Privacy policy
Last updated 5 September 2026
Key facts
- Scope
- This website, its product-update subscription, demo survey, feedback collector, and public AI template customizer, not a signed-in Moosewave account.
- Tracking
- Optional, limited site-use analytics and error diagnostics only after consent; no advertising, autocapture, replay, or cookies.
- Storage
- Primary site records: AWS Stockholm; business mailbox: Ireland. Requested AI copy is processed by Gemini; retention is explained below.
- Control
- Access, correction, or deletion requests go to info@moosewave.com.
1. Scope
This policy covers the Moosewave website at moosewave.com and the product-update subscription, interactive-demo survey, site-feedback collector, and public AI template customizer operated through it. It does not describe a signed-in Moosewave product account; a separate policy will apply when self-serve account signup opens.
2. Who is responsible for your data
Horizonfold Labs LLP is responsible for the processing described in this notice and is the data controller where the EU General Data Protection Regulation applies. India's November 2025 commencement notification phases the main processing provisions of the Digital Personal Data Protection Act 2023 in from May 2027. We provide the controls described here voluntarily before that date and will update this notice as those provisions commence.
Contact the controller at info@moosewave.com. Its registered name, office, LLPIN, and limited-liability statement are published in the legal notice.
3. What we collect and why
We collect the following when you subscribe to product updates, build a personalised interactive demo, deliberately submit site feedback, request an AI template proposal, or explicitly enable an optional measurement category. There is no account, no login, and no behavioural advertising on this site.
Scroll to compare
| Data | Why | Basis |
|---|---|---|
| Email address | To send the confirmation and, once confirmed, product updates | Consent |
| Signup timestamp | To evidence when consent was given | Consent / legal obligation |
| Confirmation timestamp | To evidence that consent was verified | Consent / legal obligation |
| Consent wording shown | To evidence exactly what you agreed to | Consent / legal obligation |
| Original subscription source page, later fixed template/action references, and latest request time | To preserve the context in which consent was given and remember a later request for a different public template or handoff path without storing its draft copy | Legitimate interests |
| Demo choices: goal, interests, perspective, client view, starting screen, and depth | To build the requested demo and understand which product areas visitors want to explore | Legitimate interests |
| Demo-survey response identifier, source page, and timestamp | To prevent duplicate records, give the response context, and locate it if needed | Legitimate interests |
| Feedback rating, category, and optional note | To understand and improve the site | Legitimate interests |
| Feedback page path, timestamp, and reference | To give the comment context and make a deletion request locatable | Legitimate interests |
| Template ID, selected language, instruction, and current preview copy | To ask Google Gemini for the template-copy proposal you deliberately request | Performance of the requested service / legitimate interests |
| One-way daily network-address digest and request count | To enforce per-network-address and global AI proposal-request limits without retaining the raw address | Legitimate interests |
| PostHog page context: path, page group, content language, event time, and an in-memory tab identifier | To count consented page runtimes and understand which public pages and deliberate paths are useful | Consent |
| PostHog page-use events: section identifiers and order; fixed depth and visible active-time milestones; same-origin destination path, navigation surface and kind; named call-to-action and article identifiers; product-update and feedback outcomes; and, for a template-origin path, fixed source, template, and handoff-action codes | To understand which parts of the public site are reached and which deliberate paths are useful, without generic click capture | Consent |
| PostHog walkthrough events: survey steps and selected answers; workflow, scene and action identifiers; presenter and playback state; detours; Atlas filters and result-count buckets; guide and trail use; completion and remix outcomes | To understand whether the sample walkthrough explains the product and where visitors stop, without recording typed or search text | Consent |
| Error class, scrubbed stack file and line, page path, and coarse browser, operating-system and device class | To diagnose browser failures through Sentry only when enabled | Consent |
| Network address disclosed in transit to an enabled measurement provider | To establish the network connection and prevent abuse; project controls must discard it from analytics use | Consent / legitimate interests |
| Network address disclosed to AWS when you request an AI proposal | To establish the connection, enforce abuse limits, and return the requested proposal | Performance of the requested service / legitimate interests |
When you select Build my demo, the selected answers listed above are sent to Moosewave and stored with a random response identifier. We do not ask for or attach your name, email address, account, URL query string, URL fragment, referrer, or browser identifier. An internal notification containing the response is sent through AWS's email delivery service to info@moosewave.com so the team can review it.
