Skip to content
Moosewave
Demo

Privacy policy

Last updated 5 September 2026

Key facts

Scope
This website, its product-update subscription, demo survey, feedback collector, and public AI template customizer, not a signed-in Moosewave account.
Tracking
Optional, limited site-use analytics and error diagnostics only after consent; no advertising, autocapture, replay, or cookies.
Storage
Primary site records: AWS Stockholm; business mailbox: Ireland. Requested AI copy is processed by Gemini; retention is explained below.
Control
Access, correction, or deletion requests go to info@moosewave.com.

1. Scope

This policy covers the Moosewave website at moosewave.com and the product-update subscription, interactive-demo survey, site-feedback collector, and public AI template customizer operated through it. It does not describe a signed-in Moosewave product account; a separate policy will apply when self-serve account signup opens.

2. Who is responsible for your data

Horizonfold Labs LLP is responsible for the processing described in this notice and is the data controller where the EU General Data Protection Regulation applies. India's November 2025 commencement notification phases the main processing provisions of the Digital Personal Data Protection Act 2023 in from May 2027. We provide the controls described here voluntarily before that date and will update this notice as those provisions commence.

Contact the controller at info@moosewave.com. Its registered name, office, LLPIN, and limited-liability statement are published in the legal notice.

3. What we collect and why

We collect the following when you subscribe to product updates, build a personalised interactive demo, deliberately submit site feedback, request an AI template proposal, or explicitly enable an optional measurement category. There is no account, no login, and no behavioural advertising on this site.

Scroll to compare

Personal data collected, purpose, and lawful basis
DataWhyBasis
Email addressTo send the confirmation and, once confirmed, product updatesConsent
Signup timestampTo evidence when consent was givenConsent / legal obligation
Confirmation timestampTo evidence that consent was verifiedConsent / legal obligation
Consent wording shownTo evidence exactly what you agreed toConsent / legal obligation
Original subscription source page, later fixed template/action references, and latest request timeTo preserve the context in which consent was given and remember a later request for a different public template or handoff path without storing its draft copyLegitimate interests
Demo choices: goal, interests, perspective, client view, starting screen, and depthTo build the requested demo and understand which product areas visitors want to exploreLegitimate interests
Demo-survey response identifier, source page, and timestampTo prevent duplicate records, give the response context, and locate it if neededLegitimate interests
Feedback rating, category, and optional noteTo understand and improve the siteLegitimate interests
Feedback page path, timestamp, and referenceTo give the comment context and make a deletion request locatableLegitimate interests
Template ID, selected language, instruction, and current preview copyTo ask Google Gemini for the template-copy proposal you deliberately requestPerformance of the requested service / legitimate interests
One-way daily network-address digest and request countTo enforce per-network-address and global AI proposal-request limits without retaining the raw addressLegitimate interests
PostHog page context: path, page group, content language, event time, and an in-memory tab identifierTo count consented page runtimes and understand which public pages and deliberate paths are usefulConsent
PostHog page-use events: section identifiers and order; fixed depth and visible active-time milestones; same-origin destination path, navigation surface and kind; named call-to-action and article identifiers; product-update and feedback outcomes; and, for a template-origin path, fixed source, template, and handoff-action codesTo understand which parts of the public site are reached and which deliberate paths are useful, without generic click captureConsent
PostHog walkthrough events: survey steps and selected answers; workflow, scene and action identifiers; presenter and playback state; detours; Atlas filters and result-count buckets; guide and trail use; completion and remix outcomesTo understand whether the sample walkthrough explains the product and where visitors stop, without recording typed or search textConsent
Error class, scrubbed stack file and line, page path, and coarse browser, operating-system and device classTo diagnose browser failures through Sentry only when enabledConsent
Network address disclosed in transit to an enabled measurement providerTo establish the network connection and prevent abuse; project controls must discard it from analytics useConsent / legitimate interests
Network address disclosed to AWS when you request an AI proposalTo establish the connection, enforce abuse limits, and return the requested proposalPerformance of the requested service / legitimate interests

When you select Build my demo, the selected answers listed above are sent to Moosewave and stored with a random response identifier. We do not ask for or attach your name, email address, account, URL query string, URL fragment, referrer, or browser identifier. An internal notification containing the response is sent through AWS's email delivery service to info@moosewave.com so the team can review it.

