Privacy

Last updated: September 2026
The short version: MoorAI reviews prompts on your device. Your prompt and response content is never stored and never sent to us — only redacted, content-free metadata (category, risk level, a one-way hash) reaches the MoorAI server so an admin or parent can see that something happened, not what was written.

Who controls your data

For the Enterprise edition, your organization (the tenant) is the data controller; MoorAI is the tool it runs. For the Families edition, the parent/guardian is in control of their household's setup.

What we collect

What we do not collect

Where data lives & how it's protected

Account and event metadata is stored on the MoorAI server, isolated per tenant — one tenant can never read another's. Secrets (SSO client secrets, your bring-your-own vision key) are encrypted at rest (AES-256-GCM) and are never sent back to any device. Sessions are signed; the admin console is restricted to the administrator (password or your SSO).

Families & children's data

MoorAI for Families is designed for data minimization. The on-device review means a child's conversations are not uploaded. Parents receive a signal that something needs attention — not their child's transcripts. Where signs of self-harm appear, the app surfaces help resources locally.

If you're a parent enrolling a minor's device, you are providing consent for that household setup. We collect the minimum needed to run the controls and never sell or share children's data. (COPPA / GDPR-K: confirm your specific obligations — see "Legal review" below.)

Your rights (GDPR / CCPA)

You can request access to, correction of, or deletion of your account data. Because MoorAI holds only redacted metadata, there is no conversation content to export or erase. Direct requests to the contact below; enterprise tenants should route requests through their administrator.

Retention

Console account data — the account, its devices, alerts and usage records — is kept while the account is active and permanently deleted within 30 days after the account is closed, or on request. Deleting an account also removes any newsletter/download subscription held under one of that account's own email addresses: one request ends both. An address that subscribed on its own and never had an account is not affected, because nothing links it to the account — those unsubscribe through the link in the email.

A minimal, content-free deletion record (which tenant, when, and how many rows of each kind were removed — counts only, no addresses) is retained in the governance/audit log. That log is tamper-evident and long-lived, so email addresses are not stored in it in readable form: an address appearing as the actor or subject of an administrative action is replaced with a one-way keyed pseudonym, which lets an auditor follow one person's actions through the log without the log holding their address. Installation tokens can be revoked at any time from the console.

Backup copies of the database taken automatically before an irreversible maintenance step are deleted after 30 days.

Contact

Questions or requests: the administrator of your tenant, or the operator of this MoorAI instance.

Legal review: this page describes MoorAI's actual data handling in plain language and is a starting point — it is not legal advice. Have it reviewed by counsel for your jurisdiction before publishing, especially the children's-data section.