes the session cookie.
Status pages set no cookies at all. Your customers can open a status page without anything being stored on their device.
6. Status pages are link-accessible
Each status page sits at an address containing 128 bits of randomness, which cannot be guessed. We send headers telling search engines not to index those pages. There is no password on them, so anyone your customer forwards the link to can read the page. You can regenerate a link at any time, which immediately breaks the previous one.
7. Who else touches the data
We use a small number of vendors to run the Service. Each is bound by a written contract limiting them to our instructions.
| Vendor | Purpose | Location |
|---|---|---|
| NixiHost LLC | Application and database hosting | Houston, Texas, United States |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | United States |
| Lemon Squeezy, LLC | Payment processing and merchant of record | United States |
We will email you before a new vendor starts handling your data, so you have time to object or leave. We may also disclose information where the law compels it, and we will tell you unless we are forbidden from doing so.
8. Where the data lives
Our vendors process data in the United States. If you or your customers are in the United Kingdom, the European Economic Area, or Switzerland, that is a transfer out of your region, and it relies on the European Commission’s Standard Contractual Clauses together with the UK Addendum.
9. How long we keep it
- Sign-in links: deleted within 24 hours of expiry.
- Sessions: deleted at expiry, or immediately when you sign out.
- Jobs, stages, and activity records: for as long as your account is open, then 30 days after it closes.
- Email delivery records: 24 months, as evidence of what was sent and whether it arrived.
- Server logs: 30 days.
- Backups: overwritten on a rolling 30 day cycle, so deleted data can persist in backups for up to 30 days.
- Billing records: as long as tax law requires, generally seven years, held by our merchant of record.
10. Security
Traffic runs over TLS. Sign-in links and session tokens are stored as hashes, so a copy of the database alone cannot be used to sign in as anyone. Status page addresses use 128 bits of randomness. Access to production systems is limited to people who need it and protected by multi-factor authentication.
No system is perfectly secure. If a breach affects your information, we will tell you without undue delay and within 72 hours of becoming aware where the law requires it, describing what happened, what it affects, and what we are doing about it.
11. Your rights
Depending on where you live, you may have the right to see the personal information we hold about you, correct it, delete it, receive a portable copy, restrict or object to certain uses, and complain to a regulator. California residents may also request the categories of information collected and the purposes, and are protected from retaliation for exercising these rights.
Email hi@monogramcreative.co and we will respond within 30 days. We do not charge for this. We may ask you to confirm control of the email address on the account before we act.
If you are one of our customers’ clients and want your information removed from a status page, contact the business that sent you the link. They control that record. Tell us at hi@monogramcreative.co and we will pass the request along.
12. Processing terms
Where we act as your processor, these terms apply and satisfy Article 28 of the UK and EU GDPR. We process personal information only on your documented instructions, which are the actions you take in the Service and this agreement. We keep the people who handle it bound to confidentiality, apply the security measures described above, and engage sub-processors only under equivalent written terms and with notice to you.
We will help you respond to requests from your customers and, given the information available to us, help you with security, breach notification, and impact assessments. When our agreement ends we delete the data on the schedule in section 9. The subject matter is operation of the Service; the duration is the term of your account; the categories of person are your customers; and the categories of data are name, email address, and job details.
13. Children
The Service is for business use and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child’s information reached us, write to hi@monogramcreative.co and we will delete it.
14. Changes
We will post any update here and change the date at the top. For a change that materially affects how we handle your information, we will email you at least 30 days beforehand.
15. Contact
Monogram Creative, LLC. Privacy questions go to hi@monogramcreative.co.