moxlade

Privacy

Updated 2 September 2026

These websites

The marketing and documentation pages set no cookies, load no analytics and make no third-party request — the fonts are served from our own origin. The server keeps ordinary access logs (IP address, user agent, path, time) for security and capacity, rotated on the usual schedule.

Getting a token

Today a token is issued by email: you write to us, we create it against an account we make for you, and we keep your email address so the token can be revoked and so we can tell you about changes to the service. When self-serve sign-in is enabled, sign-in is handled by our authentication provider, Clerk, which stores your email address and the session in your browser; we receive your account id and email.

Using the service

Every tool call is logged against your token: which tool, the workspace it named if any, a hash of the arguments (not the arguments), how long it took, and whether it succeeded or why not. This is what enforces the caps, tells us what is being used, and lets us find a runaway agent. Argument values themselves are not stored.

If you have a workspace, its files and its captured outcomes belong to that workspace and are visible only to its members. They are never used to answer another tenant’s questions.

Paying

Payments, when open, are taken by Stripe on Stripe’s pages. We receive the payment reference, the amount and the email you gave Stripe, and we never see a card number.

The corpora

The data a service answers from is compiled from publicly visible postings and public professional profiles. It is third-party data about businesses and professionals, held to answer questions in aggregate or about a specific posting a user is already working on. If you are the subject of a public profile or posting and want it removed, write to us with its URL. We remove it and say when it is done.

Where it is stored

On a dedicated server in Germany. Stripe and Clerk process their parts on their own infrastructure, in part in the United States.

How long

Account and token records: until you ask us to delete them or the service closes. Call logs: as long as they are useful for caps and capacity, then deleted in bulk. Access logs: on rotation.

Your rights

Ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. One email is enough; no reason required. If you are in the EU or UK you may also complain to your national data protection authority.

Changes

The date at the top is the current version. A material change reaches token holders by email before it takes effect.

Contact

[email protected] — Moxlade.