On this page
In short
The main points
- We collect what we need to run your workspace: your account, your mailboxes, your contacts, your campaigns and what MoonAgent does for you.
- Contacts in a workspace are that workspace's data. We process them only to provide the service to it.
- We do not sell personal data and we do not show ads.
- MoonAgent sends your requests, and the data it needs to answer them, to DeepSeek, an AI provider that processes data in China.
- Lead search and email verification use Apify and public websites. We also keep a lead library for our own outreach; it is never searched for other workspaces.
- You can export your workspace from Settings at any time, and ask us to correct or delete anything else.
Who we are
Moonreply is owned and operated by Nafran.com. In this policy, "we" and "us" mean Nafran.com. You can reach us at aamirmursleen@gmail.com.
This policy covers moonreply.com, the Moonreply app and the emails sent through it. Moonreply is also open source software that others can run on their own servers. Those copies are not covered here; whoever runs one is responsible for it.
Our role and the workspace's role
For your account, your use of our website and billing, we decide how personal data is used. In data protection law we are the controller of that data.
For the contacts a workspace adds and the emails it sends, the workspace decides who to contact and why. The workspace is the controller, and we process that data on its behalf, following its instructions and this policy. If you want to know why a workspace emailed you, or you want it to stop, contact that sender. You can also contact us and we will pass your request on.
Some contact data comes from lead search tools we provide, and we keep a lead library for our own outreach. For those records you can send your request straight to us, whether or not a workspace has contacted you.
What we collect and why
Here is each kind of data in brief. The data we collect page has the full table, with examples, how long we keep each kind and who receives it.
About you, when you use Moonreply
- Account and sign in. To create your account, sign you in and check that every request really comes from you.
- Workspace details. To keep each workspace separate, decide who may do what, and include the sender address the law requires in commercial email.
- Team invitations and team changes. To let the invited person join with the role offered, only from the email address the invitation was sent to, and to show the owner and admins how the team changed.
- Connected mailboxes. To send your campaigns and replies from your own mailbox, and to read new mail in it to find replies and bounces.
- MoonAgent conversations and memory. To answer your requests, keep a history you can return to, and remember context you chose to save.
- Job outreach profile. To tailor job search emails to your experience.
- Integrations, keys and webhooks. To import contacts from your CRM, let tools you authorize use your workspace, and notify your own systems of events.
- Usage, limits and delivery tests. To apply plan and daily limits, control costs, and show whether your mailbox authenticates correctly.
- Plans and payments. To apply the plan you paid for, add the verified contacts you bought, apply the limits of your plan and answer billing questions.
- Retired LinkedIn records. None today. The feature is retired and no longer contacts LinkedIn.
About people who receive emails sent with Moonreply
- Contacts and lists. To build campaign audiences and personalise messages for the workspace that added them.
- Campaign emails and sending history. To send each step exactly once, keep replies in the same thread and report results.
- Opens and clicks. To report on campaigns and to branch a sequence when someone opens or clicks.
- Unsubscribes and suppression. So nobody who asked to stop, or whose address bounced, is emailed again by that workspace.
- Replies and other inbox mail. To stop a sequence when someone replies, suppress bounced addresses and show replies in the inbox.
- Lead research and email checks. To search contacts already found before paying for a new search, avoid duplicates, and offer only addresses that passed a mailbox or domain check.
- Find contacts previews. So you can check the sources before importing any contact.
- Lead library. To find contacts for our own outreach before paying for a new search.
About everyone who visits our site or app
- Server and network logs. To keep the service secure, stop abuse and fix problems.
- Website analytics. To understand which pages people use and how fast they load.
- Cookies and browser storage. To keep you signed in, protect mailbox connections and remember choices such as a collapsed sidebar.
We do not ask for sensitive data such as health, religion or political views. Please keep it out of contacts, campaigns, resumes and MoonAgent messages.
Legal bases
Where laws such as the GDPR and the UK GDPR apply, we rely on these legal bases:
- Contract. To create your account, run your workspace, connect your mailboxes, send what you ask us to send and provide MoonAgent.
- Legitimate interests. To keep the service secure, prevent abuse and spam, control costs, fix and improve the service, and help business users find relevant business contacts. We weigh these interests against your rights, and you can object at any time.
- Legal obligation. To keep records the law requires, such as the sender address in commercial email, and to honour unsubscribe requests.
- Consent. For website analytics and saved display preferences, and for sending your resume to our AI provider in Job outreach. You can withdraw consent at any time.
When we process contacts for a workspace, the workspace chooses the legal basis for contacting them, usually its legitimate interest in relevant business outreach, and it must follow the sending rules in our terms of service.
If you received an email sent with Moonreply
Emails sent with Moonreply come from a workspace's own mailbox and are written by that workspace. The sender, not Moonreply, chose to contact you.
