Privacy Policy

Moondoggle LLC · Washington State, USA · Effective September 1, 2026

1. Introduction

Moondoggle is a writing app built for novelists and authors, and we believe your creative work belongs to you completely, unconditionally, and permanently. This privacy policy reflects that belief in every technical decision we've made.

Here's the short version:

  • Your manuscripts never leave your device unless you explicitly choose the Power Plan's cloud sync.
  • We never use your writing to train AI models. Period.
  • All analytics are opt-in. We optionally track usage data (e.g., what sections of the app you used and when) but we never track or collect any of your writing or AI questions. Important note During open beta, usage data collection will be required to help us identify critical bugs and provide a stable platform for v1 launch.
  • If you use BYOK (during open beta, or later as an Advanced setting on either paid plan), your AI conversations go directly to the provider. We never see them, store them, or route them through our servers.

This policy explains exactly what data we collect, what we don't, and why. Since most of us speak plain English rather than confusing jargon, that's how we chose to write it.


2. What Data We Collect

What Moondoggle knows about you depends entirely on how you use the app.

All Users (Account and Billing)

Regardless of plan, we collect the minimum needed to run your subscription:

Data When Purpose
IP address + app version Automatic update checks Delivering software updates
Email address Account creation Subscription management
Payment information Active subscription Processed entirely by LemonSqueezy (we never see your card number)
Usage analytics Only if you opt in Note: Required during open beta Improving the product (see Section 3)
Crash reports Only if you opt in Note: Required during open beta Fixing bugs (see Section 3)

Solo Plan and BYOK Users

If you're on the Solo Plan, or using BYOK on either plan, your creative work stays local. Your manuscripts, notes, Board cards, AI conversations, character sheets, outlines, and every word you write are stored in a .moon folder on your machine. We have no access to that folder. We cannot read it. We do not want to.

Power Plan (Cloud Sync and Managed AI)

If you subscribe to the Power Plan and use its cloud sync or managed AI, the following additional data is stored on our infrastructure:

Data Where Purpose
Manuscripts and project data AWS DynamoDB + S3 (us-west-2) Cross-device sync
AI conversation history AWS DynamoDB (us-west-2) Persistent AI context across devices
Account profile AWS Cognito Authentication and session management
Subscription status LemonSqueezy + our database Entitlement management

Cloud data is encrypted in transit (TLS 1.3) and at rest (AES-256). You can export all your data at any time and delete your cloud account whenever you choose.


3. Analytics and Telemetry

Our Commitment

Analytics in Moondoggle are opt-in only, with the important exception that it will be required during open beta. We have made this choice because open beta is provided as a transparent, collaborative process where early adopters can use the app free-of-charge to help Moondoggle improve and reach a stable state before v1 launch. We will NEVER track any personal data like writing or AI questions, even during beta.

Once open beta ends and v1 goes live, all analytics will return to being entirely opt-in only.

During the install wizard, you'll see a clear explanation of what we track and why. We give you this information before you make a choice. There is no fine print. There is no pre-checked box. After beta, if you skip the step, analytics are off.

You can change your mind at any time in Settings → Privacy.

What We Track (If You Opt In)

We use PostHog for product analytics. If you consent, the following events are collected:

Event Category Specific Metrics Example
Feature usage Which features are opened and how often "Editor opened 12 times this week"
Navigation patterns Screen/panel transitions "User moved from Board to Editor"
Button clicks UI interaction counts "Export button clicked"
Session data Session start, end, duration "45-minute writing session"
Performance App load time, memory usage, render times "Cold start took 2.1s"
Device info OS, OS version, screen resolution, app version "macOS 15.2, Moondoggle 1.4.0"
Geography Country and timezone (derived from IP) "United States, Pacific Time"
Subscription status Tier (free/cloud) "Cloud subscriber"
Onboarding progress Wizard steps completed "Completed step 3 of 5"
Error states (non-crash) Non-fatal error occurrences "Sync retry triggered"

What We Never Track (Even If You Opt In)

Even with analytics enabled, the following are never sent to PostHog or any other service:

  • Manuscript text, excerpts, or word counts per project
  • AI prompts, responses, or conversation content
  • File names, project titles, or folder names
  • Character names, plot details, or world-building notes
  • Board card content or connections
  • Search queries within your manuscripts
  • Any content you have written or generated

We track that you used a feature, never what you did with it.

