Privacy
Moonshot listens to your day so the next thing you need is already there when you reach for it. That only works if you know exactly what it hears, where that goes, and what we keep. This page says so in plain language, and it describes the product as it is built today — including the parts that are less private than we want them to be.
Last updated 23 September 2026.
The short version
- Moonshot uses Sign in with Apple to create your account. It verifies Apple's signed identity token, stores an irreversible hash of Apple's stable account identifier, and keeps an encrypted Apple revocation credential so Delete all data can close the authorization with Apple. This iPhone keeps Apple's opaque identifier in Keychain. Moonshot requests neither your Apple email nor your name. Moonshot has no ads. We sell nothing about you, to anyone, ever.
- The app and website use content-free usage events to understand product use. App usage analytics can be disabled in Settings. Invitation analytics have a separate control on the invitation page. The interactive Door uses cookies to preserve your signed-in session and saves conversations for beta review as described below.
- Ambient microphone audio is divided at the first quiet pause, with a 30-second maximum, and sent securely through our server to Moonshot's private speech-transcription service on Google Cloud. Each chunk is deleted when transcription finishes. Moonshot keeps the resulting text. Captured conversation recordings stay encrypted on your phone and are backed up to your account until you delete them. After verified backup, older audio can be fetched when needed instead of occupying phone storage. Backup waits when the service is unavailable; pending recordings remain on the phone.
- To understand a moment, Moonshot sends recent transcript text and selected context through our server to Anthropic, Google, or OpenAI. Selected context is also retained for account recovery and cloud memory. Older private research diagnostics can contain requests and responses for up to 30 days. Anthropic keeps permanent-study batch results available for 29 days.
- To speak a reply, Moonshot sends only the text of that spoken reply to Fish Audio. It sends no microphone audio, call audio, voiceprint, Mind, mail archive, or other stored file to Fish.
- Some of your files are mirrored on our server so that a reinstall does not erase your life: your Mind, your ledger, your morning history, your call records, and your voice enrollment, voiceprints, and conversation recordings. What that copy contains is listed below.
- Gmail, Google Calendar, Google Drive, Google Contacts, and verified Google connection connect through one Composio Google Super authorization. Moonshot has no operational first-party Google OAuth path. These features stay under the Google Limited Use terms. How sensitive data is protected is described below.
- You can delete active account data and review what remains.
Who this covers
This policy covers the Moonshot iOS app and this website, which is served at moonshot.computer, preorder.moonshot.computer, moonshot.mobile, oons.hot, m.oons.hot, inner.you, and gets.you. "We" means the small team that builds Moonshot. Write to us at privacy@moonshot.computer about anything on this page.
Moonshot is an early build in the hands of a small, known group of testers. Sign in with Apple creates the Moonshot account. Your phone also identifies itself to our server with an App Attest key generated on first launch. The server binds that proved phone to the irreversible hash of Apple's stable account identifier. Apple shares neither your name nor your email with Moonshot during this flow.
Beta conversations and admissions
When you chat with Moons to apply for the beta, we save your conversation, your verified sign-in email, the channel and message timestamps in our private Supabase database. Ojas and Tario can review these conversations and the recommendation to select the founding group. This access is restricted to their verified admin accounts.
The conversational model uses a bounded recent history. The saved transcript stays available for beta review after older model context is summarized. Earlier conversations may be incomplete. We record seat decisions and who made them. A strong AI recommendation supported by your conversation can automatically reserve a seat within the active launch batch, up to 55 automatic admissions. Ojas and Tario can approve up to 45 additional applications. Every reservation shares the same 100-seat limit. You can request a human review by contacting us.
If a spot is unavailable or the decision is “not yet,” we retain your application on the waitlist with the time and reason. Your verified Google email stays with your application. You can save an optional phone number and separately choose email and text updates about beta spots and Moonshot. These update choices are off by default and have no effect on your place.
We store contact preferences, including your preferred messaging platform, their changes and the consent version. A phone entered on the website is unverified; linked messaging can verify it for that platform. Text outreach requires an explicit opt-in and a number verified for the selected platform. A saved preference for an unavailable platform stays on file until delivery is supported. You can turn updates off in Contact & updates. Replying STOP or disconnecting linked messaging turns off text updates for that number.
You can request removal of your beta conversation and application by contacting privacy@moonshot.computer. Deleting data in the iPhone app does not currently remove this separate website application. We do not sell these records or use them for advertising.
