Mojo UpDocs
Security and trust

Data handling

What the Mojo Up platform keeps, what it never sees, how it treats credentials that slip into reports, and how to delete data.

This page applies to both Mojo Up AI Cloud and self-hosted AIOE: they are the same platform. The difference is who runs it. On Mojo Up AI Cloud, Mojo Up does, in Australia. With self-hosted AIOE, you do, and Mojo Up has no access to it.

What the platform keeps

KindWhat it is
PeopleName and email address. On Mojo Up AI Cloud, also the sign-in methods you use. On self-hosted AIOE, people come from your identity provider.
OrganisationsMembers, roles and invitations; projects; policies; the catalogue; tools; shared memory.
MachinesEach workbench and node: name, operating system, app version, owner, when it was last seen.
What machines reportEvents, usage (AI provider, model, token counts, cost, timing), audit entries and task summaries.
SecretsAPI keys and tokens that agents' tools need, encrypted.
Workbench backupsIf a person's workbench backs up to the organisation: their workbench settings and projects, readable only by them.
The audit trailA record of what people, agents and machines did.

For the full list on Mojo Up AI Cloud, and the services involved, see Where your data lives.

What it does not see

  • Your agents' conversations with AI models. Agents run on your workbenches and nodes and call the AI providers you choose directly, with your own subscriptions or keys.
  • Remote-control traffic, at rest. When you control a workbench from a browser or phone, the relay passes requests and answers through. It does not store them.
  • Your sign-in passwords. Your identity provider checks those. Mojo Up AI Cloud has no passwords of its own.

Credentials that slip into reports

Agents sometimes print a token or a key where it should not be. When a workbench reports events and audit entries, the platform masks anything that looks like a credential as it arrives, before storing it. Workbench backups are screened the same way.

When an agent reads organisation memory, the audit trail records which items it read, by their labels, never their content.

Who can see what

  • Everything belongs to one organisation, and every query the platform makes is limited to the organisation of the person or machine asking. One organisation can never read another's data.
  • Within an organisation, roles decide what each person may see and change. See People and roles.
  • A person's workbench backup is readable only by that person.
  • The console shows that a backup exists, and lets you delete it, but never shows its content.

Keeping and deleting

  • Mojo Up AI Cloud accounts: deleting your account deletes your personal space and every team where you are the only person, with everything in them, and removes you from every other team. See Delete your account. If you cannot sign in, email privacy@mojoup.com.au and we delete it within 30 days.
  • Self-hosted AIOE: your data is in your own PostgreSQL database, and your own backup and retention rules apply.
  • The audit trail is append-only. While an organisation exists, its audit rows cannot be changed or removed. That is deliberate: it is what makes the trail worth trusting. See The audit trail.

Read Mojo Up's privacy policy for how Mojo Up as a company handles personal information.

On this page