Privacy Policy
1. Overview
Moat8 connects to the sources you authorize (such as Gmail, Google Drive/Docs/Calendar, Notion, Jira, tl;dv and databases), reads them read-only, and prepares clean files for you to use with your own AI tools. This policy explains what data we handle and how. It covers both data about you as a user and the content we read from your connected sources on your behalf.
2. Data we process
- Account data — your name, email address, workspace name and authentication data.
- Connector credentials — the OAuth tokens, API keys and database connection details for the sources you connect. Stored encrypted at rest (AES-256-GCM).
- Content from your connected sources — read read-only and normalized into files. Prepared content is held only in a short-lived delivery buffer and auto-purged within 24 hours; we retain only a file index (names, checksums, timestamps), not the file contents.
- Technical data — IP address, user agent, timestamps and service logs.
3. How we use it
We use this data only to provide the Service — to connect the sources you authorize, sync and deliver the prepared files to you, and keep the Service secure and reliable.
- We never write back to your source systems. All connectors are read-only.
- We never use your data to train AI models, ours or anyone else’s.
- We never sell or rent your data, and we do not use it for advertising.
4. Google user data — Limited Use disclosure
Moat8’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We request the minimum read-only scopes needed to prepare your vault (e.g. Gmail, Drive, Docs, Calendar read scopes).
- Google user data is used only to provide and improve the user-facing feature you connected it for — preparing vault files that you and your agents read.
- We do not transfer Google user data to third parties except as necessary to provide the Service, comply with law, or as part of a merger or acquisition.
- We do not use Google user data for advertising.
- We do not use Google user data to develop, improve, or train generalized AI/ML models.
- You can disconnect any Google source at any time in the app, and revoke access at myaccount.google.com/permissions.
5. Sharing
We use a limited set of service providers (such as hosting and error monitoring) solely to run the Service. We do not sell or rent your data. We may disclose data where legally required.
6. Retention & deletion
Prepared file content in the delivery buffer is auto-purged within 24 hours. Connector credentials are deleted when you disconnect a source or close your account. You can disconnect any source or close your account at any time, and you can contact us at legal@moat8.ai to request access to or deletion of your data. Files already synced to your own machines stay on your machines and are outside our control.
7. Security
Connector credentials and agent tokens are encrypted at rest with AES-256-GCM, with TLS in transit. The Service is read-only by design, with per-workspace isolation and scoped, instantly revocable tokens.
8. Changes
We may update this policy from time to time. The “Last updated” date above always reflects the current version.
9. Contact
Moat8 LLC — 30 N. Gould St Ste R, Sheridan, WY 82801, USA
legal@moat8.ai