That demo-intent record is a separate first-party collector, not a PostHog event, and submitting it does not enable optional analytics. If analytics is already enabled, PostHog may also receive the allowlisted demo-choice codes and milestones described in the table, but never the survey response identifier.

When you choose Generate proposal in the public template studio, the selected template identifier, language, instruction, and current structured preview copy are sent through our AWS endpoint to the paid Gemini API. Google processes them to produce one text proposal. We disable Gemini interaction storage, do not enable search or other tools, and do not log or retain the instruction, draft copy, or response in Moosewave systems. The result remains in the current browser page until you dismiss, replace, apply, refresh, or leave it.

The public customizer is not a place for personal, confidential, customer, regulated, or third-party information. It is restricted to professional or business use by adults aged 18 or over. Google retains prompts, contextual information, and outputs for 55 days for abuse monitoring under its standard paid-service controls, even when interaction storage is disabled. We will state it here if Google approves zero-data-retention controls for this project.

To limit abuse and cost, AWS supplies the request's network address to the function. The function converts it into a one-way, key-protected daily digest and stores only that digest, a count, and an expiry time. The raw address, instruction, and generated copy are not placed in that table or in application and API access logs. A separate global daily counter contains no visitor data.

We use double opt-in: your address is not added to product updates until you click the confirmation link. If you never confirm, the record is scheduled for automatic deletion 30 days after signup.

4. Cookies and tracking

This website sets no cookies. Its Cookie & storage choices panel stores one first-party choice record in your browser's local storage for up to 180 days so we do not ask on every page. After that it is treated as expired and removed the next time this site reads it.

If you enable interface memory, the browser may also remember whether the feedback control has introduced itself. It may keep the current validated template draft and design in session storage for refresh recovery in that tab for up to 12 hours. Secret-like text is not stored. These values never leave your device, are not used to identify you, and can be cleared from the studio or disabled at any time through Cookie & storage choices in the footer.

Template undo history, AI prompts, proposal diffs, and review packets live only in the current page's memory. They are not part of refresh recovery. We do not put template copy in cookies, local storage, analytics, error diagnostics, or URL parameters. Closing the tab, reaching the 12-hour limit, clearing the saved draft, or withdrawing interface memory removes the session-stored snapshot.

If you choose Copy MCP brief or Copy review packet, your browser writes that plain text to your device clipboard. Moosewave does not receive, persist, or attach the copied text to an email subscription. Sharing a template uses only its canonical public page URL, never the copy or design choices in your browser draft.

If you enable Anonymous site analytics, the browser loads PostHog from our own JavaScript bundle. It sends a page-view event and only the deliberate, schema-checked events listed above: meaningful section exposure, fixed reading-depth and visible active-time milestones, same-origin navigation and named calls to action, product-update and feedback outcomes, successful article-link copying, and allowlisted interactions inside the synthetic walkthrough. Template-library measurement is limited to a fixed template identifier and a fixed action such as selecting a template, opening preflight, requesting or applying an AI proposal, copying a handoff, sharing the canonical page, opening the access gate, or following one of its three fixed handoff paths. A template-origin subscription outcome can repeat that fixed source, template identifier, and handoff intent so aggregate conversion can be counted across the new-tab boundary; it never contains draft copy, prompts, design values, or preflight text.

We reduce URLs to origin and pathname. PostHog does not receive URL query strings or fragments, referrers, campaign parameters, email addresses, feedback notes or references, typed input, Atlas search text, generated survey identifiers, or arbitrary element labels. Generic autocapture, dead-click and rage-click capture, heatmaps, exceptions, performance traces, feature flags, session replay, surveys, and persistent visitor profiles are disabled. The walkthrough events use only allowlisted codes, booleans, small counts, and count buckets. A successful feedback event includes the selected rating and category, but not the optional note.

