Privacy Policy

Last updated: 9 September 2026

1. Who We Are

Moogoose is an Android communication accessibility keyboard for adults aged 18 and over. It helps people understand or summarise visible on-screen content and draft context-aware text using screen context, voice instructions, and an optional personal profile. You review every draft and decide whether to use or send it; Moogoose never sends messages automatically.

Moogoose Limited is the data controller for personal data processed through the app where UK data protection law applies.

Moogoose Limited
Registered in England and Wales · Company number 17333615
Registered office: 75 Charlton Close, Bournemouth, BH9 3PS, United Kingdom
Email: hello@moogoose.com

2. Scope of This Policy

This policy explains how Moogoose processes information about you and, where it appears in content available to the app, information about other people. That content may include names, contact details, messages, emails, profiles, visible conversations, documents, social posts or comments, web pages, and information from websites you supply.

User-supplied and on-screen content may incidentally contain sensitive information, including information about health, disability, beliefs, sexuality, ethnicity, or other special-category data. Moogoose does not use this information for advertising, does not intentionally infer diagnoses, and does not create advertising profiles.

3. Information We Process and Where It Comes From

  • Visible screen content: text read from the current app through Android's Accessibility API, including conversations, messages, emails, documents, social posts or comments, web pages, and names or contact identifiers shown with that text.
  • Voice instructions: audio you record when asking Moogoose to dictate, explain, summarise, or draft.
  • Writing profile: optional facts, preferences, tone, and other information you enter or create through Quick Profile Setup or Manual Profile Setup. The current launch design uses one local Writing Profile across the apps where you use Moogoose.
  • Quick Profile Setup: your guided conversation, profile facts, and any business or employer identity clues you provide, such as a name, business type or main service, town or service area, and optional website. During public-business research, Moogoose may also process and locally retain up to three public candidate matches, the candidate you confirm, bounded public findings and conflict summaries, source titles and URLs, proposed profile updates, and your review choices.
  • AI content: instructions, relevant context, prompts, transcriptions, Gemini responses, summaries, explanations, and draft replies.
  • Account and app-verification information: when you choose Google sign-in, Firebase Authentication receives your Google account identifier and provider information such as your email address, name, and profile details, and creates a unique Firebase user ID. Firebase and Google also process security information such as IP address, user agent, and Play Integrity attestation material. Moogoose's protected backend stores a minimal server-only account record linked to the verified Firebase user ID.
  • Credit and purchase information: your available balance; separate welcome, promotional and purchased credit lots; reservations and ledger events; the localised Google Play product and price; purchase state; a purchase token; verified package, product, quantity and account-binding results; refund, chargeback and void state; protected recovery state; provider token use and cost; pricing and settlement records; the resulting debit; and content-free duplicate-prevention, settlement, accounting, fraud and support evidence. Moogoose does not receive or store your payment-card or bank details.
  • App information: language, feature settings, blocked-conversation choices, and other local preferences.
  • AI reports: when you choose to report a displayed AI response, the reviewed response, selected reason, optional note, displayed app/prompt/output/time metadata, random report ID, server support reference, duplicate-protection fingerprint, timestamps, and review status.
  • Diagnostic information: an always-on, bounded, content-free operational timeline; a user-prepared device, build, setup, and accepted-backend snapshot; bounded Session Journal and Merge Trace evidence; errors and feature events; and—only when you enable detailed diagnostic logging—bounded accessibility-node snapshots, complete AI request/provider/parser evidence, conversation/page context, user instructions, prompts, AI responses, transcription, extraction, website, search, editable-field content, user-reviewed AI report content and notes, and bounded Moogoose-code crash locations. Password and Android-marked accessibility-sensitive subtrees in accessibility snapshots are replaced by fixed content-free redaction markers.

These data come from you, visible content in supported apps, your device and saved profile, the Google Account you choose for sign-in, Google Play purchase and refund services, public business information returned by Perplexity during identity resolution and enrichment, and responses returned by Google Gemini.

4. How and Why We Use Information

We process information to:

  • provide the accessibility and communication features you request;
  • maintain local conversation continuity and personalise drafts using your profile;
  • authenticate access to cloud-powered features and protect the service from misuse;
  • provide welcome, promotional and purchased credits, verify and fulfil Google Play purchases, settle completed eligible actions once, and show the balance and recent activity;
  • process purchase recovery, refunds, chargebacks and voids, prevent duplicate grants and fraud, support users, and meet accounting and legal duties;
  • operate text-to-speech using Android's on-device speech engine;
  • protect the app and handle security or misuse;
  • diagnose reliability problems using bounded local records;
  • receive and review user-submitted AI reports for safety, quality, moderation, and policy escalation; and
  • create a support export only when you direct the app to do so.

Moogoose uses a Google-linked Firebase Authentication account for cloud-feature access. The release package does not sync your local profile, conversation history, voice recordings, prompts, or replies to that account. Every user-invoked AI feature connects to a protected Moogoose-operated backend, which verifies the app and signed-in user before sending the specific request to the relevant service provider. Google Gemini processes ordinary AI requests. Perplexity Sonar processes only the separately disclosed public-business identity and public-profile research actions described in section 7. Android does not contain a reusable provider credential or a direct provider request route.

