Privacy Policy
Moondoggle LLC · Washington State, USA · Effective September 1, 2026
1. Introduction
Moondoggle is a writing app built for novelists and authors, and we believe your creative work belongs to you completely, unconditionally, and permanently. This privacy policy reflects that belief in every technical decision we've made.
Here's the short version:
- Your manuscripts never leave your device unless you explicitly choose the Power Plan's cloud sync.
- We never use your writing to train AI models. Period.
- All analytics are opt-in. We optionally track usage data (e.g., what sections of the app you used and when) but we never track or collect any of your writing or AI questions. Important note During open beta, usage data collection will be required to help us identify critical bugs and provide a stable platform for v1 launch.
- If you use BYOK (during open beta, or later as an Advanced setting on either paid plan), your AI conversations go directly to the provider. We never see them, store them, or route them through our servers.
This policy explains exactly what data we collect, what we don't, and why. Since most of us speak plain English rather than confusing jargon, that's how we chose to write it.
2. What Data We Collect
What Moondoggle knows about you depends entirely on how you use the app.
All Users (Account and Billing)
Regardless of plan, we collect the minimum needed to run your subscription:
| Data | When | Purpose |
|---|---|---|
| IP address + app version | Automatic update checks | Delivering software updates |
| Email address | Account creation | Subscription management |
| Payment information | Active subscription | Processed entirely by LemonSqueezy (we never see your card number) |
| Usage analytics | Only if you opt in Note: Required during open beta | Improving the product (see Section 3) |
| Crash reports | Only if you opt in Note: Required during open beta | Fixing bugs (see Section 3) |
Solo Plan and BYOK Users
If you're on the Solo Plan, or using BYOK on either plan, your creative work stays local. Your manuscripts, notes, Board cards, AI conversations, character sheets, outlines, and every word you write are stored in a .moon folder on your machine. We have no access to that folder. We cannot read it. We do not want to.
Power Plan (Cloud Sync and Managed AI)
If you subscribe to the Power Plan and use its cloud sync or managed AI, the following additional data is stored on our infrastructure:
| Data | Where | Purpose |
|---|---|---|
| Manuscripts and project data | AWS DynamoDB + S3 (us-west-2) | Cross-device sync |
| AI conversation history | AWS DynamoDB (us-west-2) | Persistent AI context across devices |
| Account profile | AWS Cognito | Authentication and session management |
| Subscription status | LemonSqueezy + our database | Entitlement management |
Cloud data is encrypted in transit (TLS 1.3) and at rest (AES-256). You can export all your data at any time and delete your cloud account whenever you choose.
3. Analytics and Telemetry
Our Commitment
Analytics in Moondoggle are opt-in only, with the important exception that it will be required during open beta. We have made this choice because open beta is provided as a transparent, collaborative process where early adopters can use the app free-of-charge to help Moondoggle improve and reach a stable state before v1 launch. We will NEVER track any personal data like writing or AI questions, even during beta.
Once open beta ends and v1 goes live, all analytics will return to being entirely opt-in only.
During the install wizard, you'll see a clear explanation of what we track and why. We give you this information before you make a choice. There is no fine print. There is no pre-checked box. After beta, if you skip the step, analytics are off.
You can change your mind at any time in Settings → Privacy.
What We Track (If You Opt In)
We use PostHog for product analytics. If you consent, the following events are collected:
| Event Category | Specific Metrics | Example |
|---|---|---|
| Feature usage | Which features are opened and how often | "Editor opened 12 times this week" |
| Navigation patterns | Screen/panel transitions | "User moved from Board to Editor" |
| Button clicks | UI interaction counts | "Export button clicked" |
| Session data | Session start, end, duration | "45-minute writing session" |
| Performance | App load time, memory usage, render times | "Cold start took 2.1s" |
| Device info | OS, OS version, screen resolution, app version | "macOS 15.2, Moondoggle 1.4.0" |
| Geography | Country and timezone (derived from IP) | "United States, Pacific Time" |
| Subscription status | Tier (free/cloud) | "Cloud subscriber" |
| Onboarding progress | Wizard steps completed | "Completed step 3 of 5" |
| Error states (non-crash) | Non-fatal error occurrences | "Sync retry triggered" |
What We Never Track (Even If You Opt In)
Even with analytics enabled, the following are never sent to PostHog or any other service:
- Manuscript text, excerpts, or word counts per project
- AI prompts, responses, or conversation content
- File names, project titles, or folder names
- Character names, plot details, or world-building notes
- Board card content or connections
- Search queries within your manuscripts
- Any content you have written or generated
We track that you used a feature, never what you did with it.
