Menu

Data handling and privacy requests

This notice explains the application’s data categories and retention design. It does not claim a regulatory certification or replace the terms agreed for a production service.

Joining the launch waitlist

We use your email address to confirm your request and send Moolamochi launch updates, only after you choose to confirm. We store a normalized email address, request and confirmation times, consent and unsubscribe status, and hashed, expiring confirmation links. Rate-limit records help protect this public form from abuse.

Confirmation and launch email delivery uses Amazon Web Services Simple Email Service. Opening an email link alone does not change your preferences: confirm or unsubscribe on the linked page. You can unsubscribe at any time using the link in a waitlist email. We retain suppression information to honor that choice. Joining the waitlist does not create a product account or authorize a purchase.

Data used to run the service

Account identity and session records support sign-in and access checks. Workspace contacts, projects, documents, time and messages support client work. Connected providers process the information needed for their authorized role: Stripe for payments, AWS for application storage and transactional mail, and Google or Microsoft for connected mailbox and calendar access. Card credentials go to Stripe, not into the application’s invoice forms.

Visibility and optional connections

Workspace membership does not grant unrestricted access to private mailboxes. Clients receive explicitly published records and scoped grants. Disconnecting a provider revokes future application use of its connection while keeping permitted business history and suppression records. Do not place passwords or payment credentials in support messages.

Retention and deletion

The retention design expires draft previews and abandoned quarantine after 24 hours, and successfully processed raw inbound MIME after 30 days. Backup tiers retain 15-minute snapshots for 48 hours, daily copies for 30 days and monthly copies for 12 months. Issued invoice and signature artifacts do not expire under a generic file rule. These are operational settings, not a claim of a legally sufficient retention period.

An owner can request deletion with a seven-day recovery window. Access and future sends are revoked or held immediately. Unresolved payments, refunds or disputes can block final purge; the request must show the specific blockers. Minimal non-content reconciliation identifiers and deletion tombstones can remain, and backup expiry delays complete removal from historical backups.

Ask about access, export or deletion

Use workspace export and deletion settings when authorized, or contact support for help with your account. Verify the identity and authority of a requester before releasing data. Operator identity, production legal jurisdiction and any additional legally required disclosures must be established before a general production launch; this test-stage notice makes no claim that they are already settled.