Your Moogoose account and local Writing Profile have different roles. The account authenticates cloud features and owns the minimal server records needed for protected requests, reports, and deletion. The Writing Profile contains the information and style Moogoose uses when writing across your apps. Changing the Google account selected inside Gmail, Google Docs, a social app, or another app does not change the Moogoose account or Writing Profile. Moogoose does not use another app's selected account to choose or change your Writing Profile. The current launch design provides one local Writing Profile; explicit multiple Writing Profiles are a future feature.

Reporting an AI response

When you choose Report AI response, Moogoose first shows the response that will be reported, the reason you select, any optional note you write, and the displayed app version, prompt version, output type, generated time, and random report ID. The form does not automatically attach conversation history, screen context, voice audio, your Writing Profile, or diagnostic logs.

After you confirm submission, the app sends the reviewed report over HTTPS to Moogoose's protected backend with fresh Firebase Authentication and App Check credentials. The backend requires the same account to remain active. It stores the response, reason, optional note, displayed metadata, random report ID, a separate random support reference, a duplicate-protection fingerprint, server timestamps, and review status beneath the verified Firebase user ID. It does not copy the account's email address into the report. A separate rate record contains only a count and timestamps and limits one account to 20 new reports in a rolling 24-hour window. Retrying the same unchanged report does not create another report.

Moogoose uses reports to review possible harmful, offensive, inaccurate, or misleading output and to inform filtering, moderation, and policy escalation. A report is a user submission. It is not proof that an unmodified Moogoose build generated the reported text, and it does not guarantee an individual reply. The ordinary support list contains no report content or Firebase user ID. A support operator must select the exact report by its report ID and support reference and give a separate confirmation before private report content is displayed.

Each report becomes unavailable to support 90 days after receipt. It is then eligible for Firestore TTL deletion. TTL deletion is not immediate, so physical removal can occur later. Account deletion removes the reports and rate record sooner. If Detailed Logging is enabled, the private local diagnostic layer can include the reviewed report request, optional note, and bounded backend response. Clear Logs removes that local diagnostic evidence; it cannot withdraw a report that the backend already received.

5. Google Sign-In and App Verification

Google sign-in is requested immediately before the first cloud-powered feature, including Dictate, Moogoose drafting, and Quick Profile Setup. Manual profile setup and local app inspection remain available without signing in.

When you choose Continue with Google, Google Identity Services and Firebase Authentication process the selected Google account credential. Firebase creates a unique Firebase user ID and may retain provider information returned with the credential, including your email address, name, and profile details. Moogoose uses this account information for authentication, account management, security, and abuse prevention. It is not used for advertising.

Moogoose also uses Firebase App Check with Google Play Integrity. This sends app and device attestation material to Google so Moogoose can distinguish legitimate Play-distributed app installations and protect cloud services from automated misuse. Moogoose does not use the Android advertising ID for this purpose.

After sign-in, the release package sends short-lived Firebase ID and App Check tokens over HTTPS to Moogoose's protected Production endpoints. The backend verifies both tokens and creates or refreshes a minimal server-only account record containing createdAt, identityProvider, lastSeenAt, schemaVersion, and status. It does not copy your email, name, profile photo, local profile, conversations, screen content, audio, prompts, or replies into that account record.

Dictate, Moogoose drafting, Manual Profile voice editing, conversation compaction, Quick Profile conversation turns, and final profile extraction all pass through this protected backend before Google Gemini. The backend holds ordinary request content only in memory for the time needed to provide the requested result. It does not write voice audio, screen or conversation content, profile material, instructions, prompts, transcriptions, or extracted profiles to Firestore or Moogoose application logs. It retains the short-lived content-free request metadata described in section 11. Beneath the ordinary Quick Profile version 4 request records, one separate content-bearing child is permitted: after a terminal conductor, business-resolution, or public-research result is ready, the backend stores the exact encrypted result for same-request recovery for no more than 30 minutes, as described in sections 7, 11, and 12. A backend failure is not automatically repeated through a direct provider route.

The persistent operational timeline records only content-free sign-in and verification stages, timing, result categories, and safe request correlation. It does not write the Google credential, Firebase token, Firebase user ID, email address, name, profile photo, conversation content, profile content, instruction, prompt, or AI response. Existing contextual support diagnostics remain separate and retain the request/response evidence described in section 11. Google credentials, Firebase tokens, and Firebase user IDs are never deliberately logged. Names, email addresses, and profile details may still appear in the contextual layer when they are part of the visible conversation, page, local Writing Profile, or AI request/response being diagnosed, rather than as copied Google sign-in fields.

Delete Moogoose Account is separate from Clear All Data. The app obtains fresh Firebase ID and App Check tokens and asks the protected backend to start deletion. The backend verifies the request, disables the account, creates a durable deletion job, and returns an exact pending acceptance. Only that exact acceptance lets Android clear app-owned local data and sign out. A protected, bounded worker then continues the deletion even if the app closes or is uninstalled. An unavailable server, invalid token, denied request, network failure, or unclear response does not let Android assume that the request was accepted.

