Privacy Policy
Last updated: September 2026
The short version
Moodis is local-first. The desktop app works fully offline, and your boards and images live in files on your own machine. Nothing is uploaded anywhere unless you create an account and switch cloud sync on.
If you do turn cloud sync on, your boards and images are stored on our infrastructure so they can reach your other devices and the people you share with. The rest of this page sets out exactly what that means, what we keep, who processes it on our behalf, and how to export or delete all of it.
Who this policy covers
This policy applies to three things:
- The Moodis desktop app for Windows and Linux.
- The Moodis web app at web.moodis.app, including its installable (PWA) form.
- This website, moodis.app.
The data controller for the personal data described here is Roll Three One (Business ID 3217727-3), Martinlaaksontie 42 B7, 01620 Vantaa, Finland. You can reach us at support@moodis.app about anything on this page.
The desktop app, without an account
You can download, install and use Moodis without giving us anything. There is no sign-up, no licence check, and no usage tracking or telemetry in the app: the analytics interface it is built against is wired to a no-op in release builds.
Your boards, images, and settings are written to your operating system's application-data folder as ordinary files. We never see them. Deleting that folder deletes your data, completely and immediately.
Two things do leave your machine even when you are signed out, and you should know about both:
- Interface fonts. The app loads its typefaces from Google Fonts when it starts. Google receives your IP address and browser user-agent as part of that request, as it does for any site using the service.
- Update checks. On launch the app fetches the release manifest from www.moodis.app. It downloads the whole manifest and compares versions on your machine, so the request itself carries only your IP address and a generic updater user-agent — not your app version, operating system, or any account, board or image data. Release files are served through Vercel and Bunny CDN, which log the request in the ordinary course of running a CDN.
Accounts and cloud sync
Cloud sync, sharing and team features are part of the paid Moodis plans, which begin with a free trial, and they are opt-in. They begin when you create an account and sign in; until then none of this section applies to you. A small number of our staff can access account and subscription records through an internal admin tool when support or abuse handling requires it.
What we store when you have an account
- Account details — your email address, an optional display name, and your password. Passwords are hashed by our authentication provider; we never hold the plaintext. We also store a one-way hash of your email address, which is how someone who shares a board with you by email reaches your account without us exposing the address itself.
- Board content — board names and settings, saved viewport position, and every element on the canvas, including the text of your notes, to-dos and links. We treat this as your content, not ours.
- Images — the image files themselves, plus their filename, byte size, pixel dimensions and content type. Images are encrypted at rest and stored in the European Union.
- Sync bookkeeping — a device identifier, the device name and platform you sync from, and when that device last synced, so changes can be merged across your devices.
- Subscription state — your plan status and renewal date, the customer and subscription identifiers issued by our payment provider, and how much of your storage allowance you have used.
Sharing and collaboration
Sharing is always something you start. When you use it, we store what is needed to make the share work and to let you revoke it:
- Direct shares — which board you shared, with which account, and whether they may view or edit.
- Share links — a random token that forms the URL, plus the options you set: view or edit access, an optional password (stored hashed), an optional expiry date, an optional cap on uses, and a count of how many times the link has been opened. Anyone holding the link can open the board within those limits, so treat a share link as public unless you have set a password. Deleting the link revokes access.
- Teams — the team name and description, who its members are, and each member's role. An invitation is bound to the email address you send it to and can only be accepted by that address.
- Live collaboration — while several people have the same board open, your display name and cursor position are relayed to everyone else viewing it, for the duration of the session. That includes anyone holding a share link, who need not have an account.
External images
A board that was shared with you, or synced from elsewhere, can contain images pointing at any server on the internet. Loading one would tell that server your IP address and the moment you opened the board, so Moodis leaves those images unloaded. You can turn them on in Settings; the setting is off until you do. Your own images are never affected.
Payments
Subscriptions are sold and processed by Lemon Squeezy, which acts as the merchant of record. Checkout happens on their pages, and your card details go to them, never to us — we never see or store a card number. What comes back to us is your subscription status, renewal date, and the customer and subscription identifiers we use to keep your account on the right plan. So that your purchase lands on the right account, we pass your email address and account identifier to Lemon Squeezy when checkout opens.
Security and abuse prevention
Requests to our servers are logged for security purposes. Those records can include your IP address, your user-agent string, the action performed, which resource it touched, a request identifier, and any additional context relevant to the event. We use them to investigate suspicious activity, enforce rate limits, and throttle repeated password attempts against protected share links. They are not used to build a profile of you or to target anything at you.
This website and the web app
moodis.app uses Plausible Analytics to count visits. Plausible is cookieless, stores no IP addresses, and does not follow you between sites or build a profile of you; what reaches us is aggregate page views, referrers, and how far down a page you scrolled and how long it was in view. Beyond that the site sets no cookies and embeds no advertising or social trackers. It does load typefaces from Google Fonts, which means Google receives your IP address and user-agent. It stores nothing in your browser. If you follow a sign-up link from here to the web app, your preferred colour scheme is appended to that link so the app opens in the right theme.
web.moodis.app uses Vercel Speed Insights to measure page-loading performance. It collects anonymous, aggregated metrics — Web Vitals, browser and device type, country-level location, and connection speed. It sets no cookies and does not follow you between pages or sites. When you are signed in, the web app also keeps your session token in browser storage so you are not asked to sign in on every visit, along with your theme preference and the board you last had open. As an installable app it caches its own program files on your device so it can start offline; that cache holds no board content.
