Privacy Policy

Effective June 9, 2026

1. Who we are

Moonlight (“we,” “us,” “our”) is a venture product operated by Sundae Labs, Inc. Our contact email is support@trymoonlight.io.

2. Data we collect

We collect data that you provide and data from connected services:

Account information

  • Name, email address, and profile picture (from Google sign-in)
  • Timezone, preferred wake time, and briefing preferences
  • Business profile fields you enter during onboarding (including reply signature, business hours, team size, and any template-specific details)

Connected integrations

When you connect a Google account, we request access to Gmail, Google Calendar, Google Business Profile, and Google Contacts via OAuth. We store an encrypted refresh token and short-lived access tokens so Moonlight can read your data and take actions on your behalf.

  • Gmail— message metadata and content for triage. Every write to Gmail happens only after you approve it. Each morning’s briefing proposes a single inbox-cleanup action — filing informational mail (newsletters, receipts, shipping notices, and similar) into Moonlight/<Category> labels, and archiving and marking read the emails the briefing covered — applied only when you approve that proposal. You control it by approving or dismissing the proposal in each briefing; there is no unapproved filing or mark-as-read (opening or reading a briefing changes nothing in your mailbox) and no Settings toggle to manage. Draft replies are likewise sent only after you approve them.
  • Google Calendar— event data for scheduling analysis. We create or modify events only after you approve a suggested action.
  • Google Business Profile— reviews and location data for review-response drafts. We post review replies to GBP only after you approve them.
  • Google Contacts— contact names and email addresses (read-only) for identity resolution across integrations

Billing

Payments are processed by Stripe. We store your Stripe customer ID and subscription status but never see or store your card number or bank details.

Automatically collected

  • Session cookie (encrypted, HttpOnly, 30-day expiry) for authentication
  • A short-lived oauth_state cookie set during a Google OAuth handshake and deleted as soon as the handshake completes
  • Sidebar preference cookie (UI state only)
  • Our hosting provider (Vercel) keeps short-lived request logs (IP address, user agent, timestamps) for platform security and observability. We do not persist these logs in our own database.

Analytics

Where it runs (see below), we measure how Moonlight is used, using Google Analytics. We record which pages and blog posts are viewed, which features and agents are used, which briefing proposals are approved or dismissed and in which category, how far people get through setup, and a small set of similar counts. Every value we send is drawn from a fixed list we declare in advance — route names, provider names, agent names, categories, outcome codes, plan names, and public blog slugs.

This measurement carries no directly identifying data— no name, no email address, no profile or business field, no phone number, and nothing you have typed into a form. It carries no message content— no subjects, senders, bodies, draft replies, briefing headlines or details, summaries, catch-up recaps, to-do text, review text, chat messages, or calendar event titles. It carries no Moonlight record identifiers and no identifier that links it to your account, so this data is never stitched to who you are inside Moonlight.

We want to be straight with you about what that does not mean. Google still receives a pseudonymous device identifier and your device’s network address, because those are inherent to how the measurement reaches them and there is no setting on our side that removes them. So the payload we send is free of the categories listed above, and we are not going to round that up into a claim that nothing about you is involved.

Web addresses inside Moonlight can contain record identifiers and one-time state values. We replace those with a stable placeholder before anything is sent, and we send a fixed name for each screen rather than the live page title.

Measurement is on by default in the regions where it runs, and you can turn it off at any time (see “Your choices about analytics” below). We do not use it for advertising, remarketing, or any cross-site identifier; we have turned off Google’s advertising and personalisation features and its data sharing, and we do not link it to Google Ads.

Where measurement does not run at all

In regions whose law requires your prior consent before this kind of measurement, we do not measure you at all. We have not built a consent request, so rather than ask you for something we cannot properly record, we switch the whole thing off: the measurement code is never requested, nothing is placed on your device, nothing is transmitted, the page you receive contains no reference to Google Analytics, and you will not see a consent banner. That is a deliberate trade — we lose the data.

This applies to the European Union and the wider European Economic Area (including Norway, Iceland and Liechtenstein) and their outermost regions and territories; the United Kingdom, Gibraltar, and the Crown Dependencies of Jersey, Guernsey and the Isle of Man; Greenland and the Faroe Islands; Switzerland; Brazil; Quebec; China; South Korea; Turkey; Thailand; and Vietnam. Switzerland and Brazil do not in fact require prior consent — we chose to switch measurement off there anyway.