The worker removes the environment's user document and known subcollections, including protected request records, AI reports, and report-rate records, then deletes the Firebase Authentication user. To prevent account recreation during this process, the backend keeps a temporary keyed hash of the Google provider subject; it does not store the raw provider subject in the lock. The temporary job contains the Firebase user ID and pseudonymous provider key only while they are needed to complete deletion. Unexpected server data stops broad deletion and can delay completion for manual review. The job and lock are removed after verified completion. This process does not delete the underlying Google Account.

For an account that used credits or Google Play Billing, the worker also removes the current balance, credit lots, reservations and user-linked ledger. All unused credits are permanently deleted. Before it removes the user-linked data, the backend retires the random Play account generation and removes the Firebase user ID and Play account identifier from the retained financial record. A later account receives a new generation, so an old delayed Play notification cannot add value to it. The deletion process does not cancel or refund a Google Play purchase and does not limit any statutory refund or consumer right. Section 12 describes the limited pseudonymous financial records that remain for their stated purpose and period.

See Delete your Moogoose account for the in-app route, email request option, verification process, and deletion details.

Firebase Authentication processes authentication information in the United States and retains account information until Moogoose initiates deletion; Google states that logged IP addresses are normally retained for a few weeks and deleted account information may take up to 180 days to be removed from live and backup systems. Firebase App Check does not retain attestation material itself; successful tokens remain valid for their configured lifetime, currently one hour. Processing by the underlying Play Integrity provider is governed by Google's applicable terms.

6. Accessibility and AI Processing

When Context Reader is enabled, Moogoose's AccessibilityService can read visible text in the current app so it can understand or summarise on-screen content and draft context-aware text. This may include conversations, messages, emails, documents, social posts or comments, web pages, and ordinary visible editable text. Moogoose excludes nodes marked as passwords, password input types, and nodes marked accessibility-sensitive by Android 14 or later. It does not read the text, description, or descendants of an excluded subtree.

Context Reader is required to complete full Moogoose setup because understanding the current screen and conversation is a core Moogoose function. You can decline the disclosure or disable Context Reader in Android settings; declining sends no screen content and leaves setup incomplete, while disabling it later shows Action needed. Dictate can still transcribe voice without screen context. Moogoose can still use your spoken instruction, profile, and any context already stored, but it cannot read the current screen and its draft may be less relevant.

Moogoose requires the accessibility event and active screen tree to identify the same app before it reads content. Tree depth, node count, elapsed traversal time, and captured characters are bounded. If a bound or tree-reading error prevents a complete snapshot, Moogoose discards that snapshot instead of treating partial content as a complete conversation.

Recognised conversation context may be accumulated into per-conversation buffers in Android app-internal storage. It is protected by your device's security and excluded from Android cloud backup and device-to-device transfer. New installations keep this context for six months of inactivity by default. In Moogoose settings, you can choose 90 days or 30 days instead. App updates keep your saved limit, including any existing 30-day or 90-day limit. Existing users without a saved choice keep their previous six-month limit until they make an informed one-time choice. Clear All Data restores the six-month default. Choosing a shorter limit removes older history only after that choice is confirmed. Other app screens use only the latest readable capture held in memory and are not written to conversation-history storage. If optional detailed diagnostic logging is enabled, its separate disclosures and retention controls apply to any raw screen structures it records.

The keyboard eye control shows whether screen context is currently available. You can pause reading for a recognised conversation or for an app. Pausing a conversation deletes its stored context; pausing an app clears its current generic screen context and prevents further accessibility-tree traversal in that app until you resume it. You can also clear all stored conversation history in Settings or disable Context Reader through Android Accessibility settings.

When you invoke an AI feature, the information needed for that specific request is sent over HTTPS through Moogoose's protected backend to Google Gemini. This can include relevant screen context, your instruction, optional profile information, local conversation history, Quick Profile material, and voice audio where applicable. Screen content is not sent merely because Context Reader is enabled. Dictate sends temporary voice audio without screen context or profile information. The response returns through the backend to your device for your review. Moogoose does not automatically retry a failed backend request through a direct provider connection.

Voice audio is recorded to a temporary local file. The file is deleted after successful or failed AI processing. Too-short, cancelled, and failed-start recordings are also deleted locally. Quick Profile version 4 has one local recovery exception. After a valid recording is submitted, the app can move that recording into private no-backup storage for the exact interrupted call. The recording is usable for recovery for no more than 30 minutes from first submission. The app verifies it before an exact replay and deletes it earlier after a terminal result, cancellation, Clear All Data, confirmed account deletion, or session removal. If Moogoose is not running when the recovery period expires, it deletes the file on the next app start or Quick Profile entry. The audio bytes are not stored in the Quick Profile session JSON, ordinary logs, or diagnostic exports.

Moogoose cancels an active recording and deletes its temporary audio if its text field, input view, keyboard window, selected keyboard, signed-in Moogoose account, local-data generation, or keyboard service ends before submission. If a valid request was already submitted, processing may finish, but the result cannot clear or enter a different field.

If a useful AI result returns after only the original field or request has changed, Moogoose can keep up to three such results in keyboard-process memory. The current app sees a generic notice, not the result text. Moogoose copies a retained result to Android's system clipboard only when you tap Copy previous result. Copying makes that text subject to your device's clipboard behavior. Signing out, changing account, Clear All Data, eviction by a newer retained result, or the keyboard service ending removes the in-memory copy; it does not remove a result that you already chose to copy to the system clipboard.

