Get Started
Data Protection

Privacy Policy

MoodLens is operated by Moodlens Technology. This policy explains how we collect, use, secure, and disclose data when you use MoodLens websites, apps, desktop experiences, browser extension, workspaces, AI features, authentication flows, integrations, MCP/API surfaces, billing, and support channels.
Operational base: Carrer de la Riera Alta, 61, Ciutat Vella, 08001 Barcelona, Spain. Last updated: May 24, 2026

1. Information We Collect

We follow a minimal data principle: we collect the information reasonably needed to authenticate users, run workspaces, process requests, secure the service, and communicate with you. We do not sell your personal data.

Account Basics

Email address, display name, avatar, workspace membership, and basic account identifiers used to create and manage your account.

Authentication Data

If you sign in with Google, Microsoft, GitHub, or email/password, we process the provider or authentication data needed to verify identity, maintain sessions, and protect account access. Passwords are not stored by us in plain text.

Workspace Content

Tasks, projects, boards, sprints, docs, notes, files, comments, chat, meeting records, AI employee conversations, automation logs, and other content you create or store in MoodLens workspaces.

Uploaded Media & Files

Avatars, workspace icons, task covers, comment, chat, meeting, doc, and database attachments, images, audio, video, documents, archives, screen recordings, screenshots, camera overlays, clips, transcripts, summaries, generated media, imported files, and related metadata when you create, upload, share, or analyze them. Files may include embedded metadata such as author, device, timestamp, geolocation, or EXIF information.

Integrations & Keys

Connection settings, OAuth tokens, API keys, webhook endpoints, repository links, imported data, workspace secrets, and browser-extension context needed for features you enable.

Security, Usage, Billing & AI

Device, session, IP, audit, abuse-prevention, and feature-usage data, subscription state, invoices or checkout metadata, credit balances, plus prompts and context you intentionally send to Moody AI to complete a request.

2. California Privacy Notice

This section supplements the rest of this Privacy Policy for California residents where California privacy law applies. Some rights apply only if MoodLens is legally treated as a covered business under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.

Categories collected

Identifiers, account details, commercial and billing records, internet or device activity, approximate location from network data, audio/video or visual content you choose to record or upload, file metadata, workspace and professional information, inferences from product usage, and sensitive information only when needed for account security, credentials, private communications, media features, or user-directed workflows.

Purposes and disclosures

We use these categories for product operations, authentication, security, AI features, collaboration, integrations, support, analytics, billing, compliance, and abuse prevention. We disclose data to service providers, contractors, payment processors, AI and infrastructure providers, integration providers, workspace members/admins, and legal authorities when required.

Sale, sharing, and sensitive data

We do not sell personal information or share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that would require a separate California limit-use link unless we first provide the required notice and choice.

California rights

Where applicable, California residents may request access, portability, correction, deletion, information about categories collected and disclosed, opt-out of sale or sharing, limit certain sensitive-information uses, and freedom from discrimination for exercising privacy rights.

To submit a California privacy request, email support@moodlens-ai.com. Account deletion requests should be sent to account-deletion@moodlens-ai.com from the same email address used for the MoodLens account whenever possible. We may need to verify your identity, account relationship, or agent authorization before acting on requests.

3. How We Use Your Data

Product operations

  • To run tasks, projects, docs, meetings, and workspace collaboration
  • To create and secure accounts and maintain session state
  • To send transactional emails and support replies
  • To process subscriptions, one-time credit purchases, invoices, and billing support

Security and improvement

  • To prevent abuse, fraud, spam, and unauthorized access
  • To monitor uptime, errors, and product reliability
  • To improve the service using aggregate or de-identified insights where appropriate
  • To maintain audit trails, workspace safety, quota enforcement, and operational logs

Contract

We process account, workspace, AI, integration, support, and billing data when needed to provide the service you request.

Legitimate interests

We process security logs, abuse-prevention signals, product reliability data, and limited analytics to keep MoodLens safe and working.

Consent or user direction

Optional features such as OAuth integrations, the browser extension, camera/microphone access, recordings, imports, and AI requests run when you choose to enable or use them.

Legal obligations

We may process records needed for tax, accounting, legal compliance, dispute resolution, law-enforcement requests, and rights handling.