- Where your address came from. The workspace added it, for example from its own records, its CRM, a public company website, or Moonreply's lead search, which finds business contact details in public sources. If we contacted you ourselves, your details may come from our lead library, described below.
- How to stop it. Every campaign email has an unsubscribe link, and email apps that support one click unsubscribe show their own button. Either one stops all further campaign email from that workspace to your address, and your address stays on its suppression list so it stays that way.
- Unsubscribing by reply or by email. This works too. An email with the subject unsubscribe, or a reply whose first line is unsubscribe or remove me, stops campaign email from that workspace to your address automatically. Other requests go to the sender's inbox, and the sender has to act on them. The unsubscribe link is the fastest way.
- Tracking. The email may record when you open it or click a link. See email tracking.
- Your data. To ask what is held about you, or to have it deleted, contact the sender, or email us at aamirmursleen@gmail.com with the address concerned and, if you can, the sender's name. We will act on it or pass it to the workspace that controls it.
If you think a sender broke the law or our rules, tell us. We can suspend workspaces that do.
Email tracking
Workspaces can turn open and click tracking on or off for each campaign. A new campaign starts with both off, and records opens or clicks only after the workspace switches them on.
- Open tracking adds a tiny invisible image to the email. When your email app loads it, we record that the email was opened.
- Click tracking sends each link through our tracking address first. We record which link was clicked, then take you to the page.
- We do not store your IP address, device or location with these records. Our server keeps the IP address in memory for a few minutes to limit abusive traffic. Cloudflare or our server's proxy handles these requests and sees the IP address and browser details while passing them on.
- Many email apps and security scanners load images and links automatically, so these records are estimates.
- You can prevent open tracking by turning off automatic image loading in your email app.
In the European Union and the United Kingdom, tracking of this kind can require the recipient's consent. Our terms require workspaces to use tracking only where they may lawfully do so.
AI processing with MoonAgent
MoonAgent is the AI assistant in Moonreply. Its answers come from DeepSeek, an AI model provider. When you use MoonAgent, we send DeepSeek:
- your messages and the conversation so far, or a summary of it
- your workspace name, saved memories and the titles of saved items
- the results of what MoonAgent looked up for you, which can include contact names, email addresses, job titles, companies, LinkedIn profile addresses, where a contact was found, reply snippets and campaign statistics
In Job outreach, when AI drafting is on and you have agreed, we also send your resume text (up to 8,000 characters, without the file name) and your job preferences with each MoonAgent request in job mode, and with each draft request together with the name, company and role of the contact involved. Job outreach asks for your agreement before your resume is used this way and records the date on our server; without it, your resume is not sent. To withdraw it, choose Withdraw consent on the Job outreach page, remove your profile or email us. Before you save your resume, remove anything you do not want to share, such as your home address, phone number or date of birth.
DeepSeek processes data in the People's Republic of China, according to DeepSeek's privacy policy. It handles this data under its own terms and privacy policy. Do not give MoonAgent personal data you are not allowed to share with it.
AI output can be wrong. MoonAgent prepares drafts and lists for you to review; it never sends email or launches a campaign on its own. Check every fact before you approve anything. Moonreply does not use your data to train AI models. DeepSeek's Open Platform terms do not promise that API inputs are excluded from provider training; its general privacy policy says it may use personal data to improve and train models and describes an opt out. Review the current DeepSeek Open Platform terms and account settings before sending confidential data. We do not promise that DeepSeek will not train on API inputs.
Lead search and verification
MoonAgent and Find contacts help workspaces find business contacts. They look in this order:
- Saved research. Contacts already found for the same workspace, kept in a lead research database with the source of each contact.
- New searches. Business listings from Google Maps, collected by a tool that runs on Apify, and, only if we switch them on, Google Places and a business data service on RapidAPI. The Apify tool can also read each listed business's public website for contact addresses. It runs on Apify's servers, not ours, so it does not identify itself as MoonreplyContactBot.
- Public websites. Our server reads public company pages, identifies itself as MoonreplyContactBot and respects the site's robots rules. If you choose Read more deeply, the page addresses go to a page reading tool on Apify.
- Verification. We check the address format and the domain's mail servers, and a verification tool on Apify may ask the mail server whether the mailbox exists. It receives only the email address.
Our lead library
A library of business contact records (name, work email, job title, company, website, professional profile address and location) that we compiled from third party business contact datasets, including exports of professional profile data and business contact databases. We keep it in Google Colab and Google Drive, and only our own workspace searches it, for our own outreach. Research contacts and verification results from our own workspace can be copied into it. It is searched through a secure tunnel and is never searched for, or shared with, other workspaces.
