Skip to main content

Legal

Third party services

Every company that processes data for Moonreply, every script and embed on our pages, and what each one receives.

Last updated

On this page

In short

The essentials

  • Clerk signs you in. Cloudflare runs our network, and our hosting provider runs the server.
  • Your own mailbox provider sends every email. DeepSeek powers MoonAgent. Apify runs lead search and email verification.
  • Analytics loads only after you allow it in Cookie settings, and it sets no cookies.
  • No advertising networks, social media pixels or chat widgets run on our pages.

Each service below receives only what it needs for its task and processes it under its own terms and privacy policy. Our privacy policy explains why, and the data we collect page shows what we keep ourselves.

Running the service

Hosting, sign in and the network in front of Moonreply.

Running the service: services and the data they receive
ServiceWhat it receivesWhen
Our server hosting providerRuns the virtual server that holds our database, the application, the lead research database and their logs.Everything Moonreply stores, and server logs.Always.
ClerkSign in and account management.Privacy policy of ClerkYour name, email address, sign in method, sessions, IP address and device details. Our server also asks Clerk for member names and emails to show the team in Settings and label who owns an inbox conversation. Team invitations are sent from the active mailbox connected by the workspace owner.Every sign in and every signed in page.
CloudflareDomain name service, network proxy, security checks, website analytics, secure tunnels and DNS lookups.Privacy policy of CloudflareWebsite and app traffic, including IP addresses and browser details; page views if you allow analytics; open, click and unsubscribe requests from email recipients when our tracking address runs through Cloudflare; domain names checked in the DNS audit; lead library searches sent through a Cloudflare tunnel.Continuously.
Google Public DNSBackup DNS lookup for the DNS audit.Privacy policy of Google Public DNSThe sending domain names being checked.Only when the Cloudflare lookup fails.

Email and mailboxes

The providers of the mailboxes you connect. You choose them.

Email and mailboxes: services and the data they receive
ServiceWhat it receivesWhen
Google (Gmail and Google sign in)Mailbox provider for Gmail and Google Workspace, and an optional way to sign in.Privacy policy of Google (Gmail and Google sign in)For Gmail: the access you grant, every email you send, and new inbox mail read to find replies and bounces. For sign in: your Google name, email address and picture, passed to Clerk.When you connect Gmail or choose Google sign in, and whenever a Gmail mailbox sends or is checked.
Microsoft (Microsoft 365 and Outlook)Mailbox provider for Microsoft accounts.Privacy policy of Microsoft (Microsoft 365 and Outlook)Access tokens, your profile email and name, every email you send, and new inbox mail read to find replies and bounces.For Microsoft mailboxes already connected. New Microsoft connections are paused.
Your own email hostAny mailbox provider you connect with a server address and password.Your mailbox password, the emails you send and new inbox mail.Every send, connection test and inbox check.

AI

The model provider behind MoonAgent.

AI: services and the data they receive
ServiceWhat it receivesWhen
DeepSeekThe AI model behind MoonAgent and Job outreach drafting.Location: People's Republic of China, according to DeepSeek's privacy policy.Privacy policy of DeepSeekYour MoonAgent messages and conversation history or its summary; your workspace name, saved memories and item titles; and the results of MoonAgent's lookups, which can include contact names, email addresses, job titles, companies, LinkedIn profile addresses, source notes, reply snippets and campaign statistics. In job mode, your resume text (up to 8,000 characters) and preferences.Every MoonAgent request, while MoonAgent is switched on. Resume text only while Job outreach AI drafting is on.

Lead search and verification

Sources and tools used to find and check business contacts.

Lead search and verification: services and the data they receive
ServiceWhat it receivesWhen
ApifyRuns the tools we use for business search, page reading and email verification.Privacy policy of ApifyBusiness search terms and locations, public company page addresses, and the email addresses being verified.Email verification runs whenever lead verification is available, up to 300 checks per workspace a day. Business search and page reading run only when switched on.
Tool developers on Apify (Compass, BounceVerify and Apify)Third party tools that run on Apify: a Google Maps business crawler by Compass, an email verifier by BounceVerify, and a website content crawler by Apify.The search terms, page addresses or email addresses given to each tool. The maps tool can return business emails and phone numbers published on company websites and, only if we switch on its people option (off by default), names and details of employees from its own data.Whenever the matching Apify tool runs.
Google PlacesOptional business search source.Privacy policy of Google PlacesSearch text and location.Only if we switch it on. It is off by default.
RapidAPI (Local Business Data)Optional business search source.Privacy policy of RapidAPI (Local Business Data)Search text and city.Only if we switch it on. It is off by default.
Public company websitesSources for Find contacts and for MoonAgent reading a company site.Page requests from our server, identified as MoonreplyContactBot. No workspace data is sent.When you run Find contacts or MoonAgent reads a company website.
Google Colab and Google DriveHost our lead library.Privacy policy of Google Colab and Google DriveLead library records, plus new research contacts and verification results copied into it.When we import or export the library, and during live library searches.
ngrokOptional secure tunnel for the lead library.Privacy policy of ngrokLibrary search terms and the contacts returned.Only when the library runs behind an ngrok tunnel.

