privacy policy
We care about privacy
How moood collects, uses, and protects your data — and why your identity and your mood data never travel together.
// overview
this privacy policy describes how moood ("the app"), operated by Moood LLC ("we", "us", "our"), collects, uses, and protects your information. moood is designed with privacy as a core architectural principle — not as an afterthought.
by using moood, you agree to the practices described in this policy.
your identity and your mood data never travel together. moood uses a blind relay architecture that structurally separates who you are from how you feel. even we cannot connect the two.
// data collected
Account information
when you create an account, we collect:
- email address (for authentication and account recovery)
- display name (the name you choose to set for your account)
- organisation membership (which organisations you belong to)
- notification preferences (your preferred check-in time)
- Firebase Cloud Messaging token (for delivering push notifications)
Mood data
when you respond to a pulse, your mood response (positive or negative) is submitted through a blind relay. the relay verifies you are a valid participant, then discards your identity before writing the mood data. the resulting mood record contains:
- a mood value (positive or negative)
- a timestamp
- the pulse identifier
- the organisation identifier
mood records do not contain your user ID, name, email, or any other personally identifiable information.
Signal feedback
if you choose to submit written feedback (a "signal") after a pulse, it is submitted anonymously through the same blind relay. your identity is not stored alongside your feedback.
additionally, signal feedback is processed by an AI content moderator that rewrites submissions to extract themes and key points. this process removes individual writing styles, phrasing patterns, and other linguistic identifiers — providing an additional layer of anonymity beyond the blind relay.
Local data
the app stores a copy of your mood history on your device for your personal reference. this data never leaves your device unless you explicitly export it.
Timezone data
we collect your device's timezone (typically displayed as the nearest capital city, e.g. "America/New_York") to schedule pulse notifications at your preferred local time. this is not precise location data — it only identifies a broad geographic region.
Camera
moood uses your device camera only when you open the in-app QR scanner to join a pulse. camera frames are processed on-device to decode the QR code and are never recorded, stored, or transmitted. you can deny or revoke this permission at any time from your device settings — pulses can also be joined by tapping a link instead of scanning a code.
Data I do not collect
- precise location data (GPS, Wi-Fi, or cell tower)
- contacts or address book
- browsing history
- advertising identifiers
- biometric data
- health data
// how we use your data
Account data
your email and account information is used to:
- authenticate you and manage your account
- deliver pulse notifications at your preferred time
- associate you with your organisation(s)
Mood data
anonymous mood data is aggregated to provide organisations with sentiment trends — daily, weekly, and monthly. because mood data carries no user identifier, it cannot be traced back to you by anyone, including us.
Third-party services
moood uses the following third-party services:
- Google Firebase — authentication, database (Firestore), push notifications (FCM), and cloud functions. subject to Firebase Terms of Service and Google Privacy Policy
- Cloudflare — DNS, CDN, and bot protection for the website. subject to Cloudflare Privacy Policy
we do not sell, rent, or share your personal information with any other third parties.
// data storage & security
Where data is stored
- account data — stored in Google Cloud Firestore
- anonymous mood data — stored in Google Cloud Firestore, with no link to your identity
- local mood history — stored on your device only, in the app's sandboxed storage
The blind relay
moood's core privacy guarantee is architectural, not just policy. the blind relay ensures that authentication and mood submission happen in two separate requests. your identity is verified first, then discarded. the mood data is written by a service account with no knowledge of who submitted it.
this means that even with full database access, it is not possible to connect a mood response to a specific user.
Data retention
- account data — retained while your account is active. deleted when you delete your account
- anonymous mood data — retained indefinitely. because it contains no personal identifiers, it cannot be attributed to you after account deletion
- local mood history — retained on your device until you wipe it or uninstall the app
// your rights
you have control over your data:
- export — you can export your local mood history as a JSON file at any time from Settings
- delete local data — you can wipe all mood data stored on your device from Settings
- delete your account — you can permanently delete your account from Settings or the support FAQ. this removes your profile, email, and organisation membership. anonymous mood data remains in the database but cannot be linked to you
- manage emails — you can add, remove, and change your primary email from Settings
Children's privacy
moood is not directed at children under the age of 16. we do not knowingly collect personal information from children. if you believe a child has provided us with personal information, please contact us and we will delete it.
Changes to this policy
we may update this policy from time to time. material changes will be communicated through the app or via email. continued use of moood after changes constitutes acceptance of the updated policy.