Crash Reports (Sentry)

Crash reporting via Sentry is a separate opt-in. If enabled, crash reports include:

  • Stack traces and error messages
  • Device and OS information
  • App state at time of crash (e.g., which panel was active)
  • App version and build number

Crash reports never contain manuscript text, AI conversations, file contents, or any creative work.


4. What We Never Collect

Regardless of your tier, settings, beta phase, or subscription status, Moondoggle never collects, accesses, transmits, or stores:

  • ❌ Your manuscript text, drafts, or revisions
  • ❌ Your AI conversations, prompts, or responses
  • ❌ Your Board cards, connections, or spatial layouts
  • ❌ Your character profiles, plot outlines, or world-building notes
  • ❌ Your file names, project titles, or folder structures
  • ❌ Your search queries within the app
  • ❌ Your writing habits correlated to content (e.g., "wrote 500 words about dragons")
  • ❌ Screenshots or recordings of your workspace
  • ❌ Clipboard contents
  • ❌ Keystrokes or keystroke timing
  • ❌ Contents of other files on your computer
  • ❌ Precise GPS location

Your creative work is invisible to us by design.


5. How We Use Your Data

Data Use Legal Basis (GDPR)
Email address Account management, critical product updates, license delivery Contract performance
Payment info Processing purchases (via LemonSqueezy) Contract performance
Cloud project data Providing sync service you subscribed to Contract performance
Analytics (opt-in) Understanding feature usage to improve the product Consent
Crash reports (opt-in) Diagnosing and fixing bugs Consent
IP address (update checks) Delivering software updates, basic geo for analytics Legitimate interest

We do not:

  • Sell your data to anyone, for any reason, ever
  • Share your data with advertisers
  • Use your data for behavioral profiling or ad targeting
  • Monetize analytics data in any way beyond improving Moondoggle

6. BYOK Privacy Model

This section describes our BYOK AI mode. During the open beta period, BYOK is the only way to access AI features. After the Solo Plan and Power Plan launch, BYOK becomes an optional Advanced setting available on either plan for subscribers who prefer to use their own AI provider.

What Is BYOK?

"Bring Your Own Key" means you enter your own API key for an AI provider (Anthropic, OpenAI, Google, or DeepSeek) directly into Moondoggle's settings.

How It Works

When you use BYOK:

  1. Your AI queries (including any manuscript passages you share with the AI Assistant) travel directly from your machine to the AI provider's API.
  2. These requests do not pass through Moondoggle's servers. We do not proxy, log, cache, inspect, or store them.
  3. Your API key is stored locally on your device in your system's secure credential storage. It is never transmitted to Moondoggle.
  4. We have zero visibility into your AI conversations in BYOK mode.

What This Means in Practice

Your Machine ──────────→ AI Provider (Anthropic/OpenAI/Google/DeepSeek)
                         ↑
              Direct connection.
              Moondoggle is not in this path.

The privacy relationship for AI queries in BYOK mode is between you and your chosen AI provider. Their privacy policies and data handling practices govern those interactions. We encourage you to review them:

Power Plan Managed AI (Comparison)

If you use the Power Plan's managed AI (powered by AWS Bedrock) instead of BYOK, your AI queries do route through our infrastructure. In this case:

  • Queries are processed through AWS Bedrock (which does not use inputs for training)
  • Conversation history is stored encrypted in your cloud account
  • You can delete your AI history at any time
  • We still never use your queries to train any model (see Section 8)

7. Third-Party Services

Every external service Moondoggle communicates with, what data reaches them, and why:

Service Purpose Data Shared Your Control
Anthropic, OpenAI, Google, DeepSeek (BYOK) AI Assistant Query text + manuscript passages included in prompts Direct from your machine; governed by provider's policy
AWS Bedrock (Power Plan managed AI) Managed AI Query text + manuscript passages included in prompts Routed through Moondoggle; encrypted; not used for training
AWS (DynamoDB, S3, Lambda, Cognito) (Power Plan only) Storage, sync, auth All project data for Power Plan subscribers Export/delete anytime
LemonSqueezy Payment processing, subscriptions Email, payment information Handled entirely by LemonSqueezy; we never see card numbers
Vercel Website hosting (moondoggle.app) Standard web request data (IP, user agent) Only when visiting our website
Apple App notarization, auto-updates App metadata, version info No user data transmitted
PostHog (opt-in only) Product analytics Usage patterns (see Section 3) Opt-in/out anytime in Settings
Sentry (opt-in only) Crash reporting Stack traces, device info Opt-in/out anytime in Settings
Discord Community forum N/A — external link only, not integrated into app Voluntary participation