Text-to-speech uses Android's on-device speech engine. No content is sent to Moogoose or Google for that step.

7. Quick Profile Setup and Websites

Quick Profile Setup sends its guided conversation, current profile context, action history, and relevant evidence through Moogoose's protected backend to Google Gemini. Gemini conducts the interview and chooses one action at a time. It does not receive a web-search tool or a provider credential. If it needs a public business identity check or public profile research, it asks the app to start a separate protected Perplexity Sonar action.

Before the app sends private details to Perplexity, it shows a code-owned disclosure immediately beside the decision. The disclosure lists the exact labels and values, the purpose of the check, the recipient as Perplexity Sonar public web search, and that the approval applies to one check and expires after 30 minutes. Selecting Do not send these details sends none of those listed details to Perplexity. An approved check sends only the exact listed details and the bounded task-specific public context required for that action. It does not send the full interview, unrelated profile facts, assistant-authored conversation turns, or private records that were not approved for that action. A raw provider report is not sent back to Perplexity as public context for a later action; a later action can use only its provider-owned public source records and fixed technical metadata unless you approve the private detail again.

Perplexity can return public identity candidates, a bounded report, citations, search-result metadata, and source evidence. The backend validates the provider-owned sources and returns a typed action result to the app. Candidate identities remain proposed until you select or decline one. Gemini receives the complete typed action result and evidence on the next turn and decides whether to ask you, research again, continue, stop, or prepare the final plan. Code does not treat a public search result as an accepted profile fact.

For each terminal Quick Profile version 4 conductor, business-resolution, or public-research request, the protected backend stores one AES-256-GCM encrypted copy of the exact terminal HTTP response, whether successful or failed, in a separate replay child beneath the content-free request record. The encryption is bound to the Firebase user ID, operation, request binding, and random idempotency key. The child can contain the typed Gemini or Sonar result, public candidates, reports, citations, source titles and URLs, evidence records, and the bounded detailed-diagnostic payload only when you requested Detailed Logging for that call. The backend will not return the child after 30 minutes, even if Firestore TTL physical deletion happens later. It is used only to recover the same terminal request without another provider call. It is not written to Moogoose application logs or ordinary diagnostic exports. Account deletion removes it with the request record.

The app stores the unfinished version 4 guided conversation, actions and results, approved disclosures, candidate identities, bounded reports, citations, search results, evidence, work summary, and pending review state in private no-backup storage. It expires an unfinished session after 30 days without Quick Profile activity and removes it on the next app start or Quick Profile entry. On successful completion, it first saves the smaller Review profile suggestions record, then removes the raw session. Clear All Data, confirmed account deletion, a confirmed fresh Quick Profile reset, uninstall, and expiry also remove the local session. A submitted pending recording follows the separate 30-minute limit described in section 6.

When Quick Profile finishes, Moogoose creates one local Review profile suggestions record. Each proposed field records its previous value, proposed value, provider, available source label and URL, retrieval time, intended use, review status, and whether it is already being used. To let you start using Moogoose immediately, facts you supplied yourself may be added provisionally to the local Writing Profile and included in relevant Gemini requests before you review them. A non-volatile official-website proposal for a business name, service, or product or range can also be provisional only under the existing blank-field or safe-addition rules and never as an unreviewed replacement for a direct user fact. Every wider-internet fact remains inactive. Higher-risk researched details, including prices, hours, policies, qualifications or credentials, official contact details, and uncertain or conflicting findings, also remain inactive until you accept or edit them.

The review reminder does not block normal use. In Review profile suggestions, you can accept a proposed value, edit and accept it, or reject it. Rejecting a provisionally active value restores the value that existed before Quick Profile. If that profile field was changed elsewhere after the suggestion was created, Moogoose reports a conflict instead of silently overwriting the newer value. Once every item is decided and the review is successfully applied, the separate review record is removed.

The separate review record remains only until you complete and apply the review, use Clear All Data, or uninstall the app. The resulting local Writing Profile remains until Clear All Data or uninstall and is included in relevant Gemini requests. If public research is declined, skipped, cancelled, unavailable, or produces no credible match, Quick Profile can continue using information you provide directly.

8. Google Gemini and Perplexity

Google provides Gemini as Moogoose's AI service provider. The production project must use Paid Services treatment for UK users. Under Google's current Paid Services terms, Google does not use prompts or responses to improve its products, but may retain limited prompts and responses for abuse monitoring and legal or regulatory purposes.

The Quick Profile public-business research flow does not use Google Search Grounding or URL Context. If a future build restores either Google web tool, its then-current processing, retention, display, and disclosure requirements must be reassessed before release. Google AI Studio Logs & Datasets project logging is disabled for Moogoose's production project, so complete Generate Content prompts and responses are not retained through that optional project-logging feature.

Google processing or transient caching may occur in countries where Google or its agents operate. Google describes its data-protection and transfer commitments in its applicable processing terms.

