← Back

Privacy & Data

⚠️ PLACEHOLDER — draft copy for layout only. Your attorney supplies the final, binding text.

This policy explains what [ENTITY — legal name, to be supplied] ("MoxyMind") holds, how it's used, who processes it, and the choices you have. MoxyMind is offered to members in the United States at launch.

Last updated: [DATE — set at counsel sign-off].

Your reflections are private

Your private reflections are yours alone. They are never shown to other members, to your pod, to Moxy, or to our team; they are never sold; and they are never sent to the AI model or used to train anything. This is enforced at the database level, not just by policy — only your own signed-in account can read your reflections.

What we collect

Account: your email, name, timezone, and a community pseudonym. Billing: handled by Stripe — we store purchase records and Stripe references, not your full card number. Usage: your program progress and completion, and your notification preferences. Community: anything you post to a pod or the community (shown under your pseudonym, not your name). Private: your reflections, described above.

[PLACEHOLDER — counsel: legal basis for each category, and confirmation of which elements are "consumer health data" under WA MHMDA / similar (see the standalone CHD policy).]

How Moxy (Claude) uses your text

Moxy is built on Claude, an AI model from Anthropic. Only public community text (pod and community posts) and program content are ever sent to the model, and only to check a post against our guidelines and to write gentle community nudges. Your private reflections are never sent. Under our commercial agreement with Anthropic, your inputs and outputs are not used to train Anthropic's models.

Who else processes your data (sub-processors)

We use a small set of service providers to run MoxyMind: Supabase (database, accounts, storage), Stripe (payments), Cloudflare R2 (audio storage), Anthropic (the Moxy AI, public community text only), Resend (transactional email), and your browser's web-push service (notifications). We do not use analytics, advertising, or tracking SDKs.

[PLACEHOLDER — counsel: confirm the list and attach each provider's DPA / terms.]

How long we keep it & how to delete it

We keep your data while your account is active. You can request a copy of your data or delete your account at Account → Your data; we confirm and process the request within 30 days. Deleting your account removes your personal data. Blocked posts are not stored, and we don't keep a per-member record of moderation categories.

[PLACEHOLDER — counsel: the specific retention schedule (MHMDA requires a stated period), including the admin audit log of staff actions.]

Your rights & choices

You can manage notifications and two-step verification in your profile, edit your name and pseudonym in Account, and request export or deletion as above. As a US resident you may have rights under laws such as the CCPA (California) and Washington's My Health My Data Act. [PLACEHOLDER — counsel: the specific state-law rights disclosure and how to exercise them.]

Cookies & analytics

The MoxyMind app uses only the cookies needed to keep you signed in and secure. It runs no analytics, advertising, or third-party tracking. [PLACEHOLDER — counsel: confirm, and cover the separate marketing website if it differs.]

Security

Data is encrypted in transit and at rest, access is default-deny and scoped to your own account, audio is served only through short-lived signed links, and admin access requires two-step verification.

Children's data

MoxyMind is for adults 18 and older and is not directed at minors. We do not knowingly collect data from anyone under 18.

Changes & contact

We may update this policy; material changes will be communicated to members. Questions or requests: [CONTACT — privacy email / address, to be supplied]. MoxyMind is educational, not clinical — see our Terms of Service.