Legal · Data protection
Mose Privacy Policy
Effective: 5 October 2026 · Version: 1.1
This policy explains how Mose (trymose.com and app.trymose.com) collects, uses, stores and shares personal data.
1. Who we are
Mose is operated by MOZME LLC (30 N Gould St Ste R, Sheridan, WY 82801, USA). For any privacy request: [email protected]. We are the data controller (KVKK/GDPR) and "business" (CCPA).
2. What Mose is
Mose is an SEO content automation service for website owners: it reads a connected site, extracts a brand profile, finds content opportunities in Google Search Console data, generates articles and images with AI, publishes them to WordPress or Shopify and measures the results. It is aimed at businesses and not directed at anyone under 18.
3. Data we collect
- Account: name, email, password (hashed only).
- Workspace and site: site URL, brand profile, business facts you approve.
- Connection credentials: WordPress / Shopify access tokens (stored encrypted).
- From connected services: Google Search Console performance data (read-only access); your site's public content; PageSpeed scores.
- Automatically: server logs (IP, browser, time), session cookie, usage events, cost records of AI calls.
- Advertising measurement (only if you accept it): Meta Pixel identifiers and page events, as described in section 12.
- Payments: web subscriptions are processed by Stripe; if you install Mose from the Shopify App Store, charges are processed by Shopify (Shopify App Pricing). Mose never receives your card details. We keep only subscription status, plan and invoice IDs.
Free site scan (no account needed). When you ask for a free report we store the email address you give us, the website address you entered, the language you were reading in, whether you ticked the marketing box, and a one-way hash of your IP address (used to limit abuse — the address itself is not kept). We use your email address to send you that report and nothing else; we write to you about Mose only if you ticked the box, and every such email carries an unsubscribe link. The report link in that email stops working after 7 days, after which the measurement itself is deleted. The record that you asked for the scan is kept until you ask us to delete it: email [email protected] and we will remove it.
We collect no special-category data. Advertising measurement runs only if you accept it: see section 12.
4. Why, and on what basis
Providing and billing the service (contract), security and debugging (legitimate interest), service notifications (contract), marketing email (consent only, unsubscribe in every email), advertising measurement with the Meta Pixel (consent only, see section 12), legal obligations.
5. Google data
Mose's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We request only read access to Search Console; signing in with Google is not required. We use this data to show your search performance, propose content opportunities and measure results after publication. We do not sell it, use it for advertising or use it to train AI models; humans see it only with your consent, in security reviews or when required by law. Tokens are stored encrypted. When you click "Remove connection" in the dashboard or revoke access at https://myaccount.google.com/permissions we delete the tokens; stored data is deleted within 30 days.
6. AI
We use third-party AI providers for content and image generation. They receive the brand profile, the topics and business facts you approved — never passwords, tokens or payment data. We work with providers under API terms that do not use your data for model training. Generated content is yours; reviewing it before publishing is your responsibility.
7. Who we share with
We do not sell your data. Only to provide the service: hosting and database (Hetzner Online GmbH, Germany · Cloudflare, Inc.), payments (Stripe, Inc. for web subscriptions; Shopify for installs from the Shopify App Store), AI providers, email delivery, and the platforms you connect (your WordPress site, your Shopify store, Google). If you accept advertising cookies, Meta Platforms also receives the Meta Pixel data described in section 12. Email [email protected] for the current sub-processor list. We may disclose data where required by law or in a company transfer (with prior notice).
8. International transfers
The company is in the U.S. and servers are in the EU, so your data may be transferred abroad. We rely on KVKK Art. 9 and GDPR mechanisms (Standard Contractual Clauses).
9. Retention
Account data: deleted within 30 days of account closure. Connection tokens: immediately on disconnection. Invoice records: for the legally required period. Logs: 90 days. Backups: rolling 30-day cycle.
10. Security
TLS, encrypted token storage, workspace-level data isolation, hashed passwords, regular backups. If a breach occurs we notify within the statutory period (72 hours). Found a vulnerability? [email protected].
11. Your rights
For your rights under KVKK Art. 11, GDPR and CCPA/CPRA (access, correction, deletion, objection, portability, withdrawing consent, non-discrimination; we do not sell personal data) email [email protected]; we respond within 30 days after verifying your identity. You may complain to the Turkish Personal Data Protection Board or your EU supervisory authority. You can close your account and remove any connection from the dashboard.
12. Cookies
Strictly necessary cookies (session, CSRF) and preference cookies (language, your cookie choice) are always on. You can delete them in your browser; blocking necessary cookies prevents sign-in.
Advertising measurement is off by default. Only if you press "Accept" in the cookie banner does the Meta Pixel (Meta Platforms) run on trymose.com and app.trymose.com. We use it to measure how our ads perform: page views, registration, choosing a plan, checkout start and purchase. It sets the cookies _fbp and _fbc and sends these events to Meta together with technical identifiers such as those cookies, your IP address and browser details. Meta processes this data under its own terms and may transfer it abroad (see section 8). Nothing from Meta loads before you accept, and if you press "Decline" it never loads.
If you accepted and you are signed in to the panel, a one-way hash (SHA-256) of your account email address is also sent to Meta through the Pixel so the measurement can be matched; the address itself, your name or your phone number is never sent.
If you accepted, when a purchase is completed the same measurement is also sent to Meta from our server (Conversions API): the amount, currency and plan, the checkout ID, the cookies, IP address and browser details captured when you started checkout, a one-way hash (SHA-256) of your email address, never the address itself, and a one-way hash of your workspace identifier. For this purpose, if you accepted, those cookie, IP address and browser details are stored with your payment record at our payment provider, Stripe. If you did not accept, our server sends nothing either.
You can change your mind at any time with "Cookie settings" in the footer: choosing "Decline" there withdraws your consent and stops the Pixel from sending data. Your choice is stored in a cookie called mose_ads_consent for 6 months. Withdrawing consent does not affect processing carried out before it.
13. Changes and contact
We notify material changes by email at least 14 days in advance; the current version is always at this address. Contact: [email protected] · MOZME LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA