Skip to main content
Moow account policy

Moow privacy notice

A plain-language notice for Moow health features, Moow AI, The Daily, and optional website analytics.

Last updated September 22, 2026

Who is responsible for your information

Moow AI LLC, a limited liability company formed in New Mexico, United States, operates Moow and is responsible for the personal data described in this notice.

Business mailing address: Moow AI LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States. For privacy questions or requests, email hello@moow.ai.

What this notice covers

This notice covers your Moow account, health and fitness features, Moow AI, The Daily community, and optional website analytics. The website and mobile app use the same Moow account; deleting it from either place affects both. Mobile and connected-health features described below may be limited to early access and are not all available on the website. Material new uses require an updated notice and, where appropriate, a new in-product choice.

Mobile early-access requests

When you request mobile early access on the website, we save your email, selected device, confirmation that you are 18 or over, permission to contact you about that request, and the wording version and time of your submission. We also keep the request’s review status. This lets the team manage requests and contact you when an invitation is available.

This list is separate from your Moow account and newsletter preferences. A request does not create an account, subscribe you to The Daily newsletter, or grant mobile access. No confirmation email is sent when you submit the form, and a submitted address is not treated as verified ownership. Repeating a request does not create another entry or change an existing request’s choices.

Requests are available to authorized administrators, not other visitors. We keep them while handling early access and remove them when they are no longer needed or after a verified removal request. To change your device, withdraw permission for access emails, or remove your request, contact hello@moow.ai from the address you submitted. We may need to verify the request before making changes. Deleting a reader account does not automatically remove this separately submitted request.

The form uses short-lived, hashed network identifiers to limit repeated submissions. Request details are not saved in browser storage or added to page URLs. If you allow website analytics, we count a completed request without sending your email, selected device, or other form answers to Google Analytics.

Age eligibility

Moow website accounts are for adults aged 18 or over. Signup asks you to confirm this together with the current account agreements; we record the accepted version and time, without collecting a full date of birth for website registration. Public articles can be read without an account.

If you believe someone under 18 has created a website account, contact hello@moow.ai. We will review the report, restrict an ineligible account, and arrange appropriate deletion. Do not include identity documents or sensitive information in your initial email.

Information we keep

  • Your name, email address, account ID, role, and account status.
  • Profile and plan preferences, meals, workouts, movement summaries, and progress entries that you choose to record.
  • When you choose to connect Apple Health, approved daily step totals, sleep intervals and stages, source-app identifiers and names, time zone, sync timestamps, and a random Moow installation identifier used to make sync and deletion reliable. This release does not request heart rate, location, reproductive health, or clinical records.
  • Private images that you upload for profile, meal, or other product features.
  • Moow AI consent, chats, and generated nutrition estimates until you use the available deletion controls or delete your account.
  • Your comments, reactions, saved stories, and their timestamps. Where mobile circles or challenges are available, this also includes memberships, sharing preferences, check-ins, and reports or blocks you submit.
  • Voice recordings you choose to send for transcription, and the resulting text if you send it as a chat message.
  • Support messages and the contact details you provide with them.
  • Newsletter consent and unsubscribe status when you use the mailing list.
  • Limited technical and security records needed to operate and protect the service.
  • If you allow website analytics, public page views, successful early-access request counts, a browser cookie identifier, approximate country, device and browser information, and referral source. These reports are separate from your Moow account.
  • If mobile product analytics is enabled for your app release and on for your device, manually defined interaction events, app version and environment, operating-system and device metadata, an SDK device identifier before sign-in, and an opaque Moow account identifier plus bounded sign-in-provider and setup-status labels after sign-in.

Passwords are handled by the authentication service and are not stored in the blog tables.

How the information is used

We use it to sign you in, keep your reading activity together, personalize the health and fitness features you request, publish and moderate comments, protect the service, respond to support requests, send the newsletter only when you subscribe, and—when enabled—use limited mobile product analytics to understand onboarding and feature reliability. With your website analytics choice, we also use aggregate reports to understand public page visits, traffic sources, and successful early-access requests. We do not sell your account or health information. We do not use health information for targeted advertising.

Camera movement features

Camera movement features process video frames on your device. Saved workout and movement summaries, such as repetitions, timing, and movement observations, may sync to your account. Photos you separately choose to upload, including meal photos, use the upload and AI flows described in this notice.

Connected health data

Apple Health access is optional, read-only, and requested only after you enable the connection in Moow. Your iPhone reads the categories you approve and sends the minimized records securely to your Moow account so Today can show steps and sleep across your devices. Moow does not write imported information back to Apple Health, use it for advertising or marketing, sell it, or use it for insurance, employment, credit, or eligibility decisions.