That demo-intent record is a separate first-party collector, not a PostHog event, and submitting it does not enable optional analytics. If analytics is already enabled, PostHog may also receive the allowlisted demo-choice codes and milestones described in the table, but never the survey response identifier.
When you choose Generate proposal in the public template studio, the selected template identifier, language, instruction, and current structured preview copy are sent through our AWS endpoint to the paid Gemini API. Google processes them to produce one text proposal. We disable Gemini interaction storage, do not enable search or other tools, and do not log or retain the instruction, draft copy, or response in Moosewave systems. The result remains in the current browser page until you dismiss, replace, apply, refresh, or leave it.
The public customizer is not a place for personal, confidential, customer, regulated, or third-party information. It is restricted to professional or business use by adults aged 18 or over. Google retains prompts, contextual information, and outputs for 55 days for abuse monitoring under its standard paid-service controls, even when interaction storage is disabled. We will state it here if Google approves zero-data-retention controls for this project.
To limit abuse and cost, AWS supplies the request's network address to the function. The function converts it into a one-way, key-protected daily digest and stores only that digest, a count, and an expiry time. The raw address, instruction, and generated copy are not placed in that table or in application and API access logs. A separate global daily counter contains no visitor data.
We use double opt-in: your address is not added to product updates until you click the confirmation link. If you never confirm, the record is scheduled for automatic deletion 30 days after signup.
5. Where your data is stored
Waitlist, demo-survey, and feedback data are stored on Amazon Web Services infrastructure in the eu-north-1 region, located in Stockholm, Sweden. Internal survey notifications are sent through AWS's email delivery service to Moosewave's business mailbox in the eu-west-1 region, located in Ireland.
If you enable optional measurement, PostHog and Sentry process the limited records described above in projects restricted to their EU data regions. We do not activate either integration against a non-EU project.
AI requests pass through our AWS infrastructure in Stockholm and then to Google's paid Gemini API. We disable interaction storage and optional log sharing. Google may process operational and abuse-prevention data in countries where it operates, subject to the safeguards and data-processing terms that apply to its paid service. Do not use the public customizer for personal or confidential information.
Authorised personnel of the Indian operating entity may access this data from India when handling product updates, the demo survey, feedback, or a rights request. EU storage describes where the primary records are hosted; it does not mean that remote access from another country never occurs. We assess access and any resulting transfer under the data-protection law applicable to the person and processing involved.
7. How long we keep it
- Unconfirmed signups: scheduled for automatic deletion 30 days after signup; DynamoDB may complete deletion shortly afterward.
- Confirmed signups: retained until you unsubscribe or ask for deletion.
- Consent records: retained for the duration of the subscription and for three years afterwards, to evidence that consent existed.
- Demo-survey database records: scheduled for automatic deletion 180 days after submission; DynamoDB may complete deletion shortly afterward. The operational email copy is retained only while it remains useful for reviewing the response and handling related requests.
- Site feedback: scheduled for automatic deletion 180 days after submission. DynamoDB may complete an expired-record deletion shortly after that point.
- Local interface preferences: treated as expired after 180 days and removed the next time this site reads them, unless you clear them sooner.
- Template draft and design recovery: when interface memory is enabled, a validated current snapshot may remain in that tab's session storage for up to 12 hours. Undo history, AI prompts, proposals, review packets, and secret-like text remain page-only and are not persisted. Moosewave never receives this local recovery state.