Services you connect

These receive data because you connect them. They are your choice, not our providers.

Services you connect: services and the data they receive
ServiceWhat it receivesWhen
HubSpotCRM you can connect to import contacts.Privacy policy of HubSpotYour HubSpot access token. We read contact email, name, company, job title and website.When you connect it and at each sync, up to 2,000 contacts.
AI assistants you connect, and apps using your API keyTools you authorize, such as an AI assistant, a script or a notebook.What you let them work with in the workspace: contacts, research contacts, campaigns, replies, reports, and mailbox settings and health. A connected assistant can also change these, launch campaigns and send replies after asking you. No tool ever receives a mailbox password or other mailbox sign in secret.Whenever they use the connection or key, until you disconnect or revoke it.
Your webhook endpointsYour own systems.The event type and record IDs only, signed with your secret.On the events you subscribe to.

Billing

Checkout, payments and the billing portal.

Billing: services and the data they receive
ServiceWhat it receivesWhen
StripePayment processing, checkout and the billing portal.Privacy policy of StripeStripe test mode today, so no real payment is taken. For each workspace, Stripe receives the workspace name and ID, the email of the workspace owner who opens checkout and the plan or pack chosen. For real payments it will also process the card details and billing address you enter on its payment page. We never see full card numbers.When the workspace owner chooses a plan, buys verified contacts or opens Manage billing, and for each renewal.

Scripts and embeds on our pages

Scripts and embeds on Moonreply pages
WhatWhereWhat it doesConsent
Cloudflare Web AnalyticsOur public pages.Counts page views and measures page speed. Sets no cookies.Optional. Runs only after you allow analytics.
Clerk sign inThe sign in page and the signed in app. Not loaded on public pages for visitors who are signed out.Signs you in and keeps you signed in.Strictly necessary.
Cloudflare TurnstileMay appear during sign up, if bot protection is on in our sign in settings.Checks that a person, not a bot, is signing up.Strictly necessary for security.
Google and Microsoft consent screensA full page visit to Google or Microsoft when you connect a mailbox.Lets you grant Moonreply access to your mailbox.Only when you choose to connect.
Stripe Checkout and billing portalStripe's own pages, opened when the workspace owner chooses a plan, buys verified contacts or opens Manage billing. Nothing from Stripe loads on our pages.Takes payment details and lets you change the plan, the card and billing details, see invoices or cancel.Strictly necessary for a purchase you start. Stripe's own privacy policy and cookies apply there.
Our own scripts and fontsEvery page.Run the site, check for a sign in cookie and describe pages to search engines. Our three typefaces are served from our own server; nothing is requested from a font service.Strictly necessary.

What emails sent with Moonreply contain

Tracking and unsubscribe elements in emails
WhatWhereWhat it doesConsent
Open tracking imageCampaign emails, when open tracking is on for that campaign.A tiny invisible image. Loading it records that the email was opened.The sender needs a lawful basis, which in the European Union and the United Kingdom may mean your consent.
Click tracking linksCampaign emails, when click tracking is on for that campaign.Links pass through our tracking address, which records the click and then opens the page.As for open tracking.
Unsubscribe link and headerA link and a header in every campaign email; the header in every reply sent from the Moonreply inbox.Lets you stop further email from that sender in one click.Always included. There is no setting to remove it.

What we do not use

  • advertising networks or retargeting
  • social media pixels or share buttons
  • chat widgets, session recording or heatmaps
  • font or icon services: our typefaces are served from our own server

If we add a service that receives personal data, we list it here first. Questions go to aamirmursleen@gmail.com.

Questions about this page?

Email aamirmursleen@gmail.com. Write from the address your question is about, so we can find the right records.