What the app hears
When listening is on, Moonshot divides microphone audio at the first quiet pause, with a 30-second maximum. The app sends each short chunk securely through our authenticated server to a private GPU speech-transcription service on Google Cloud. The service uses the audio only to produce text. Its temporary audio file is deleted when that request finishes. This temporary processing copy is separate from the saved recording described below. What survives is the transcript and its source recording, so you can listen back and correct who said what. Captured conversation recordings are encrypted on your phone with a key that never leaves the phone and backed up to your account until you delete them. Once the app has moved it, the key that encrypts recordings on your iPhone can only be unlocked by its Secure Enclave: a copy of the app's Keychain, or a backup read on another machine, opens none of them. The app itself can still unlock it once the phone has been unlocked since restart, so recording continues while the phone is locked. After verified backup, the phone keeps a recent cache and fetches older audio when needed. Pending backups remain on the phone. A voiceprint is a set of numbers describing a voice, not a replacement for the recording. Account audio is protected by provider-managed encryption, which our privileged server can read, and server-side analysis can read selected ones to process the requested source. Delete all data removes active phone and account copies; historical backups and provider retention have separate limits described below.
Speaker separation also sends selected audio to OpenAI's transcription API. This is separate from Moonshot's Google Cloud transcription service. Saved voice enrollment archives, including sample audio and voice statistics, and voiceprints are included in account recovery, sealed on your phone with a key kept in your iCloud Keychain; voice recognition is not a promise that every voice sample stays only on the phone.
That text is the substrate for everything else: the ledger of real things you said you would do, and the Mind — the profile of people, projects, promises, and preferences that Moonshot studies from your own words.
What a model call carries
Understanding uses one model request for each job, sent through a small server we run on Google Cloud. Anthropic's Claude studies permanent Mind updates, Google's Gemini judges ambient sections, and OpenAI writes re-derivable section titles and notes. Your phone holds no model keys. Our server relays each request and reply without logging or storing the contents.
A request can carry:
- recent transcript lines from what was just heard, as text
- your name and time zone
- people from your contacts — names, and the phone numbers and email addresses saved with them — so Moonshot spells a name right and knows who you mean
- calendar events in roughly the next two days: titles, times, and locations
- reminders you ask about: titles, notes, dates, and locations
- sleep timing and duration from HealthKit when you ask about your sleep
- the current Apple Weather result when you ask about weather
- relevant turns from your stored Moonshot call transcripts when you ask about a call
- your Mind: the profile Moonshot has built about your life
- for the Gmail catch-up, mail headers and previews — sender, recipients, subject, and the snippet Gmail shows in the inbox list
Permanent Mind study runs through Anthropic's Message Batches API three times daily. Anthropic's published Batch documentation says results remain available for 29 days after a batch is created. Our server keeps only the content-free batch id, state, token counts, cost, and request hash needed to avoid a duplicate paid request. Erasing Moonshot removes that server metadata. Anthropic's retained result follows its 29-day provider window. Provider retention and training terms differ. We do not claim that every processor provides zero retention or a no-training agreement; Fish's public terms below expressly allow training and improvement uses.
Moonshot's spoken voice is generated by Fish Audio from only the text of Moonshot's spoken reply, requested by our server. Fish's public terms permit Fish to use submitted content and usage data to develop, train, or improve its models and third-party components. Fish's privacy policy says it may keep content as long as needed to operate its systems. Fish publishes no fixed retention period for this text in those public terms. Read Fish's Terms of Use and Privacy Policy. Weather comes from Apple WeatherKit with a coarse location.
iOS permissions, and what each one is for
Every one of these is an iOS permission you grant, and every one can be revoked at any time in Settings. Where a permission's data can travel in a model request, it says so.
- Microphone
- Ambient listening. Short ambient chunks travel through our authenticated server to Moonshot's private Google Cloud speech-transcription service and are deleted when transcription finishes. Selected audio also travels to OpenAI for speaker separation. Captured conversation recordings are backed up to your account until you delete them; verified backups allow older audio to be released from the phone and fetched when needed. Voice enrollment archives and voiceprints are backed up to your account, sealed with a key kept in your iCloud Keychain. Transcript text can travel in later model requests.
- Contacts
- Names for correct spelling and for knowing who you mean. Names, numbers, and email addresses can travel in model requests.
- Calendar
- Your rhythm and what is coming. Event titles, times, and locations can travel in model requests.
- Reminders
- Creating and completing reminders you asked for. Relevant reminder text can travel in a model request when you ask about reminders.
