moonshotback

Privacy

Moonshot listens to your day so the next thing you need is already there when you reach for it. That only works if you know exactly what it hears, where that goes, and what we keep. This page says so in plain language, and it describes the product as it is built today — including the parts that are less private than we want them to be.

Last updated 1 September 2026.

The short version

  • Moonshot uses Sign in with Apple to create your account. It verifies Apple's signed identity token, stores an irreversible hash of Apple's stable account identifier, and keeps an encrypted Apple revocation credential so Delete all data can close the authorization with Apple. This iPhone keeps Apple's opaque identifier in Keychain. Moonshot requests neither your Apple email nor your name. Moonshot has no ads. We sell nothing about you, to anyone, ever.
  • The app ships with no analytics, telemetry, or tracking SDK. This website sets no cookies and loads no trackers. Forms store only the details listed below.
  • Ambient microphone audio is divided at the first quiet pause, with a 30-second maximum, and sent securely through our server to Moonshot's private speech-transcription service on Google Cloud. Each chunk is deleted when transcription finishes. Moonshot keeps the resulting text.
  • To understand a moment, Moonshot sends recent transcript text and selected context through our server to Anthropic, Google, or OpenAI. Our server keeps no content copy. Anthropic keeps permanent-study batch results available for 29 days.
  • To speak a reply, Moonshot sends only the text of that spoken reply to Fish Audio. It sends no microphone audio, call audio, voiceprint, Mind, mail archive, or other stored file to Fish.
  • Some of your files are mirrored on our server so that a reinstall does not erase your life: your Mind, your ledger, your morning history, and your call records. What that copy contains is listed below.
  • Gmail, Google Calendar, Google Drive, Google Contacts, and verified Google connection connect through one Composio Google Super authorization. Moonshot has no operational first-party Google OAuth path. These features stay under the Google Limited Use terms. How sensitive data is protected is described below.
  • You can delete all of it.

Who this covers

This policy covers the Moonshot iOS app and this website, which is served at moonshot.computer, moonshot.mobile, oons.hot, m.oons.hot, inner.you, and gets.you. "We" means the small team that builds Moonshot. Write to us at privacy@moonshot.computer about anything on this page.

Moonshot is an early build in the hands of a small, known group of testers. Sign in with Apple creates the Moonshot account. Your phone also identifies itself to our server with an App Attest key generated on first launch. The server binds that proved phone to the irreversible hash of Apple's stable account identifier. Apple shares neither your name nor your email with Moonshot during this flow.

What the app hears

When listening is on, Moonshot divides microphone audio at the first quiet pause, with a 30-second maximum. The app sends each short chunk securely through our authenticated server to a private GPU speech-transcription service on Google Cloud. The service uses the audio only to produce text. Its temporary audio file is deleted when that request finishes, and neither our relay nor the transcription service keeps a recording. What survives the moment is text.

That text is the substrate for everything else: the ledger of real things you said you would do, and the Mind — the profile of people, projects, promises, and preferences that Moonshot studies from your own words.

What a model call carries

Understanding uses one model request for each job, sent through a small server we run on Google Cloud. Anthropic's Claude studies permanent Mind updates, Google's Gemini judges ambient sections, and OpenAI writes re-derivable section titles and notes. Your phone holds no model keys. Our server relays each request and reply without logging or storing the contents.

A request can carry:

  • recent transcript lines from what was just heard, as text
  • your name and time zone
  • people from your contacts — names, and the phone numbers and email addresses saved with them — so Moonshot spells a name right and knows who you mean
  • calendar events in roughly the next two days: titles, times, and locations
  • reminders you ask about: titles, notes, dates, and locations
  • sleep timing and duration from HealthKit when you ask about your sleep
  • the current Apple Weather result when you ask about weather
  • relevant turns from your stored Moonshot call transcripts when you ask about a call
  • your Mind: the profile Moonshot has built about your life
  • for the Gmail catch-up, mail headers and previews — sender, recipients, subject, and the snippet Gmail shows in the inbox list

Permanent Mind study runs through Anthropic's Message Batches API three times daily. Anthropic's published Batch documentation says results remain available for 29 days after a batch is created. Our server keeps only the content-free batch id, state, token counts, cost, and request hash needed to avoid a duplicate paid request. Erasing Moonshot removes that server metadata. Anthropic's retained result follows its 29-day provider window. We do not authorize any model provider to train on your material.

