PRIVACY POLICY
Moat8
Last updated: August 6, 2026
Applies to: the full Moat8 Data Vault product and all sources a Customer may connect. The Moat8 application submitted for Google verification is governed by a separate, narrower privacy policy.
This Privacy Policy ("Policy") describes how Moat8 LLC, a Wyoming limited liability company doing business as "Moat8" ("Moat8," "we," "us," or "our"), collects, uses, discloses, and safeguards information in connection with the Moat8 Data Vault product, the website located at moat8.space (the "Site"), the Moat8 web application (moat8.space/app), the Moat8 desktop application, the moat8 command-line tool, the Moat8 HTTP API, and any related applications and services that reference this Policy (collectively, the "Service").
Moat8 is a data vault for AI agents. The Service connects to a customer's existing work tools — including Gmail, Google Drive, Google Docs, Google Calendar, Notion, Atlassian Jira, meeting-recording and transcription tools, messaging tools, business-intelligence tools, and customer-designated databases — reads them read-only, and converts their content into clean, structured Markdown and CSV files, so that the customer's own AI agents have accurate, up-to-date business context.
The prepared output files are written to and stored on the customer's own computer or the customer's own server infrastructure. Moat8's servers hold encrypted credentials for the customer's connected accounts, account and operational metadata, an index of the files prepared for the customer's vault, and prepared file content held briefly in a delivery buffer, each as described in Sections 2 and 3.
Please read this Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not access or use the Service.
1. Scope of This Policy; Roles of the Parties
1.1 Three categories of individuals interact with, or are affected by, the Service, and this Policy addresses all three:
- "Customer" or "Controller" — the business or organization that signs up for the Service, connects its own work accounts, and uses the Service to generate context files for its AI agents.
- "Authorized Users" — individuals authorized by a Customer to access or administer the Service on the Customer's behalf (for example, employees, contractors, or administrators of the Customer).
- "Data Subjects" — individuals whose personal data may be contained within the Customer's own emails, files, pages, tickets, meeting transcripts, messages, or databases that the Customer chooses to connect to the Service (for example, the Customer's own employees, clients, or counterparties).
1.2 With respect to the underlying business content that a Customer connects to the Service (emails, files, pages, tickets, meeting transcripts, messages, and databases), the Customer is the data controller or "business" under applicable data protection laws (including the GDPR and the CCPA/CPRA), and Moat8 acts solely as a data processor or "service provider" on the Customer's behalf. Moat8 processes such content only on the Customer's documented instructions, does not use it for Moat8's own independent purposes, does not sell or share it for cross-context behavioral advertising, and implements appropriate technical and organizational measures to protect it, as further described in this Policy.
1.3 With respect to the limited categories of personal data that Moat8 itself collects directly — namely Account Data, Connector Credentials, Technical Data, and Communications Data (each as defined in Section 3) — Moat8 acts as an independent data controller for the purposes described in this Policy.
1.4 This Policy is directed at Customers and Authorized Users of the Service and at visitors to the Site. If you are a Data Subject whose information has been processed by a Customer using the Service and you have questions about that processing, please contact the relevant Customer directly: Moat8 does not control which accounts a Customer connects or what content those accounts contain.
2. How the Service Processes Data; Local-First Architecture
2.1 What happens when a source is connected. When a Customer connects a source (such as Gmail, Google Drive, Google Docs, Google Calendar, Notion, Jira, a meeting-recording tool, a messaging tool, or a database):
- The Service uses the applicable Connector Credential to retrieve content from that source, read-only, under the Customer's own authorization.
- The Service transforms that content into Markdown and/or CSV files on Moat8's servers.
- Those files are delivered to, and stored on, the Customer's own computer, virtual machine, or server infrastructure ("Customer Infrastructure"). The Service performs no write operation against any connected source.
2.2 What Moat8 stores on its own servers. Moat8's servers store:
- (a) Connector Credentials — encrypted at rest (see Section 7), used solely to authenticate to the Customer's connected accounts on the Customer's behalf;
- (b) Account Data and billing records necessary to administer the Customer's subscription;
- (c) A vault file index — a record of each file prepared for the Customer's vault, including its path, title, source URL, content hash, size, and timestamps. This index does not contain file bodies. Paths and titles are derived from source content (for example, email subject lines or document names) and therefore typically contain personal data;
- (d) Prepared file content in a short-lived delivery buffer, held in object storage until the Customer's devices have retrieved it and then purged as described in Section 2.3;
- (e) Message records from chat and messaging sources, where the Customer connects such a source and the source's API requires Moat8 to maintain a message record in order to perform incremental synchronization. These records include message text, sender name and identifier, chat title, and timestamps;
- (f) Connection metadata, audit records, and technical logs necessary to operate, secure, monitor, and troubleshoot the Service.
