Privacy Policy
Controller: Silicon Group Inc., 3101 SW 34th Avenue, #905-249, Ocala, FL 34474, United States. Effective date: June 19, 2026.
This Privacy Policy ("Policy") explains how Silicon Group Inc. ("Silicon Group," "Silicon Society," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with Megacosm, including megacosm.ai, its subdomains, related Megacosm domains, applications, and services (collectively, the "Services").
This Privacy Policy is specific to Megacosm. Silicon Group's general website and other Silicon Group products are covered by their own separate privacy notices, not this Policy. Cookie notices, data processing agreements, business associate agreements, order forms, or other written agreements may also apply to the processing of Customer Data. If a data processing agreement conflicts with this Policy on the processing of personal data, the data processing agreement governs.
1. Our Role
For account, billing, marketing, website, support, security, and product operations data, Silicon Group generally acts as a business or controller.
For personal information contained in Customer Data that we process on behalf of a customer, Silicon Group generally acts as a service provider or processor, and the customer acts as the business or controller. In those cases, we process the data according to the customer's instructions, the applicable agreement, and any data processing agreement.
If you use Megacosm through your employer or another organization, that organization controls many aspects of your workspace, including users, permissions, retention settings, integrations, and the contents of the organization's operating representation. Direct privacy questions about that workspace to your organization first.
2. Information We Collect
We collect personal information and Customer Data in the following categories.
Account and Identity Information
We may collect name, email address, organization, title, profile information, authentication identifiers, identity-provider subject identifiers, workspace membership, role assignments, invite status, administrator status, agent identity records, and related access information.
Customer Workspace and Product Data
Megacosm may process organizational representations, records, documents, messages, files, comments, external references, activity history, audit records, and other information submitted to or generated inside a customer workspace.
This information may include personal information about a customer's employees, contractors, candidates, customers, vendors, partners, patients, clients, investors, or other individuals, depending on how the customer configures and uses the Services.
Integration Information
If a customer connects third-party services, we may receive and process information from those services. Examples include but are not limited to identity-provider data, Slack workspace and channel information, HubSpot pipeline data, Linear issues, GitHub events, Google Workspace or Drive metadata, Notion references, Stripe billing or payment events, webhook payloads, OAuth metadata, connection status, and outbound delivery records. The exact information depends on the customer's configuration and the third-party service.
AI and LLM Information
When AI features are used, we may process prompts, context, retrieved workspace data, AI-generated outputs, model identifiers, usage and token counts, timestamps, success or error outcomes, and related usage records. This may include Customer Data sent to configured AI providers to generate responses or perform requested functionality.
Billing and Commercial Information
We may collect plan, subscription, invoice, payment status, credit balance, credit usage, overage, tax, billing contact, purchase history, and related commercial information. Payment-card details are generally processed by our payment processor, not stored directly by Silicon Group.
Website, Device, and Usage Information
We may collect IP address, browser type, device type, operating system, referring URL, pages viewed, interactions, session information, cookie identifiers, approximate location, API request metadata, logs, diagnostics, performance data, security events, and similar technical information.
Communications and Support Information
We may collect messages, support tickets, call notes, feedback, survey responses, event registrations, sales communications, and other information you provide when communicating with us.
Sensitive Personal Information
We do not intentionally collect sensitive personal information through public, sign-up, or sales pages. Customer workspaces may process sensitive personal information if Customer chooses to submit it, connect systems that contain it, or configure Megacosm for regulated workflows. Customer should not submit sensitive personal information, health information, government identifiers, payment-card data, or other regulated data unless the applicable order form, DPA, BAA, or regulated-data terms permit that use and the deployment is configured for it.
3. Sources of Information
We collect information directly from you, from customers and their administrators, from identity providers, from connected third-party services, from payment and billing providers, from analytics and cookie technologies, from service providers, and automatically through operation of the Services.
4. How We Use Information
We use information to:
- provide, operate, maintain, secure, and improve the Services;
- authenticate users and agents;
- provision workspaces, invites, roles, permissions, and integrations;
- process Customer Data according to customer instructions;
- operate organizational representations, workflows, approvals, and audit features;
- provide AI-assisted drafting, interpretation, summarization, recommendations, maintenance proposals, generated copy, and agent functionality;
- meter LLM usage, enforce budgets, administer credits, and bill customers;
- troubleshoot, support, communicate with, and train users and administrators;
- send transactional email such as invites, security notices, product notices, and administrative messages;
- send marketing communications where permitted, with opt-out where required;
- analyze usage, reliability, performance, security, and abuse patterns;
- comply with legal obligations and enforce agreements;
- protect the rights, safety, and security of Silicon Group, customers, users, service providers, and the public; and
- carry out other purposes disclosed at collection or authorized by you or the applicable customer.
5. AI Providers and Model Training
Some Services use third-party AI providers. We provide a current list of our sub-processors, including AI providers, to customers and prospective customers on request and under our data processing agreement. Additional or customer-selected providers may be used if enabled for a deployment or agreed in an order form.
We send AI providers the prompts, context, Customer Data, and metadata needed to provide the requested feature. We do not authorize third-party AI providers to train their general models on Customer Data unless the customer has expressly agreed.
