Appearance
Privacy Policy
Last updated: July 21, 2026
1. Who We Are
Moonomat (the "Service") is operated by:
Christian Schulz
Austr. 43, 8045 Zurich, Switzerland
Contact: support@moonomat.com
We are not required to appoint a Data Protection Officer.
This Privacy Policy explains how we collect, use, and protect your information when you use the Service across our web, Android, and Meta Quest applications.
2. Overview
The following table summarizes what data exists and where it is stored:
| What | Stored where | By whom |
|---|---|---|
| Your content and files | Your browser / device (locally) | You |
| Google Drive / GitHub data | Google / GitHub (your accounts) | You |
| AI backend credentials (e.g., OpenRouter API key, endpoint API keys, agent-cli-bridge pairing token) | Your browser (locally) | You |
| Authentication session | A secure cookie on your device | Your browser |
| Subscription status & Stripe customer ID | Our server | Us |
| Design agent request counter (free accounts) | Our server | Us |
| Pseudonymized analytics events | Our server | Us |
| Payment & billing details | Stripe's servers | Stripe |
We do not store your email address, your name, your files, or your content on our servers.
We do not engage in automated decision-making or profiling.
3. Legal Bases for Processing (GDPR)
| Processing activity | Legal basis |
|---|---|
| Authentication | Performance of contract (Art. 6(1)(b)) |
| Subscription management | Performance of contract (Art. 6(1)(b)) |
| Design agent request metering | Performance of contract (Art. 6(1)(b)) — providing the free request allowance and enforcing plan limits |
| Analytics (pseudonymized) | Legitimate interest (Art. 6(1)(f)) — improving the Service and understanding usage patterns |
| Fraud / abuse prevention | Legitimate interest (Art. 6(1)(f)) — protecting the Service and its users from misuse |
4. Data We Collect and Process
4.1. Authentication Data
When you sign in with Google, we request access to your basic profile information (user ID) and, if you choose to enable Google Drive sync, access to a designated app folder in your Google Drive.
Our server exchanges authentication credentials with Google to verify your identity. As part of this process:
- A secure session cookie containing a refresh token is stored on your device (90-day expiry) to keep you signed in.
- Your Google user ID is used as an internal account identifier.
- Your name and email address are not stored on our server. Your email address is read during sign-in and used only transiently in memory; we store a non-reversible keyed hash of it as an account lookup index, which is deleted with your account.
For GitHub integration, a similar authentication exchange occurs. The resulting access token is returned to your browser and not stored on our server.
4.2. Subscription & Billing Data
When you subscribe, we store the following on our server:
- Your Google user ID (internal identifier)
- Your Stripe customer ID
- Your subscription status and expiry date
- Your plan type
We do not process or store your payment method, billing address, or email address. All payment processing is handled directly by Stripe. When you subscribe, you are redirected to a Stripe-hosted checkout page where Stripe independently collects your payment details and email. See Stripe's Privacy Policy.
4.3. Design Agent Usage Metering
On free accounts, use of the Design agent is subject to a request allowance. To enforce it, our server stores a minimal usage record per account, keyed by your Google user ID: the number of requests in the current time window and the window's start time. The record is overwritten as the window rolls over, is deleted when you delete your account, and contains no content — your prompts and the AI's responses never pass through our server (see Section 5). On paid subscriptions, no usage records are written.
4.4. Analytics Data
We operate our own analytics system — no third-party analytics services are used. When you use the Service, the following data may be collected:
- Event name (e.g., page view, feature used)
- Timestamp
- A random per-session identifier
- For authenticated users: a pseudonymous identifier derived from your account (not your actual user ID)
- Contextual event properties (e.g., feature name, error type)
- Technical device context (e.g., operating system, browser, screen size, graphics hardware model)
- The address of the web page that referred you to the Service (without query parameters) and, for embedded viewers, the domain of the embedding website
Analytics data is stored on our server in pseudonymized form. Your actual user ID is never stored in analytics records. Some events tied to account activity (e.g., sign-in, subscription changes) are recorded directly by our server rather than sent from your device.
Errors encountered during use may also be collected as analytics events. These may include technical context (e.g., error messages, browser type) but do not contain your personal content.
4.5. Data Stored Locally on Your Device
The following data is stored only on your device and is never sent to our server:
- Your content and files
- Your AI backend credentials (e.g., OpenRouter API key, API keys of custom endpoints you configure, and the pairing token of a bridge application you run yourself)
- Your app preferences and settings
- Short-lived access tokens (Google, GitHub) held temporarily in your browser
4.6. Cookies
We use a single cookie:
| Cookie | Purpose | Expiry |
|---|---|---|
refresh_token | Maintains your authentication session | 90 days |
We do not use advertising cookies, tracking cookies, or any third-party cookies.