Moat8's servers do not durably store the bodies of the Customer's emails, documents, tickets, or meeting transcripts. Those are held only in the delivery buffer described in Section 2.3 and are then purged.
2.3 The delivery buffer. In order to deliver prepared files to a Customer's devices, the Service holds prepared file content in object storage operated within Moat8's own hosting infrastructure, on storage encrypted at rest by the hosting platform. An automated sweep runs hourly and purges content that is older than the retention window configured for the Service, which is twenty-four (24) hours by default. Purging is deferred while a vault is actively synchronizing, so that a device performing a first full synchronization is not served an error for a file that existed when it started; content in that state is purged by the first sweep after the vault becomes idle. Content in the delivery buffer is used for no purpose other than delivering the files the Customer requested.
2.4 No advertising, no sale, no model training. Moat8 does not use content that passes through the Service for advertising, does not sell it, does not share it with third parties for their own independent purposes, and does not use it to develop, improve, or train generalized or shared machine-learning or artificial-intelligence models, whether our own or a third party's. See Section 5 for the specific commitments that apply to data received from Google APIs.
2.5 Customer responsibility for connected accounts. The Customer is solely responsible for ensuring that it has all necessary rights, consents, and legal bases (including under applicable data protection and employment laws) to connect its accounts to the Service and to permit the Service to process the content of those accounts on the Customer's behalf.
3. Information We Collect
3.1 Account Data. Name, work email address, workspace or company name, job title, phone number (if provided), password (stored only as a salted hash), and billing information. Payment card details are collected and processed by our payment provider acting as merchant of record; Moat8 does not receive or store payment card numbers.
3.2 Connector Credentials. When a Customer connects a source via OAuth or an equivalent authorization protocol, we collect and store, in encrypted form, the resulting access token, refresh token, API key, bot token, or database connection credential necessary to connect to that source on the Customer's behalf. Credentials are requested with the minimum permissions the relevant platform offers for the functions the Service performs, and are read-only wherever the platform supports read-only scopes.
3.3 Vault File Index. For each file prepared for a Customer's vault we retain the record described in Section 2.2(c). Paths and titles are derived from source content and therefore typically contain personal data.
3.4 Message Records from Chat and Messaging Sources. Where a Customer connects a chat or messaging source, we retain the message records described in Section 2.2(e) for as long as that connection exists, because those sources deliver messages as events and do not permit re-reading history on demand. For message records from chat and messaging sources, Moat8 acts solely as a data processor or service provider, processing message content under the Customer's instructions for the purpose of incremental synchronization. Message records are retained only for as long as the relevant connection exists and are deleted when the Customer disconnects that source.
3.5 Connection and Job Metadata. The type of source connected, the date and time of connection, the status and timing of each extraction or transformation job, file counts, and file sizes.
3.6 Device and Agent Tokens. Tokens issued by the Service to a Customer's own devices and AI agents are stored only as a SHA-256 hash; the token value itself is shown once at issuance and is never recoverable from our systems.
3.7 Technical Data. IP address, browser type and version, device identifiers, operating system, referring URLs, pages viewed, and timestamps, collected through server logs, cookies, and similar technologies described in Section 10.
3.8 Communications Data. If you contact us, the content of your communication together with your contact details and any information you choose to provide.
3.9 Special categories. Moat8 does not seek, and the Service is not designed to process, special categories of personal data under the GDPR or sensitive personal information under the CCPA/CPRA. Where such data is present in a Customer's connected sources, it is processed as described in Section 2 and is stored on Customer Infrastructure, save for the limited server-side records enumerated in Section 2.2.