- Photos
- Moonshot analyzes dates, locations, and a small image sample on-device to learn places and recurring themes. Photos stay on the phone unless you choose to send one, such as with a question or feedback. Derived place and theme facts can become part of the Mind mirrored on our server.
- Location
- Coarse position for Apple Weather and an on-device place diary. Precise routes stay on the phone. Weather and derived place facts can appear in model context or the Mind mirrored on our server.
- Health
- Read-only sleep timing for the morning brief. When you ask about sleep, relevant timing and duration can travel in a model request.
- Notifications
- Push. Your device's Apple push token is stored on our server so Moonshot can reach you.
- Focus
- One bit — whether a Focus is on — so Moonshot stays quiet.
Calls
Moonshot calling is retired.
Creator referrals
Joining referrals at /creators uses Google sign-in to verify your email and an irreversible hash of your stable Google account identifier. We store these with your referral code so you keep the same link when you return. This sign-in does not request access to Gmail, Calendar, Drive, or Contacts.
Your shareable link contains a referral code, not your email. We retain campaign attribution in your visitor's browser for up to 30 days and associate tracked visits and confirmed paid pre-orders with that code. You can see your own totals; verified Moonshot and OpenTrade workspace accounts can see referral identities and the team report. Referral reports show only aggregate orders; the authenticated team report separately reads buyer contact and shipping details from Stripe. Payment card details and engraving are not shown. Contact privacy@moonshot.computer for referral-account deletion requests.
Google user data
Connecting Google is required to finish initial setup. One Composio Google Super connection asks once for Gmail, Calendar, Drive, Contacts, and verified Google email. That consent powers Gmail reading and reviewed sending, Calendar reading and reviewed changes, contact-name recognition, Drive file-name and metadata context, and account-owned snapshots. Moonshot restricts the connection to the named Composio tools for those features. Moonshot requests these scopes and no others:
- mail.google.com
- Google describes this scope as full Gmail access. Moonshot restricts its Composio auth config to fetching mail metadata and preview snippets, fetching one selected message, reading the Gmail profile, sending a reviewed email, and replying to a reviewed thread. The app does not fetch message bodies during inbox import. Every send waits for the five-second confirmation bar.
- calendar
- Google describes this scope as full Calendar access. Moonshot reads events and uses the create, change, or remove tools only after your confirmation. Apple Calendar on the phone is a separate source.
- drive
- Google describes this scope as full Drive access. Moonshot restricts its Composio auth config to listing file names and metadata. It does not download file contents through this connection.
- contacts.readonly
- Moonshot reads contact display names for recognition and spelling. It does not import Google contact email addresses through this connection.
- userinfo.email
- In the same Google Super connection, Google returns a verified email and stable account id (`sub`). Our server uses that response to verify the connected Google service, returns a short-lived proof bound to this phone, and uses the email only to show which Google connection supplied a snapshot. The Apple-backed Moonshot account owns the snapshot.
When Composio manages a connection, it presents Google's authorization screen and stores and refreshes the resulting Google token. Moonshot's app and server do not receive that token. The app asks our server for mail metadata, preview snippets, calendar events, contact names, and Drive file names and metadata; the server relays those requests through Composio and does not store the responses.
If you enable Use email details in Settings, Moonshot can also request text from selected relevant emails when a preview is incomplete. Selected text is processed by our AI providers to understand people and plans. Attachments are excluded. This option starts off, applies to this Google connection on this iPhone, and can be turned off to stop future reads. Inbox import continues to use headers and previews.
A fresh connection checks Composio's live managed Google catalog before opening. Moonshot opens no second Google authorization client.
All active Google requests run through Composio. Managed Gmail connections check for new mail while the app is awake. Gmail, Calendar, Drive, Contacts, and account identity share one revokable grant. Moonshot does not fetch Gmail message bodies during inbox import or Drive file contents. Older builds may have left a Google credential in the iPhone Keychain; the current app can only revoke or erase that dated credential and never uses it for a feature.
The mail headers and preview snippets described above travel in the model request that builds your Mind. Facts learned from mail or Calendar, Google contact-name vocabulary, and Drive file-name context can become part of the Mind we mirror (see what we keep). Google user data is used for those features and for nothing else: never for advertising, never sold or transferred, never used to train any model, and never read by a human on our side except with your permission or where the law requires it.
Moonshot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnect Google from the app at any time, and revoke Moonshot's access to your Google account at myaccount.google.com/permissions.
The controls that protect this data in transit, at rest, and from unnecessary access are listed in How sensitive data is protected.