Perplexity provides the bounded business identity resolution and public profile research described in section 7. Perplexity states that Sonar API prompt and response content is handled with Zero Data Retention by default and is not used for model training. It may retain content-free operational and billing metadata such as token counts, model, timestamps, request duration, and API-key identification. Its published API terms include its standard Data Processing Agreement and transfer terms, and its published information states that API compute is hosted through Amazon Web Services in North America.

9. Lawful Bases

Depending on the feature and circumstances, we rely on:

  • Contract: where processing is necessary to provide an AI communication feature, credit account, or Google Play purchase that you expressly request.
  • Legitimate interests: proportionate security, reliability, duplicate prevention, purchase and settlement recovery, fraud prevention, support, and bounded diagnostics needed to keep the app, wallet and protected backend safe and functioning. Local records are limited and user-deletable; backend operational records are content-free, access-restricted, and retained only for the configured Cloud Logging period.
  • Consent: optional detailed diagnostic logging. You can withdraw consent by turning it off. Turning it off stops new detailed records; use Clear Logs or Clear All Data to delete existing local records. Those controls do not delete an encrypted Quick Profile server replay already created. That replay becomes unavailable after 30 minutes and is removed sooner only by account deletion.
  • Legal obligation: where financial, accounting, tax, refund, dispute or other information must be retained or disclosed to comply with law.

Where content includes special-category data, additional protections and a valid condition under applicable law are required. Moogoose processes such content only as incidental content within features initiated by the user, not to target advertising or infer a diagnosis.

10. Credits, Google Play Billing, and Financial Records

Google Play processes the payment method and shows the localised product and price before payment. Moogoose does not receive or store payment-card or bank details. The app receives the product and price, purchase state and a purchase token. The protected backend uses the token to verify the package, product, quantity, state and Moogoose account binding with Google Play, grant the matching purchased credit lot once, consume the product, process refunds or voids, and recover interrupted fulfilment.

Active credit-account data is stored beneath the Firebase user ID. It includes the balance summary, separate welcome, promotional and purchased lots, reservations, immutable ledger events and content-free request evidence. The lots are internal financial provenance behind one available balance. App features do not receive or use the credit source. Moogoose uses this data to provide value, prevent duplicate grants, record AI use and provider cost, calculate the customer debit, handle refunds and chargebacks, prevent fraud, support users, and meet accounting or legal duties.

Moogoose records the AI usage and pricing information needed to calculate and check each complete action's credit charge. The number of credits used depends on the action. You can see your balance and recent credit activity in Account & Credits. Failed actions, cancellations before completion, safety blocks and unusable actions do not use credits.

The encrypted replay described in sections 7, 11 and 12 can recover the same completed request without another provider call. For a credit-funded AI or business-research action, it can also contain the pricing and settlement records needed to withhold an unsettled result and prevent a second debit. Its decrypted plaintext is limited to 512 KiB. It is used only to recover the same request, becomes unavailable after 30 minutes, and can be physically deleted later by Firestore TTL. Account deletion removes it sooner. It does not start a different request and never enters operational logs or ordinary diagnostic exports.

An unfulfilled purchase is left unconsumed so Google Play can cancel or refund it, and its token is not retained. If credits were delivered but Play consumption is incomplete, only a Cloud KMS-protected token remains until reconciliation consumes the product and clears the token. Purchase tokens, order IDs, billing-account identifiers, Firebase user IDs and email addresses never enter operational logs or diagnostic exports.

While a Moogoose account exists, a keyed pseudonymous claim derived from the Google sign-in identity records whether that account lifecycle received the welcome offer. Moogoose uses it to administer the offer and prevent duplicate awards during that lifecycle. It is not used for advertising or profiling. Account deletion removes this claim.

Pseudonymous Google Play purchase, refund, void, accounting, and fraud records are separate from the welcome claim. They do not contain the email address, Firebase user ID, profile, messages, screen content, or audio. They become eligible for automatic deletion seven calendar years after the relevant financial event. Automated disposal must be configured and verified before Billing is enabled.

11. Diagnostics and Support Export

Moogoose keeps two separate diagnostic layers so technical failures can be reconstructed without removing the contextual evidence needed to diagnose screen capture, conversation merging, prompts, and AI behavior.

The persistent operational timeline is always on and content-free. It records app build identity, setup and permission stages, text-to-speech state, operation stages, durations, result categories, crash class, and safe backend request correlation. Each protected network attempt creates a random client-request UUID before the connection starts. The phone records it, and the backend echoes only a valid UUID and places the same value in its content-free metric. The timeline excludes messages, page or conversation text, profile facts, instructions, prompts, AI responses, credentials, tokens, Firebase user IDs, email addresses, and raw provider errors. It uses two rolling 1 MB files in Android app-internal storage, for a maximum of approximately 2 MB.

When you prepare a Content-Free Summary or Complete Diagnostic Review, Moogoose also creates a content-free environment snapshot. It can contain the app version and build, Android version and API level, device manufacturer and model, locale, time zone, display size, installation source, whether a Moogoose account is signed in, setup and permission states, selected backend configuration, and the most recently accepted backend environment and revision. It contains no hardware identifier, network name, Google account detail, Firebase user ID, email address, profile content, conversation content, or credential.