No service listed above ever receives your manuscript content, except AI providers when you explicitly send passages to the AI Assistant as part of a conversation.


8. No AI Training Pledge

We do not, under any circumstances, use your manuscripts, notes, cards, AI conversations, or any creative content to train artificial intelligence or machine learning models. Your work is yours alone.

  • This applies to all plans (open beta, Solo, Power).
  • This applies regardless of whether you opt in to analytics.
  • This applies to data stored locally and data synced to our cloud.
  • This applies now and retroactively to all data we have ever processed.
  • This survives account deletion, and we cannot train on data we have purged.

9. Data Storage and Security

Local Storage (Solo Plan and BYOK)

  • All creative data stored in a .moon folder on your device
  • Encrypted at the filesystem level by your operating system's full-disk encryption (BitLocker, FileVault, LUKS)
  • Moondoggle does not implement its own encryption layer for local files (your OS handles this)
  • API keys stored in your system's secure credential store (macOS Keychain, Windows Credential Manager, Linux Secret Service)

Cloud Storage (Power Plan)

  • All data stored in AWS us-west-2 (Oregon, USA)
  • Encrypted at rest using AES-256 (AWS-managed keys)
  • Encrypted in transit using TLS 1.3
  • Authentication via AWS Cognito with secure token handling
  • Infrastructure access limited to Moondoggle engineering team with MFA and audit logging
  • No third-party access to production user data

Application Security

  • Built with Tauri (Rust backend), memory-safe by design
  • Content Security Policy (CSP) enforced
  • No remote code execution vectors
  • Automatic security updates delivered through signed builds
  • All builds notarized by Apple (macOS)

10. Data Retention and Deletion

Data Type Retention Your Action
Local .moon files Forever (on your device) Delete locally at any time
Cloud project data Until you delete your account Delete account → 30-day grace period → permanent purge
Account information Until account deletion + 30 days Request deletion anytime
Analytics data (opt-in) Anonymized after 90 days; deleted after 12 months Opt out anytime; request deletion
Crash reports (opt-in) 30 days Opt out anytime
Payment records As required by tax/legal obligations Managed by LemonSqueezy
Backup copies (cloud) Purged within 30 days of account deletion Automatic

Account Deletion Process

  1. Go to Settings → Account → Delete Account (or email us)
  2. You'll receive a confirmation email
  3. 30-day grace period begins (you can reactivate by logging back in)
  4. After 30 days: all cloud data permanently purged from DynamoDB and S3
  5. Your local .moon folder is never affected by account deletion, and your files remain on your device

11. Your Rights

Regardless of where you live, you have the right to:

  • Access — Request a copy of all data we hold about you
  • Rectification — Correct inaccurate personal information
  • Erasure — Delete your account and all associated cloud data
  • Portability — Export all your data in standard formats (Markdown, JSON, .docx)
  • Objection — Object to any processing based on legitimate interest
  • Withdraw consent — Revoke analytics/crash reporting consent at any time

For Solo Plan and BYOK-only users: we hold almost no data about you. Your right to your local files is absolute, and we couldn't access them even if compelled.

To exercise any right, email support@moondoggle.app. We respond within 14 days (30 days maximum for complex requests).