How sensitive data is protected
Public connections use HTTPS/TLS. That covers connections from your phone and to our external providers. The private Google Cloud transcription service also uses an internal HTTP hop behind its authenticated ingress; we do not claim every internal hop uses TLS.
Server-held data uses provider-managed encryption at rest. Google Cloud and Supabase manage the storage encryption for their respective copies. Data stored by Moonshot on your iPhone also receives iOS's built-in device encryption and data protection. Apart from voice enrollment archives and voiceprints, the server copies listed below are not encrypted under a key only you hold; that limit remains stated in What our server keeps.
Moonshot limits access to the least privilege needed for each feature. A random per-device identity key is kept in the iOS Keychain and our server uses its irreversible hash to separate one device's records from another's. Sign in with Apple supplies the stable identity for the Moonshot account; the server stores only an irreversible hash of that Apple identifier. The server also keeps the Apple refresh token needed for deletion inside an AES-256-GCM encrypted envelope. Its encryption key is kept separately in Doppler and mirrored only to the server runtime. Composio reads Google's verified userinfo to prove which Google service is connected. The server returns a short-lived signed proof bound to the authenticated phone. It stores only an irreversible hash of a previously watched Gmail address. Composio stores Google tokens, while Moonshot receives only the requested tool results and identity fields. Each managed auth config is limited to the listed scopes and named tools. Moonshot does not fetch Gmail message bodies, and no person on our team reads Google user data unless you give permission or the law requires it.
Delete all data removes active account content; recovery records and backups have separate retention. That single request removes the device record, mirrored files, call records, standing orders, receipts, account snapshots, the Apple account record, its encrypted Apple revocation credential, and its device bindings. Moonshot first asks Apple to revoke that credential, then removes the records after Apple confirms the request. Backup retention, recovery records, and the Gmail-watch exception are described under Your control.
We promptly investigate any breach affecting your data and notify affected users. We also take steps to contain the incident and prevent it from recurring. Write to privacy@moonshot.computer to report a suspected incident.
Google user data is never sold, never used for advertising, and never used to train models. Moonshot uses it only for the user-facing features described in this policy.
What our server keeps
Our server runs on Google Cloud. Supabase is the active storage authority; Firestore remains involved in migration and recovery. Recovery file contents are also copied to private Supabase Storage, with ownership, versions, and checksums in Supabase Postgres. The account and per-device records include:
- an irreversible hash of Apple's stable account identifier, an AES-256-GCM encrypted Apple refresh token used only for deletion-time revocation, and the proved devices bound to that Moonshot account
- the standing orders you wrote and the receipts of what Moonshot did about them
- your Apple push token, and your time zone
- the phone number you verified as your caller ID, and when you verified it
- an irreversible hash of the Gmail address being watched
- the update-note version IDs you acknowledged, and when you acknowledged them
- your call records: the transcript turns from both sides, and what Moonshot made of them
- content-free model batch receipts: provider batch id, state, token counts, cost, and a one-way request hash. These receipts contain no transcript text or model output
- mirrored copies of your Mind, your pending notes, your ledger, and your morning history. The Mind can contain derived facts from sources you connected, including contacts, calendars, and on-device photo or place analysis. Cloud memory can read selected profile and transcript content for server-side understanding
- captured conversation source recordings, kept in your account until you delete them. Older copies remain readable during storage migration. Account-scoped server analysis can read referenced recordings
- your voiceprints: numbers describing each voice Moonshot measured in your saved moments, sealed on your phone with a key kept in your iCloud Keychain before upload
Voice enrollment recovery includes owner samples, calibration, anonymous speaker archives, and retained earlier voice generations. Photos and your managed Gmail token are not part of that recovery archive. Voice archives and voiceprints are sealed on your phone with a key kept in your iCloud Keychain, so Moonshot's server stores bytes it cannot read; voice archives saved by earlier versions are resealed while your phone charges. Account recordings use provider-managed encryption; Moonshot's privileged server can read their bytes. Moonshot also encrypts the Apple revocation credential with a separate application key in addition to provider-managed storage encryption.
Half of every call transcript belongs to the person you were talking to, who agreed to a conversation with you. We think that is the most sensitive material Moonshot holds, and we treat requests to remove it accordingly.
Your control
- Every fact in the Mind can be corrected or forgotten one at a time, and the whole Mind can be erased, from the Mind screen.