Moonshot's spoken voice is generated by Fish Audio from only the text of Moonshot's spoken reply, requested by our server. Fish's public terms permit Fish to use submitted content and usage data to develop, train, or improve its models and third-party components. Fish's privacy policy says it may keep content as long as needed to operate its systems. Fish publishes no fixed retention period for this text in those public terms. Read Fish's Terms of Use and Privacy Policy. Weather comes from Apple WeatherKit with a coarse location.

iOS permissions, and what each one is for

Every one of these is an iOS permission you grant, and every one can be revoked at any time in Settings. Where a permission's data can travel in a model request, it says so.

Microphone
Ambient listening. Short ambient chunks travel through our authenticated server to Moonshot's private Google Cloud speech-transcription service and are deleted when transcription finishes. Transcript text can travel in later model requests.
Contacts
Names for correct spelling and for knowing who you mean. Names, numbers, and email addresses can travel in model requests.
Calendar
Your rhythm and what is coming. Event titles, times, and locations can travel in model requests.
Reminders
Creating and completing reminders you asked for. Relevant reminder text can travel in a model request when you ask about reminders.
Photos
Moonshot analyzes dates, locations, and a small image sample on-device to learn places and recurring themes. Photos never leave the phone. Derived place and theme facts can become part of the Mind mirrored on our server.
Location
Coarse position for Apple Weather and an on-device place diary. Precise routes stay on the phone. Weather and derived place facts can appear in model context or the Mind mirrored on our server.
Health
Read-only sleep timing for the morning brief. When you ask about sleep, relevant timing and duration can travel in a model request.
Notifications
Push. Your device's Apple push token is stored on our server so Moonshot can reach you.
Focus
One bit — whether a Focus is on — so Moonshot stays quiet.

Calls

Moonshot calling is retired.

Google user data

Connecting Google is required to finish initial setup. One Composio Google Super connection asks once for Gmail, Calendar, Drive, Contacts, and verified Google email. That consent powers Gmail reading and reviewed sending, Calendar reading and reviewed changes, contact-name recognition, Drive file-name and metadata context, and account-owned snapshots. Moonshot restricts the connection to the named Composio tools for those features. Moonshot requests these scopes and no others:

mail.google.com
Google describes this scope as full Gmail access. Moonshot restricts its Composio auth config to fetching mail metadata and preview snippets, fetching one selected message, reading the Gmail profile, sending a reviewed email, and replying to a reviewed thread. The app does not fetch message bodies during inbox import. Every send waits for the five-second confirmation bar.
calendar
Google describes this scope as full Calendar access. Moonshot reads events and uses the create, change, or remove tools only after your confirmation. Apple Calendar on the phone is a separate source.
drive
Google describes this scope as full Drive access. Moonshot restricts its Composio auth config to listing file names and metadata. It does not download file contents through this connection.
contacts.readonly
Moonshot reads contact display names for recognition and spelling. It does not import Google contact email addresses through this connection.
userinfo.email
In the same Google Super connection, Google returns a verified email and stable account id (`sub`). Our server uses that response to verify the connected Google service, returns a short-lived proof bound to this phone, and uses the email only to show which Google connection supplied a snapshot. The Apple-backed Moonshot account owns the snapshot.

When Composio manages a connection, it presents Google's authorization screen and stores and refreshes the resulting Google token. Moonshot's app and server do not receive that token. The app asks our server for mail metadata, preview snippets, calendar events, contact names, and Drive file names and metadata; the server relays those requests through Composio and does not store the responses. A fresh connection checks Composio's live managed Google catalog before opening. Moonshot opens no second Google authorization client.