PostHog's random identifier exists in memory for the current tab only and person-profile processing is disabled for every event. While analytics remains enabled, PostHog also stores a grant/deny flag in local storage; that flag is not a visitor identifier and is removed when the category is disabled or preferences are cleared.

Form-outcome analytics does not carry an email address, feedback reference, demo-survey response identifier, draft content, or a unique collector join key. Template-origin outcomes can carry only the same low-cardinality source, template, and handoff-intent codes described above, and we do not join the PostHog stream to first-party form records. The provider still records when an event arrives, so authorised personnel could theoretically compare close timestamps across systems. We restrict access and do not use timestamps for that purpose.

If you enable Error diagnostics, Sentry receives an error class and scrubbed stack location when the browser fails. Error messages, typed input, user fields, request headers, cookies, bodies, query strings, navigation breadcrumbs, source-code context, tracing, logs, metrics, profiles, and replay are disabled or removed before sending.

Consented PostHog analytics can run on the product walkthrough. Sentry never loads there. Neither integration loads on the product-update confirmation page, because its URL may carry a one-time token. The browser's Do Not Track signal also prevents PostHog capture. You can withdraw either choice at any time through Cookie & storage choices in the footer; withdrawal stops future collection but cannot undo processing already completed with your consent.

Fonts are served from our own domain rather than a third-party font service. Without optional measurement consent, merely loading a page discloses your network address only to us and our AWS hosting provider. Google receives a request only when you deliberately choose Generate proposal.

5. Where your data is stored

Waitlist, demo-survey, and feedback data are stored on Amazon Web Services infrastructure in the eu-north-1 region, located in Stockholm, Sweden. Internal survey notifications are sent through AWS's email delivery service to Moosewave's business mailbox in the eu-west-1 region, located in Ireland.

If you enable optional measurement, PostHog and Sentry process the limited records described above in projects restricted to their EU data regions. We do not activate either integration against a non-EU project.

AI requests pass through our AWS infrastructure in Stockholm and then to Google's paid Gemini API. We disable interaction storage and optional log sharing. Google may process operational and abuse-prevention data in countries where it operates, subject to the safeguards and data-processing terms that apply to its paid service. Do not use the public customizer for personal or confidential information.

Authorised personnel of the Indian operating entity may access this data from India when handling product updates, the demo survey, feedback, or a rights request. EU storage describes where the primary records are hosted; it does not mean that remote access from another country never occurs. We assess access and any resulting transfer under the data-protection law applicable to the person and processing involved.

6. Who else sees it

We do not sell, rent, or share your personal data for anyone else's marketing. Amazon Web Services provides the hosting, database, security controls, and email delivery this site runs on. Google provides the Gemini model only when you request an AI template proposal. If you enable the matching category, PostHog provides limited site-use analytics and Sentry provides browser error diagnostics. Each processes data only for the limited purpose described above.

You can read the providers' own notices at PostHog and Sentry, and Google's Gemini API terms. Their notices do not expand what Moosewave permits them to collect from this site.

We may disclose data where legally required to do so, and will tell you unless prohibited from doing so.

7. How long we keep it

  • Unconfirmed signups: scheduled for automatic deletion 30 days after signup; DynamoDB may complete deletion shortly afterward.
  • Confirmed signups: retained until you unsubscribe or ask for deletion.
  • Consent records: retained for the duration of the subscription and for three years afterwards, to evidence that consent existed.
  • Demo-survey database records: scheduled for automatic deletion 180 days after submission; DynamoDB may complete deletion shortly afterward. The operational email copy is retained only while it remains useful for reviewing the response and handling related requests.
  • Site feedback: scheduled for automatic deletion 180 days after submission. DynamoDB may complete an expired-record deletion shortly after that point.
  • Local interface preferences: treated as expired after 180 days and removed the next time this site reads them, unless you clear them sooner.
  • Template draft and design recovery: when interface memory is enabled, a validated current snapshot may remain in that tab's session storage for up to 12 hours. Undo history, AI prompts, proposals, review packets, and secret-like text remain page-only and are not persisted. Moosewave never receives this local recovery state.
  • AI-generation rate-limit digest and count: scheduled to expire within three days. DynamoDB may complete deletion shortly after the expiry time. The raw network address is not stored in that record.
  • Gemini interaction storage is disabled. Under Google's standard abuse-monitoring process, prompts, contextual information, and outputs are retained for 55 days. We will state it here if Google approves zero-data-retention controls for this project.
  • Optional page analytics and error diagnostics: retained in the vendor project for no more than 90 days. Aggregated counts that no longer identify a device or event may be retained longer.

