Skip to content

Privacy Policy

Last updated 4 October 2026

This policy explains what personal data Mololab, LLC (“Molo Lab”, “we”, “us”) collects through MoloPilot, our website at molopilot.com and our emails, what we do with it, who we share it with, and the choices and rights you have. For the personal data of the people who use MoloPilot, we are the controller.

In short

  • We collect what MoloPilot needs to run your advertising: your Google sign-in, your product’s information, and what you let it read from Meta and Slack.
  • We use it to provide MoloPilot to you. We never sell it, never use it to advertise to you, and never use it to train AI systems.
  • Card details go to Stripe, never to us.
  • Disconnect Meta and we delete what MoloPilot read from it. Ask, and we delete your whole account: see How to delete your data.
  • MoloPilot uses only the cookies it needs to keep you signed in.

The sections below are what apply.

1. Who this covers

This policy applies to anyone who visits our website, signs in to MoloPilot, or receives an email from us.

MoloPilot is used by businesses. When a business uses it to handle personal data about other people, such as the people in its photos and posts or the colleagues it adds to receive reports, that business decides how the data is used and we handle it for them, as Data we handle for our customers explains. If that is you, the business is the first place to ask, and we will help it answer.

2. What we collect

When you sign in with Google

Your name, email address, profile picture, Google account identifier, whether Google has verified your email address, and your language setting. We never see your Google password.

What you give MoloPilot

Your workspace’s name and time zone; the websites and app store listings you add; the files you upload; anything you type or correct, such as your product’s description, brand, audiences and facts about your business; your boundaries and settings; and the email addresses and Slack channels you choose for reports.

What MoloPilot creates

Its understanding of your product, brand and audiences; the advertisements it writes and makes; its decisions and the reasons for them; your activity log; and the lessons it learns from your results.

When you connect Meta

With your permission, MoloPilot receives:

  • a credential that lets it act on your behalf, which we store encrypted, and the list of permissions you granted;
  • your Meta user identifier, and the advertising accounts, Facebook Pages and pixels you can use, with their names and the businesses they belong to;
  • for the advertising account you choose: its status, currency and time zone, and, where Meta shows them to you, how it pays Meta (the payment method’s description, such as a card’s brand and last four digits, the balance due, any spending limit, and recent payments);
  • the campaigns, ad sets and advertisements on that account and their results, such as spend, reach, impressions, clicks and conversions. These are totals about your advertising, not information about individual people;
  • if you turn on Use my Instagram posts: posts your Instagram account published in the past year and the ones it publishes after, with their pictures, videos, captions, links, dates, and like and comment counts, and whether each can run as an advertisement.

When you connect Slack

Your Slack workspace’s name and identifier, a credential that lets MoloPilot post (stored encrypted), the channels it can see, and the channels you choose.

When you subscribe

Stripe collects your payment details. We receive your Stripe customer and subscription identifiers, your plan and billing status, invoice records, and a fingerprint Stripe calculates from your card, which recognizes a card without revealing its number. We never receive your card number or security code.

Public information

The pages of the websites and store listings you add, and advertisements that businesses in your market have made public in Meta’s Ad Library.

Technical information

When you sign in, we record the IP address and browser your session started from, to keep your account secure. Our servers keep logs of requests to keep MoloPilot running and to investigate problems. We do not use analytics or advertising trackers.

When you contact us

Your message and our reply.

3. How we use it

We use personal data to:

  • create your account, sign you in and keep your account secure;
  • provide MoloPilot: understand your product, make advertisements, run them on your advertising account within your boundaries, and show you what happened and why;
  • send your reports and alerts. The person who creates a workspace receives a daily report by default, which they can change or stop at any time;
  • take payments, manage your plan and credits, and prevent fraud and repeated free trials;
  • answer your questions and requests;
  • keep MoloPilot working, investigate problems and improve it;
  • tell you about changes to MoloPilot, to these policies or to your plan;
  • meet legal obligations, such as keeping financial records, and protect our rights.

We never sell personal data, never share it for advertising across other companies’ services, and never use it to advertise to you.

5. AI and automated decisions

MoloPilot uses AI services to read your product’s information and pictures, write and make advertisements, check them, and decide what to change in your advertising. For each task we send them only the content it needs, such as product information, pictures, posts and advertising results. They work for us as service providers, as Who we share it with explains.

We do not use your data to train AI systems.

MoloPilot’s automated decisions are about your advertising, within the boundaries you set. It makes no decision about an individual person that has a legal or similarly significant effect on them.

6. Information from Google

We use the information Google provides when you sign in only to create your account, sign you in, identify you in your workspace, and contact you about MoloPilot, including your reports. We keep it in our database while your account exists. We share it only with the service providers that help us run MoloPilot, such as our hosting and email providers, with Stripe, where your email address is the contact on your customer record, and where the law requires. We never sell it, use it for advertising, pass it to data brokers, or send it to AI services.

You can remove MoloPilot’s access in your Google Account. To delete the information itself, see How to delete your data.

7. Information from Meta and Instagram

We use what we receive from Meta only to provide MoloPilot to the business that connected it: to show its accounts, read its advertising, run and change its advertisements within its boundaries, show how its account pays Meta, and, with its consent, use its Instagram posts. We never sell or license it, never use it to build profiles of people, never use it to decide anyone’s eligibility for housing, employment, credit or insurance, never use it for surveillance, and share it only with the service providers that help us run MoloPilot.

Disconnecting your Meta account in MoloPilot deletes the credential and the campaigns, results and posts MoloPilot read from it. Turning off Use my Instagram posts deletes the posts and pictures MoloPilot imported from Instagram. Your activity log keeps its record of what MoloPilot did, and advertisements already published stay on your advertising account, which is yours.