Moogoose's own entries in Android's temporary Logcat buffer also use fixed content-free values such as stages, counts, timings, status values and error classes. They do not include user text, provider responses, exception messages, absolute file paths or credentials. Android can add its own platform crash lines. Moogoose does not upload Logcat automatically; relevant lines are included only when you prepare the complete local diagnostic file described below.

The existing contextual diagnostics remain available for troubleshooting. A bounded in-memory Session Journal and Merge Trace record the current journey and may include conversation/page context, instructions, prompts, AI responses, and short message snippets needed to determine whether context capture or AI interpretation failed. Merge Trace keeps the newest 500 entries and limits each entry to 2,000 characters.

Detailed diagnostic logging is off by default. You must deliberately open Manage Moogoose → Advanced Diagnostics and enable it after a warning. While enabled, it can retain bounded accessibility-node snapshots; ordinary Dictate, Moogoose, profile-editing, conversation-compaction and Quick Profile request/provider/response/parser/repair evidence; user-reviewed AI report content and notes; and bounded Moogoose-code crash class/method/file/line locations. It can therefore include complete AI, transcription, extraction, website, search, editable-field, message, profile, and proposed-profile content. It never retains voice-audio bytes, identity tokens, App Check tokens, Firebase user IDs, email addresses copied from sign-in, exception messages, unrestricted crash stacks, or absolute local paths. In accessibility snapshots, password and Android-marked accessibility-sensitive subtrees use a fixed redaction marker with no text or description.

New detailed files use Android private no-backup storage. They are excluded from Android cloud backup and device-to-device transfer and share a rolling 10 MB limit that removes the oldest new captures first. Each accessibility snapshot also has a one-file 1 MB limit. Older detailed cache files remain readable in the reviewed export during the storage migration until they are cleared or Android removes them.

After the sensitive-node protection is installed, Moogoose removes older accessibility-tree capture files and any previously prepared complete diagnostic exports once because those files pre-date the protection. It keeps other detailed files, including Quick Profile, ordinary AI, profile-suggestion, AI-report, and bounded crash evidence, that are not legacy accessibility captures.

Turning detailed logging off stops new detailed records but does not delete existing evidence. Clear Logs removes the persistent operational timeline, Session Journal, Merge Trace, current no-backup detailed captures, older detailed cache files, Android log buffer where available, and prior export files.

Normal support starts with Prepare Content-Free Summary. This creates one private-cache text file using only the content-free environment snapshot and persistent operational timeline. It does not read the profile, current or stored screen/conversation content, Session Journal, Merge Trace, Android Logcat, AI/report content, or detailed captures. You can review the exact summary in bounded pages. Nothing is shared unless you confirm Share content-free summary and select a destination.

When contextual evidence is needed, Prepare Complete Diagnostic Review creates one separate retained text file in private cache containing both the content-free operational timeline and all currently retained contextual diagnostic sections. You can review the exact file in bounded pages. The review screen states that sharing sends the complete file, including pages you did not open, and requires a separate confirmation. Nothing is shared unless you confirm Share complete file and select a destination. The review Activity blocks screenshots and Android Recents previews and does not save the displayed diagnostic page in Android view state. The recipient and destination you choose then handle the shared copy under their own terms.

For each protected AI operation, Firestore keeps a short-lived content-free request record under the verified Firebase user ID so duplicate submissions can be rejected and provider usage can be measured. The record is keyed by a client-generated idempotency UUID and contains an opaque server request ID, operation, status, bounded request-size metadata, timestamps and expiry, model, token counts, provider duration, provider request ID, and a fixed failure category where applicable. It does not contain the user's email address, messages, conversation/page context, profile, instruction, prompt, audio, transcription, extracted profile, AI response, credentials, tokens, raw provider errors, or request body. A pending record expires after ten minutes and a completed or failed record expires after seven days; application expiry is authoritative even if physical TTL removal occurs later.

For each protected public-business research operation, Firestore keeps a separate short-lived content-free request record under the verified Firebase user ID. It may contain an opaque request and idempotency ID, resolve or enrich stage, status, timestamps and expiry, model and token/cost counts, provider attempt count and duration, provider request ID, sanitized retry/failure category and upstream status where available, and result counts such as candidates, sources, or suggestions. It does not contain the supplied business clues or website, candidate identities, source URLs, public findings, provider response, credentials, or request body. Pending records expire after ten minutes and terminal records after seven days; account deletion removes these records with the user's server data.

Quick Profile version 4 also keeps separate content-free journey-guard and action-claim records under the verified Firebase user ID. They can contain random or bound execution and idempotency identifiers or hashes, the operation, remaining action count, journey deadline, status, fixed technical outcome, and timestamps. They do not contain the guided conversation, profile, disclosure facts, audio, prompt, provider response, report, candidate, evidence text, source URL, credential, or token. They expire logically after seven days and are then eligible for later Firestore TTL deletion. Account deletion removes them sooner.