4. How We Use Information
We use the information described in Section 3 to:
- create, administer, and authenticate Customer and Authorized User accounts;
- establish, maintain, and refresh authenticated connections to a Customer's connected sources;
- perform the core function of the Service — retrieving content from connected sources and transforming and delivering it as Markdown/CSV files to Customer Infrastructure;
- process payments, issue invoices, and manage subscriptions;
- provide customer support and respond to inquiries;
- monitor, secure, debug, and improve the performance, reliability, and security of the Service, including detecting and preventing fraud, abuse, and unauthorized access;
- send billing and payment notices, which are issued by our payment provider acting as merchant of record, and correspond with you about the Service in response to your enquiries;
- comply with applicable law, legal process, and enforceable governmental requests, and to establish, exercise, or defend legal claims.
We do not use Connector Credentials, the vault file index, message records, or connection metadata for any purpose other than operating, securing, and supporting the Service on the applicable Customer's behalf.
5. Google User Data — Limited Use Disclosure
Moat8's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
5.1 Scopes we request. The Service requests only the following Google scopes, each for an implemented, user-facing feature:
| Scope | Feature it supports |
|---|---|
https://www.googleapis.com/auth/drive.readonly | Browsing the user's Drive to select folders; incremental synchronization of the selected folders; exporting Drive and Google Docs content into the user's vault files |
https://www.googleapis.com/auth/gmail.readonly | Writing the user's own mail threads into their vault as Markdown files |
https://www.googleapis.com/auth/calendar.readonly | Writing the user's own calendars and events into their vault as Markdown files |
openid, email, profile | Signing the user in to Moat8 and identifying their account |
We do not request write, modify, or delete scopes for any Google API, and no code path in the Service writes to a Google service.
5.2 Use limitation. Google user data is used only to provide and improve the user-facing features the user connected it for — preparing the vault files that the user and the user's own AI agents read. It is not used for any other purpose.
5.3 No advertising. We do not use Google user data for advertising.
5.4 No model training. We do not use Google user data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.
5.5 No transfer. We do not transfer Google user data to third parties, except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
5.6 No human access. We do not allow humans to read Google user data, except: (a) with the affected user's affirmative agreement for specific messages or files; (b) where necessary for security purposes, such as investigating abuse or a security incident; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized and is used for internal operations.
5.7 Retention and deletion of Google user data. Google user data retrieved by the Service is written to the user's own infrastructure and is held on Moat8's servers only in the delivery buffer and file index described in Sections 2.2 and 2.3. A user may disconnect any Google source at any time from within the Service, may revoke Moat8's access at myaccount.google.com/permissions, and may request deletion of the data Moat8 holds as described in Section 12.
5.8 Security assessment. Because the Service requests restricted Google API scopes, it is subject to Google's Cloud Application Security Assessment (CASA) regime, which Moat8 maintains as a condition of continued access to those scopes.
6. Legal Bases for Processing
6.1 EEA / UK / Switzerland. Our legal bases under the GDPR and equivalent UK and Swiss legislation are:
- Performance of a contract (Art. 6(1)(b) GDPR) — to create and administer accounts, process payments, and provide the Service pursuant to our terms of service with the Customer.
- Legitimate interests (Art. 6(1)(f) GDPR) — to secure and improve the Service, prevent fraud, and communicate with Customers and Authorized Users about the Service, where those interests are not overridden by your data protection interests or fundamental rights and freedoms.
- Consent (Art. 6(1)(a) GDPR) — where we rely on consent, for example for certain marketing communications or non-essential cookies, which you may withdraw at any time.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR).
Where Moat8 processes Customer content as a processor on behalf of a Customer (Section 1.2), the Customer, as controller, is responsible for establishing an appropriate legal basis for that processing under Articles 6 and, if applicable, 9 of the GDPR.
6.2 United States. Moat8 processes personal data in the United States consistent with applicable federal and state privacy laws, including the CCPA/CPRA and comprehensive state privacy laws such as the Virginia CDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA, to the extent applicable, on the following bases: necessity for performance of a contract with the Customer; our legitimate business interests in operating, securing, and improving the Service, balanced against your privacy interests; compliance with applicable law, legal process, or an enforceable governmental request; and consent where required by applicable state law. U.S. state privacy laws generally do not require an enumerated "legal basis" in the same manner as the GDPR; instead they grant specific consumer rights (Section 14) and impose purpose- and use-limitation obligations, which Moat8 observes by processing personal data only for the purposes described in Section 4.
6.3 Canada. If you are located in Canada, our processing is governed by PIPEDA and, where applicable, substantially similar provincial legislation. We collect, use, and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances, relying on consent (express or implied, depending on sensitivity), necessity for the performance of a contract, or legal authorization, as applicable. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting us using the details in Section 17; we will explain any resulting implications before giving effect to your request.
