Privacy Policy
Last updated: May 12, 2026
1. What We Collect
When you create a MoonDB account we store:
- Account info — email address and hashed password.
- Project data — schemas, database records, and uploaded files you create through the API.
- Usage metrics — API request counts, storage usage, and AI credit consumption for billing and rate-limiting.
- Request logs — HTTP method, path, status code, response time, and IP address. Logs are retained for up to 30 days.
2. How We Use It
- Operate and maintain the service.
- Enforce usage limits and prevent abuse.
- Process payments via Stripe (we never store card numbers).
- Send transactional emails (account verification, billing receipts).
- Improve reliability and performance through aggregated, anonymized analytics.
3. Third-Party Services
We rely on the following processors:
- Cloudflare — hosting, CDN, DNS, database (D1), object storage (R2), and edge compute.
- Stripe — payment processing.
- Google — Google Analytics and Google Ads, used to measure site traffic and advertising. In the EEA and UK these load only after you accept cookies (see Cookies below).
- Third-party AI providers — when you use AI endpoints, prompts and generated content are sent to the configured model provider. We do not use your data to train models.
4. Data Storage & Security
All data is stored on Cloudflare's global network. Passwords are hashed with scrypt before storage. API keys are generated using cryptographically secure random functions. All traffic is encrypted in transit via TLS.
5. Data Retention
Your project data is retained as long as your account is active. If you delete a project, its database and files are permanently removed within 30 days. If you delete your account, all associated data is purged within 30 days.
6. Your Rights
You can:
- Export your data at any time through the API.
- Delete your projects or entire account from the dashboard.
- Request a copy of all personal data we hold — email us at the address below.
7. Cookies
Essential — we store an authentication token in your browser to keep you signed in to the dashboard. This is required for the service to work and is always on.
Analytics & advertising — we use Google Analytics (GA4) and Google Ads to understand site traffic and measure our advertising. These set cookies and are not essential.
If you visit from the European Economic Area or the United Kingdom, these analytics and advertising cookies are disabled by default and load only after you choose "Accept" in the cookie banner. You can change your choice at any time by clearing the moondb_cookie_consent value in your browser's site storage, which brings the banner back. Visitors outside these regions are measured by default; you can opt out using a browser extension such as the Google Analytics Opt-out Add-on.
8. Changes
We may update this policy from time to time. Material changes will be communicated via email to active accounts.
9. Contact
Questions about privacy? Email privacy@moondb.ai.