All active Google requests run through Composio. Managed Gmail connections check for new mail while the app is awake. Gmail, Calendar, Drive, Contacts, and account identity share one revokable grant. Moonshot does not fetch Gmail message bodies during inbox import or Drive file contents. Older builds may have left a Google credential in the iPhone Keychain; the current app can only revoke or erase that dated credential and never uses it for a feature.

The mail headers and preview snippets described above travel in the model request that builds your Mind. Facts learned from mail or Calendar, Google contact-name vocabulary, and Drive file-name context can become part of the Mind we mirror (see what we keep). Google user data is used for those features and for nothing else: never for advertising, never sold or transferred, never used to train any model, and never read by a human on our side except with your permission or where the law requires it.

Moonshot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnect Google from the app at any time, and revoke Moonshot's access to your Google account at myaccount.google.com/permissions.

The controls that protect this data in transit, at rest, and from unnecessary access are listed in How sensitive data is protected.

How sensitive data is protected

All network traffic is encrypted in transit with HTTPS/TLS. That covers traffic between your phone and our server, your phone and Google, and our server and Anthropic, Composio, or Fish Audio.

Server-held data is encrypted at rest by Google Cloud's provider-managed encryption. Data stored by Moonshot on your iPhone also receives iOS's built-in device encryption and data protection. The server copies listed below are not encrypted under a key only you hold; that limit remains stated in What our server keeps.

Moonshot limits access to the least privilege needed for each feature. A random per-device identity key is kept in the iOS Keychain and our server uses its irreversible hash to separate one device's records from another's. Sign in with Apple supplies the stable identity for the Moonshot account; the server stores only an irreversible hash of that Apple identifier. The server also keeps the Apple refresh token needed for deletion inside an AES-256-GCM encrypted envelope. Its encryption key is kept separately in Doppler and mirrored only to the server runtime. Composio reads Google's verified userinfo to prove which Google service is connected. The server returns a short-lived signed proof bound to the authenticated phone. It stores only an irreversible hash of a previously watched Gmail address. Composio stores Google tokens, while Moonshot receives only the requested tool results and identity fields. Each managed auth config is limited to the listed scopes and named tools. Moonshot does not fetch Gmail message bodies, and no person on our team reads Google user data unless you give permission or the law requires it.

We keep server-held data until you use Delete all data. That single request removes the device record, mirrored files, call records, standing orders, receipts, account snapshots, the Apple account record, its encrypted Apple revocation credential, and its device bindings. Moonshot first asks Apple to revoke that credential, then removes the records after Apple confirms the request. The exact behavior and the Gmail-watch exception are described under Your control.

We promptly investigate any breach affecting your data and notify affected users. We also take steps to contain the incident and prevent it from recurring. Write to privacy@moonshot.computer to report a suspected incident.

Google user data is never sold, never used for advertising, and never used to train models. Moonshot uses it only for the user-facing features described in this policy.

What our server keeps

Our server runs on Google Cloud and stores the account and per-device records listed below. Everything is kept until you erase it; there is no other schedule.

  • an irreversible hash of Apple's stable account identifier, an AES-256-GCM encrypted Apple refresh token used only for deletion-time revocation, and the proved devices bound to that Moonshot account
  • the standing orders you wrote and the receipts of what Moonshot did about them
  • your Apple push token, and your time zone
  • the phone number you verified as your caller ID, and when you verified it
  • an irreversible hash of the Gmail address being watched
  • the update-note version IDs you acknowledged, and when you acknowledged them
  • your call records: the transcript turns from both sides, and what Moonshot made of them
  • content-free model batch receipts: provider batch id, state, token counts, cost, and a one-way request hash. These receipts contain no transcript text or model output
  • mirrored copies of your Mind, your pending notes, your ledger, and your morning history. The Mind can contain derived facts from sources you connected, including contacts, calendars, and on-device photo or place analysis. These copies are stored as opaque bytes that the server never opens, parses, or sends to a model

Call audio, ambient audio, your voiceprint, your photos, and your Gmail token are never stored on our server. What is stored there is held in ordinary storage rather than encrypted under a key only you hold; encrypting it that way is the next thing we want to do, and until it ships this sentence is the honest description. The Apple revocation credential is the exception: Moonshot encrypts it with a separate application key in addition to Google Cloud's storage encryption.