We work out which region a request comes from using the network location of the request itself, not anything your device reports about itself. That method can be wrong: a connection routed through another country — a corporate network or a VPN — presents that country’s location, and we have no way to see past it. If you are signed in and the region on your account is one of the above, we switch measurement off on that basis too, even when your connection says otherwise. If we cannot determine the region at all, or anything in that determination fails, we treat it exactly as if it were one of the regions above and measure nothing.

To do this we look at the network address of the request, for that purpose only, and we do not retain itfor that purpose — it is read as the request is handled and never written to our database. To be precise about what we are claiming: in those regions we do not measure you. We are not claiming that handling your request involves nothing at all, because working out that you are there is itself something we had to look at.

Your choices about analytics

  • With an account— there is a single “Analytics” switch in Settings. Turning it off stops measurement immediately, without a page reload, and removes the measurement identifier already stored in that browser. It is recorded on your account, so it applies on every device you sign in on. You can turn it back on from the same switch; measurement then resumes from your next page load, and only in the regions where it runs.
  • Without an account— there is a “Turn off analytics” control in the footer of our public pages. It is honored for that browser.
  • Browser signals— if your browser sends a Global Privacy Control signal, we honor it as a legal obligation, and the outcome is identical to the regions above: nothing is measured. We also honor a Do Not Track header, as a voluntary courtesy rather than an obligation — it has no legal force anywhere and only a minority of browsers still send it, so please do not rely on it as your only control. We honor whichever signal your browser sends, on every request it sends it with, and we do not copy it onto your account: it applies to that browser, which is what the signal means. These two signals are not equivalent, and we do not treat them as such.

Turning measurement off changes nothing else. Your briefing, your connected accounts, and everything Moonlight does for you carry on exactly as before.

3. How we use your data

  • Generate your daily briefing— we process data from connected integrations through an AI-powered pipeline to surface action items, draft replies, and scheduling insights
  • Execute approved actions— when you approve a draft reply or action, we send it through the originating integration on your behalf
  • Improve suggestions— rules you create teach Moonlight your preferences for future briefings
  • Billing and account management
  • Security and abuse prevention

4. AI processing

Moonlight uses large language models (LLMs) to analyze your integration data and generate briefing items. This processing happens in isolated sandboxed environments on each briefing run.

LLM requests are routed through Vercel AI Gateway (our infrastructure provider) to underlying model providers (currently Anthropic and OpenAI). We have enabled Zero Data Retention (ZDR) on the gateway, which means:

  • Your prompts, the model outputs, and any data sent with a request are not retained by the gateway. They are processed solely to fulfill the request and are immediately and permanently deleted once it completes.
  • Requests are routed only to model providers that have a Zero Data Retention agreement in place with Vercel. Providers without such an agreement are not used.
  • Every ZDR-compliant provider also contractually agrees not to use your prompts or responses to train or improve their models.

Moonlight does not use your data to train models, and we do not sell or repurpose your content.

5. Data sharing

We do not sell your personal data. We share data only with:

  • Infrastructure providers— Vercel (hosting and AI gateway), Neon (database), for service operation
  • AI providers— Anthropic and OpenAI, accessed via Vercel AI Gateway under the Zero Data Retention terms described in Section 4, to process your briefing data
  • Resend— to deliver transactional emails that you initiate from inside the product (such as messages to support or billing)
  • Stripe— for payment processing
  • Google— to read from and write to your connected accounts via their APIs
  • Google Analytics— Google also receives the analytics described in Section 2, in the regions where measurement runs. This is a separate flow from the integration access above, and it is the only one an opt-out affects. Signing in also involves a redirect to Google, which is how sign-in works and is unrelated to measurement.
  • Legal obligations— when required by law or to protect our rights

6. Data security

Your content and the data we pull in from your connected integrations — briefing headlines, details, drafts, summaries, catch-up recaps, action and undo payloads, and the small amount of processing-log content we re-read — are encrypted at rest at the application layer under a Moonlight-controlled key, in addition to your provider’s own at-rest encryption. That key is rotatable without data loss and without forcing you to reconnect any integration. OAuth tokens and session cookies are encrypted under the same rotatable scheme. Session cookies are marked HttpOnly, Secure, and SameSite=Lax; database connections use TLS; and we rotate session nonces on privilege changes to prevent session fixation.