If you are a business contact and you do not want to be found through Moonreply, email aamirmursleen@gmail.com. We will delete the records we hold about you in our lead research database. Removing you from our lead library is a manual step today, and we will tell you when it is done. Public sources can list your details again later; if that happens, tell us and we will remove them again.
Access to your mailbox
When you connect a mailbox, Moonreply can send email from it and read new messages in its inbox. Our software reads each new message to find replies, bounces and automatic replies to emails sent with Moonreply. We store what we need from those (subject, the first 160 characters, message IDs and how we classified them). Other messages, including automatic messages that do not answer an email we sent, are checked and then discarded.
Your mailbox password or access token is encrypted with AES 256 GCM, using a key held on our server. It is never shown again after you save it and never included in exports.
Gmail and Google user data
To connect Gmail, Moonreply asks Google for full Gmail access, which Google requires for sending and reading mail over standard mail protocols. Moonreply's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Gmail data only to send the emails you ask us to send, to find replies and bounces, to show them to you, and, when you ask MoonAgent about your replies, to let it read short reply snippets.
- We do not use Gmail data for advertising, we do not sell it, and we do not use it to train AI models.
- People at Moonreply do not read your Gmail data unless you ask us to for support, it is needed for security, or the law requires it.
How long we keep data
- Your account: while it exists. To close it, email us.
- Workspace data, including campaigns, sending history, tracking records and MoonAgent conversations: while the workspace exists. Workspaces are deleted on request.
- Contacts: until a workspace member deletes them. Records of sent emails keep the recipient's address, subject and first 160 characters.
- Unsubscribes and bounces: for as long as the workspace exists, so the address is not emailed again by that workspace.
- Mailbox passwords and tokens: until the mailbox is removed. A mailbox that has sent campaign email can only be paused in the app; ask us to erase its credentials.
- Job outreach profile: until you remove it.
- Find contacts previews: seven days.
- Webhook delivery records: 30 days.
- Lead research, email checks and the lead library: until the workspace or the person concerned asks us to delete them.
- Server and network logs: for the periods set in our hosting and Cloudflare settings.
When we delete a workspace at your request, we delete its records from our database, including its lead research records, except where the law requires us to keep them. Copies in our daily backups expire after 14 days.
International transfers
Our main server runs with our hosting provider. Several of our providers may process data in other countries, including the United States and, for DeepSeek, the People's Republic of China.
Where data protection law requires it, we rely on the transfer safeguards our other providers offer in their data processing terms, such as the European Commission's standard contractual clauses. We have not confirmed that DeepSeek offers such a safeguard, so do not assume one applies to data sent to it. China has no adequacy decision from the European Union or the United Kingdom, so data sent to DeepSeek may not be protected to the same standard as at home. If that concerns you, do not use MoonAgent or AI drafting in Job outreach.
Security
- Connections to Moonreply use HTTPS.
- Mailbox passwords and tokens, Job outreach profiles, Find contacts previews, integration tokens and webhook secrets are encrypted with AES 256 GCM.
- API and MCP keys are stored only as a fingerprint (a SHA 256 hash).
- Every request is checked against your sign in and your workspace membership.
Other data, including the lead research database, is protected by our server's access controls rather than separate encryption. No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities when the law requires it.
Your rights
Depending on where you live, the law gives you rights over your personal data. Wherever you are, you can ask us to:
- give you a copy of your data
- correct data that is wrong
- delete your data
- limit how we use it, or object to our use of it, including for lead search
- give your data to you, or to another service, in a common format
- withdraw a consent you gave, without affecting what was done before
How to use them today
- Export. Any workspace member can download the workspace's contacts, lists, campaigns, messages, events, suppression list and mailbox settings (without passwords) from Settings, Export your data. MoonAgent conversations, the Job outreach profile, lead research records and a few other records are not in that export yet; email us for a copy.
- Job outreach profile. Choose Remove profile on the Job outreach page.
- MoonAgent memories. Open Memory in MoonAgent and delete any entry.
- Everything else. Email aamirmursleen@gmail.com. This includes closing your account, deleting a workspace or its contacts, deleting MoonAgent conversations, and removing yourself from our lead research database or lead library.
We answer within one month. We may ask you to confirm your identity first. When a workspace controls the data, we pass your request to it and help it respond.
You can also complain to a data protection authority, for example where you live or work. In the United Kingdom that is the Information Commissioner's Office; in the European Union it is your national data protection authority. We would welcome the chance to help first.
People in some US states, such as California, have similar rights to know, correct and delete their data and to opt out of its sale. We do not sell personal data.
Children
Moonreply is for people aged 18 and over, using it for work or for their own job search. We do not knowingly collect data about children. If you think a child has given us personal data, email us and we will delete it.
Changes to this policy
We post every change here with a new date. If a change is significant, we also tell account holders by email or in the app before it takes effect.
Contact
For privacy questions and requests, email aamirmursleen@gmail.com.