7. Data Security
We implement technical and organizational measures designed to protect information from unauthorized access, disclosure, alteration, and destruction, including:
- Encryption at rest. Connector Credentials and agent tokens are encrypted with AES-256-GCM using a random initialization vector per encryption and a verified authentication tag.
- Encryption in transit. All traffic to the Service is served over TLS 1.2 or higher.
- Read-only by design. The Service requests read-only scopes wherever the source platform offers them, and contains no code path that writes to a connected source.
- Credential handling. Device and agent tokens are stored only as SHA-256 hashes and are never recoverable after issuance; account passwords are hashed with scrypt using a random salt and compared in constant time; the Service refuses to start in production with default or weak secrets; secrets are not committed to our source repositories.
- Tenant isolation. Every stored object is scoped to a workspace and a vault, and every device or agent token is bound to a single vault and to the specific connections it was granted.
- Access control and audit. Access to production systems holding Connector Credentials is restricted to personnel who require it to operate the Service. Authentication failures, credential access, and connector revocations are written to an audit log.
- Web application hardening. A Content Security Policy, an origin allowlist for cross-origin requests, and session cookies marked
HttpOnly,Secure, andSameSite. - Security assessment. The Service is subject to the CASA assessment regime described in Section 5.8, which is based on the OWASP Application Security Verification Standard.
No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. Because the prepared output files reside on Customer Infrastructure, Customers are responsible for securing their own systems, including the storage of the files the Service delivers to them.
If we become aware of a security incident affecting Account Data, Connector Credentials, or other data we control, we will notify affected Customers and, where required, the relevant supervisory authorities and Data Subjects, without undue delay and in accordance with applicable law, including Articles 33 and 34 of the GDPR where applicable.
8. How We Share Information
We do not sell personal data, and we do not share Connector Credentials or the content accessible through them with third parties for their own independent marketing or advertising purposes. We share information only as follows:
- Sub-processors and service providers, each engaged under contractual confidentiality and data protection obligations consistent with this Policy:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Application hosting, database, and object storage for the delivery buffer | United States (us-central1) |
| Paddle | Payment processing, merchant of record | United Kingdom / United States |
An up-to-date list is maintained at https://moat8.space/subprocessors and is also available on request to legal@moat8.ai.
- Third-party sources you connect — by design, the Service exchanges data with the platforms a Customer chooses to connect, strictly as necessary to perform the functions the Customer has authorized.
- Corporate transactions — in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to customary confidentiality protections and continued application of this Policy or a substantially similar policy.
- Legal requirements — where required to comply with applicable law, regulation, legal process, or an enforceable governmental request, or to protect the rights, property, or safety of Moat8, our Customers, or others.
- With your direction or consent — in any other circumstance where you have directed or consented to the disclosure.
9. Third-Party Sources and Services
The Service interoperates with third-party platforms selected by the Customer, which may include Google (Gmail, Drive, Docs, Calendar), Notion, Atlassian (Jira), meeting-recording and transcription tools, messaging tools, business-intelligence tools, and Customer-designated databases ("Connected Sources"). Each Connected Source is governed by its own privacy policy and terms, and Moat8 is not responsible for their privacy or security practices. We encourage Customers to review the privacy policy of any Connected Source before authorizing a connection.
10. Cookies and Similar Technologies
The Site and web application use cookies and similar technologies to operate core functionality, authenticate sessions, and remember preferences, and, where applicable, to measure aggregate usage. You can control cookies through your browser settings; disabling certain cookies may affect the availability or functionality of parts of the Service. Where required by applicable law, we obtain your consent before placing non-essential cookies and provide a mechanism to manage your preferences. We do not use analytics or advertising cookies.
11. International Data Transfers
Moat8 and its sub-processors process Account Data, Connector Credentials, the vault file index, delivery-buffer content, and Technical Data in the United States. Where we transfer personal data originating from the EEA, the United Kingdom, Switzerland, or Canada to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, or another valid transfer mechanism recognized under applicable law.