Crash Reports (Sentry)
Crash reporting via Sentry is a separate opt-in. If enabled, crash reports include:
- Stack traces and error messages
- Device and OS information
- App state at time of crash (e.g., which panel was active)
- App version and build number
Crash reports never contain manuscript text, AI conversations, file contents, or any creative work.
4. What We Never Collect
Regardless of your tier, settings, beta phase, or subscription status, Moondoggle never collects, accesses, transmits, or stores:
- ❌ Your manuscript text, drafts, or revisions
- ❌ Your AI conversations, prompts, or responses
- ❌ Your Board cards, connections, or spatial layouts
- ❌ Your character profiles, plot outlines, or world-building notes
- ❌ Your file names, project titles, or folder structures
- ❌ Your search queries within the app
- ❌ Your writing habits correlated to content (e.g., "wrote 500 words about dragons")
- ❌ Screenshots or recordings of your workspace
- ❌ Clipboard contents
- ❌ Keystrokes or keystroke timing
- ❌ Contents of other files on your computer
- ❌ Precise GPS location
Your creative work is invisible to us by design.
5. How We Use Your Data
| Data | Use | Legal Basis (GDPR) |
|---|---|---|
| Email address | Account management, critical product updates, license delivery | Contract performance |
| Payment info | Processing purchases (via LemonSqueezy) | Contract performance |
| Cloud project data | Providing sync service you subscribed to | Contract performance |
| Analytics (opt-in) | Understanding feature usage to improve the product | Consent |
| Crash reports (opt-in) | Diagnosing and fixing bugs | Consent |
| IP address (update checks) | Delivering software updates, basic geo for analytics | Legitimate interest |
We do not:
- Sell your data to anyone, for any reason, ever
- Share your data with advertisers
- Use your data for behavioral profiling or ad targeting
- Monetize analytics data in any way beyond improving Moondoggle
6. BYOK Privacy Model
This section describes our BYOK AI mode. During the open beta period, BYOK is the only way to access AI features. After the Solo Plan and Power Plan launch, BYOK becomes an optional Advanced setting available on either plan for subscribers who prefer to use their own AI provider.
What Is BYOK?
"Bring Your Own Key" means you enter your own API key for an AI provider (Anthropic, OpenAI, Google, or DeepSeek) directly into Moondoggle's settings.
How It Works
When you use BYOK:
- Your AI queries (including any manuscript passages you share with the AI Assistant) travel directly from your machine to the AI provider's API.
- These requests do not pass through Moondoggle's servers. We do not proxy, log, cache, inspect, or store them.
- Your API key is stored locally on your device in your system's secure credential storage. It is never transmitted to Moondoggle.
- We have zero visibility into your AI conversations in BYOK mode.
What This Means in Practice
Your Machine ──────────→ AI Provider (Anthropic/OpenAI/Google/DeepSeek)
↑
Direct connection.
Moondoggle is not in this path.
The privacy relationship for AI queries in BYOK mode is between you and your chosen AI provider. Their privacy policies and data handling practices govern those interactions. We encourage you to review them:
Power Plan Managed AI (Comparison)
If you use the Power Plan's managed AI (powered by AWS Bedrock) instead of BYOK, your AI queries do route through our infrastructure. In this case:
- Queries are processed through AWS Bedrock (which does not use inputs for training)
- Conversation history is stored encrypted in your cloud account
- You can delete your AI history at any time
- We still never use your queries to train any model (see Section 8)
7. Third-Party Services
Every external service Moondoggle communicates with, what data reaches them, and why:
| Service | Purpose | Data Shared | Your Control |
|---|---|---|---|
| Anthropic, OpenAI, Google, DeepSeek (BYOK) | AI Assistant | Query text + manuscript passages included in prompts | Direct from your machine; governed by provider's policy |
| AWS Bedrock (Power Plan managed AI) | Managed AI | Query text + manuscript passages included in prompts | Routed through Moondoggle; encrypted; not used for training |
| AWS (DynamoDB, S3, Lambda, Cognito) (Power Plan only) | Storage, sync, auth | All project data for Power Plan subscribers | Export/delete anytime |
| LemonSqueezy | Payment processing, subscriptions | Email, payment information | Handled entirely by LemonSqueezy; we never see card numbers |
| Vercel | Website hosting (moondoggle.app) | Standard web request data (IP, user agent) | Only when visiting our website |
| Apple | App notarization, auto-updates | App metadata, version info | No user data transmitted |
| PostHog (opt-in only) | Product analytics | Usage patterns (see Section 3) | Opt-in/out anytime in Settings |
| Sentry (opt-in only) | Crash reporting | Stack traces, device info | Opt-in/out anytime in Settings |
| Discord | Community forum | N/A — external link only, not integrated into app | Voluntary participation |
No service listed above ever receives your manuscript content, except AI providers when you explicitly send passages to the AI Assistant as part of a conversation.
