Privacy Policy
Last updated: 12 July 2026
1. Who We Are
Moogoose is an Android communication accessibility keyboard for adults aged 18 and over. It helps people understand or summarise visible on-screen content and draft context-aware text using screen context, voice instructions, and an optional personal profile. You review every draft and decide whether to use or send it; Moogoose never sends messages automatically.
Moogoose Limited is the data controller for personal data processed through the app where UK data protection law applies.
Moogoose Limited
Registered in England and Wales · Company number 17333615
Registered office: 75 Charlton Close, Bournemouth, BH9 3PS, United Kingdom
Email: hello@moogoose.com
2. Scope of This Policy
This policy explains how Moogoose processes information about you and, where it appears in content available to the app, information about other people. That content may include names, contact details, messages, emails, profiles, visible conversations, documents, social posts or comments, web pages, and information from websites you supply.
User-supplied and on-screen content may incidentally contain sensitive information, including information about health, disability, beliefs, sexuality, ethnicity, or other special-category data. Moogoose does not use this information for advertising, does not intentionally infer diagnoses, and does not create advertising profiles.
3. Information We Process and Where It Comes From
- Visible screen content: text read from the current app through Android's Accessibility API, including conversations, messages, emails, documents, social posts or comments, web pages, and names or contact identifiers shown with that text.
- Voice instructions: audio you record when asking Moogoose to dictate, explain, summarise, or draft.
- Personal profile: optional facts, preferences, tone, and other information you enter or create through Quick Profile Setup.
- Quick Profile Setup: your guided conversation, profile facts, supplied website addresses, discovered website URLs, selected website content, and temporary grounding material.
- AI content: instructions, relevant context, prompts, transcriptions, Gemini responses, summaries, explanations, and draft replies.
- App information: language, feature settings, blocked-conversation choices, and other local preferences.
- Diagnostic information: bounded Session Journal and Merge Trace entries, errors, feature events, and—only when you enable detailed diagnostic logging—raw accessibility trees and complete AI, transcription, extraction, website, search, and editable-field diagnostic content.
These data come from you, visible content in supported apps, your device and saved profile, websites you supply, Google Search results used during Quick Profile Setup, and responses returned by Google Gemini.
4. How and Why We Use Information
We process information to:
- provide the accessibility and communication features you request;
- maintain local conversation continuity and personalise drafts using your profile;
- operate text-to-speech using Android's on-device speech engine;
- protect the app and handle security or misuse;
- diagnose reliability problems using bounded local records; and
- create a support export only when you direct the app to do so.
Moogoose has no user accounts and currently has no developer-operated server that receives your conversation content or AI requests.
5. Accessibility and AI Processing
When Context Reader is enabled, Moogoose's AccessibilityService can read visible text in the current app so it can understand or summarise on-screen content and draft context-aware text. This may include conversations, messages, emails, documents, social posts or comments, and web pages.
Recognised conversation context may be accumulated into per-conversation buffers in Android app-internal storage. It is protected by your device's security and expires after six months of inactivity. Other app screens use only the latest readable capture held in memory and are not written to conversation-history storage. If optional detailed diagnostic logging is enabled, its separate disclosures and retention controls apply to any raw screen structures it records.
The keyboard eye control shows whether screen context is currently available. You can pause reading for a recognised conversation or for an app. Pausing a conversation deletes its stored context; pausing an app clears its current generic screen context and prevents further accessibility-tree traversal in that app until you resume it. You can also clear all stored conversation history in Settings or disable Context Reader through Android Accessibility settings.
When you tap Moogoose, relevant screen context, your instruction, optional profile information, and voice audio where applicable are sent over HTTPS to Google Gemini. Screen content is not sent merely because Context Reader is enabled. The response is returned to your device for your review.
Voice audio is recorded to a temporary local file. The file is deleted after successful or failed AI processing. Too-short, cancelled, and failed-start recordings are also deleted locally.
Text-to-speech uses Android's on-device speech engine. No content is sent to Moogoose or Google for that step.
6. Quick Profile Setup and Websites
Quick Profile Setup sends the guided conversation and relevant profile material to Gemini. If you provide a website address, Gemini may use Grounding with Google Search to discover useful pages on the same domain and URL Context to read selected URLs. Supplied addresses, discovered URLs, website content, search context, and temporary grounding material may therefore be processed by Google.
Temporary onboarding material is stored locally so setup can resume. It is removed after successful profile creation, when you use Clear All Data, or when you uninstall the app. The resulting personal profile is stored locally and included in relevant Gemini requests until you clear it.
7. Google Gemini
Google provides Gemini as Moogoose's AI service provider. The production project must use Paid Services treatment for UK users. Under Google's current Paid Services terms, Google does not use prompts or responses to improve its products, but may retain limited prompts and responses for abuse monitoring and legal or regulatory purposes.