12. Data Retention and Deletion
We retain the categories of information described in Section 3 only for as long as reasonably necessary:
| Category | Retention |
|---|---|
| Prepared file content in the delivery buffer | Purged by an automated hourly sweep once older than the configured retention window (24 hours by default); where purging is deferred during an active synchronization, on the first sweep after the vault becomes idle |
| Connector Credentials | Deleted, and revoked at the source platform where the platform supports revocation, when the Customer disconnects the source or closes the account, and in any event within thirty (30) days of disconnection |
| Vault file index | Retained while the corresponding connection exists; deleted when the Customer disconnects the source or deletes their vault data, and in any event within thirty (30) days |
| Message records from chat and messaging sources | Deleted when the Customer disconnects the source or deletes their vault data, and in any event within thirty (30) days |
| Account Data and billing records | Retained for the duration of the Customer's subscription and for seven (7) years thereafter to comply with tax, accounting, and applicable limitation-period obligations, consistent with U.S. accounting, billing, and tax record-keeping practice, after which they are deleted or anonymized, unless a longer period is required by law or to resolve a pending dispute |
| Technical Data, service logs, and audit records | Retained for a limited period, typically ninety (90) days, for security, debugging, and operational purposes, unless a longer period is reasonably necessary to investigate a specific security incident or suspected fraud, or is required by law |
| Records of consumer / data-subject requests and our responses | Retained for at least twenty-four (24) months, as required under the CCPA regulations (11 CCR § 7101), solely for compliance record-keeping |
How to delete your data. A Customer or Authorized User may disconnect any source at any time from within the Service, may delete all vault data held on Moat8's servers from the Service's settings, and may request deletion of the remaining data Moat8 holds by writing to legal@moat8.ai. Files already delivered to Customer Infrastructure remain on the Customer's own systems and are outside Moat8's control.
We may retain information for longer where required by applicable law, to resolve disputes, or to enforce our agreements.
13. Your Data Protection Rights
If you are located in the EEA, the United Kingdom, or Switzerland and are the data subject of personal data controlled by Moat8 (Section 1.3), you have the right, subject to applicable law and certain exceptions, to: access the personal data we hold about you and obtain a copy; request rectification of inaccurate or incomplete data; request erasure; request restriction of processing; object to processing based on legitimate interests or for direct marketing; request portability in a structured, commonly used, machine-readable format; withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and lodge a complaint with your local supervisory authority.
To exercise these rights with respect to personal data controlled by Moat8, contact us using the details in Section 17. If your request relates to content held within a Customer's Connected Sources or on Customer Infrastructure, we may direct you to the relevant Customer, who acts as controller of that content.
14. Additional Disclosures for California Residents (CCPA/CPRA)
If you are a California resident, the CCPA as amended by the CPRA grants you the right to: know what personal information we collect, use, disclose, and sell; request deletion; request correction of inaccurate personal information; opt out of the sale or sharing of personal information; limit the use of sensitive personal information; and not be discriminated against for exercising these rights.
Moat8 does not sell personal information as that term is defined under the CCPA/CPRA, and does not share personal information for cross-context behavioral advertising. In the twelve (12) months preceding the effective date of this Policy, the categories of personal information we collected are those described in Section 3, collected from the sources described in this Policy, for the business purposes described in Section 4, and disclosed to the categories of third parties described in Section 8.
California residents may exercise their rights by contacting us using the details in Section 17. We will verify your request using information associated with your account before responding, and you may designate an authorized agent to make a request on your behalf in accordance with applicable law.
15. Children's Privacy
The Service is intended for use by businesses and their Authorized Users and is not directed at individuals under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take reasonable steps to delete it.
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, the Service, or applicable law. If we make material changes, we will notify Customers by email or through a notice on the Site before the change takes effect, and we will update the "Last updated" date at the top of this Policy. Your continued use of the Service after the effective date of an update constitutes acceptance of the updated Policy.
17. Contact Us
If you have questions, concerns, or requests regarding this Policy or our data practices, or if you wish to exercise any of the rights described above, please contact:
Moat8 LLC Attn: Privacy / Data Protection 30 N. Gould St, Ste R, Sheridan, WY 82801, USA legal@moat8.ai
Moat8 has not appointed, and does not currently intend to appoint, a representative in the European Economic Area or the United Kingdom under Article 27 GDPR / UK GDPR, and has not appointed a Data Protection Officer under Article 37 GDPR / UK GDPR, as Moat8 does not meet the applicable thresholds for such appointments. If our processing activities change such that an appointment becomes required by law, we will update this Policy accordingly and provide the relevant contact details here.