moonwind
PrivacyTermsData deletion
Open Moonwind
Back to MoonwindPRIVACY & DATA USE

Privacy Policy

This policy explains what Moonwind processes when you sign in, connect a social account, publish content, view analytics, or use the unified inbox.

Effective and last updated: 5 August 2026
Moonwind policiesPrivacy PolicyTerms of ServiceData Deletion

Questions?hello@moonwind.app

1. Scope and contact

This Privacy Policy applies to the Moonwind website, application, APIs, and related services available through moonwind.app (together, the “Service”). “Moonwind,” “we,” “our,” and “us” refer to the operator of the Service.

Questions, privacy requests, and complaints can be sent to hello@moonwind.app. Please do not send passwords, OAuth tokens, or other account secrets by email.

2. Information we process

Account and authentication information

When you sign in with Google, we receive your Google account identifier, verified email address, name, and profile picture. Google authenticates you; Moonwind does not receive your Google password. Administrator credentials, where enabled, are stored as password hashes rather than readable passwords.

Connected social-account information

When you authorize a platform connection, we may process account or channel identifiers, profile names, handles, avatars, granted permissions, access tokens, refresh tokens, token expiry information, and connection timestamps. Provider tokens are encrypted before being stored.

Social content and performance data

Depending on the platform and permissions you choose, we may process posts, videos, captions, thumbnails, comments, mentions, direct messages, replies, follower or subscriber totals, views, watch time, engagement metrics, channel analytics, publishing history, and public competitor-account metrics. Moonwind processes actions such as publishing or replying only when initiated by you or an authorized workspace user.

Service and device information

We may process IP address, browser and device information, request timestamps, authentication events, error details, security signals, and service logs to operate, protect, diagnose, and improve the Service. Moonwind also stores session credentials in your browser so you can remain signed in.

3. Google and YouTube user data

Moonwind requests only the Google permissions needed for the features you choose. Google identity data is used to create and secure your Moonwind account. If you connect YouTube, Moonwind uses authorized data to identify your channel, display uploads and channel statistics, show owned-channel analytics, synchronize comments, and send a comment reply after you explicitly submit it.

Moonwind does not use Google user data for advertising, credit decisions, sale to data brokers, or training general-purpose artificial intelligence models. We do not transfer Google user data except as needed to provide or secure the user-facing Service, comply with law, or complete an action you request.

Moonwind’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect YouTube in Moonwind or revoke Moonwind through your Google Account permissions. Revocation prevents future access but does not by itself delete your Moonwind login account; see our Data Deletion page.

4. X, Facebook, Instagram, and other platforms

For X, Moonwind may access profile information, public metrics, posts, mentions, messages available to your developer plan, and permissions to publish or reply. For Facebook and Instagram, once those integrations are available, Moonwind may access Pages and professional accounts you select, their content and insights, comments, messages, and publishing permissions.

Personal Instagram accounts are not supported by the planned professional-account integration. Each provider controls what data its APIs expose, and your use remains subject to that provider’s terms and settings.

5. How we use information

  • Authenticate users and maintain secure sessions.
  • Connect the social accounts and channels you select.
  • Display dashboards, analytics, competitor signals, and unified inbox items.
  • Publish posts or send replies after an authorized user requests the action.
  • Prevent fraud, abuse, unauthorized access, and service disruption.
  • Debug, maintain, and improve user-facing Moonwind functionality.
  • Meet legal obligations and enforce our Terms of Service.

6. When information is shared

We do not sell personal information or social-platform user data. We may disclose limited information:

  • To connected platforms, when needed to authenticate, retrieve authorized information, publish, or reply at your direction.
  • To infrastructure providers, including Amazon Web Services, which hosts Moonwind’s application, encrypted storage, database, logs, and content delivery infrastructure.
  • To professional advisers or authorities, when reasonably necessary to comply with law, protect rights and safety, or address fraud and abuse.
  • During a business transaction, subject to appropriate confidentiality and continued protection of the information.

7. Retention and deletion

We retain account data while your Moonwind account is active and retain connected-platform data for as long as needed to provide the features you use. Short-lived OAuth authorization records expire automatically. Disconnecting a channel removes its stored connection credentials; some synchronized records may remain until you request account-data deletion.

Verified deletion requests are ordinarily completed in active systems within 30 days. Limited information may be retained longer where required for security, fraud prevention, legal compliance, dispute resolution, or in time-limited backups, which are isolated from ordinary use and expire according to the backup cycle.

8. Security

Moonwind uses HTTPS in transit, private cloud storage, access controls, encrypted provider credentials, managed database protections, request throttling, and operational monitoring. No system can guarantee absolute security, so you should protect your device and promptly report suspected unauthorized access.

9. Your choices and rights

You may disconnect providers, revoke provider permissions, and request access, correction, export, restriction, objection, or deletion where applicable. Submit a request using the steps on our Data Deletion page. We may need to verify your identity before acting on a request.

10. International processing and children

Moonwind and its providers may process information in countries other than your own, including where our AWS infrastructure is located. We apply the protections described in this policy to that processing.

The Service is intended for people who are at least 18 years old and is not directed to children. If you believe a child has provided personal information, contact us so we can investigate and delete it.

11. Changes to this policy

We may update this policy as Moonwind’s features, providers, or legal obligations change. We will update the effective date and provide additional notice when a change materially affects how we use personal information.

moonwind© 2026 Moonwind
PrivacyTermsData deletion