You can stop future device reads in Apple Health settings. You can also disconnect Apple Health inside Moow to delete the information imported through that provider from Moow while leaving the original information in Apple Health. While connected, a successful sync keeps the current local date and previous 29 local dates and prunes older imported step and sleep content. Remaining imported information stays with your account until you disconnect or delete the account. Apple intentionally does not tell apps whether read access was denied, so Moow may show an opaque no-data state instead of a permission label.

After a provider disconnect, Moow retains only non-content security metadata needed to stop a delayed request from restoring deleted data: your account and provider boundary, the provider generation and connected/disconnected state, one-way hashes of disconnected installation identifiers, and revocation times. It contains no step or sleep values, does not directly reveal an installation identifier, and is removed when you delete your Moow account.

If your phone cannot reach Moow when you request a disconnect, it keeps a protected, content-free deletion instruction containing the account, provider, installation identifier, and provider generation needed to retry safely. It contains no step or sleep values, is used only when that same account returns online, and is removed after Moow confirms the provider or account deletion.

Optional website analytics

Google Analytics 4 loads only after you choose to allow analytics in the website's Cookie settings. It counts public page views and successful early-access requests so we can understand overall traffic, approximate country, device and browser use, and referral sources. Google uses cookie identifiers to distinguish browsers. Moow does not send your account ID or link this activity to your account.

We exclude private account, administration, sign-in, and invitation pages from measurement. Analytics data excludes URL query strings and fragments, submitted email addresses, device choices and other form values, search text, health records, calculator inputs and results, and AI conversations. Article visits and coach-profile visits are grouped, without the individual article or profile in the analytics URL. External referrals include only the referring site, without its full page URL. We do not enable advertising features, session replay, or automatic form and interaction tracking.

Analytics is optional. You can reject it or change your choice through Cookie settings in the website footer without affecting sign-in, articles, or tools. Turning it off stops future collection in that browser and removes the website's Google Analytics cookies; it does not erase data Google already received. Repeat this choice in each browser you use. See the cookies and storage notice for the storage inventory and Google's privacy information.

Optional mobile product analytics

The mobile app includes a “Product analytics on this device” control. If analytics is enabled for your app release and the control is on, Moow sends manually defined interaction events to Mixpanel to measure product funnels and feature reliability. Before sign-in, Mixpanel uses an SDK-generated device identifier. After sign-in, those events may be linked to your opaque internal Moow account ID and include bounded sign-in-provider and onboarding-status labels. This makes the data pseudonymous, not anonymous.

Moow does not include names, email addresses, health values, meal or workout contents, photos, AI prompts or replies, free text, or precise location in analytics events. Automatic event, text, and form capture, session replay, and IP-derived geolocation are disabled. Mixpanel may still attach standard technical metadata such as operating-system and SDK versions, device model or manufacturer, and Moow app version.

This control is stored separately on each device. Turning it off stops future collection from that installation and asks the SDK to clear events waiting to upload, but it does not erase events Mixpanel already received. Deleting your Moow account also requests deletion of the Mixpanel profile and event history linked to your opaque account ID; Mixpanel's provider-side processing may take up to 30 days.

Production analytics will remain disabled until Moow has selected and stated here the exact Mixpanel data region, retention period, and reviewed basis for offering the control in the production project.

How Moow AI works

Moow AI is optional and is initially available only to members whose profile records an age of 18 or older. Before first use, Moow asks you to accept a separate in-product disclosure. When you use it, your question, recent messages in the same chat, time zone, relevant bounded Moow profile or activity records, selected published Learn stories, and any meal photo you choose are sent securely to OpenAI to generate the requested answer or estimate. Moow configures these generation requests not to create provider-side response state. OpenAI does not use API data to train its models unless Moow opts in, but its default abuse-monitoring logs normally retain request and response content for up to 30 days. Approved stricter controls may reduce that period; OpenAI states legal and safety exceptions can still apply. See OpenAI's API data controls.

If you use voice input, Moow sends your recording to OpenAI for transcription and removes the temporary device recording afterward. The transcript appears in the message composer for you to review. If you send it, the text becomes part of your saved chat history. Do not include another person's private information in a recording.

Moow stores normal chat history so you can return to it. You can delete a chat at any time. Deterministic emergency guidance is generated locally without OpenAI, stays available without AI consent or age eligibility, creates no AI records, and is clearly marked as not saved. A meal-photo estimate is not logged as a meal unless you review it and explicitly add it. An unneeded photo can be discarded; if it is not saved with a meal, it is scheduled for automatic deletion 24 hours after upload and normally removed within the following hour. AI results can be wrong and are not medical advice, diagnosis, allergy verification, or emergency support.

What other people can see

Published comments and your display name are public. Saved stories and your per-story reactions are private to your account and authorized Moow operations. Do not include medical records, contact details, or another person's private information in a comment.

In mobile circles and challenges, your display name, membership, check-ins, and the progress you choose to share may be visible to other participants according to that feature's sharing controls. Reports are handled for moderation rather than published as posts.

