Privacy Policy

MoodLens is operated by Moodlens Technology ("MoodLens", "we", "us", or "our"). This policy explains how we collect, use, secure, and disclose data when you use MoodLens websites, apps, desktop experiences, browser extension, workspaces, AI features, authentication flows, integrations, MCP/API surfaces, billing, and support channels.

Controller contact and operational base: Moodlens Technology, Carrer de la Riera Alta, 61, Ciutat Vella, 08001 Barcelona, Spain. Privacy and support contact: supports@moodlens-ai.com. Last updated: September 5, 2026.

1. Information We Collect

We follow a minimal data principle: we collect the information reasonably needed to authenticate users, run workspaces, process requests, secure the service, and communicate with you. We do not sell your personal data.

Financial, Invoice, and Payment Data: When using invoice, billing, contract-linked invoicing, or online invoice-payment features, MoodLens may collect invoice information including client names, email addresses, company details, billing addresses, VAT/tax numbers, invoice amounts, the related contract identifier and version, billing stage or period, stable duplicate-billing identifiers, payment-link status, provider and order references, payment status, paid and expected amounts and currencies, refund or manual-review status, and connected-account status. For a linked invoice, MoodLens compares limited agreement and invoice information—including status, project, currency, commercial amount, deposit schedule, version, related invoices, and billing identifiers—to prefill the requested draft, display its relationship and payment status, and reduce duplicate or excess billing. Stripe, PayPal, or NOWPayments processes card, bank-account, PayPal, blockchain, wallet-address, identity-verification, compliance, custody, conversion, and payout information in its own hosted systems as applicable. MoodLens does not store full card numbers, full bank-account numbers, PayPal login credentials, wallet seed phrases, or private keys. For NOWPayments, we securely store encrypted API and notification credentials supplied by the workspace owner and limited provider identifiers and status data required to create links, authenticate callbacks, reconcile payments, prevent duplicate fulfillment, and preserve legally or operationally necessary payment records. We use this information to provide the requested invoice, payment-link, reconciliation, and refund or review workflow, prevent fraud and abuse, and comply with legal obligations. It may be processed by infrastructure, storage, email, payment, blockchain-payment, or accounting providers needed to provide that workflow, and disclosed where law requires. Financial and tax records may be retained for up to 7 years where applicable law requires or permits that retention. You may request deletion or a review of invoice data by contacting supports@moodlens-ai.com; records that we must retain by law will be restricted rather than deleted until the applicable retention period ends.

2. Controller and Workspace Roles

Moodlens Technology is the data controller for account administration, service security, billing, direct support, and our own service operations. When an organization uses MoodLens to manage its staff, customers, or other workspace content, that organization may be the controller of the personal data it puts into MoodLens and Moodlens Technology generally processes that workspace content on its documented instructions in order to provide the service. Workspace owners and admins are responsible for configuring membership, permissions, public links, integrations, and the lawful use of the data they place in a workspace.

Notice for invited contract signers: The sending organization supplies the client and signer details, chooses which people are required to sign for the named client, and normally determines the agreement content and why those details are used. For that workspace-controlled agreement content, the sender is generally the controller and MoodLens acts as its service provider or processor. MoodLens separately determines limited processing needed to authenticate access, protect the service, prevent abuse, deliver transactional messages, provide support, and maintain defensible security records. We receive signer details from the sender and create a separate private link, verification challenge, access session, delivery status, and signature status for each invited signer. We collect the one-time-code events, consent choice, signature or optional decline reason, timestamps, document/evidence hashes, salted technical fingerprints, and an approximate network location when each recipient first opens the agreement after email verification. Authorized members of the sending workspace can see each signer's progress and that approximate city, region code, and country—or that no location was available—in the agreement audit history, but not the raw IP address. We use these records to deliver the requested agreement workflow, protect the parties and service, preserve the transaction record, and establish, exercise, or defend legal claims. Depending on the context, the legal basis may be performance of the requested service or agreement, the sender's and parties' legitimate interests in completing and evidencing a transaction, compliance with law, or the signer's explicit electronic-signature choice. Electronic-signature consent is not consent to advertising or unrelated processing.

The signing page provides direct links to this policy, the Terms, signing help, and our contact before the agreement is revealed and while it is reviewed. The signer can refuse to sign; without email verification and the required signing information, MoodLens cannot authenticate access or record the electronic signature. Authorized members of the sending workspace can see the agreement status, audit history, and any decline reason. For questions about the agreement or the sender's use of contract data, contact the sender. For MoodLens signing security, service data, or a privacy-rights request, contact supports@moodlens-ai.com. Rights may be limited where retaining a completed transaction record is necessary to protect another party's rights, comply with law, or handle legal claims.