We do not use your personal data for third-party advertising, and we do not sell or rent your personal data to advertisers or data brokers. Some information is required to create an account or provide a requested feature; if you do not provide it, that feature may not work.

4. Authentication, Providers, Integrations & AI

MoodLens relies on operational service providers to run infrastructure, hosting, storage, analytics, authentication, AI responses, communications, payments, calling, and integrations. Depending on the feature you use, limited data may be processed by those providers to complete the requested workflow.

If you choose Google, Microsoft, or GitHub sign-in, those providers authenticate you and may share basic profile data with us, such as your name, email address, profile image, and provider account identifier, depending on the scopes or claims granted and your provider settings.

We do not allow your personal data or workspace content to be used to train third-party AI models for their own products. When Moody AI or related AI features are used, request content is sent only as needed to generate the requested output or complete the requested action.

If you use AI features with uploaded files or media, our servers may read, download, parse, resize, transcribe, summarize, or convert authorized content into text, image parts, PDF/document parts, audio transcripts, screenshots, or extracted video frames before sending the needed content to AI providers for the requested workflow. Conversation history may cause earlier attachments to be included again as context.

Workspace owners and admins may see workspace content, member profiles, membership records, audit activity, billing state, integrations, automation logs, and other information needed to operate a shared workspace. Other members may see content shared with their workspace, channels, meetings, docs, tasks, or permissions.

Private media is served through authenticated access controls and workspace membership checks. If you publish a doc, share an artifact, or create another public link, the linked content and referenced media may be accessible to anyone with the link until it is unpublished or removed. External file URLs and embeds are controlled by the third-party service that hosts them.

Infrastructure & operations

Hosting, Firebase/Google Cloud services, storage, delivery, logging, monitoring, backups, Vercel website analytics, and other systems needed to keep MoodLens available and secure.

Identity & authentication

Authentication systems and supported login methods, including email/password and social login via Google, Microsoft, and GitHub, used for sign-in, session management, and account recovery.

Analytics, AI & integrations

AI model providers, GitHub connections, import sources, connected tools, workspace secrets, webhooks, and linked services may require limited data exchange with the relevant provider or platform.

AI file processing

AI employees, Team Discussions, Moody intake, Clip AI, reference-image analysis, and automation features may process attached images, PDFs, text files, audio clips, screenshots, and selected video frames when you ask the feature to analyze or act on them.

Email, support & payments

Transactional email and support providers may receive contact details and message context. Stripe processes checkout, subscriptions, invoices, payment status, and billing portal workflows where paid features are used. We do not store full card numbers.

Calls, clips & media

Calling, recording, transcript, clip, screen-share, camera, microphone, and attachment workflows may use infrastructure and real-time media providers, storage, and AI processing when you start or upload them. Local browser call recordings may download to your device, while transcripts, call chat, and summary PDFs may be stored, posted, or emailed when meeting summaries are enabled.

Extension, MCP & API access

The browser extension can process selected text, current-page content, meeting page content, images, local extension history, and reminders when you use those features. MCP, API keys, developer apps, and webhooks can expose workspace data to tools or services you connect.

Messaging, imports & embeds

Messaging links, WhatsApp or Telegram workflows, import sources, Notion-like imports, and document embeds may include messages, voice notes, media, file metadata, external file URLs, or transcripts supplied by the connected platform or by you.

5. AI, Automation & Human Control

MoodLens AI features can summarize, draft, classify, search, review, recommend, generate artifacts, participate in team discussions, and help run automations or connected-tool workflows based on the context you provide and the permissions configured in the workspace.

AI context can include prompts, workspace records, uploaded attachments, reference images, generated media, task-intake files, clip frames, call transcripts, meeting chat, summary PDFs, and previous conversation messages where the feature needs that context to answer or act.

MoodLens does not use solely automated processing to make decisions that produce legal effects or similarly significant effects about users. AI output should be reviewed by a human before you rely on it for important decisions, external actions, regulated advice, employment, finance, health, legal, or safety-sensitive matters.

AI employees, automations, MCP clients, webhooks, and integrations may act on workspace content only within the permissions, tokens, or secrets configured by users or workspace admins. You can disconnect integrations, rotate keys, delete stored secrets, or contact us for help reviewing data access.

