Privacy Policy
Effective October 4, 2026.
1. Who is responsible
MASTERPIECE Technologies Inc. operates Moov and is responsible for Moov's handling of personal information described here. Contact support@trymoov.app for privacy questions or requests. This policy covers the Mac app, website and connected account services; features described as optional or conditional process data only when available and used.
2. Camera and local app data
With your device permission, Moov uses live camera frames and movement keypoints on your Mac to check exercises and calibrate the experience. The inspected implementation does not upload or record camera video or send movement keypoints to our account service or PostHog. Camera streams are stopped when the camera flow ends. This is an exercise check, not identity verification. Decline camera permission or revoke it in your device settings to use the timed fallback.
The app stores onboarding completion, exercise choices, reminder settings and related preferences locally. Activation credentials are stored using the Mac's credential storage; verification uses the connected license service. Local preferences can persist across restarts until changed or local app data is removed. Removing local data does not delete remote account or payment records.
Local camera processing can still require network downloads: the current app loads TensorFlow scripts from jsDelivr and the movement model through its model library. Website pages also request Google Fonts. Those providers receive connection information such as your IP address when supplying those resources; camera frames are not included in those downloads. Release, update and license checks similarly send network requests when used.
3. Accounts, purchases and support
When account services are connected, we process your email, optional name, account identifiers, verification status, sign-in codes and sessions to create accounts and verify access. Session records can include IP address and browser information; security rate limits use derived identifiers. Better Auth is the authentication software running on our service, with Cloudflare providing the configured hosting and database infrastructure.
Stripe processes checkout and billing information, including payment details entered into its checkout. Our integration stores checkout references, account ownership, payment-event references and activation records, and retrieves purchase or subscription status to verify entitlement. The inspected Moov database does not store full card numbers. Stripe also processes information for its own payment, security and legal purposes.
Resend is the configured email delivery provider for sign-in codes and, when enabled, feedback and invitations. It receives the recipient and message content needed to send those emails. Feedback is sent only when you select Send or Retry. It includes your chosen category, message and optional reply address, plus identifiers needed for delivery and duplicate prevention. Please do not include camera footage, activation tokens or sensitive health or financial details. Email acceptance does not guarantee inbox delivery.
4. Invitations and referral information
When available, a referral link can place a pending code and request identifier in browser session storage. Applying it requires your action and a verified account. The service records inviter/referee attribution, related purchase status and any reward records needed by an approved program. Rewards are currently disabled.
For an invitation you choose to send, Resend receives your friend's email and invitation content. The invitation handler does not store that raw recipient email in Moov's referral records; it uses a keyed derived identifier for abuse prevention and duplicate control. Invite only someone who has agreed to receive it. Invitation and feedback contents are excluded from usage analytics.
5. Optional PostHog analytics
Customer analytics collection is disabled. Declining optional analytics does not prevent registration, purchase verification or core app features. We will update this policy before enabling customer analytics.
Optional events describe website pages or sections viewed, buttons clicked and exercise previews; app opens, foreground session duration, reminder choices, exercise starts, completions or abandonment, setting names, update outcomes, app version and operating system. With account analytics permission, an opaque account identifier can link this usage and purchase journey; consented anonymous history may be linked to that identifier. This is pseudonymous information, not necessarily anonymous information.
The event payloads exclude emails, names, form contents, sign-in codes, tokens, activation keys, camera frames, pose measurements, screen recordings, health measurements and full URLs. Session replay is not enabled by this integration.
If optional analytics is enabled in a future release, PostHog may estimate country, region and city from the connection IP of direct website or app events. This is approximate and does not use GPS. We do not promise that PostHog discards IP addresses. Customer collection is currently disabled.
6. Storage and retention
Required session cookies support sign-in. Local storage holds app preferences and analytics choices or identifiers; referral pending state uses session storage. These have different purposes. Declining analytics does not disable essential account security or billing records.
Sign-in codes expire after five minutes and configured account sessions after seven days, with session renewal possible. Expiry stops validity; it does not prove immediate deletion of database records. Auth cleanup exists as a manual maintenance helper, without an automatic production schedule.
The feedback handler deletes Moov feedback database records older than 30 days when a subsequent feedback request runs. This does not guarantee deletion exactly on day 30 or delete support mailbox and Resend copies. Account, purchase and support records may remain as needed to provide services, maintain transaction records, address disputes and meet applicable obligations. Contact support to request access or deletion; required records may need to remain.
7. Recipients, purposes and international processing
We use operational information to provide accounts, purchases, license verification, requested communications and support, and to prevent abuse. Optional usage information helps us understand use and improve Moov. Service providers receive information needed for these functions: Cloudflare, Stripe, Resend, and, only if collection is enabled and allowed, PostHog. Providers may process data outside your country. Their own notices describe their practices; those notices do not replace our responsibilities.
Moov does not sell personal information or send analytics for advertising. Information may need to be disclosed to comply with law or protect against abuse. Accepting Terms does not itself authorize optional analytics.
8. Your choices and requests
Change optional analytics in the website footer or account screen, or in app Settings. Turning it off stops future collection, clears pending events and local analytics identifiers, and does not undo events already delivered. Account-level denial is checked before linked sends. Contact support to request deletion of previously delivered data; a local toggle does not perform remote deletion. Withdrawing consent does not affect the lawfulness of earlier consent-based processing.
Depending on applicable law, you may have rights to access, correct, delete or obtain a copy of your information, restrict or object to processing, withdraw consent, and complain to a relevant privacy authority. Send requests to support; we may need proportionate identity verification. Required transaction or legal records may limit deletion. Without account or purchase information we may be unable to provide those connected services, while optional analytics is not required for core features.
9. Security and changes
Moov uses secure account cookies, protected activation storage and bounded verification attempts. No system can guarantee absolute security. We will communicate material changes to this policy as required by applicable law.