8. No AI Training Pledge
We do not, under any circumstances, use your manuscripts, notes, cards, AI conversations, or any creative content to train artificial intelligence or machine learning models. Your work is yours alone.
- This applies to all plans (open beta, Solo, Power).
- This applies regardless of whether you opt in to analytics.
- This applies to data stored locally and data synced to our cloud.
- This applies now and retroactively to all data we have ever processed.
- This survives account deletion, and we cannot train on data we have purged.
9. Data Storage and Security
Local Storage (Solo Plan and BYOK)
- All creative data stored in a
.moonfolder on your device - Encrypted at the filesystem level by your operating system's full-disk encryption (BitLocker, FileVault, LUKS)
- Moondoggle does not implement its own encryption layer for local files (your OS handles this)
- API keys stored in your system's secure credential store (macOS Keychain, Windows Credential Manager, Linux Secret Service)
Cloud Storage (Power Plan)
- All data stored in AWS us-west-2 (Oregon, USA)
- Encrypted at rest using AES-256 (AWS-managed keys)
- Encrypted in transit using TLS 1.3
- Authentication via AWS Cognito with secure token handling
- Infrastructure access limited to Moondoggle engineering team with MFA and audit logging
- No third-party access to production user data
Application Security
- Built with Tauri (Rust backend), memory-safe by design
- Content Security Policy (CSP) enforced
- No remote code execution vectors
- Automatic security updates delivered through signed builds
- All builds notarized by Apple (macOS)
10. Data Retention and Deletion
| Data Type | Retention | Your Action |
|---|---|---|
Local .moon files |
Forever (on your device) | Delete locally at any time |
| Cloud project data | Until you delete your account | Delete account → 30-day grace period → permanent purge |
| Account information | Until account deletion + 30 days | Request deletion anytime |
| Analytics data (opt-in) | Anonymized after 90 days; deleted after 12 months | Opt out anytime; request deletion |
| Crash reports (opt-in) | 30 days | Opt out anytime |
| Payment records | As required by tax/legal obligations | Managed by LemonSqueezy |
| Backup copies (cloud) | Purged within 30 days of account deletion | Automatic |
Account Deletion Process
- Go to Settings → Account → Delete Account (or email us)
- You'll receive a confirmation email
- 30-day grace period begins (you can reactivate by logging back in)
- After 30 days: all cloud data permanently purged from DynamoDB and S3
- Your local
.moonfolder is never affected by account deletion, and your files remain on your device
11. Your Rights
Regardless of where you live, you have the right to:
- Access — Request a copy of all data we hold about you
- Rectification — Correct inaccurate personal information
- Erasure — Delete your account and all associated cloud data
- Portability — Export all your data in standard formats (Markdown, JSON, .docx)
- Objection — Object to any processing based on legitimate interest
- Withdraw consent — Revoke analytics/crash reporting consent at any time
For Solo Plan and BYOK-only users: we hold almost no data about you. Your right to your local files is absolute, and we couldn't access them even if compelled.
To exercise any right, email support@moondoggle.app. We respond within 14 days (30 days maximum for complex requests).