Quick Profile version 4 adds one separate encrypted result-replay child beneath its content-free request record. This is the only content-bearing child beneath the ordinary Quick Profile version 4 request-state records. It contains the exact bounded terminal response needed to recover the same conductor, business-resolution, or public-research request. It can include AI text, proposed candidates, public reports, citations, source titles and URLs, evidence records, and a requested bounded detailed-diagnostic payload. The backend protects it with AES-256-GCM and authenticated binding to the Firebase user ID, operation, request, and idempotency key. It refuses recovery after 30 minutes. Firestore TTL deletion can occur later. The seven-day parent remains content-free. The replay child is not copied into application logs or ordinary diagnostic exports, and account deletion removes it.

The backend also writes content-free Cloud Run operational metrics containing an opaque server request ID, the valid random client-request UUID where supplied, route, status, duration, service revision, bounded stage trace, and fixed failure stage/category. A Firebase identity failure may include an allowlisted normalized Firebase SDK code, numeric upstream HTTP status, and fixed upstream reason. These metrics do not deliberately contain a Firebase user ID, email address, user content, credentials, tokens, request body, or raw provider error. Google Cloud Run also creates automatic platform request logs, which may contain normal network metadata such as IP address and user agent. These records are used only for service operation, security, abuse prevention, usage measurement, and technical diagnosis; they are not copied into the Android app automatically.

12. Retention and Deletion

InformationLocal retention and deletion
Firebase Authentication accountRetained by Firebase until Moogoose initiates deletion. Clear All Data and uninstall do not delete it or the underlying Google Account. An accepted in-app request starts the durable server process described above. A verified request can also be made through hello@moogoose.com.
Moogoose identity recordRetained while the Moogoose account is active. The durable deletion worker removes the user document and known subcollections before deleting the Firebase Authentication user.
Active credit account and walletStored beneath the verified Firebase user ID while the Moogoose account is active. It contains the available balance, welcome, promotional and purchased lots, reservations, ledger events, request settlement evidence and billing-hold state. Account deletion removes the current wallet, all unused credits and user-linked ledger.
Google Play purchase and protected recovery recordA verified purchase record contains bounded package, product, state, quantity, account-binding, fulfilment, refund or void evidence. An unfulfilled purchase is not consumed and its token is not retained. After credits are delivered, an incomplete consumption can retain only a Cloud KMS-protected purchase token until bounded reconciliation consumes the product and clears the token.
Welcome-credit eligibility claimA keyed pseudonymous claim exists while the Moogoose account is active. It prevents duplicate welcome grants during that account lifecycle. Account deletion removes it. Reopening, updating, or reinstalling the app does not remove it while the account exists.
Pseudonymous financial evidenceBefore user-linked deletion, Moogoose removes the Firebase user ID and random Play account identifier. Separate retained purchase, refund, void, accounting, and fraud records contain pseudonymous hashes and bounded financial state, not the email address, profile, messages, screen content, or audio. They become eligible for automatic deletion seven calendar years after the relevant financial event. Automated Firestore TTL then makes each record eligible for physical deletion.
Protected AI request recordStored beneath the verified Firebase user ID. Pending records expire after ten minutes; succeeded or failed records expire after seven days. The record contains content-free idempotency, operation, status, bounded size, model, usage, timing and provider-request metadata, but no audio, prompt, transcription, message, profile, extracted profile or AI-response content. Account deletion removes the user document and these subcollections.
Public-business research request recordStored beneath the verified Firebase user ID. Pending records expire after ten minutes and terminal records after seven days. It contains content-free stage, status, timing, provider-attempt, sanitized failure/retry and result-count metadata, but no supplied business clues, website, candidate identities, source URLs, public findings, or provider response. Account deletion removes it with the user's server data.
Quick Profile version 4 journey guard and action claimsStored beneath the verified Firebase user ID. These content-free records contain bounded identifiers or hashes, operation, remaining action count, deadline, state, fixed outcome, timestamps, and expiry. They expire logically after seven days and are then eligible for later Firestore TTL deletion. They contain no conversation, profile, disclosure fact, audio, prompt, provider response, report, candidate, evidence text, source URL, credential, or token. Account deletion removes them sooner.
Encrypted result and settlement replayOne AES-256-GCM encrypted terminal response is stored in a separate child beneath the content-free request record. It is bound to the account, operation, request, and idempotency key and is available only to recover the same request. The response can include typed Gemini or Sonar output, public candidates, reports, citations, source URLs, evidence, a requested bounded detailed-diagnostic payload, and for a credit-funded action the exact pricing snapshot and settlement evidence. It becomes logically unavailable after 30 minutes. Firestore TTL deletion can occur later. Account deletion removes it sooner.
AI reports and rate recordA submitted report is available to authorised support for 90 days, then becomes logically unavailable and is eligible for eventual Firestore TTL deletion. The separate rate record contains only a count and timestamps. Account deletion removes both sooner.
Temporary deletion job and lockThe job contains the Firebase user ID and bounded deletion state. The lock contains a keyed hash, not the raw Google provider subject. Both exist only while needed to finish or safely review deletion and are removed after verified completion.
Conversation buffersNew installations use six months of inactivity by default. You can choose 90 days or 30 days. App updates preserve saved limits; existing users without a saved choice keep six months until they confirm a choice. Clear All Data restores the six-month default. Clear Conversation History or Clear All Data can remove the buffers sooner.
Voice audioTemporary; deleted after completed or failed processing, cancellation, a too-short recording, or a failed start. A submitted Quick Profile version 4 recording is usable for exact interrupted-call recovery for no more than 30 minutes from first submission. It is removed earlier after a terminal result, cancellation, Clear All Data, confirmed account deletion, session removal, or uninstall. If Moogoose is not running at expiry, it is removed on the next app start or Quick Profile entry.
Delayed unapplied AI resultsUp to three results in keyboard-process memory only. Removed after explicit copy, newer-result eviction, authentication change, Clear All Data, or keyboard-service termination. A user-copied result then follows Android system clipboard behavior.
Personal profileRetained locally until Clear All Data or uninstall.
Quick Profile version 4 unfinished sessionThe guided conversation, actions and results, approved disclosures, candidate identities, bounded reports, citations, search results, evidence, work summary, and pending review state are retained in private no-backup storage. An unfinished session expires after 30 days without Quick Profile activity. It is removed on the next app start or Quick Profile entry after expiry, after the review record is safely saved on successful completion, by Clear All Data, confirmed account deletion, a confirmed fresh reset, or uninstall.
Review profile suggestions recordRetained locally after Quick Profile only while review remains unfinished. It contains each affected profile field, its previous and proposed or edited value, provider, available source label and URL, retrieval time, intended use, review choice, and provisional activation state. It is removed after every item is decided and the review is successfully applied, by Clear All Data, or by uninstall. Provisionally active values are also part of the local Writing Profile; rejecting one restores its recorded previous value unless a newer manual change creates a conflict.
Session Journal and Merge TraceBounded local records; removed by Clear Logs, Clear All Data, or uninstall.
Persistent operational timelineTwo rolling 1 MB app-internal files, approximately 2 MB maximum; removed by Clear Logs, Clear All Data, or uninstall.
Detailed raw diagnosticsNew files use private no-backup storage, are excluded from cloud backup and device transfer, and share a rolling 10 MB limit. Each accessibility snapshot is bounded to 1 MB and excludes password and Android-marked accessibility-sensitive subtrees. Older detailed cache files remain available to the reviewed export during migration and may also be removed by Android. Current and older files are removed by Clear Logs, Clear All Data, or uninstall. Switching logging off alone does not delete existing files. Pre-protection accessibility snapshots and prepared exports are removed once after update.
Content-free summaries and complete diagnostic exportsStored in private cache until Clear Logs, Clear All Data, uninstall, or Android clears the cache. Neither file type is uploaded automatically.
Backend operational and Cloud Run request logsThe Production release boundary uses a 30-day _Default bucket for ordinary service and request logs. Google's _Required audit bucket retains required administrative and system records for 400 days. These records are not used for advertising. The exact Production configuration must be verified again before this version is published.

