Moonpool ("the app," "we," "us") is a personal wellness journaling app for mood check-ins, journaling, gratitude notes, breathing exercises, movement logging, custom habit tracking, and optional AI-assisted reflections. This policy explains what we collect, why, where it goes, and the choices you have.
The essentials:
- Your data is yours. Synced data is isolated to your account with per-user access rules, protected with TLS in transit, and encrypted at rest.
- AI never trains on you. Content sent for AI features is processed under Anthropic's commercial API terms, which do not permit using it to train models — and we never allow it to be used for advertising.
- Nothing goes to AI until you say so. AI features are optional, disclosed before first use, and send content only for the requests you make.
- Delete means delete. Deleting entries or your account removes them from our backend, not just your screen.
- No ads, no tracking. No advertising SDKs, no cross-app tracking, no advertising identifier.
We use two third-party SDKs — TelemetryDeck (anonymous product analytics) and Sentry (crash and error diagnostics) — described below. Neither receives your name, email, wellness content, or a stable identifier that could be used to track you. We do not use advertising SDKs, we do not track you across other apps or websites, and we do not use the Advertising Identifier (IDFA) or App Tracking Transparency tracking.
What we collect and why
Your wellness content. Mood check-ins (including any emotion words you tag), journal entries, gratitude notes, breathing sessions, movement entries, and any custom habits you create. Your entries are saved on your device, and if you sign in they sync to your private account on our backend so your devices stay in step. If you don't sign in, nothing is synced; entries are sent off your device only for AI requests you make or exports you create.
Account information (only if you sign in). Signing in is optional. If you sign in with Sign in with Apple or an emailed one-time code, we receive your email address and an account identifier so we can create your account and sync your data across your devices. Sign in with Apple lets you choose to hide your email, in which case we receive Apple's private relay address.
A device-scoped identifier. To run optional AI features and verify premium status without an account, the app generates a random per-install identifier and uses Apple's App Attest to confirm requests come from a genuine, unmodified copy of the app (anti-fraud). This is not used to track you and is not the IDFA.
Subscription status. Premium subscriptions are processed by Apple and managed through RevenueCat. We receive whether you have an active subscription (keyed to the identifiers above, never your email); we do not receive or store your payment card details.
Anonymous usage and diagnostics. To understand which features are used and to find and fix crashes, the app sends anonymous product-analytics events (via TelemetryDeck) and crash/error diagnostics (via Sentry). These carry no wellness content, no email, no name, and no advertising or cross-app identifier — only bounded event names, counts, and technical crash information. Analytics run only in released builds.
We collect this data to provide the app's features (saving and showing your entries, syncing them to your account, generating AI responses you request, and unlocking premium). We do not sell your data, and we do not use your health, fitness, or wellness data for advertising, marketing, or data mining.
Where your data is stored and who processes it
- On your device. Your entries are stored on your device, so the app works instantly and offline. Your AI conversation history is currently stored only on your device.
- Our backend (Supabase, hosting/database). If you sign in, your entries — and the companion's "memory" notes about you — sync to your private account, accessible only to you (enforced by per-user access rules and encrypted at rest by our infrastructure provider). If you don't sign in, nothing is synced.
- AI provider (Anthropic — the Claude API). When you use an AI feature, the app sends the content that feature needs to our backend, which forwards it to Anthropic's Claude API to generate your response. Depending on the feature, that can include the journal entry you're reflecting on, your recent mood, journal, gratitude, and movement data, your conversation messages, the app's memory notes about you, and — if you've set them — your first name and preferred language. In conversations, the AI can also look up your own synced entries (and only yours) to answer questions about your history. Our backend does not keep any of this content after your response is returned; it records only anonymous, aggregate token counts to monitor cost. Anthropic processes the content to produce your response under its commercial API terms, which do not permit it to be used to train Anthropic's models, and we do not permit it to be used for advertising.
- RevenueCat (subscription management) and Apple (Sign in with Apple, App Attest, in-app purchases).
- TelemetryDeck (anonymous product analytics) and Sentry (crash and error diagnostics). Both receive only anonymous, bounded technical data — no wellness content, email, or advertising identifier.
- Apple Health (optional). If you turn on the Apple Health toggles in Settings › Data, the app can write mood check-ins as State of Mind samples, completed breathing sessions as Mindful Minutes, and logged movement as workouts into Apple Health on your device. We do not read Health data back into the app. You can turn these off at any time; existing Health samples stay until you remove them in the Health app.
Each of these processors is required to protect your data consistent with this policy. We do not store personal health information in iCloud.
Reminders are local notifications scheduled entirely on your device — we run no push-notification servers. The Apple Watch app talks only to your iPhone over Apple's device-to-device connection; it makes no network connections of its own.
AI features and your consent
AI features are optional. Before the first time you use one, the app shows a disclosure and asks you to continue; nothing is sent for AI processing until you agree, and content is sent only for the requests you make. You can stop using AI features at any time.
Not medical care
Moonpool is a companion for reflection — not therapy, medical care, or a substitute for professional help. The app and its AI companion do not diagnose, treat, or give medical advice. If you are in crisis or thinking about harming yourself, please reach out to a person: someone you trust, or a free, confidential helpline near you via findahelpline.com (also linked in the app under Settings → About → Crisis resources).
Your choices and rights
- Export your data as a JSON backup from Settings → Data. The file is created on your device; nothing is uploaded.
- Optionally save mood check-ins to Apple Health from Settings → Data (State of Mind). Off by default.
- Delete all your data from Settings → Data. This removes your entries, AI conversations, and companion memory from your device — and, if you're signed in, also deletes your synced entries and memory from your account on all your devices.
- Sign out to stop syncing; or delete your account from the account screen, which removes your account, email, and all synced entries from our backend. Anonymous records that contain no personal data (aggregate AI token counts and the device-attestation keys used for anti-fraud) are not linked to your account and may persist.
- Manage or cancel your subscription through your Apple ID settings.
Depending on where you live, you may have additional rights (access, correction, deletion, portability). Contact us at the address above to exercise them.
Data retention
Data stored on your device is kept until you delete it or remove the app. Synced data is kept in your account until you delete the relevant entries or delete your account, at which point it is removed from our backend. Content sent for AI processing is not retained by our backend after your response is generated. Subscription-status records are kept while needed to operate the service.
Security
Data in transit is protected with TLS. Synced data is isolated per account with row-level access rules and encrypted at rest by our infrastructure provider, requests are verified with App Attest, and sessions use standard token-based authentication with credentials kept in your device's Keychain.
Children
The app is not directed to children under 13, and we do not knowingly collect personal information from them.
Changes to this policy
We may update this policy as the app changes. Material changes will be reflected here with a new effective date.
Contact
Questions or requests: brad.hill@noctis.net.