- Settings has Delete all data: it clears the Mind, the ledger, your voiceprint, every call record and its audio, and your connected service grants from the phone. The server revokes Moonshot's Sign in with Apple refresh token, then deletes the Apple-backed Moonshot account, device bindings, account snapshots, recordings, voice archives, and active associated server records. After the server confirms deletion, the local Apple sign-in receipt is removed. The app shows you what came back: how many records were deleted, or, if the server could not be reached, that the copy is still there.
- Any call record can be deleted on its own, and every synced call can be erased in one action.
- Disconnecting Google revokes the one Composio Google Super grant for Gmail, Calendar, Drive, and Contacts. The app also erases any dated phone-held Google credential left by an older build.
- Revoking any iOS permission in Settings stops that channel immediately.
Delete all data removes active account content from the connected stores. It can leave deletion and recovery records, including object identifiers, hashes, byte counts, and cleanup status. These records support consistency checks and retries. Their complete retention limit is still being verified during the storage migration.
Recovery content is kept while you keep the account, until you delete it; we do not silently expire saved recordings or voice enrollment history. Research diagnostics written by older server versions can contain requests and responses and remain in a private log for up to 30 days from each entry. Account deletion does not remove individual entries from that historical log. Current research diagnostics retain only timing and status, and server-side model-content replay capture is disabled.
Optional Google Drive backups are independent exports that you control in Drive. They pass through Moonshot and Composio and include stored profile and history files, voice profiles, retained transcripts and notes, and recordings if you enable that option. Files are readable in Drive by anyone you share them with. Turning off or disconnecting backup stops future automatic exports; Delete all data leaves existing Drive files in place. Remove the Moonshot folder in Google Drive to delete those copies.
Short-lived server response caches expire separately from account deletion: model retry responses and spoken-reply audio after five minutes, and morning readings after one hour. These caches are scoped to the authenticated device and schedule cleanup even when idle. Expiry removes application references; it is not a claim of forensic memory wiping.
Historical database copies have separate retention. Firestore point-in-time recovery is enabled with a seven-day window, so earlier versions can remain for up to seven days after a deletion. Supabase Pro provides access to seven days of daily database backups; deleting a live row does not remove it from an existing backup. Supabase point-in-time recovery is currently disabled. See the providers' descriptions of Firestore recovery and Supabase backups.
Conversation recordings in Google Cloud Storage have a seven-day soft-delete recovery period. Deleting a recording removes its active copy and playback access; a private recoverable copy can remain for seven days. This bucket setting was verified on 23 September 2026. See Google Cloud Storage recovery.
The Firestore and Supabase backup settings were observed on 20 September 2026; they are not a promise of immediate erasure from provider disaster-recovery systems. OpenAI, Anthropic, Google, Fish Audio, and Composio apply their own terms to material they process. Moonshot's Delete all data does not certify removal from all of those systems. We have not verified a special Fish agreement overriding its public training or retention terms.
Supabase database backups contain Storage metadata, without the stored file bytes. Restoring a database backup does not restore a deleted Storage file. A successful active deletion therefore has a different scope from verified removal of every historical copy. The app returns to account creation after a completed erase. If a Gmail watch cannot be stopped at Google immediately, it expires there within seven days.
If any of that does not behave the way this page describes, write to privacy@moonshot.computer and we will fix it and delete what is left by hand.
Who else touches it
- Anthropic
- Claude studies permanent Mind updates. Message Batch results remain available at Anthropic for 29 days.
- OpenAI
- The model that writes re-derivable section titles and notes, and an audio transcription API that separates speakers in selected recordings.
- Gemini judges ambient sections; Google also provides Gmail, Calendar, Drive, Contacts, and the verified email for the connected Google service. Google Cloud runs our server and stores what is listed above.
- Composio
- Managed authorization and encrypted Google tokens for the active Google Super connection; it executes only the tools and scopes listed above.
- Apple
- Account authentication and deletion-time token revocation through Sign in with Apple, push notifications, and WeatherKit.
- Textbelt
- Sending the two creator launch texts a person requests.
- Photon
- Delivering iMessage conversations when you connect with Moons.
- Fish Audio
- Turning only the text of Moonshot's spoken reply into speech. Fish's public terms permit model training and improvement uses described above.
- Vercel
- This website and its server-side functions.
- Google Ads
- The homepage loads Google's advertising tag, which sets Google cookies so we can tell which of our Google ads lead to pre-orders. After a paid pre-order it reports one purchase conversion with the amount, currency, and Stripe checkout identifier.
- Mixpanel
- Charts of optional app usage and the website creator metrics described below, with pseudonymous identifiers and campaign tags.
