This policy describes what Moonmark (moonmark.ai) collects, why, and what never happens to your data. The short version: we collect what the service needs to run, we run our own minimal analytics instead of installing trackers, your payment details go to our payment provider rather than to us — and your private stories stay private.
1. What we collect
- Account data. Your email address, a display name if you set one, and — if you sign in with Google — the name and profile picture Google shares. Passwords are stored only as salted hashes.
- Story activity. Your saves: the text of your playthroughs, including what you type into stories, plus the structured state the engine keeps (location, clock, facts) so stories can resume. Stories you create in the workroom are stored with your account.
- Wallet history. An itemized ledger of Moon grants and spends (needed for honest billing), including the real computational cost of your turns.
- Feedback. Messages you send through the feedback page, with the contact email you provide.
- Page views. First-party only — see section 3.
2. How your content is processed
Generating a story turn requires sending the relevant context — including text you typed — to third-party AI model providers, routed through OpenRouter, which process it to produce the story’s response. This processing serves your request; we do not use your private story content to train AI models, and we do not permit our sub-processors to use it for training under the terms we rely on.
Private stories stay private. The content of your saves and of stories you keep private is never shown to other users, never published, and never used for model training. Stories you explicitly submit for publication are reviewed by a human before appearing publicly.
3. Analytics without tracking
We run our own first-party page-view counter. It records which page surface was visited and when. For visitors who are not signed in, the visit is attributed to an anonymous identifier derived from your network address and browser through a one-way hash whose key rotates daily — so we can count daily unique visitors, but the identifier cannot be linked across days and your raw IP address is never stored. When you arrive from an external link, we also record the referring site's domain (never the full address you came from) and, if the link carries them, our own campaign tags (the utm parameters in the link) — so we can tell which sites and campaigns bring readers. There are no third-party analytics, no advertising trackers, and no ad SDKs on the site.
4. Cookies
Moonmark uses only essential cookies: the session cookie that keeps you signed in. There are no advertising or cross-site tracking cookies, which is why the site has no cookie banner.
5. Service providers
We use a small set of infrastructure providers, each receiving only what its role requires:
- Railway — application hosting
- Neon — database hosting (account, saves, ledger)
- Cloudflare — network routing and security in front of the site
- OpenRouter and the AI model providers it routes to — story-turn generation (section 2)
- Resend — transactional email (verification, password reset)
- Stripe — payment processing. Checkout happens on Stripe’s hosted pages; we receive confirmation of what was purchased but never your full payment details. Stripe’s own privacy policy applies to checkout.
- Google — only if you choose Google sign-in
6. What we never do
- We do not sell your personal data.
- We do not run ads or share data with ad networks.
- We do not train AI models on your private stories.
- Pricing never depends on what you write — there is no content-based price discrimination.
7. Retention and deletion
Your data is kept while your account is active so your shelf and saves persist. You can delete individual saves at any time.
You can delete your whole account from your account page (Delete account) or, without the app, at moonmark.ai/account/delete. The account is deactivated the moment you confirm — you are signed out everywhere and no notices are sent — and its data is deleted 30 days later. Signing in during those 30 days shows a choice to keep the account or delete it immediately.
What deletion removes: your story saves, your Ever After scenes and his memories, your Messages, your keepsakes and album, your voice unlocks, your profile, avatar, reviews, bookmarks and votes, your sign-in credentials and devices, and the stories you created that no other reader holds. A published story that other readers have already started stays available to those readers only, under “A former member”, and leaves the public shelf.
What we keep: purchase, refund and spending records, under the deleted account’s internal id only, for as long as tax and accounting rules require; a one-way hash of your email address so that welcome credits are not granted twice; aggregate usage statistics with your account id removed; and any report you filed about content, with your account id removed. If you subscribed through the App Store or Google Play, cancel that subscription in your phone’s settings — the store, not Moonmark, bills it. If you signed in with Apple, we revoke the sign-in token Apple issued us.
8. Your rights
Depending on where you live (including under the GDPR and California’s CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Exercise any of these through the feedback page; we honor them for everyone regardless of jurisdiction.
9. Children
Moonmark is not directed to children and requires users to be at least 18. We do not knowingly collect data from anyone under that age; if we learn we have, we will delete it.
10. Changes
If this policy changes materially, we will announce it on the site before the change takes effect. The date above always reflects the current version.
Back to top