Privacy
MoonWise holds a log of your baby’s days. That is sensitive, and it is yours. Here is exactly what we keep, where it lives, who else touches it, and how to take it back.
Last updated 1 August 2026
The short version
- We collect what the app needs to work: your account details, your baby’s profile, everything you log, and your conversations with Luna.
- It is stored in our own PostgreSQL database on a server we rent and manage in Canada. We do not use a third-party data platform.
- When you use Luna, your message and a summary of your baby’s logged data are sent to Google’s Gemini API to generate the reply. That is the only place your content leaves our servers.
- We do not sell or share your data, we run no advertising or analytics trackers, and we send no marketing email.
- You can export everything or delete everything yourself, from Settings, at any time. Both are free on every plan and neither needs to go through us.
What we collect
Your account. Your name, your email address, and either a password (stored only as a salted hash — we never see or store the password itself) or, if you sign in with Google, the identifiers Google returns for your account. Also the date you signed up.
Your baby’s profile. The name or nickname you give them, their date of birth, a colour, and an optional bedtime. Nothing else — no photos, no health records, no identifiers.
What you log. Every entry you create: sleeps (start and end time), feeds (bottle, breast or solid — including amount, minutes per side, and the food text you type), pumping amounts, and diapers (wet/dirty and consistency), plus any note you attach to an entry.
Goals. The goal text you write, the plan Luna drafts for it, and the progress notes you add.
Conversations with Luna. Every message you send and every reply she gives, kept by day so you can read back through them. If Luna logs or edits an entry on your behalf, a record of that action is stored alongside the message.
Preferences. Your theme and Luna’s appearance.
Sign-in records. For each active session we store the session token, its expiry, and the IP address and browser user-agent it was created from. This is how the app knows it is you, and how a stolen session could be spotted.
Usage records. Each time Luna generates something we record which surface it was (chat, schedule, goals), which AI model was used, the number of tokens in and out, an estimated cost, and the time. This is how the free allowance and the paid daily cap are counted. It contains no message content.
Billing. If you subscribe, we store the Stripe customer and subscription identifiers, the plan status and the renewal date. We never receive or store your card number — that goes directly to Stripe, who process the payment.
What we do not collect. No advertising or analytics trackers, no third-party cookies, no location data, no contacts, no device fingerprinting, and no data about anyone other than you and the children on your account.
Why we hold it
- To run the app you asked for. The log, the profiles, the predictions and the conversations are the product — without them there is nothing to show you.
- To keep your account secure. Sessions, sign-in records and password hashes exist to keep other people out of your data.
- To count usage fairly. The free tier gives everyone a few Luna messages and the paid tier has a daily cap; the usage records are how those are counted and how we keep the service affordable.
- To take payment, if you choose to subscribe.
We do not use your data or your conversations to train any AI model of our own, and we do not use them for advertising.
Where it lives
MoonWise runs on a server we rent and administer ourselves, located in Canada. Your data sits in a PostgreSQL database on that server, reachable only over the local loopback interface — it is not exposed to the internet. Traffic between your device and the app is encrypted over HTTPS.
We are a Canadian operation, so Canadian law applies to us. If you are in the European Economic Area or the UK, storing your data in Canada is an international transfer: Canada has been recognised by the European Commission as providing an adequate level of protection for personal data handled by commercial organisations under PIPEDA.
Luna, and what reaches Google
Luna is powered by Google’s Gemini API. Every AI call is made from our server using our key — the key is never in your browser, and your device never talks to Google directly.
What we send Google, and only when you actually ask Luna for something:
- the message you typed;
- your baby’s first name and their exact age in weeks;
- a summary of their recent logged entries — sleep patterns, feeds, diapers — so the answer is about your baby rather than a generic one;
- the earlier messages in that day’s conversation, for continuity.
What we do not send: your name, your email address, your account identifier, your payment details, or anything about any other family.
Once that request reaches Google, Google’s own terms govern what happens to it, including whether it is retained and for how long. That is their policy and not something we control, so if it matters to you, read Google’s Gemini API terms before you type anything into Luna that you would not want a third party to hold.
If you never open Luna, nothing about your baby is ever sent to Google. The tracker, the stats, the wake-window tables and the sounds all run without any AI call at all.
Cookies
MoonWise sets three cookies. None of them are for advertising or analytics.
- better-auth.session_token — proves you are signed in.
- better-auth.session_data — a short-lived signed copy of your session so most page loads do not need a database read. It expires after five minutes.
- mw.activeBaby — remembers which child you were last looking at.
How long we keep it
Your log is kept for as long as your account exists. It is a history — a six-month-old sleep pattern is exactly the thing that makes next month’s prediction useful — so we do not quietly expire it.
When you delete your account, the deletion is immediate and permanent. There is no soft-delete, no thirty-day grace period, and no archived copy we could restore for you if you changed your mind. Everything goes in one database transaction: the account, the children, the entries, the goals, the conversations, the sign-in records and the usage log.
The one exception is operational backups of the database. A deleted record can survive inside an existing backup until that backup is overwritten or destroyed. Backups are retained for no more than 30 days and are then deleted automatically, so a deleted account is gone from every backup within 30 days of deletion. Sessions expire on their own, and email-verification and password-reset tokens are short-lived and are deleted with your account.
Your rights
Two of them are buttons rather than requests. Both are free on every plan, take effect immediately, and never involve emailing us:
- Export everything.Settings → Data & backup → Export all data gives you a JSON file containing every profile, entry, goal and conversation on your account. It is readable, portable, and can be imported back into MoonWise.
- Delete everything.Settings → Data & backup → Delete my account. You confirm by typing your own email address, because it cannot be undone.
If you are in Canada, PIPEDA gives you the right to know what personal information we hold about you and why, to access it, to have inaccurate information corrected, to withdraw consent, and to challenge how we handle it. If we cannot resolve a complaint to your satisfaction you can take it to the Office of the Privacy Commissioner of Canada.
If you are in the EEA or the UK, the GDPR gives you the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests — and the right to lodge a complaint with your national supervisory authority. The export and delete buttons cover access, portability and erasure without you having to ask. For anything else, write to privacy@alpacalaunch.com and we will answer within 30 days.
Children
MoonWise is a tool for parents and caregivers. The account belongs to an adult; the data in it is about a baby or young child who cannot consent for themselves, which is exactly why we keep the collection narrow, refuse to sell or share it, and make deletion a one-step, no-questions operation.
MoonWise is not intended for use by children, and we do not knowingly create accounts for anyone under 16.
Who else touches your data
- Google (Gemini API) — generates Luna’s replies. Receives only what is listed above, and only when you use an AI feature.
- Stripe — processes subscription payments and holds your card details. Only involved if you subscribe.
- Our hosting provider — rents us the server the app and database run on. They do not access the data; they operate the machine.
That is the entire list. There are no others, and we do not sell data to anyone.
Security, honestly stated
Passwords are hashed, traffic is encrypted, the database is not exposed to the internet, AI keys stay on the server, and every read and write is checked against the signed-in account so one family can never reach another’s data.
No system is perfectly secure. If we ever discover a breach affecting your data we will tell you and the relevant regulator, promptly and specifically, rather than vaguely and late.
Changes, and how to reach us
If this policy changes in a way that affects what we collect or who we send it to, we will say so in the app rather than quietly editing this page and changing the date at the top.
Questions, requests, or complaints: privacy@alpacalaunch.com.