- Supabase
- The waitlist, creator launch reminder records, active recovery records in Postgres, and private recovery files in Storage.
Each one is a supplier doing a job for us. Mixpanel visualizes optional app usage and the website creator metrics described below. Google Ads is the one advertising network, and only for measuring our own ads on this website. Moonshot works with no data brokers.
This website
When you connect Moons to iMessage, Google sign-in happens on this website. Sending your prepared first message links your iMessage number to that account. Photon receives your number and message content to deliver the conversation. Moonshot stores the linked account, conversation, and a summary of earlier messages so Moons can continue across visits. Individual message records expire after one year. The active conversation and account link expire after a year without activity. Type STOP in iMessage or disconnect your number on the website to stop replies. You can request deletion at privacy@moonshot.computer.
Friend invitations store a pseudonymous Apple account identifier, first onboarding completion, invitation eligibility time, three invitation slots and redemption state. When you typed or imported your name in the app, your first name is stored with your invitations and shown to anyone who opens one of your invitation links. Website sign-in uses a secure session cookie lasting up to seven days. A short-lived sign-in cookie expires after ten minutes. We retain an encrypted Apple credential for revocation when you delete your account. If you request a TestFlight email, we send your supplied email address to Apple to deliver beta access. Invitation operation receipts record provider acceptance separately from app use. Optional invitation analytics contain event names, timestamps and pseudonymous identifiers; they expire after 90 days. Turning invitation analytics off deletes the account-level invitation event history. Account deletion removes the invitation account, links and email delivery records. Email addresses and invitation secrets are excluded from analytics exports.
This website records landing page views and campaign tags (source, channel, campaign, content, and term). Your browser remembers the most recent campaign for up to 30 days so a later signup can be attributed. We store those tags with waitlist and reminder signups. The hardware pre-order page uses the same 30-day campaign window. It records page views and clicks that open Stripe with campaign tags, referrer origin, a pseudonymous browser identifier, quantity, and the selected finish or color. It does not include an engraving, name, email, or other checkout details in those events. After Stripe confirms a paid pre-order, creator analytics record the campaign tags, amount, currency, and number of devices against an irreversible hash of the checkout identifier. Buyer email, name, address, phone number, payment details, and engraving are excluded from creator analytics. For the website onboarding funnel, we record starts, verified sign-ins, and completion through a first chat message or a sent messaging handoff. Account identifiers in these analytics are hashed; analytics contain no conversation text. We send the six non-commerce funnel event types, their timestamps, campaign tags, and pseudonymous identifiers, along with the pre-order page and checkout-click events described above, to Mixpanel for staff analytics. Email addresses, phone numbers, and conversation content stay outside this export. The creator sync uses our stored records; the pre-order page sends its two event types through a first-party endpoint. Neither adds a browser tracking SDK or session replay. The homepage separately loads Google's advertising tag, described under Google Ads. Aggregate reports are available to staff signing in with a verified @moonshot.computer Google Workspace or @opentrade.live account. The team dashboard separately retrieves paid-order contact and shipping details directly from Stripe; these are not part of creator analytics or the Mixpanel export. Dashboard sign-in requests basic Google identity only. Our host also keeps ordinary server logs.
The creator launch page stores the phone number you type, the campaign and reminder time, the exact consent language you accepted, the time you accepted it, the site domain, your browser's user-agent string, and text delivery state. We use that record only to send the two launch texts you requested. The X text is planned for September 8 at 8:00 AM Pacific, followed by LinkedIn at 9:00 AM Pacific. Each sends after the Moonshot team gives the go-ahead. Supabase holds the record. Textbelt receives the number and text content when each requested message is sent. Reply STOP to a text or email privacy@moonshot.computer to withdraw consent. We retain the consent and delivery record for up to four years so we can show that the communication was requested, unless you ask us to delete it sooner.
To be removed from the email waitlist, email privacy@moonshot.computer from that address. For a creator reminder, include the phone number you entered. We will delete the matching row.
Other people in the room
Moonshot hears whoever is near you and reads mail written by people who never installed it. Their words can end up in a transcript, and facts about them can end up in your Mind. Moonshot builds no profile of anyone to sell or share, and anyone can write to us to have material about them removed.
Children
Moonshot is built for adults and is not directed at children. We do not knowingly collect data from anyone under 13.
Changes
When the product changes what it collects, this page changes with it and the date at the top moves. If a change materially expands what leaves your phone, we will say so in the app before it takes effect.
Contact
Questions, deletion requests, and corrections to anything written here go to privacy@moonshot.computer.