Both sites are hosted on Vercel, which logs requests as part of serving them.
Who processes data on our behalf
We keep this list short on purpose. Each provider only receives what its job requires:
- Supabase — accounts and authentication, the database holding your boards and their metadata, and realtime collaboration. See the Supabase Privacy Policy.
- Wasabi — object storage for your images, both full-resolution and thumbnails, and for application downloads. Your images are held in Wasabi's eu-central-1 region, inside the EU.
- Bunny CDN — content delivery for application downloads and update manifests. It does not deliver your board images.
- Vercel — hosting for this website and the web app.
- Plausible Analytics — cookieless visit statistics for this website. Each request carries your IP address and user-agent; Plausible hashes them with a salt that rotates daily to count unique visitors, and never stores the raw values. Because the salt rotates and the hash covers our domain, the result links neither across days nor to other sites. Your data is processed and stored in Germany, inside the EU.
- Lemon Squeezy — subscription payments and billing. See the Lemon Squeezy Privacy Policy.
- Resend — sending transactional email, such as a team invitation. It receives the recipient's address, the team name, and the inviter's name.
- Sentry — error monitoring for our server-side functions, which records your account identifier alongside a diagnostic report when something fails.
- Google Fonts — the typefaces used by this site and the desktop app.
We do not sell your data, and we do not share it with advertisers or data brokers. Your images are stored inside the EU. Some of the providers above are established outside the European Economic Area, so other data covered by this policy — account records, billing, diagnostics — may be processed in other countries, including the United States.
Why we are allowed to hold it
- To provide what you asked for. Account data, board content and sync records exist because you asked us to sync, share or collaborate.
- To meet our obligations. Payment and subscription records are kept because tax and accounting rules require it.
- Our legitimate interest in a working service. Security logs and rate limiting keep the service available and accounts safe, and the cookieless visit statistics described above tell us which pages are worth keeping without identifying anyone.
- Your consent. Optional behaviour, such as loading external images, happens only after you turn it on, and you can turn it off again at any time.
Your rights
Export and account deletion are built into your account settings, on the web app's account page and in the desktop app. You can also email us and we will action the same requests for you.
- Get a copy. Request an export of your account data and boards from your account settings. The file downloads straight to your device; we do not keep a copy or put it behind a link. Exports are limited to one per 24 hours.
- Correct it. Change your display name and the email address on your account from the web app's account page. A new email address takes effect once you confirm it from the link we send.
- Delete it. Requesting account deletion starts a 30-day cool-off period, during which you can cancel and keep everything. After it ends your data is taken out of service, and it is permanently erased within 90 days of the original request. The same timeline runs automatically for accounts that lapse — see how long we keep things, below.
- Object or restrict. Ask us to stop or limit a particular use of your data.
- Complain. Write to us at support@moodis.app. If you are in the EEA or the UK you can also complain to your local data protection authority.
We respond to any of these requests within 30 days.
None of this applies to the free desktop app used without an account, because we hold nothing to export or delete — the files are already yours.
How long we keep things
- Account and board data — until you delete the content or close your account, subject to the deletion timeline above.
- Accounts that lapse — we do not keep cloud data forever just because you stopped using it. 90 days after a subscription or trial ends without being renewed, the account is automatically scheduled for deletion, and it then follows the same timeline as a deletion you request yourself: taken out of service after 30 days, permanently erased 90 days after scheduling. Your local files are untouched by this — it applies only to what is stored in the cloud.
- Security and audit records — kept for security and abuse investigation. These are not yet on an automatic expiry schedule; we are adding one that will delete them after 12 months, and until it is running we are not promising a shorter period than we actually enforce.
- Visit statistics — the aggregate counts Plausible holds for this website have no fixed expiry. They carry no identifier that could be traced back to you, and the daily salt used to count unique visitors is deleted every 24 hours, so a day's figures cannot be re-linked to a visitor afterwards.
- Payment records — as long as tax and accounting law requires.
- After an account is erased — we keep a minimal record that the deletion happened, including the email address it applied to, so we can show the request was honoured. Security-log entries are unlinked from your account but the entries themselves remain, subject to the point above.
Children
Moodis is not directed at children under 13, and we do not knowingly create accounts for them. If you believe a child has given us personal data, contact us and we will remove it.
Changes to this policy
When what we do with data changes, this page changes with it and the date at the top is updated. If a change materially affects you, we will tell you in the app or by email rather than relying on you to re-read this page.
Contact
Questions, requests, or something on this page that does not match what you see in the product — write to support@moodis.app.