1. Controller and scope
MOONWIND PRIVATE LIMITED (CIN U62012TS2026PTC220847), incorporated on 7 August 2026 with its registered office at Plot. no 165, TNGOs, Gachibowli, Seri Lingampally, K.V.Rangareddy- 500032, Telangana, India, operates moonwind.app and is the controller of information described here. Privacy requests: hello@moonwind.app. Support: hello@moonwind.app.
This policy covers Moonwind workspaces, brands, APIs, publishing, inbox, listening, benchmarking and connected social accounts.
2. Information Moonwind processes
- Moonwind account: verified email, name, profile image, sign-in provider, workspace/brand settings, session and security events.
- Connections: provider account/Page/channel IDs, usernames, names, avatars, granted permissions, Page tasks, token expiry, encrypted OAuth tokens and webhook subscription state.
- Content and conversations: posts, captions, media references, comments, mentions, direct messages, replies, authors, timestamps and engagement data exposed by the provider.
- Publishing: drafts, schedules, target accounts, publishing results and media uploaded for provider ingestion.
- Listening and benchmarking: configured keywords/hashtags, public results, Instagram Business Discovery competitor profiles, public professional-account posts, snapshots and metrics. Instagram hashtag discovery has no backfill. Facebook Page Public Content Access, when approved, is limited to finding and benchmarking known public Pages and filtering the posts fetched from them; Moonwind does not offer platform-wide Facebook post keyword search.
- Owned insights: metrics for connected Instagram professional accounts, Facebook Pages and YouTube channels when the relevant account-specific permission is granted. These analytics do not authorize access to private or unrelated accounts.
- Operations: IP address, browser/request metadata, error and audit records used for security and reliability.
3. YouTube API Services
Moonwind uses YouTube API Services to connect channels, show channel analytics and recent videos, retrieve and reply to comments, upload videos, find public listening results and compare selected public channels. Use of these features is also subject to the YouTube Terms of Service, the Google Privacy Policy and this Privacy Policy.
Depending on the feature you choose, Moonwind reads and stores:
- Authorization and channel data: encrypted OAuth access and refresh tokens, token expiration, granted access, channel ID, title, handle, description, thumbnail and uploads-playlist ID.
- Channel and video statistics: subscriber, channel-view and video counts; video IDs, titles, publication times, thumbnails, links, views, likes and comment counts; and authorized channel analytics such as watch time, average view duration and subscriber changes.
- Comments and replies: comment and thread IDs, video ID, author channel ID, display name, profile image, comment text, publication time, like and reply counts, reply status and replies sent through Moonwind.
- Listening and benchmarking: configured searches, public video titles and descriptions, channel names, thumbnails, publication times, links, public statistics and calculated comparisons for public channels selected by a workspace user.
- Publishing records: the selected channel, video ID, title, description, visibility, audience and synthetic-media declarations, schedule, upload status and result.
Moonwind uses this data only to provide the YouTube feature you request, keep workspace records current, protect the service and meet legal duties. Authorized workspace users can view data for their workspace. Moonwind sends data to Google and YouTube when it retrieves data or performs your instruction. Moonwind's hosting and security providers process the minimum data needed to run the service. Moonwind does not sell YouTube data, use it for targeted advertising or train general-purpose AI models with it.
Moonwind refreshes or deletes stored YouTube metadata, comments, public listening results, public competitor content and related statistics no later than 15 days after collection or the previous refresh. If YouTube no longer returns a channel, video, comment or other resource, Moonwind deletes its stored copy. Moonwind also checks the connected authorization during refresh. If Google revokes it or the refresh token becomes invalid, Moonwind disconnects the channel and purges the related authorized YouTube data.
Direct upload uses a separate short-lived Google access token in your browser. Moonwind does not send that token to its servers or store it. For a YouTube-only upload, your browser sends the video file directly to YouTube and Moonwind does not receive or store the file. If you select YouTube and another social platform in one publishing action, your browser also sends a separate copy to Moonwind so Moonwind can deliver it to the other selected platform. That temporary copy follows the publishing-media retention period below.
You can review or revoke Moonwind's Google access on the Google third-party connections page. When you disconnect YouTube in Moonwind, Moonwind asks Google to revoke its token and deletes the credentials and related authorized YouTube data as soon as practical and no later than seven days. Moonwind can keep a limited deletion receipt that does not contain the deleted YouTube content.
4. Separate Facebook and Instagram connections
Instagram Login authorizes professional-account profile access, publishing, comments, messages and owned insights. Facebook Login separately authorizes selected Pages, Facebook publishing/inbox and owned Page insights, plus linked-Instagram access used for Business Discovery. Page Public Content Access is a separate Meta-reviewed feature for configured public Page benchmarking; it is not general Facebook keyword search. Connecting one login does not automatically authorize the other.
Meta sends subscribed comments, mentions and messages to Moonwind webhooks. Moonwind verifies provider signatures, associates events with the correct workspace brand and connected account, and makes them available in the unified inbox.
5. Purposes and user-directed actions
Moonwind uses data to authenticate users; operate selected connections; show dashboards, insights, inbox and listening results; publish or schedule content; send replies and moderation instructions requested by an authorized user; secure and troubleshoot the service; enforce terms; and meet legal duties.
Moonwind does not sell provider data, use it for credit or surveillance decisions, serve targeted advertising from it, or train general-purpose AI models with it. Automated provider actions occur only from a user instruction or an enabled schedule.
6. Service providers and transfers
Data is sent to the connected platform when needed to authenticate, retrieve authorized data or perform your instruction. Amazon Web Services hosts Moonwind application, database, object storage, delivery and logs. Google provides authentication and YouTube APIs. Meta, X and other connected providers process requests under their own terms.
Providers may process information outside your country. Moonwind uses contractual, access-control and security measures appropriate to the transfer. We may disclose limited information to advisers or authorities when legally required, or during a business transaction subject to continued protection.
Moonwind's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Retention matrix
Retention is purpose-based: Moonwind deletes data sooner when it is no longer needed or when a valid deletion/deauthorization event requires it. Restricted backups expire on their rotation schedule. A restored environment stays isolated and must be reconciled against an independently retained deletion ledger before receiving traffic.
8. Security and temporary public media
Moonwind uses HTTPS, access controls, tenant/brand ownership checks, encrypted provider credentials, webhook signature verification and operational monitoring. Publishing media must be reachable by the social provider, so its temporary object URL is publicly retrievable by anyone who has the unguessable URL until deletion; do not upload confidential media.
9. Choices, rights and deletion
You can choose the accounts and permissions connected to each brand, disconnect an exact account, revoke Moonwind in provider settings, and request access, correction, export, restriction, objection or deletion where applicable. See Data Deletion for the in-product purge and persisted confirmation-status flow.
Deletion removes or anonymizes Moonwind-held provider data and credentials. For YouTube, Moonwind requests Google token revocation. For Meta connections, Moonwind also attempts provider-side unsubscribe or token revocation where supported. Deletion does not remove content already published on a provider; delete that content on the provider or with Moonwind's supported live delete action.
10. Children, complaints and updates
Moonwind is for users aged 18 or older. Contact hello@moonwind.app if you believe a child supplied data or to raise a complaint. You may also contact the competent privacy authority. Material policy changes will be posted with an updated effective date.