12. For EU Users (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply under the General Data Protection Regulation (GDPR):

Legal Bases for Processing

Processing Activity Legal Basis GDPR Article
Providing the service (sync, auth) Performance of a contract Art. 6(1)(b)
Processing payments Performance of a contract Art. 6(1)(b)
Analytics collection Consent Art. 6(1)(a)
Crash reporting Consent Art. 6(1)(a)
Software update checks Legitimate interest Art. 6(1)(f)
Legal compliance (tax records) Legal obligation Art. 6(1)(c)

Your Additional GDPR Rights

  • Right to restrict processing (Art. 18) — Request we limit how we use your data
  • Right to data portability (Art. 20) — Receive your data in a structured, machine-readable format
  • Right to lodge a complaint — With your local Data Protection Authority
  • Right not to be subject to automated decision-making (Art. 22) — We do not engage in automated decision-making or profiling

International Data Transfers

Your data is stored in the United States (AWS us-west-2). For EU users, this transfer is governed by:

  • AWS's compliance with EU-US Data Privacy Framework
  • Standard Contractual Clauses (SCCs) where applicable

Data Protection Contact

For GDPR-specific inquiries: support@moondoggle.app

We do not currently appoint a Data Protection Officer (DPO) as we do not meet the threshold requiring one.


13. For California Users (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:

Your CCPA Rights

  • Right to know — What personal information we collect, use, and disclose
  • Right to delete — Request deletion of your personal information
  • Right to opt out of sale — We do not sell your personal information. Never have. Never will.
  • Right to non-discrimination — We will not treat you differently for exercising your rights
  • Right to correct — Request correction of inaccurate personal information
  • Right to limit use of sensitive personal information — We do not collect sensitive personal information as defined by CPRA

Categories of Personal Information Collected

Under CCPA's classification framework:

Category Collected? Details
Identifiers (name, email) Yes (if account created) Account management
Commercial information (purchase history) Yes (via LemonSqueezy) License/subscription
Internet/network activity Only if analytics opted-in Feature usage patterns
Geolocation Approximate only (country), only if analytics opted-in Product improvement
Professional/employment info No
Education info No
Biometric info No
Sensory data (audio, visual) No
Inferences drawn No We do not build profiles

Do Not Sell or Share

We do not sell or share (as defined by CCPA/CPRA) your personal information with third parties for cross-context behavioral advertising or any other purpose.

To exercise your rights: support@moondoggle.app or submit a request through your account settings. We verify your identity before processing requests.


14. Children's Privacy

Moondoggle is intended for users aged 13 and older (or 16 where required by local law, such as in the EEA under GDPR).

We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.

If you believe a child under 13 has provided us with personal information, please contact us at support@moondoggle.app.


15. Data Breach Notification

In the unlikely event of a data breach affecting your personal information:

  • We will notify affected users within 72 hours of becoming aware of the breach (as required by GDPR Art. 33)
  • Notification will be sent via email to your registered address
  • We will also post a notice on our website and in-app (for Power Plan subscribers)
  • Notification will include: nature of the breach, data affected, steps we've taken, steps you can take, and contact information

For Solo Plan and BYOK-only users with no Power Plan account: a breach of our systems would not affect your local data, as we do not have access to it.


16. Cookies and Website Analytics

The Moondoggle Application

The desktop app does not use cookies. It is not a web browser. Local preferences are stored in your .moon configuration folder.

The Moondoggle Website (moondoggle.app)

Our marketing website, hosted on Vercel, uses:

Cookie/Technology Purpose Duration
Essential cookies Session management, CSRF protection Session
Analytics (Umami) Cookie-free website usage patterns N/A (no cookies)

We use Umami for privacy-focused website analytics. Umami does not use cookies, does not track users across sites, and does not collect personal information. All data is aggregated and anonymous. We do not use advertising cookies, retargeting pixels, or social media tracking widgets on our website.


17. Changes to This Policy

If we make material changes to this policy:

  • We will notify you via email (if you have an account) at least 30 days before the changes take effect
  • We will post the updated policy with a clear changelog
  • We will display an in-app notification for Power Plan subscribers
  • The "Last Updated" date at the top will reflect the revision

For significant changes affecting data rights or our No AI Training Pledge, we will provide 90 days' notice and the option to export your data and close your account before changes take effect.

We will never retroactively weaken privacy protections for data already collected.


18. Contact Information

Moondoggle LLC Washington State, USA

For urgent privacy concerns (suspected breach, unauthorized access), email support@moondoggle.app with "URGENT" in the subject line.


This privacy policy is written for humans, not lawyers. If anything is unclear, email us and we'll explain it plainly. We believe privacy policies should be readable by the people they protect.

© 2026 Moondoggle LLC. All rights reserved.