6. Your Rights Over Your Data

Depending on your location and the laws that apply, you may have rights to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing or withdraw consent where consent is the legal basis.

Access & portability

You can request a copy of applicable personal data in a reasonably portable format where feasible.

Correction & deletion

You can correct information in the product where available and request deletion of your account and associated personal data by emailing account-deletion@moodlens-ai.com from the email address used for your MoodLens account, subject to verification and legal retention requirements.

Consent & objections

Where we rely on consent for an optional feature, you may withdraw it. You may also object to or request restriction of certain processing where applicable law gives you that right.

Complaints

You may lodge a complaint with an applicable supervisory authority, including the Spanish Data Protection Agency (AEPD) where applicable. We encourage you to contact us first so we can try to resolve the issue.

To exercise these rights, contact us at support@moodlens-ai.com. For account deletion requests, email account-deletion@moodlens-ai.com from the same email address you use to sign in to MoodLens so we can match the request to the account. If we cannot verify the requester, we may ask for additional confirmation or be unable to complete the request. We will respond within the timeframes required by applicable law.

You can also visit the AEPD at aepd.es.

7. Retention, Security & International Processing

We retain personal data for as long as needed to provide the service, secure accounts and workspaces, maintain audit trails, preserve billing and tax records, comply with legal obligations, resolve disputes, and enforce agreements. After deletion requests, we delete or anonymize data within a reasonable period except where retention is legally required or where limited backup, security, billing, or dispute records must be retained.

Some in-product deletion actions soft-delete records or remove visible links before underlying files, generated PDFs, transcripts, AI context, cached results, or backups are fully removed. Workspace clips are designed to delete the linked storage object when deleted; local clips are stored in your browser and can be removed from that browser. For broader deletion, email account-deletion@moodlens-ai.com so we can review account, workspace, storage, backup, and legal-retention records.

We use industry-standard safeguards designed to protect data, including access controls, encrypted transport, and secure infrastructure practices. No method of storage or transmission is completely secure, but we work to reduce risk and respond appropriately to security incidents.

MoodLens applies authentication, membership checks, file size limits, supported content-type checks, private media proxy controls, and public-link checks for published content. These controls reduce risk but do not guarantee that every unsafe, infringing, or malicious file will be detected before it is uploaded or viewed.

Because we use providers that may operate in multiple countries, your data may be processed outside your city, region, or country. Where required, we rely on appropriate contractual, technical, or organizational safeguards, such as adequacy decisions, standard contractual clauses, or equivalent transfer measures.

8. Cookies & Similar Technologies

We use cookies and similar technologies only where needed for authentication, security, session continuity, preferences, and basic product functionality. We do not use third-party advertising cookies to profile you across unrelated sites for ads. Public website analytics may be used to understand page performance, traffic, and reliability without selling personal data.

These technologies may include session cookies, local storage, security tokens, and login-state markers. If you use Google, Microsoft, or GitHub sign-in, those providers may also use their own cookies or similar technologies as part of their OAuth or OpenID Connect authentication flows, subject to their own policies. You can control browser cookies through your settings, but disabling some technologies may affect how the service works.

Because there is no single industry standard for browser Do Not Track signals, we do not currently respond to those signals. Where a legally recognized opt-out preference signal applies to a sale or sharing of personal information, we will honor it as required; at present, we do not sell personal information or share it for cross-context behavioral advertising.

9. Changes, Controller Details & Contact

We may update this Privacy Policy from time to time. We will post the updated version here and revise the "Last updated" date. For material changes, we may notify you in-product or by email when required by law.

For the purposes of this policy, MoodLens is operated by Moodlens Technology, Carrer de la Riera Alta, 61, Ciutat Vella, 08001 Barcelona, Spain. If you need to exercise privacy rights or contact us about a data issue, please email support@moodlens-ai.com.

We use this email as the primary privacy contact. If a dedicated data protection officer, representative, or additional controller contact becomes required or appointed, we will publish those details here.

We will respond in good faith and within the timeframes required by applicable law.

Version 2.1 - May 24, 2026

Questions? Contact support@moodlens-ai.com