4.7. Server Access Data
When you access the Service, our infrastructure provider (Cloudflare) may automatically process technical data such as your IP address, browser type, and request timestamps for security and performance purposes. We do not have direct access to these logs. See Cloudflare's Privacy Policy.
5. Third-Party Services
The Service interacts with the following third-party services:
| Service | What is shared | Purpose | Privacy policy |
|---|---|---|---|
| Authentication credentials (server-side); access tokens and Drive API calls (client-side) | Sign-in, optional Google Drive sync | Google Privacy Policy | |
| GitHub | Authentication credentials (server-side); access tokens and API calls (client-side) | Sign-in, optional GitHub sync and publishing | GitHub Privacy Statement |
| Stripe | Stripe customer ID (server-side); payment details and email collected directly by Stripe | Subscription billing | Stripe Privacy Policy |
| OpenRouter | API key and prompts (client-side only, never via our server) | Optional Design agent backend | OpenRouter Privacy Policy |
| Anthropic | Prompts and attachments, routed from your device through a bridge application running on your computer to your own Anthropic account (never via our server) | Optional Design agent backend (Claude) | Anthropic Privacy Policy |
| OpenAI | Prompts and attachments, routed from your device through a bridge application running on your computer to your own OpenAI account (never via our server) | Optional Design agent backend (Codex) | OpenAI Privacy Policy |
| jsDelivr | Requests for bundles you published in your public GitHub repositories (viewer and embed traffic) | CDN delivery of published content | jsDelivr legal |
| Cloudflare | Infrastructure provider; processes IP addresses and request metadata in transit | Hosting, data storage, security | Cloudflare Privacy Policy |
Google Drive and GitHub: All file operations are performed directly from your browser to these services. Your content does not pass through our server.
AI backends: Your credentials and all Design agent requests are handled entirely on your device — prompts go directly from your browser to the backend you connected and are never sent to or stored on our server. If you configure a custom AI endpoint (e.g., a local server such as Ollama, or a provider account such as OpenAI or Groq), your prompts are sent to that endpoint; which provider processes them is determined entirely by your configuration, and a local server keeps everything on your own machine.
6. International Data Transfers
Our infrastructure is provided by Cloudflare, whose global network includes locations outside of Switzerland and the European Economic Area (EEA). Cloudflare maintains appropriate safeguards for international data transfers, including Standard Contractual Clauses (SCCs). See Cloudflare's Data Processing Addendum.
7. Data Retention
| Data | Retention period |
|---|---|
| Authentication session cookie | 90 days, or until you clear cookies / revoke access |
| Subscription data | Retained while your account exists (see Section 9) |
| Design agent usage record | Covers a rolling 24-hour window and is overwritten as it rolls; deleted with your account |
| Analytics data | 36 months in pseudonymized form |
| Locally stored data | Until you clear browser/app data or uninstall |
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate data |
| Erasure | Request deletion of your data |
| Restriction | Request that we limit processing of your data |
| Data portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interest (e.g., analytics) |
To exercise any of these rights, you can use the self-service options available within the Service while logged in (see Section 9), or contact us (see Section 12).
We will respond within one month (or within the timeframe required by applicable law).
Swiss residents may also contact the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch
EU residents may lodge a complaint with their local data protection supervisory authority.
9. Account & Data Deletion
Deleting your account
You can delete your account and all associated server-side data from within the Service while logged in. This will:
- Delete your subscription record from our server
- Cancel your active subscription, if applicable
Pseudonymized analytics records, which contain no direct identifiers, are retained as described in Section 7.
Because we identify accounts solely through Google authentication and do not store your email address or other contact details, account deletion is only available while you are logged in. This ensures that only the verified account holder can initiate deletion. We are unable to process deletion requests that we cannot reliably verify.
Analytics opt-out
You can opt out of analytics collection using the option available within the Service. When opted out, no analytics events will be sent from your device. A minimal set of server-side events tied to account activity (e.g., sign-in, subscription changes) is still recorded in pseudonymized form, as described in Section 4.4.
Other data
- Authentication session: Clear your browser cookies, or revoke access via your Google Account permissions.
- Stripe data: Stripe retains billing data under their own policies. You can manage your data via the Stripe customer portal or contact Stripe support.
- Locally stored data: Clear your browser storage or uninstall the application.
10. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us and we will delete it.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated policy within the Service and updating the "Last updated" date. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
12. Contact
For any questions or requests regarding this Privacy Policy or your personal data, contact us at support@moonomat.com.