Clear All Data additionally removes profiles, conversations, settings, blocked-conversation data, onboarding data, current and older detailed diagnostics, diagnostic exports, and temporary local audio. Android cloud backup and device-to-device transfer are disabled for Moogoose app data. Temporary audio and new detailed diagnostics use Android's no-backup internal storage. Clear All Data does not delete your Firebase Authentication account, Moogoose identity or credit account, Google Play purchase, or Google Account. Use the separate Delete Moogoose Account action for server-account deletion, or make a verified request through hello@moogoose.com. Confirmed in-app account deletion also clears app-owned local data and current user-linked server data, subject to the limited pseudonymous financial retention above. Google's limited retention and any security or legal retention are governed by Google's terms and cannot be cleared through the app.

13. Other Services We Do Not Use

Moogoose uses no advertising or tracking SDK, product-usage analytics SDK, crash-reporting service, Firebase Analytics, Firebase remote logging, or automatic upload of Android diagnostic files. Its Firebase use is limited to Authentication, App Check, and the server-only account, request, report, credit, billing, deletion, recovery and retention records described above. The content-free backend and Cloud Run operational records described in section 11 are retained in Google Cloud Logging for service functionality, security, fraud prevention, usage measurement and technical diagnosis.

14. Your Data Protection Rights

Depending on the circumstances and lawful basis, you may have rights to be informed and to request access, rectification, erasure, restriction, portability, or objection. Where processing relies on consent, you may withdraw it at any time. These rights are not absolute and exemptions may apply.

Most app data can be viewed, corrected, or deleted directly on your device. For help or a rights request, email hello@moogoose.com. We may need enough information to verify and respond to your request.

You can complain to the UK Information Commissioner's Office. See Make a complaint to the ICO.

15. Adults Only

Moogoose is intended only for people aged 18 and over. We do not knowingly provide the app to children.

16. Security

Data sent to Google is encrypted in transit using HTTPS/TLS. Local information is held in Android app-internal storage and protected by your device's security. No method of storage or transmission is completely secure, so you should use device access controls and avoid enabling detailed logging unless needed.

17. Changes to This Policy

We will update the date above when this policy changes. Where required, material changes will be brought to your attention before new processing begins. We will seek consent where applicable rather than treating continued use alone as consent to a new purpose.

18. Contact

Moogoose Limited
Company number: 17333615
Registered office: 75 Charlton Close, Bournemouth, BH9 3PS, United Kingdom
Email: hello@moogoose.com
Website: moogoose.com