12. For EU Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply under the General Data Protection Regulation (GDPR):
Legal Bases for Processing
| Processing Activity | Legal Basis | GDPR Article |
|---|---|---|
| Providing the service (sync, auth) | Performance of a contract | Art. 6(1)(b) |
| Processing payments | Performance of a contract | Art. 6(1)(b) |
| Analytics collection | Consent | Art. 6(1)(a) |
| Crash reporting | Consent | Art. 6(1)(a) |
| Software update checks | Legitimate interest | Art. 6(1)(f) |
| Legal compliance (tax records) | Legal obligation | Art. 6(1)(c) |
Your Additional GDPR Rights
- Right to restrict processing (Art. 18) — Request we limit how we use your data
- Right to data portability (Art. 20) — Receive your data in a structured, machine-readable format
- Right to lodge a complaint — With your local Data Protection Authority
- Right not to be subject to automated decision-making (Art. 22) — We do not engage in automated decision-making or profiling
International Data Transfers
Your data is stored in the United States (AWS us-west-2). For EU users, this transfer is governed by:
- AWS's compliance with EU-US Data Privacy Framework
- Standard Contractual Clauses (SCCs) where applicable
Data Protection Contact
For GDPR-specific inquiries: support@moondoggle.app
We do not currently appoint a Data Protection Officer (DPO) as we do not meet the threshold requiring one.
13. For California Users (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
Your CCPA Rights
- Right to know — What personal information we collect, use, and disclose
- Right to delete — Request deletion of your personal information
- Right to opt out of sale — We do not sell your personal information. Never have. Never will.
- Right to non-discrimination — We will not treat you differently for exercising your rights
- Right to correct — Request correction of inaccurate personal information
- Right to limit use of sensitive personal information — We do not collect sensitive personal information as defined by CPRA
Categories of Personal Information Collected
Under CCPA's classification framework:
| Category | Collected? | Details |
|---|---|---|
| Identifiers (name, email) | Yes (if account created) | Account management |
| Commercial information (purchase history) | Yes (via LemonSqueezy) | License/subscription |
| Internet/network activity | Only if analytics opted-in | Feature usage patterns |
| Geolocation | Approximate only (country), only if analytics opted-in | Product improvement |
| Professional/employment info | No | — |
| Education info | No | — |
| Biometric info | No | — |
| Sensory data (audio, visual) | No | — |
| Inferences drawn | No | We do not build profiles |
Do Not Sell or Share
We do not sell or share (as defined by CCPA/CPRA) your personal information with third parties for cross-context behavioral advertising or any other purpose.
To exercise your rights: support@moondoggle.app or submit a request through your account settings. We verify your identity before processing requests.
14. Children's Privacy
Moondoggle is intended for users aged 13 and older (or 16 where required by local law, such as in the EEA under GDPR).
We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.
If you believe a child under 13 has provided us with personal information, please contact us at support@moondoggle.app.
15. Data Breach Notification
In the unlikely event of a data breach affecting your personal information:
- We will notify affected users within 72 hours of becoming aware of the breach (as required by GDPR Art. 33)
- Notification will be sent via email to your registered address
- We will also post a notice on our website and in-app (for Power Plan subscribers)
- Notification will include: nature of the breach, data affected, steps we've taken, steps you can take, and contact information
For Solo Plan and BYOK-only users with no Power Plan account: a breach of our systems would not affect your local data, as we do not have access to it.
16. Cookies and Website Analytics
The Moondoggle Application
The desktop app does not use cookies. It is not a web browser. Local preferences are stored in your .moon configuration folder.
The Moondoggle Website (moondoggle.app)
Our marketing website, hosted on Vercel, uses:
| Cookie/Technology | Purpose | Duration |
|---|---|---|
| Essential cookies | Session management, CSRF protection | Session |
| Analytics (Umami) | Cookie-free website usage patterns | N/A (no cookies) |
We use Umami for privacy-focused website analytics. Umami does not use cookies, does not track users across sites, and does not collect personal information. All data is aggregated and anonymous. We do not use advertising cookies, retargeting pixels, or social media tracking widgets on our website.
17. Changes to This Policy
If we make material changes to this policy:
- We will notify you via email (if you have an account) at least 30 days before the changes take effect
- We will post the updated policy with a clear changelog
- We will display an in-app notification for Power Plan subscribers
- The "Last Updated" date at the top will reflect the revision
For significant changes affecting data rights or our No AI Training Pledge, we will provide 90 days' notice and the option to export your data and close your account before changes take effect.
We will never retroactively weaken privacy protections for data already collected.
18. Contact Information
Moondoggle LLC Washington State, USA
- Privacy inquiries: support@moondoggle.app
- General support: support@moondoggle.app
- Website: https://moondoggle.app
For urgent privacy concerns (suspected breach, unauthorized access), email support@moondoggle.app with "URGENT" in the subject line.
This privacy policy is written for humans, not lawyers. If anything is unclear, email us and we'll explain it plainly. We believe privacy policies should be readable by the people they protect.
© 2026 Moondoggle LLC. All rights reserved.