Customer should not submit sensitive personal information, regulated data, trade secrets, or confidential information to AI features unless Customer is comfortable with that information being processed as described in this Privacy Policy, the applicable order form, and any data processing or regulated-data terms.
6. How We Disclose Information
We may disclose information to the following recipients.
Customer and Workspace Participants
Information in a customer workspace may be visible to that customer, its administrators, authorized users, agents, and other participants according to the customer's configuration, permissions, integrations, and settings.
Service Providers and Sub-Processors
We use service providers to host, secure, operate, support, analyze, and improve the Services. These include categories such as cloud hosting and infrastructure, identity and authentication, AI processing, transactional email, payment processing, analytics, logging and monitoring, support tools, and professional advisors.
We provide a current list of our sub-processors to customers and prospective customers on request and under our data processing agreement.
Third-Party Integrations
When a customer connects or uses a third-party integration, we may disclose information to that third-party service as configured by the customer. For example, an outbound action may send a message, update a CRM, create an issue, deliver a webhook, or process a payment event through a connected service.
Legal, Safety, and Compliance
We may disclose information if we believe disclosure is reasonably necessary to comply with law, legal process, or governmental requests; enforce agreements; investigate abuse or security incidents; prevent harm; or protect the rights, property, and safety of Silicon Group, customers, users, service providers, or the public.
When legally permitted and reasonably practicable, we will try to notify the affected customer before disclosing Customer Data in response to legal process.
Business Transfers
We may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction.
With Consent or Direction
We may disclose information with your consent or at the direction of the applicable customer.
8. Retention
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with law, resolve disputes, enforce agreements, maintain security, preserve backups, and support auditability.
Customer Data retention may be governed by the applicable order form, DPA, customer settings, backup cycles, deployment configuration, and legal requirements. Certain audit, security, billing, and compliance records may be retained after account closure where needed for legitimate business, legal, security, or contractual purposes.
Megacosm maintains audit logs. Where deletion of personal information would conflict with legal, security, or audit obligations, we may retain, restrict, de-identify, or pseudonymize information as permitted by law and the applicable agreement.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. Depending on the deployment, safeguards may include authentication and access controls, encryption in transit and at rest, logging and monitoring, rate limiting, and backups.
No system is completely secure. We cannot guarantee that information will never be accessed, disclosed, altered, or destroyed without authorization.
10. International Transfers
Silicon Group is based in the United States, and the Services may be hosted or processed in the United States and other countries where Silicon Group, its customers, service providers, or sub-processors operate. Those countries may have data protection laws different from the laws where you live.
Where required, international transfers will be supported by appropriate legal mechanisms, such as standard contractual clauses or other approved safeguards.
11. Your Choices and Rights
You may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, depending on your location and the context of the processing.
For personal information controlled by a customer, submit your request to that customer. If you submit a request to us about Customer Data, we may refer the request to the customer or process it according to the customer's instructions.
For personal information controlled by Silicon Group, contact us at privacy@megacosm.ai. We may need to verify your identity and may deny or limit requests where permitted by law, including to protect security, prevent fraud, preserve legal claims, comply with legal obligations, or respect another person's rights.
You can opt out of marketing emails by using the unsubscribe link in those emails or contacting us. You may still receive transactional, security, billing, and administrative messages.
12. US State Privacy Disclosures
We do not sell Customer Data for money. We do not use Customer Data for third-party targeted advertising.
Some analytics or advertising cookies may be considered "sharing" or "targeted advertising" under certain US state privacy laws. Where required, we will provide a way to opt out of those activities.
Where your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of the sale or sharing of personal information, and the advertising and analytics categories are turned off automatically. You can also review or change these choices through "Your Privacy Choices" in the site footer.
Depending on your state, you may have rights to know, access, correct, delete, obtain a copy of, or opt out of certain processing of personal information, including sales, targeted advertising, certain profiling, or certain uses of sensitive personal information. Silicon Group will not discriminate against you for exercising privacy rights, but different Services, prices, or quality levels may be available where permitted by law and reasonably related to the value of the data involved.
California residents may also authorize an agent to submit privacy requests on their behalf. We may ask the authorized agent to provide proof of authorization and may ask you to verify your identity directly with us. California residents may request information about certain disclosures to third parties for direct marketing purposes.
Virginia and other state residents may have the right to appeal a decision we make about a privacy request. If we deny your request and your state provides an appeal right, you may appeal by contacting privacy@megacosm.ai with "Privacy Appeal" in the subject line.
Nevada residents may have the right to opt out of certain sales of covered information. Silicon Group does not currently sell covered information as defined by Nevada law, but Nevada residents may submit an opt-out request to privacy@megacosm.ai.
To exercise rights for information controlled by Silicon Group, contact privacy@megacosm.ai. Your request must provide enough information for us to verify your identity and understand the request. We use verification information only to verify and respond to the request. We may deny or limit a request where permitted by law, including where fulfilling it would conflict with legal, security, audit, fraud-prevention, or other rights and obligations.
13. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact privacy@megacosm.ai.
14. Third-Party Sites and Services
The Services may link to or integrate with third-party websites, products, and services. This Privacy Policy does not apply to third-party services. Review the privacy policies and terms of those third parties.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated Privacy Policy and update the effective date. If changes materially affect how we process personal information in paid Services, we will use reasonable efforts to notify the applicable customer.