7. Data retention and deletion

We retain your account data — including briefing items, approved and pending drafts, and rules — for as long as your account is active. Detailed processing logs from each briefing run, and the run summaries and catch-up recaps, are automatically deleted after 14 days.

You can delete your account at any time from Settings (including while it is locked or past-due). Deletion permanently removes your account, connected integrations, briefing history, drafts, and associated content, and withdraws Moonlight’s Google permission grants. A few bounded residues are retained and then purged: an anonymized deletion audit record (a one-way HMAC of your account id, your tier at deletion, and counts of related rows — no name, no email address, and no content); content-free diagnostic error records, retained up to 90 days; and Stripe’s own billing records, kept on Stripe’s side per its retention policy. If you’ve contacted us through the in-app support or billing form, those messages — including the email address, account identifier, and text you submitted — are delivered and stored by our email provider and in our support inbox per their retention policies, which our deletion process cannot reach. For security and accountability, we also keep internal operator-access records noting which Moonlight staff member viewed an account (by its internal identifier) and when; these hold no message content and are kept independently of account deletion. Because our database provider keeps encrypted point-in-time backups, residual copies of deleted data may persist in those backups for up to 7 days — our provider’s point-in-time-recovery window — before they age out.

Analytics

Measurement data is held by Google, not by us, and it does not have a single deletion date. There are three distinct horizons, and we would rather state all three than give you one tidy number that is not true:

  • Event-level data— the individual recorded events are set to Google’s shortest available retention, 2 months, after which Google deletes them.
  • Aggregated report data— the summary tables Google builds from those events are kept beyond that window. That retention setting does not govern them, and we cannot make it.
  • The device identifier— the measurement cookie in your browser has its own lifetime, which we have cut down from Google’s two-year default to 180 days. Turning measurement off removes it immediately.

Because we deliberately send no identifier that links measurement to your account, measurement records cannot be located in response to an access or deletion request — there is nothing in them to search by. We are telling you this rather than offering a deletion we could not actually perform. What you can do instead is stop it: turn measurement off, and the identifier in your browser is removed and no further data is sent.

8. Your rights

You can:

  • Access your data through the Moonlight app (briefings, settings, integrations)
  • Correct your profile information in Settings
  • Disconnectany integration at any time. Moonlight deletes the credentials it holds for that account and stops reading it. Disconnecting does not itself withdraw the permission you granted at Google — to do that, remove Moonlight from your Google account’s third-party connections.
  • Opt out of analytics— from the single switch in Settings, or, if you do not have an account, from the “Turn off analytics” control in the footer of our public pages. See Section 2 for what that does.
  • Delete your account and all associated data from Settings
  • Export— download a JSON export of your account, integration metadata (never tokens), briefing items, drafts, run summaries and catch-up recaps, and rules from Settings (internal execution metadata such as action/undo payloads and source references is not included), or contact support@trymoonlight.io

9. Cookies and device storage

These are needed to run the product or to remember a preference you set:

  • session— encrypted authentication cookie (30 days)
  • oauth_state— short-lived CSRF-protection cookie used during a Google OAuth handshake; deleted as soon as the handshake completes
  • ml_rail_collapsed— remembers your navigation rail collapsed/expanded preference (1 year)
  • ml_no_measure— records that you used the “Turn off analytics” control without an account, so the objection survives past that page (1 year). Set only if you use that control.

These are not strictly necessary. They are set only where measurement runs — in the regions described in Section 2 nothing below is written to your device, and neither is anything else that is not strictly necessary:

  • ml_attribution— a first-party cookie set when you land on a blog post, recording which piece of writing brought you here as a short content label (30 days). It holds no name, email address, or content of its own, it is set once and never overwritten by a later visit, and if you go on to create an account its value is saved to that account so we can tell which writing leads to signups. It is ours — it is not shared with anyone — and it is deleted with your account.
  • _ga and _ga_* — Google Analytics’ own cookies, holding the pseudonymous device identifier described in Section 2, with a lifetime of 180 days. Turning measurement off removes them.

We use no advertising cookies and no cross-site identifier, and we do not use any of this for advertising or remarketing.

10. Children

Moonlight is not directed to children under 13. We do not knowingly collect data from children.

11. Changes

We may update this policy and will note the effective date above. If we make material changes, we will surface an in-product notice.

12. Contact

Questions or requests? Email support@trymoonlight.io.