Legal
Privacy Policy
Last updated 1 October 2026
MUNIC is operated by Ofek Zukerman, registered as an Osek Zair (small business), based in Hod Hasharon, Israel. We are the controller of the personal data described in this policy. Questions and requests go to team.munic@gmail.com.
"MUNIC" (municai.com) is the platform, and in this policy "the Services" means every tool, sub-product, and piece of software offered through it, now or later, including but not limited to MUNIC Collabs. That covers the marketing site, waitlists, your account, product workspaces, checkout, and the systems that run your automations.
When a product needs data that the rest of the platform doesn't, we describe it under Product-specific data.
- When you visit the site: your IP address, browser, and the pages you request, in our hosting provider's logs. When you use a waitlist form, your IP address is also held in server memory for about ten minutes to stop spam; it is never stored.
- When you join a waitlist: your email, the product you asked about, where the sign-up came from (for example our website), the date, which version of our sign-up wording you agreed to (so we can show your consent), and your answers to any optional follow-up questions.
- When you create an account: your email, your password (stored only as a secure hash by our authentication provider), your name if you add it, and your sign-in session.
- When you subscribe: your subscription status and billing identifiers from Paddle. Card details go to Paddle and never reach our servers.
- When you connect a tool: the API keys or tokens you provide, encrypted at rest and decrypted only to run your automations or when you ask to see a stored value.
- When your automations run: run metadata such as status, timing, and retries. If a run fails, we may keep the content it was processing for a limited period so we can troubleshoot it.
- When you contact us: the messages you send and our replies.
- If you allow ad measurement: the measurement data described under Cookies and ad measurement.
Giving us personal data is voluntary. Without an email we can't add you to a waitlist or create your account, and without payment details you can't subscribe.
MUNIC Collabs (waitlist). After you join, the Collabs waitlist asks up to four optional questions: what kind of business you run, how you find creators today, the hardest part of working with creators, and how you prefer to handle the final outreach to creators (fully automated, or reviewed and sent by you). Some answers open an optional text box (for example, which tool you use, or your own answer when you pick “Other”). You can skip any of them. Your answers are stored with your waitlist sign-up so we can decide what to build first and whom to ask for feedback. We also store which early-access offer was shown when you joined, so we can honor it. All of this is kept as long as the sign-up and is never sent to Meta or any other advertising platform.
New products add their own paragraph here before they open to customers.
- Waitlists (your consent): to email you when access opens, and to ask for your feedback on the product. No newsletters. You can unsubscribe at any time by replying to any email from us or writing to us, and we delete your sign-up.
- Accounts, workspaces, and billing (our contract with you): to provide the Services you signed up for, including running the automations you set up.
- Security and abuse prevention (our legitimate interest): to keep the Services safe, stop spam, and investigate problems.
- Ad measurement (your consent only): to measure visits, sign-ups, purchases, and ad results. Nothing is sent to Meta unless you choose "Allow" in the cookie notice or turn ad measurement on in Cookie settings.
- Legal obligations: to keep the records tax and accounting law requires, and to answer lawful requests.
We don't sell personal data, and we don't use it for automated decisions that have legal or similar effects on you.
Some features use third-party artificial intelligence and API providers, for example to generate a draft, analyze text, or deliver a message through another platform. When you use such a feature, we send the provider only the content that feature needs, under a contract with that provider. Providers may change as the Services grow; the categories below stay the same. A current list of providers is available on request from team.munic@gmail.com.
We use service providers in these categories. They process data on our instructions.
- Category
- Database and authentication
- What they do
- Stores platform data, sign-in, and files
- Where
- Ireland (EU)
- Category
- Web hosting
- What they do
- Serves the site and app; keeps request logs
- Where
- United States
- Category
- Automation infrastructure
- What they do
- Runs product automations on a private server
- Where
- United Kingdom
- Category
- Backups
- What they do
- Stores backups of automation data
- Where
- Europe
- Category
- Email delivery
- What they do
- Sends sign-in and account emails
- Where
- Varies by provider
- Category
- Payments
- What they do
- Paddle.com, Merchant of Record: checkout, tax, invoices, refunds
- Where
- Varies by provider
- Category
- Ad measurement
- What they do
- Meta Pixel and Conversions API, only if you allow ad measurement
- Where
- United States and worldwide
- Category
- Support email
- What they do
- Our support and privacy mailbox
- Where
- Varies by provider
- Category
- AI and API providers
- What they do
- Features described above
- Where
- Varies by provider
| Category | What they do | Where |
|---|---|---|
| Database and authentication | Stores platform data, sign-in, and files | Ireland (EU) |
| Web hosting | Serves the site and app; keeps request logs | United States |
| Automation infrastructure | Runs product automations on a private server | United Kingdom |
| Backups | Stores backups of automation data | Europe |
| Email delivery | Sends sign-in and account emails | Varies by provider |
| Payments | Paddle.com, Merchant of Record: checkout, tax, invoices, refunds | Varies by provider |
| Ad measurement | Meta Pixel and Conversions API, only if you allow ad measurement | United States and worldwide |
| Support email | Our support and privacy mailbox | Varies by provider |
| AI and API providers | Features described above | Varies by provider |
We are based in Israel. Our database is in the European Union and our automation servers are in the United Kingdom. Some providers, including our web host and Meta, process data in the United States or elsewhere. Where data leaves the EU, the UK, or Israel, we rely on the protections the law recognizes for that transfer, such as adequacy decisions or the providers' standard contractual clauses.