- AI-generation rate-limit digest and count: scheduled to expire within three days. DynamoDB may complete deletion shortly after the expiry time. The raw network address is not stored in that record.
- Gemini interaction storage is disabled. Under Google's standard abuse-monitoring process, prompts, contextual information, and outputs are retained for 55 days. We will state it here if Google approves zero-data-retention controls for this project.
- Optional page analytics and error diagnostics: retained in the vendor project for no more than 90 days. Aggregated counts that no longer identify a device or event may be retained longer.
8. Your rights
The main processing and rights provisions of the DPDP Act 2023 are not yet in force. Until they commence, we voluntarily honour requests to access a summary of your personal data and how it is processed; to correct, complete, or erase data; to nominate someone to act in the event of death or incapacity; and to seek grievance redressal. Once those provisions commence and apply, Data Principals will have the corresponding statutory rights.
Under the GDPR, if you are in the EU or EEA you have the right of access; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interests; and withdrawal of consent at any time, which does not affect the lawfulness of processing before you withdrew it. You also have the right to lodge a complaint with your national supervisory authority.
To exercise any of these, email info@moosewave.com. We respond without undue delay and ordinarily within one month. If applicable law permits additional time, a reasonable fee, or refusal for a manifestly unfounded or excessive request, we will explain that decision. Include the feedback reference if your request concerns an otherwise unlinked feedback submission. For a demo-survey response, include the approximate submission time and choices so we can locate it. Future product updates will include an unsubscribe mechanism; the initial confirmation email does not add you to the list unless you click its confirmation link.
You can withdraw analytics or diagnostics consent immediately through Cookie & storage choices in the footer. Because the site deliberately keeps no persistent measurement identifier, we may be unable to locate an individual anonymous event after it has been received; include the approximate date, time, page, and browser if your request concerns one.
Moosewave keeps no application copy or account identifier with which to locate a public AI request later, and cannot reverse the daily one-way rate-limit digest back into a network address. Google-retained abuse-monitoring data is handled under its paid-service terms. You can remove the browser draft immediately with Clear saved draft, by closing the tab, or by withdrawing interface memory through Cookie & storage choices.
9. Grievance Officer
The following named contact handles discrepancies and complaints about personal-data processing under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and serves as the website's single privacy grievance contact.
Harsh Bishnoi
Grievance Officer
Email: info@moosewave.com
Postal correspondence: registered office in the legal notice
Complaints are acknowledged within 24 hours and we aim to resolve general grievances within seven days, subject to any shorter period required by law. If you are in the EU or EEA and the GDPR applies, you may also complain to your national supervisory authority. The Data Protection Board route will apply as the corresponding DPDP provisions commence.
10. Children
This site and its public AI customizer are not directed at children and we do not knowingly collect data from anyone under 18. The AI customizer is restricted to professional or business use by adults aged 18 or over. The DPDP Act requires verifiable parental consent for children's data; rather than build that, we simply do not accept signups from children. If you believe a child has signed up, tell us and we will delete the record.
11. Changes
If we change this policy we will update the date at the top. If a change materially affects how we handle data you have already given us, we will email you rather than rely on you rechecking this page.
Revision history: Last updated 27 July 2026, previous notice covering the product-update subscription, feedback collector, and local interface memory. The 28 July 2026 revision adds the interactive-demo survey collector and the separate, consent-based PostHog and Sentry categories with their data boundaries. The 29 July 2026 revision expands the PostHog category to limited site-use and walkthrough events, explains form-outcome correlation risk, and clarifies the separate route boundaries for PostHog and Sentry. It also names the grievance officer, links the consolidated legal notice, and clarifies remote access to EU-hosted records. The 15 August 2026 revision adds the public template customizer, its paid Gemini API processing, disabled interaction storage, browser-only draft, one-way rate-limit record, provider disclosure, safe-use boundary, and related retention and rights information.