Your controls

  • Edit or delete your own comments from Your activity.
  • Remove saved stories and change reactions at any time.
  • Delete individual Moow AI conversations from AI history.
  • Turn off Moow AI to stop future AI processing while keeping access to your existing history and its deletion controls.
  • Use Cookie settings in the website footer to allow or reject optional Google Analytics. This browser choice is separate from the mobile Product analytics control and your Moow account.
  • Turn off Product analytics on this device to stop future Mixpanel collection from that installation and clear events waiting to send. Repeat this on each device you use; deleting the account also covers previously received analytics linked to it.
  • Discard an unused AI meal photo before logging it. Photos retained with a meal remain private and are removed with account deletion.
  • Disconnect a health provider to stop Moow sync and delete the steps, sleep records, derived summaries, and active connection metadata imported through that provider. The non-content replay fence described above remains until account deletion.
  • Manage newsletter preferences while signed in with your confirmed account email. New signups may be paused; opt-out remains available.
  • Delete your shared Moow account from the website account overview or the mobile app’s Settings. This affects both the website and mobile app. Your login and profile, meals, workouts, movement, imported health and progress records, private images, Moow AI consent, chats and estimates, saves, reactions, memberships, sessions, matching newsletter record, and pseudonymous Mixpanel profile and event history linked to the account are removed. Mixpanel processing may take up to 30 days. Your Daily comment text is also removed from active services, including comments previously hidden or deleted from view. Recovery copies follow the retention explained below. Account deletion does not cancel App Store or Google Play subscriptions.

To request a copy of your data, contact support before confirming deletion and wait until you receive the information you want to keep. Data-copy requests are currently support-assisted; the website does not provide an automatic downloadable export. An accepted deletion request can continue processing in the background; “Deletion started” does not mean every cleanup step has finished. The account deletion guide explains the scope, results, export help, and store subscription controls.

To keep a stale sign-in token or in-flight request from recreating a deleted account, Moow retains a one-way deletion marker containing no original account ID or account content. If a provider is temporarily unavailable while deletion is active, the server keeps an authenticated-encrypted continuation containing the account and matching-email linkage only until the remaining account, newsletter, storage, and login deletion steps finish, then removes it. An authenticated-encrypted inventory of exact private object paths may also be kept temporarily to re-delete files after an upload URL issued before deletion expires; in a healthy deployment this re-sweep normally completes within four hours, after which that inventory is cleared.

Retention and recovery copies

Account information and content generally remain in active services while your account exists, unless you remove an item or a shorter feature-specific period described above applies. Support, security, and policy-acceptance records are retained as needed to resolve the matter, protect the service, establish applicable obligations, or meet a legal retention requirement. Retention depends on the record and purpose; there is no single period for every category.

Deletion from active services does not instantly erase recovery copies. Routine database backups currently use a seven-day window. Encrypted Storage backups target 30 days, retain at least two snapshots, and defer pruning if backup verification fails. Separately held launch and recovery copies have a 30-day retention period from capture. Longer retention requires a documented recovery incident or legal preservation need, reviewed at least weekly, and ends when that need no longer applies. These recovery copies are not used for ordinary account access. Contact us for questions about how a deletion request applies to a particular record or recovery copy.

Service providers and processing locations

  • Supabase provides authentication, databases, and file storage.
  • Railway hosts Moow services and the encrypted asset-backup repository.
  • Resend delivers account emails, including confirmation and password reset.
  • Sentry supports operational error monitoring.
  • OpenAI processes the AI generation and voice transcription you request.
  • Google provides our support mailbox and the website's font delivery, and processes optional website analytics when you allow it.
  • Mixpanel is used only if optional mobile analytics is enabled as described above; production collection remains disabled.

Our production Supabase project is hosted in the United States. Moow and its service providers may process information in the United States and other countries where they operate; privacy protections can differ from those in your location. Contact us for information about arrangements applicable to your data. We may also disclose information when required by law or reasonably necessary to address fraud, security, or threats to people, subject to applicable law.

The website sends limited failure reports containing a failure type and broad page category to Moow's API. The report payload excludes account identifiers, sign-in tokens, full page URLs, and page content. Hosting and delivery providers still receive ordinary connection information, such as IP addresses. See the browser-storage notice for the website inventory, optional analytics, and font requests.

Privacy requests and your rights

Email hello@moow.ai to ask for access to, a copy of, correction of, or deletion of your information. Depending on the law that applies to you, you may also have rights to restrict or object to processing, withdraw consent, use an authorized agent, or appeal a decision. Withdrawing consent does not change processing already lawfully completed.

We may need to verify your request through your account or ask for limited information necessary to establish your identity or an agent's authority. Do not email passwords, sign-in tokens, or medical records. We will explain any applicable limit or refusal and respond within the period required by applicable law. To request a review of our response, reply with “Privacy appeal.” You can also raise a concern with the privacy regulator or attorney general responsible for your location. We do not penalize you for exercising applicable privacy rights.