Half of every call transcript belongs to the person you were talking to, who agreed to a conversation with you. We think that is the most sensitive material Moonshot holds, and we treat requests to remove it accordingly.

Your control

  • Every fact in the Mind can be corrected or forgotten one at a time, and the whole Mind can be erased, from the Mind screen.
  • Settings has Delete all data: it clears the Mind, the ledger, your voiceprint, every call record and its audio, and your connected service grants from the phone. The server revokes Moonshot's Sign in with Apple refresh token, then deletes the Apple-backed Moonshot account, every device binding, account snapshot, and associated server record in one request. After the server confirms deletion, the local Apple sign-in receipt is removed. The app shows you what came back: how many records were deleted, or, if the server could not be reached, that the copy is still there.
  • Any call record can be deleted on its own, and every synced call can be erased in one action.
  • Disconnecting Google revokes the one Composio Google Super grant for Gmail, Calendar, Drive, and Contacts. The app also erases any dated phone-held Google credential left by an older build.
  • Revoking any iOS permission in Settings stops that channel immediately.

Deleting is a deletion, not a flag: the request removes the mirrored files, the call records, the standing orders, the account, and every device binding, and nothing is kept behind to remember that the account was ever there. The app returns to account creation after a completed erase. One honest exception: if a Gmail watch cannot be stopped at Google in the moment, it lapses there within seven days; while it lasts it points at nothing.

If any of that does not behave the way this page describes, write to privacy@moonshot.computer and we will fix it and delete what is left by hand.

Who else touches it

Anthropic
Claude studies permanent Mind updates. Message Batch results remain available at Anthropic for 29 days.
OpenAI
The model that writes re-derivable section titles and notes.
Google
Gemini judges ambient sections; Google also provides Gmail, Calendar, Drive, Contacts, and the verified email for the connected Google service. Google Cloud runs our server and stores what is listed above.
Composio
Managed authorization and encrypted Google tokens for the active Google Super connection; it executes only the tools and scopes listed above.
Apple
Account authentication and deletion-time token revocation through Sign in with Apple, push notifications, and WeatherKit.
Textbelt
Sending the two creator launch texts a person requests.
Fish Audio
Turning only the text of Moonshot's spoken reply into speech. Fish's public terms permit model training and improvement uses described above.
Vercel, Supabase
This website, the waitlist, and creator launch reminder records.

Each one is a supplier doing a job for us. Moonshot works with no advertising networks, no data brokers, and no analytics vendors.

This website

The landing page loads an image, a font, and the code that draws it. It sets no cookies and runs no analytics. Joining the waitlist stores three things: the email address you typed, which of our domains you typed it on, and the time. Our host keeps ordinary server logs, as every web host does.

The creator launch page stores the phone number you type, the campaign and reminder time, the exact consent language you accepted, the time you accepted it, the site domain, your browser's user-agent string, and text delivery state. We use that record only to send the two launch texts you requested. The first arrives when the launch opens and the second confirms it 10 minutes later. Supabase holds the record. Textbelt receives the number and text content when each requested message is sent. Reply STOP to a text or email privacy@moonshot.computer to withdraw consent. We retain the consent and delivery record for up to four years so we can show that the communication was requested, unless you ask us to delete it sooner.

To be removed from the email waitlist, email privacy@moonshot.computer from that address. For a creator reminder, include the phone number you entered. We will delete the matching row.

Other people in the room

Moonshot hears whoever is near you and reads mail written by people who never installed it. Their words can end up in a transcript, and facts about them can end up in your Mind. Moonshot builds no profile of anyone to sell or share, and anyone can write to us to have material about them removed.

Children

Moonshot is built for adults and is not directed at children. We do not knowingly collect data from anyone under 13.

Changes

When the product changes what it collects, this page changes with it and the date at the top moves. If a change materially expands what leaves your phone, we will say so in the app before it takes effect.

Contact

Questions, deletion requests, and corrections to anything written here go to privacy@moonshot.computer.