Business customers that need a data processing agreement, security information, or a review of provider access can contact supports@moodlens-ai.com. This policy does not replace a separately agreed data processing agreement where one applies.

3. California Privacy Notice

This section supplements the rest of this Privacy Policy for California residents where California privacy law applies. Some rights apply only if MoodLens is legally treated as a covered business under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.

To submit a California privacy request, email supports@moodlens-ai.com from the email address used for your MoodLens account whenever possible. We may need to verify your identity, account relationship, or agent authorization before acting on requests.

4. How We Use Your Data

Product operations

Security and improvement

Contract: We process account, workspace, AI, integration, support, and billing data when needed to provide the service you request.

Legitimate interests: We process security logs, abuse-prevention signals, product reliability data, and limited analytics to keep MoodLens safe and working.

Consent or user direction: Optional features such as OAuth integrations, the browser extension, camera/microphone access, recordings, imports, and AI requests run when you choose to enable or use them.

Legal obligations: We may process records needed for tax, accounting, legal compliance, dispute resolution, law-enforcement requests, and rights handling.

We do not use your personal data for third-party advertising, and we do not sell or rent your personal data to advertisers or data brokers. Some information is required to create an account or provide a requested feature; if you do not provide it, that feature may not work.

5. Authentication, Providers, Integrations & AI

MoodLens relies on operational service providers to run infrastructure, hosting, storage, analytics, authentication, AI responses, communications, payments, calling, and integrations. Depending on the feature you use, limited data may be processed by those providers to complete the requested workflow.

If you choose Google, Microsoft, or GitHub sign-in, those providers authenticate you and may share basic profile data with us, such as your name, email address, profile image, and provider account identifier, depending on the scopes or claims granted and your provider settings.

We configure our supported AI providers so that personal data and workspace content sent for a MoodLens AI request are used to provide that request, not to train their generally available models for their own products. This statement applies only to providers and account configurations that we control; content you deliberately send to a third-party integration is also subject to that provider's own terms and privacy policy.

If you use AI features with uploaded files or media, our servers may read, download, parse, resize, transcribe, summarize, or convert authorized content into text, image parts, PDF/document parts, audio transcripts, screenshots, or extracted video frames before sending the needed content to AI providers for the requested workflow. Conversation history may cause earlier attachments to be included again as context.

Workspace owners and admins may see workspace content, member profiles, membership records, audit activity, billing state, integrations, automation logs, and other information needed to operate a shared workspace. Other members may see content shared with their workspace, channels, meetings, docs, tasks, or permissions.

Private media is served through authenticated access controls and workspace membership checks. If you publish a doc, share an artifact, or create another public link, the linked content and referenced media may be accessible to anyone with the link until it is unpublished or removed. External file URLs and embeds are controlled by the third-party service that hosts them.

Where and how data is stored

MoodLens stores account and workspace information in secured Google Cloud application services in the United States, including authentication, application databases, private file storage, and server-side processing services. In practical terms, account records, workspace records, chat and collaboration data, settings, security records, and attachment metadata are held in those systems; uploaded files and media are held in private cloud storage unless you choose to publish or share them.

We protect access through authenticated sessions, role and workspace membership checks, server-side authorization for privileged operations, Google Cloud security controls, HTTPS/TLS for data in transit, and restricted access to operational systems. Password authentication is handled by our authentication provider; Moodlens Technology does not keep your password in readable plain text. No security measure is perfect, and users must also protect their own credentials, devices, public links, API keys, and integration secrets.

Categories of providers that may process data

Depending on the features you use, the following categories of providers may process limited data on our behalf or at your direction: Google Cloud (application infrastructure and storage); AI service providers; payment and subscription processors; transactional email providers; real-time call and media providers; website delivery or analytics providers where enabled; and identity providers when you choose a third-party sign-in method. Connected integrations, messaging platforms, and external tools you authorize may receive the data needed to complete your request. We do not sell personal data.

6. AI, Automation & Human Control

MoodLens AI features can summarize, draft, classify, search, review, recommend, generate artifacts, prepare project plans, suggest task estimates, estimate budgets or rates, research public pricing, participate in team discussions, and help run automations or connected-tool workflows based on the context you provide and the permissions configured in the workspace. AI-generated plans, estimates, research, and assumptions are suggestions for human review, not professional financial, tax, legal, procurement, or vendor advice.

AI context can include prompts, workspace records, uploaded attachments, reference images, generated media, task-intake files, clip frames, call transcripts, meeting chat, summary PDFs, and previous conversation messages where the feature needs that context to answer or act.

