Moonveil

Legal

Moonveil Privacy Policy

Version 1.3 · effective 16 September 2026

1. Controller and contact

The controller is TealDev Mateusz Pilarski, ul. Orzechowa 37/17, 21-500 Biała Podlaska, Poland, NIP 5651479302.

For privacy requests and support, email [email protected].

2. Local data

In the Moonveil mobile app, your profile, birth date, numerology results, readings, cards, notes, and custom spreads are stored in the device’s local database by default. Moonveil does not receive them during ordinary local use.

The public Moonveil website does not store user readings, profiles, or journals. The site connects to Moonveil services for content and updates. Infrastructure providers receive ordinary technical metadata such as IP address and request information.

3. Online-feature data

  • Account (mobile and Content Studio): Moonveil ID, identity provider and provider ID, optional verified email, and basic data returned by the provider.
  • Purchases (mobile): product, entitlements, subscription status, billing events, dates, price, and currency.
  • Backup (mobile): a JSON copy of the local profile, spreads, readings, and notes with version and revision — only after separate confirmation.
  • Security: request method/path, status, duration, request ID, and limited error details. We do not intentionally log tokens, signed URLs, or backup payloads.

4. Backup and special-category data

Backup in the mobile app is disabled by default. Every upload requires separate confirmation because profile or journal content may reveal beliefs. Consent for future processing can be withdrawn by deleting the backup.

HTTPS/TLS and authenticated access protect transmission, but the app does not end-to-end encrypt the backup.

5. Purposes, legal bases, and recipients

Feature-specific data may be processed by identity providers, RevenueCat and billing, hosting/VPS/database, Cloudflare R2/CDN, build providers, and email/support. User backup stays in the private database and is not published to public content storage.

Transfers outside the EEA use adequacy decisions, the EU–US Data Privacy Framework, Standard Contractual Clauses, or another GDPR-permitted mechanism as applicable.

  • Contract: account, sign-in, paid mobile access, restore, and requested backup.
  • Explicit consent: special-category content in optional backup.
  • Legitimate interests: security, abuse prevention, diagnostics, and claims.
  • Legal obligation: records required by law.

6. Retention, rights, and deletion

You may request access, correction, erasure, restriction, portability, object, or withdraw consent, and may complain to UODO. Deleting the account does not cancel a subscription; cancel it separately with the billing provider.

  • Local data in the mobile app remains until removed or app / device data is cleared.
  • Account and entitlement data remains while the account exists, subject to legal exceptions.
  • Backup remains until backup or account deletion; restricted recovery copies rotate.
  • The operational log-retention target is 30 days unless needed for an incident or claim.

Contact: [email protected]