8. Your rights

The main processing and rights provisions of the DPDP Act 2023 are not yet in force. Until they commence, we voluntarily honour requests to access a summary of your personal data and how it is processed; to correct, complete, or erase data; to nominate someone to act in the event of death or incapacity; and to seek grievance redressal. Once those provisions commence and apply, Data Principals will have the corresponding statutory rights.

Under the GDPR, if you are in the EU or EEA you have the right of access; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interests; and withdrawal of consent at any time, which does not affect the lawfulness of processing before you withdrew it. You also have the right to lodge a complaint with your national supervisory authority.

To exercise any of these, email info@moosewave.com. We respond without undue delay and ordinarily within one month. If applicable law permits additional time, a reasonable fee, or refusal for a manifestly unfounded or excessive request, we will explain that decision. Include the feedback reference if your request concerns an otherwise unlinked feedback submission. For a demo-survey response, include the approximate submission time and choices so we can locate it. Future product updates will include an unsubscribe mechanism; the initial confirmation email does not add you to the list unless you click its confirmation link.

You can withdraw analytics or diagnostics consent immediately through Cookie & storage choices in the footer. Because the site deliberately keeps no persistent measurement identifier, we may be unable to locate an individual anonymous event after it has been received; include the approximate date, time, page, and browser if your request concerns one.

Moosewave keeps no application copy or account identifier with which to locate a public AI request later, and cannot reverse the daily one-way rate-limit digest back into a network address. Google-retained abuse-monitoring data is handled under its paid-service terms. You can remove the browser draft immediately with Clear saved draft, by closing the tab, or by withdrawing interface memory through Cookie & storage choices.

9. Grievance Officer

The following named contact handles discrepancies and complaints about personal-data processing under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and serves as the website's single privacy grievance contact.

Harsh Bishnoi
Grievance Officer
Email: info@moosewave.com
Postal correspondence: registered office in the legal notice

Complaints are acknowledged within 24 hours and we aim to resolve general grievances within seven days, subject to any shorter period required by law. If you are in the EU or EEA and the GDPR applies, you may also complain to your national supervisory authority. The Data Protection Board route will apply as the corresponding DPDP provisions commence.

10. Children

This site and its public AI customizer are not directed at children and we do not knowingly collect data from anyone under 18. The AI customizer is restricted to professional or business use by adults aged 18 or over. The DPDP Act requires verifiable parental consent for children's data; rather than build that, we simply do not accept signups from children. If you believe a child has signed up, tell us and we will delete the record.

11. Changes

If we change this policy we will update the date at the top. If a change materially affects how we handle data you have already given us, we will email you rather than rely on you rechecking this page.

Revision history: Last updated 27 July 2026, previous notice covering the product-update subscription, feedback collector, and local interface memory. The 28 July 2026 revision adds the interactive-demo survey collector and the separate, consent-based PostHog and Sentry categories with their data boundaries. The 29 July 2026 revision expands the PostHog category to limited site-use and walkthrough events, explains form-outcome correlation risk, and clarifies the separate route boundaries for PostHog and Sentry. It also names the grievance officer, links the consolidated legal notice, and clarifies remote access to EU-hosted records. The 15 August 2026 revision adds the public template customizer, its paid Gemini API processing, disabled interaction storage, browser-only draft, one-way rate-limit record, provider disclosure, safe-use boundary, and related retention and rights information.