Only data available to the current account is selected
Privacy Policy
Account and business data is handled around user isolation, limited use, portability and human decision-making.
Version date: August 23, 2026 · Operator details and legal review required before production launchNo business-data sale and no shared customer pool
The deployer controls the database and infrastructure
AI cannot send messages or make commitments automatically
1. Scope and controller
This policy applies to the MooYeah website, authenticated workspace and backend APIs. Before production launch, the operator’s legal name, registered address and privacy contact must be completed here. For a self-hosted deployment, the server operator is the relevant data controller.
2. Information we process
Account data includes name, workspace name, email, irreversible password hash, login sessions and membership status. Business data includes companies, contacts, products, applications, communications, follow-up tasks, file names, AI prompts and outputs. Technical data may include security logs, request times, errors, IP addresses and browser information. We do not request identity documents, card data or payment credentials; a compliant payment provider should process future payments.
3. Purposes and legal basis
Data is used only for authentication, user isolation, lead and follow-up management, AI-assisted analysis, import and export, membership entitlements, security, troubleshooting and legal compliance. Business data is not sold and is not placed in a shared customer pool. Users must have a lawful business-contact basis for uploaded contact data.
4. AI and prompt desensitization
AI features read only workspace data available to the signed-in user. When prompt desensitization is enabled, known company, product and price values are replaced with symbols before context is sent to an external AI provider. Free text can still contain identifying information, so users should not submit unauthorized personal data or trade secrets. AI may be inaccurate; prices, regulations, delivery, quality conclusions and external commitments require human review.
5. Cookies and sessions
MooYeah uses necessary cookies for the HttpOnly login session and language preference. The login cookie authenticates the account and is unavailable to browser JavaScript. The locale cookie retains the Chinese or English selection. Advertising tracking cookies are not used unless separately disclosed with any required consent.
6. Storage, isolation and retention
Business data is stored on the operator-configured server and MySQL database with workspace and user access controls. It is retained only as long as needed to provide the service, maintain audits and meet legal duties. Lead deletion currently archives the record for audit; users may request export, permanent deletion or a defined retention schedule. Backup copies are removed through the backup rotation cycle.
7. Processors and international transfers
Data may be sent to an AI, email, payment, storage or integration provider only when that feature is enabled. Before launch, the provider name, data categories, purposes, storage region and transfer mechanism must be disclosed and any required processing agreement completed. The current project contains no Cloudflare functionality.
8. Security
Controls include password hashing, HttpOnly sessions, server-side authorization, user and workspace isolation, input validation, audit records and human approval boundaries. Future payment integration must use signed, idempotent server callbacks and server-side order status. No internet service can guarantee absolute security; incidents will be handled and notified as required by applicable law.
9. User rights
Users may access, correct, export or request deletion of their information, withdraw consent for optional processing and object to automated recommendations. Requests concerning accounts, membership or audit data can be sent to the contact below and will be answered after identity verification within the applicable legal period.
10. Children, updates and contact
MooYeah is intended for business professionals and not children. Material policy changes should be prominently notified with a revised effective date. This version is a project configuration template and must be legally reviewed before launch for the operator’s location, target markets and actual third-party services.
Email contact@your-domain.com. Replace this placeholder with an active privacy contact before production launch.