You choose. We use two kinds of cookies and browser storage: necessary ones that keep the site and your account working, and optional ad measurement through Meta. Nothing optional runs until you choose "Allow" in the cookie notice, and no boxes are pre-checked. You can change your mind any time through Cookie settings in the footer; we ask again after 12 months. If your browser sends a Global Privacy Control signal, we treat it as a "No thanks" automatically and don't show the cookie notice; you can still turn ad measurement on in Cookie settings.
- Name
munic_cookie_consent_v1- Type
- Local storage
- Purpose
- Remembers your cookie choice
- Lifetime
- 12 months, then we ask again
- When
- Always (necessary)
- Name
sb-…-auth-token- Type
- Cookie
- Purpose
- Keeps you signed in (a short-lived companion cookie protects the sign-in step)
- Lifetime
- Up to 400 days, or until you sign out
- When
- Only when you sign in (necessary)
- Name
munic_last_product- Type
- Cookie
- Purpose
- Remembers the last product dashboard you opened, so the dashboard opens it next time
- Lifetime
- 180 days
- When
- Only when signed in (necessary)
- Name
munic_utm_v1- Type
- Session storage
- Purpose
- Remembers which campaign brought you here
- Lifetime
- Until you close the tab
- When
- Only if you allow ad measurement
- Name
_fbp- Type
- Cookie (Meta)
- Purpose
- Meta Pixel browser identifier
- Lifetime
- 90 days
- When
- Only if you allow ad measurement
- Name
_fbc- Type
- Cookie (Meta)
- Purpose
- Meta click identifier from an ad link
- Lifetime
- 90 days
- When
- Only if you allow ad measurement
| Name | Type | Purpose | Lifetime | When |
|---|---|---|---|---|
munic_cookie_consent_v1 | Local storage | Remembers your cookie choice | 12 months, then we ask again | Always (necessary) |
sb-…-auth-token | Cookie | Keeps you signed in (a short-lived companion cookie protects the sign-in step) | Up to 400 days, or until you sign out | Only when you sign in (necessary) |
munic_last_product | Cookie | Remembers the last product dashboard you opened, so the dashboard opens it next time | 180 days | Only when signed in (necessary) |
munic_utm_v1 | Session storage | Remembers which campaign brought you here | Until you close the tab | Only if you allow ad measurement |
_fbp | Cookie (Meta) | Meta Pixel browser identifier | 90 days | Only if you allow ad measurement |
_fbc | Cookie (Meta) | Meta click identifier from an ad link | 90 days | Only if you allow ad measurement |
If you decline, or later turn ad measurement off, we delete the _fbp and _fbc cookies from your browser and the stored campaign details, and stop sending anything to Meta.
If you allow ad measurement, we also send Meta a server-side sign-up event when you join a waitlist. It contains a hashed (scrambled) version of your email, the product, and the campaign that brought you, so Meta can match the sign-up to our ads. Your answers to the optional questions are never included. Once checkout opens, a purchase event (hashed email and product) is sent the same way, only if ad measurement was on when you started checkout. If you decline, no such events are sent. Checkout is run by Paddle, which sets its own necessary cookies.
- Waitlist sign-ups: until 12 months after the product you joined opens to the public, or sooner if you ask us to delete them.
- Accounts: while your account is active. Deleting your account removes your login immediately.
- Deleted workspaces: stored credentials are wiped and the workspace is closed immediately. Remaining workspace records are kept for a limited period for security, billing, and legal reasons. Email us to have them erased.
- Logs and automation run data: for a limited period, for troubleshooting and security.
- Backups: backups of our main database are overwritten after up to 7 days; other backups are kept for a limited period.
- Billing records: as long as tax and accounting law requires. Paddle keeps its own records as Merchant of Record.
Depending on where you live, you can ask us to access, correct, delete, restrict, or export your personal data, and you can object to processing or withdraw your consent at any time (withdrawing doesn't affect what happened before).
- Delete your account or a workspace yourself from Account settings.
- Change your ad measurement choice through Cookie settings in the footer.
- For anything else, email team.munic@gmail.com. We reply within 30 days and may ask you to confirm your identity.
You can also complain to Israel's Privacy Protection Authority or, if you are in the EU or UK, to your local data protection authority.
Connected-account keys are encrypted at rest, all traffic uses HTTPS, and every request for workspace data is checked against your membership in that workspace. Access to production systems is limited to what operating the Services requires. Details are on our Security page.
The Services are business tools for people aged 18 and over. We don't knowingly collect data from children.
When we change this policy we update the date at the top. If a change materially affects how we use your data, we tell you by email or on the site before it takes effect, and ask for consent again where the law requires it.