You can also remove MoloPilot in your Facebook settings, under Business integrations. MoloPilot can then no longer read or change anything, and you can ask us to delete what we hold, as How to delete your data describes.

8. Who we share it with

We share personal data only in these ways:

  • Service providers that run parts of MoloPilot for us, under contracts that require them to protect it and use it only to serve us: hosting and databases; file storage; reading and rendering the web pages you give MoloPilot; AI services that analyze content and make words, pictures and video; a service that collects public advertisements from Meta’s Ad Library; email delivery; and maps. Email us for the current list.
  • The services you connect: Meta, to run your advertising, and Slack, to post your reports.
  • Google, to sign you in.
  • Stripe and Link, to take payments and prevent fraud. They handle your payment details under their own privacy policies.
  • People you choose: the report recipients you add receive the reports you send them.
  • For legal reasons: when the law, a court or a public authority requires it, or to protect the rights, safety and property of our customers, the public or Molo Lab.
  • In a business transfer: if Molo Lab merges, is acquired or sells its assets, personal data may move with it under this policy, and we will tell you before it becomes subject to a different one.

9. Data we handle for our customers

Some data a business brings into MoloPilot is about other people: the people who appear in its photos, videos and posts, people named on its website, and colleagues it adds to receive reports. We handle that data for the business and on its instructions, as our Terms of Service describe.

Someone added to receive reports is asked by email to confirm before any report is sent to them, and every report email can be stopped with one click.

10. Cookies and browser storage

MoloPilot uses only the cookies it needs to work, which is why it does not ask for cookie consent:

  • molopilot_access and molopilot_refresh keep you signed in, for up to 30 days at a time, renewed while you use MoloPilot;
  • molopilot_session tells the site whether to show the home page or your dashboard, and holds nothing about you;
  • short-lived cookies protect a sign-in or a connection while you are on Google’s, Meta’s or Slack’s page, for a few minutes.

MoloPilot also keeps a few things in your browser’s own storage, such as your sound setting, or a plan or a link you chose before signing in, so they are not lost. We do not use advertising or analytics cookies.

When you open a map in MoloPilot, it is loaded from our map provider, which receives your IP address to deliver it.

11. How long we keep it

We keep personal data only as long as we need it for the purposes in this policy:

  • your account and workspace, while your account exists;
  • what MoloPilot read from Meta, while the connection exists, and your Instagram posts, while Use my Instagram posts is on;
  • report recipients, until they are removed;
  • your Slack workspace’s name and the channels you chose, until your account is deleted, even after you disconnect Slack;
  • billing records, as long as tax and accounting law requires, usually up to 7 years, even after your account is deleted;
  • a record of the websites and advertising accounts that have had a free trial, so that one business cannot take a second, even after an account is deleted;
  • server logs, for a limited time, to investigate problems.

A product you delete in MoloPilot leaves your list, and its records, including what was spent on your behalf, stay with your workspace until your account is deleted. Once data is deleted, its copies in our backups are removed as those backups expire, within 30 days.

12. How to delete your data

You can delete your data at any time:

  • Disconnect Meta. In MoloPilot, open Connections and disconnect your account. We delete the credential, and the campaigns, results and posts MoloPilot read from Meta, straight away.
  • Stop using your Instagram posts. Turn off Use my Instagram posts on your connection. We delete the posts and pictures MoloPilot imported from Instagram.
  • Remove MoloPilot from Facebook. In Facebook, open Settings and privacy, then Settings, then Business integrations, and remove MoloPilot. It can no longer read or change anything. Then ask us to delete what we hold, as below.
  • Disconnect Slack. In MoloPilot, open Settings, then Reports, and disconnect Slack. Slack withdraws MoloPilot’s access straight away.
  • Delete your account. Email support@molopilot.com from the address you sign in with and ask us to delete your account. We confirm by email, and within 30 days we delete your account, your workspace and everything in it, except what the law requires us to keep and the free-trial record described in How long we keep it. Cancel your plan first, so you are not charged again.

Deleting your data in MoloPilot does not delete anything on your Meta advertising account. Advertisements already published stay there, and they are yours.

13. Your rights

Wherever you are, you can ask us what personal data we hold about you, for a copy of it, to correct it, or to delete it. Email support@molopilot.com from the address you sign in with. We may need to confirm it is you before acting, and we answer within 30 days.

In the EEA, the UK and Switzerland

You also have the right to restrict or object to how we use your data, to receive it in a portable form, and to withdraw consent at any time, without affecting what was done before. You can complain to your data protection authority, though we would like the chance to help first.

In California and other US states

You have the right to know what personal information we collect, use and disclose, to delete it, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information, and we will not treat you differently for using your rights. Someone you authorize may make a request for you. If we decline a request, you can ask us to reconsider by replying to our answer.

14. Security

We protect personal data with measures suited to it: connections to MoloPilot are encrypted, the credentials for the accounts you connect are encrypted when stored, access is limited to what each part of MoloPilot needs, and only Stripe handles card details. No method is completely secure. If a breach affects your personal data, we will tell you, and the authorities, as the law requires.

15. International transfers

Mololab, LLC is a US company, and we and our service providers handle data in the United States and other countries. When we transfer personal data out of the EEA, the UK or Switzerland, we rely on an adequacy decision, such as the EU-US Data Privacy Framework where the recipient takes part in it, or on the European Commission’s standard contractual clauses, with the UK addendum where it applies.

16. Children

MoloPilot is for businesses and is not meant for anyone under 18. We do not knowingly collect personal data from children. If you think a child has given us personal data, contact us and we will delete it.

17. Changes to this policy

When we change this policy, we post the new version here with its date. If a change is material, we tell you by email or in MoloPilot before it takes effect.

18. Contact

Mololab, LLC. Email support@molopilot.com with any question or request about your personal data.