Grounding with Google Search stores prompts, contextual information, and generated output for 30 days to create grounded results and for debugging and testing. Google AI Studio Logs & Datasets project logging is disabled for Moogoose's production project, so complete Generate Content prompts and responses are not retained through that optional project-logging feature.
Google processing or transient caching may occur in countries where Google or its agents operate. Google describes its data-protection and transfer commitments in its applicable processing terms.
- Gemini API Additional Terms
- Gemini API data-retention information
- Gemini Logs & Datasets documentation
- Google Data Processing Addendum
- Google Privacy Policy
8. Lawful Bases
Depending on the feature and circumstances, we rely on:
- Contract: where processing is necessary to provide an AI communication feature that you expressly request.
- Legitimate interests: proportionate security, reliability, and bounded basic diagnostics needed to keep the app safe and functioning, balanced against the privacy impact because records are local, limited, and user-deletable.
- Consent: optional detailed diagnostic logging. You can withdraw consent by turning it off. Turning it off stops new detailed records; use Clear Logs or Clear All Data to delete existing records.
- Legal obligation: where information must be retained or disclosed to comply with law.
Where content includes special-category data, additional protections and a valid condition under applicable law are required. Moogoose processes such content only as incidental content within features initiated by the user, not to target advertising or infer a diagnosis.
9. Local Diagnostics and Support Export
A bounded Session Journal and Merge Trace are retained locally for troubleshooting. Merge Trace keeps the newest 500 entries and limits each entry to 2,000 characters; entries may include short message snippets.
Detailed diagnostic logging is off by default. You must enable it under Tester Tools after a warning. While enabled, it can retain raw accessibility trees and complete AI, transcription, extraction, website, search, and editable-field diagnostic content. Raw captures use a rolling 10 MB limit and remove the oldest files first.
Turning detailed logging off stops new detailed records but does not delete existing evidence. Clear Logs removes the Session Journal, Merge Trace, raw captures, and prior export files.
Export creates one complete retained diagnostic text file in private cache. You can review the exact file in bounded pages. Nothing is shared unless you choose Share complete file and select a destination. The recipient and destination you choose then handle that copy under their own terms.
10. Retention and Deletion
| Information | Local retention and deletion |
|---|---|
| Conversation buffers | Expire after six months of inactivity; can be removed sooner using Clear Conversation History or Clear All Data. |
| Voice audio | Temporary; deleted after completed or failed processing, cancellation, a too-short recording, or a failed start. |
| Personal profile | Retained locally until Clear All Data or uninstall. |
| Quick Profile Setup material | Removed after successful profile creation, Clear All Data, or uninstall. |
| Session Journal and Merge Trace | Bounded local records; removed by Clear Logs, Clear All Data, or uninstall. |
| Detailed raw diagnostics | Rolling 10 MB local limit; removed by Clear Logs, Clear All Data, or uninstall. Switching logging off alone does not delete existing files. |
| Diagnostic exports | Stored in private cache until Clear Logs, Clear All Data, uninstall, or Android clears the cache. |
Clear All Data additionally removes profiles, conversations, settings, blocked-conversation data, onboarding data, and temporary local audio. Android Auto Backup is disabled, and temporary audio is stored in Android's no-backup internal storage. Because there are no app accounts or Moogoose-operated content servers, most deletion is performed directly on your device. Google's limited retention and any security or legal retention are governed by Google's terms and cannot be cleared through the app.
11. Other Services We Do Not Use
Moogoose currently uses no analytics, advertising or tracking SDK, crash-reporting service, Firebase remote logging, or automatic diagnostic upload.
12. Your Data Protection Rights
Depending on the circumstances and lawful basis, you may have rights to be informed and to request access, rectification, erasure, restriction, portability, or objection. Where processing relies on consent, you may withdraw it at any time. These rights are not absolute and exemptions may apply.
Most app data can be viewed, corrected, or deleted directly on your device. For help or a rights request, email hello@moogoose.com. We may need enough information to verify and respond to your request.
You can complain to the UK Information Commissioner's Office. See Make a complaint to the ICO.
13. Adults Only
Moogoose is intended only for people aged 18 and over. We do not knowingly provide the app to children.
14. Security
Data sent to Google is encrypted in transit using HTTPS/TLS. Local information is held in Android app-internal storage and protected by your device's security. No method of storage or transmission is completely secure, so you should use device access controls and avoid enabling detailed logging unless needed.
15. Changes to This Policy
We will update the date above when this policy changes. Where required, material changes will be brought to your attention before new processing begins. We will seek consent where applicable rather than treating continued use alone as consent to a new purpose.
16. Contact
Moogoose Limited
Company number: 17333615
Registered office: 75 Charlton Close, Bournemouth, BH9 3PS, United Kingdom
Email: hello@moogoose.com
Website: moogoose.com