MoodLens does not use solely automated processing to make decisions that produce legal effects or similarly significant effects about users. AI output should be reviewed by a human before you rely on it for important decisions, external actions, regulated advice, employment, finance, health, legal, or safety-sensitive matters.

AI employees, automations, MCP clients, webhooks, and integrations may act on workspace content only within the permissions, tokens, or secrets configured by users or workspace admins. You can disconnect integrations, rotate keys, delete stored secrets, or contact us for help reviewing data access.

AI Transparency and Generated Content

MoodLens identifies features intended for direct interaction with AI, including Moody and AI Employees. Content generated or materially modified by these features may include a visible AI-generated notice and machine-readable origin information where the format and technology support it.

AI-origin information may be stored with workspace content and generated files so the disclosure can remain attached when content is viewed, shared, published, or downloaded. It may include whether content was AI-generated, the MoodLens feature involved, and the generation time. Some file formats, external platforms, or later edits may remove or alter embedded metadata.

We process this information to provide transparency, preserve content history, prevent misleading attribution, maintain security, and comply with applicable law. AI-origin information does not by itself determine whether content is accurate or who owns it, and we do not use it to make decisions about users or infer sensitive characteristics.

You remain responsible for reviewing AI output before relying on, sharing, or publishing it. If you remove an AI disclosure or modify generated content outside MoodLens, you are responsible for any disclosure that remains legally required.

7. Your Rights Over Your Data

Depending on your location and the laws that apply, you may have rights to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing or withdraw consent where consent is the legal basis.

To exercise these rights, contact us at supports@moodlens-ai.com from the same email address you use to sign in to MoodLens so we can match the request to the account. If we cannot verify the requester, we may ask for additional confirmation or be unable to complete the request. We will respond within the timeframes required by applicable law. You can also visit the AEPD at aepd.es.

8. Retention, Security & International Processing

We use the following retention criteria:

After a verified deletion request, we remove or anonymize data from active systems where applicable, subject to the retention criteria above. We do not use retained backup, security, billing, or dispute records for unrelated product activity.

Some in-product deletion actions soft-delete records or remove visible links before underlying files, generated PDFs, transcripts, AI context, cached results, or backups are fully removed. Workspace clips are designed to delete the linked storage object when deleted; local clips are stored in your browser and can be removed from that browser. For a broader deletion request, email supports@moodlens-ai.com so we can review account, workspace, storage, backup, and legal-retention records.

We use industry-standard safeguards designed to protect data, including access controls, encrypted transport, and secure infrastructure practices. No method of storage or transmission is completely secure, but we work to reduce risk and respond appropriately to security incidents.

MoodLens applies authentication, membership checks, file size limits, supported content-type checks, private media proxy controls, and public-link checks for published content. These controls reduce risk but do not guarantee that every unsafe, infringing, or malicious file will be detected before it is uploaded or viewed.

Because we use providers that may operate in multiple countries, your data may be processed outside your city, region, or country. Where required, we rely on appropriate contractual, technical, or organizational safeguards, such as adequacy decisions, standard contractual clauses, or equivalent transfer measures.

9. Cookies & Similar Technologies

We use strictly necessary cookies and similar technologies for authentication, security, session continuity, preferences, and basic product functionality. We do not use third-party advertising cookies to profile you across unrelated sites for ads.

MoodLens does not intentionally set non-essential analytics or advertising cookies on its public pages without first providing any consent and preference controls required by applicable law. If we introduce non-essential cookies or similar technologies, we will update this policy and present the applicable choice before those technologies are set.

These technologies may include session cookies, local storage, security tokens, and login-state markers. If you use Google, Microsoft, or GitHub sign-in, those providers may also use their own cookies or similar technologies as part of their OAuth or OpenID Connect authentication flows, subject to their own policies. You can control browser cookies through your settings, but disabling some technologies may affect how the service works.

Because there is no single industry standard for browser Do Not Track signals, we do not currently respond to those signals. Where a legally recognized opt-out preference signal applies to a sale or sharing of personal information, we will honor it as required; at present, we do not sell personal information or share it for cross-context behavioral advertising.

10. Changes, Controller Details & Contact

We may update this Privacy Policy from time to time. We will post the updated version here and revise the "Last updated" date. For material changes, we may notify you in-product or by email when required by law.

For the purposes of this policy, MoodLens is operated by Moodlens Technology, Carrer de la Riera Alta, 61, Ciutat Vella, 08001 Barcelona, Spain. If you need to exercise privacy rights or contact us about a data issue, please email supports@moodlens-ai.com.

We use this email as the primary privacy contact. If a dedicated data protection officer, representative, or additional controller contact becomes required or appointed, we will publish those details here. We will respond in good faith and within the timeframes required by applicable law.