Privacy Policy
Last updated: September 30, 2026
This Privacy Policy explains how MoonCo, Inc., a Delaware corporation (“MoonCo,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when a business customer or its personnel use our websites, application programming interfaces, documentation, support channels, and related services (the “Service”).
The Service is offered to businesses, not to consumers. If you use the Service for a business customer, that customer may also control personal information that it submits. The customer is responsible for its own notices and instructions to you.
Our role
MoonCo is the controller of business contact, account, billing, website, support, and security information that it uses for its own purposes. If a written data processing agreement permits a customer to submit personal data in Customer Content, MoonCo acts as that customer’s processor or service provider for that content, and the customer remains responsible for deciding why and how it is processed.
Information we collect
Business contact and account information
We may collect your name, business email address, company, role, billing contact details, account identifiers, access permissions, and communications with MoonCo. Customers receive access by invitation, so we may receive this information directly from you, your organization, or a person who asks us to provide access to you.
Customer Content
We process prompts, other API inputs, and generated outputs (“Customer Content”). Customer Content can contain personal information if a customer includes it. Customers must not submit protected health information, financial account numbers, government identification numbers, GDPR special-category data, or similar regulated sensitive information unless a written customer agreement expressly permits it.
Usage and technical information
We may collect API endpoint and model selections, request times, token counts, cost and balance records, response status, latency, error details, team and key identifiers, retention settings, and related service telemetry. We may also receive internet protocol addresses, user-agent data, and security or access logs from requests to the Service and our public sites.
Payment information
Our payment processor may collect payment-card and billing information. MoonCo receives transaction details, such as the payer, amount, currency, payment status, and processor identifiers. MoonCo does not receive full payment-card numbers from the payment processor.
How we use information
We use personal information and Customer Content to:
- provide, route, operate, maintain, and improve the Service;
- authenticate customers, issue and manage credentials, apply use limits, and calculate charges;
- process payments, maintain account balances, and keep business records;
- provide support and respond to requests;
- detect abuse, protect the Service, investigate incidents, and prevent fraud;
- enforce our agreements and comply with legal duties; and
- only with the customer’s prior, explicit consent, create aggregated and de-identified data and use it to evaluate, develop, train, and improve MoonCo products and models.
Before MoonCo uses Customer Content for model training, MoonCo aggregates it and uses commercially reasonable efforts, consistent with industry-standard technology, to de-identify it. By default, MoonCo does not use Customer Content or usage data for model training.
Legal grounds for processing
Where applicable law requires a legal ground, we process personal information as needed to perform a contract or take requested pre-contract steps, for our legitimate interests in operating and securing the Service, to comply with legal obligations, and with consent when we specifically request it. You may withdraw consent at any time, but this does not affect processing that occurred before withdrawal or processing based on another legal ground.
Business contact and billing information is necessary to enter into and manage a customer agreement. Other account and support information is optional, but without it MoonCo may be unable to provide access, respond to a request, or support the Service. MoonCo does not use personal information covered by this Policy to make solely automated decisions that produce legal or similarly significant effects.
How we disclose information
We may disclose information to the following recipients:
- Cloud infrastructure providers. Amazon Web Services and related infrastructure services host, store, transmit, and secure Service data.
- Payment providers. Stripe and related financial-service providers process payments and help prevent fraud.
- Inference providers. Contracted routing and model-service providers process API inputs and outputs to provide requested responses. MoonCo does not authorize these providers to use Customer Content to train their own models.
- Professional advisers. Auditors, insurers, accountants, lawyers, and other advisers may receive information when reasonably necessary and subject to appropriate duties.
- Authorities and affected parties. We may disclose information when we reasonably believe it is necessary to comply with law, protect rights or safety, investigate misuse, or establish or defend legal claims.
- Transaction parties. Information may be reviewed or transferred as part of a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.
MoonCo does not sell personal information. MoonCo does not share personal information for cross-context behavioral advertising or use it for targeted advertising.
International processing
MoonCo is a United States company. We and our service providers may process information in the United States and other countries where we or they operate. These countries may have different data-protection laws. Where applicable law requires it, we use an approved transfer mechanism or another lawful safeguard.
You may email privacy@moonco.io to ask for more information about an applicable transfer safeguard or how to obtain a copy.
Retention and deletion
By default, MoonCo does not archive raw Customer Content. With the customer’s prior, explicit consent, retention may be set to 30, 90, or 365 days; or no scheduled expiry. Changes apply only to new requests. Closing an account does not delete stored raw content.
An authorized customer representative may request deletion at privacy@moonco.io. We delete requested raw content within 60 days after verification, unless law or a security, dispute, or contract need requires retention. Protected backups may remain until their normal removal.
We keep account, billing, usage, security, and audit records as needed or required by law. Aggregated or de-identified training data and model improvements may remain indefinitely; deletion does not reverse training.
Security
MoonCo uses commercially reasonable administrative, technical, and organizational measures designed to protect personal information. No internet transmission or storage system is completely secure, and we cannot guarantee absolute security. Customers are responsible for protecting their API credentials and must promptly report suspected compromise to security@moonco.io.
Cookies and analytics
MoonCo’s current public websites do not set analytics or tracking cookies and do not use third-party analytics tools. Our infrastructure can still create ordinary server and security logs when you request a page. If these practices change, we will update this Policy and provide any notice or choice required by law.
MoonCo does not collect personal information over time across unrelated websites, and we do not knowingly allow third parties to do so on our public sites. Browser “Do Not Track” and Global Privacy Control signals do not change these practices because MoonCo does not sell or share personal information for targeted advertising.
Your privacy rights
Depending on where you live and which law applies, you may have rights to request access to, correction of, deletion of, or a copy of your personal information; to restrict or object to processing; to withdraw consent; or to appeal a denied request. You may also have a right to complain to a data-protection authority. These rights can be subject to verification, legal exceptions, and limits.
To make a request, email privacy@moonco.io. Tell us your relationship with MoonCo and the account or organization involved. We may ask for information needed to confirm your identity and authority. MoonCo will not discriminate against you for exercising a privacy right.
Business customer responsibilities
Customers must have the rights and lawful grounds needed to submit Customer Content. Before submitting personal data governed by the GDPR, a customer must enter into a data processing agreement with MoonCo. Customers must also follow the prohibited-data limits in their agreement.
Children
The Service is for business customers and is not directed to anyone under 18. We do not knowingly collect personal information directly from children through the Service. If we learn that a child submitted personal information directly to MoonCo, we will take reasonable steps to delete it. A parent or guardian may contact privacy@moonco.io.
Other websites
Our sites may link to services that MoonCo does not operate. Their privacy practices are governed by their own notices, not this Policy.
Changes to this Policy
We may update this Policy as our Service or legal duties change. We will post the updated Policy at this URL and change the “Last updated” date. When required by law or a customer agreement, we will also provide notice before a material change takes effect.
Contact us
For privacy questions and privacy-rights requests, email privacy@moonco.io. For legal notices, email legal@moonco.io.
Template credit
This Privacy Policy was generated by TermsFeed SaaS Privacy Policy Template.