Privacy Policy
Effective Date: September 10, 2026 Last Updated: September 10, 2026
This Privacy Policy explains how Moodscape ("Moodscape," "we," "us," or "our") collects, uses, shares, and protects personal information when you use our mobile application and related services (collectively, the "Service").
This Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), India's Digital Personal Data Protection Act, 2023 (DPDP Act), and other applicable privacy laws.
This notice describes our practices; it does not replace consent where consent is required.
1. Who We Are (Data Controller / Data Fiduciary)
For the purposes of GDPR, UK GDPR, and similar laws, the data controller is:
Atul Kumar Jaiswal, operating Moodscape Email: support@getmoodscape.com
For the purposes of India's DPDP Act, Atul Kumar Jaiswal, operating Moodscape, is the data fiduciary. Moodscape is operated from India.
You can contact us at the address above for any privacy-related questions, requests, or complaints.
If you are located in the European Economic Area (EEA) or the United Kingdom and we are required to appoint a representative under Article 27 GDPR, we will publish their contact details here.
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples |
|---|---|
| Account information | Email address, name, profile image, and authentication identifiers received from our authentication provider or your chosen sign-in provider. |
| Profile and onboarding information | First name, last name, date of birth (optional), wellness goals, onboarding questionnaire responses, app preferences. |
| Journal content | Journal entries, titles, mood selections, and associated timestamps you create. Journal content is stored using encryption controls and is private to your authenticated account. |
| AI moodscape prompts | Text prompts you submit to personalize moodscape sessions, plus saved moodscape records. |
| Support and feedback | Messages, cancellation reasons, and survey responses you submit. |
| Subscription information | In-app purchase product IDs, transaction identifiers, original transaction IDs, app account tokens, subscription status, renewal status, period start/end dates, environment (sandbox/production), and auto-renew flags received from the app store payment provider. We do not receive or store your payment card details. Payments are processed by the app store payment provider. |
2.2 Information Collected Automatically
| Category | Examples |
|---|---|
| Usage and progress data | Listening activity, listening seconds, streaks, achievements, recently played items, journal activity, moodscape generation counts, completion rates, feature interactions, and non-content safety-control events such as whether a journal save was blocked. |
| Device and notification data | Push notification tokens, notification preferences, timezone, app version, operating system, and basic device information needed to operate notifications and core functionality. |
| Advertising attribution data | Advertising identifier (IDFA) only when you allow tracking through Apple's App Tracking Transparency prompt, app version, referral or attribution metadata, and limited measurement events: app installs/opens, completed registration, login, trial activation, verified subscription activation (including server-confirmed trial-to-paid conversion), and aggregate SKAN revenue measurement. We do not send journal content, moodscape prompts, listening activity, or health-related information for advertising attribution. |
| Diagnostics | Error and performance information generated by the app or service infrastructure used for reliability and security. |
Product analytics and subscription measurement
We use Amplitude for product analytics. It receives feature and screen events, listening interactions, purchase-funnel events and subscription lifecycle events, with an analytics device identifier and, when signed in, our account identifier. Campaign source, campaign/ad metadata and an AppsFlyer identifier may be attached to that analytics profile so we can understand how people discover and use Moodscape. This data is linked to an account or device, not anonymous merely because an identifier is pseudonymous.
We configure Amplitude's client SDK not to record the device IP address as an analytics property. Network providers still process connection metadata to deliver requests. Generated soundscape names are replaced with a generic label in analytics; prompts and journal text are not event properties.
App stores also notify our servers about subscription changes while the app is closed. We send trial conversion, renewal, cancellation, renewal re-enabling, expiry and refund events to Amplitude. For advertising measurement, our servers send only eligible verified trial-to-paid conversions to AppsFlyer, not cancellation or renewal events. We store analytics identifiers and the last reported tracking choice to address these events. The server checks that recorded permission before AppsFlyer delivery; a changed device setting is synchronized when the app next opens or returns to the foreground. Sandbox server events are excluded from AppsFlyer delivery.
AppsFlyer measures installs and limited conversions and can forward these to Meta and Google Ads, including privacy-preserving SKAN measurement. We do not send journal text, moodscape prompts, listening history or wellness questionnaire responses to these attribution or advertising partners. Product analytics in Amplitude and advertising measurement have different data scopes.
2.3 Information We Do Not Collect
We do not collect:
- Payment card numbers, CVVs, or billing addresses (handled by the app store payment provider).
- Precise geolocation. Attribution providers may derive approximate country or region from network information; this is not GPS location.
- Contacts, calendars, photos (beyond images you explicitly choose to use), microphone audio, or biometric identifiers.
- The IDFA when you decline Apple's App Tracking Transparency prompt. App-scoped analytics and attribution identifiers are distinct from the IDFA and may still be processed as described below. We do not display third-party advertising inside the app.
2.4 Sources
Personal information comes from: (a) you directly; (b) your device; (c) our authentication provider; (d) the app store payment provider, when you make in-app purchases; and (e) advertising attribution providers, when you interact with a Moodscape ad or allow tracking.
3. How and Why We Use Information (Purposes and Legal Bases)
For users in the EEA and the UK, the table below sets out the legal basis under GDPR for each purpose:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide authentication, account management, and access to the Service. | Performance of a contract (Art. 6(1)(b)). |
| Store and sync journal entries, listening progress, achievements, saved moodscapes, and notification preferences. | Performance of a contract. |
| Apply journal privacy, local-lock, and safety controls, including preventing certain high-risk journal entries from being saved. | Performance of a contract; legitimate interest in protecting the Service and our users. |
| Personalize moodscape sessions when you submit a prompt. | Performance of a contract; consent where required for AI processing of your prompts. |
| Verify purchases, manage subscriptions, and prevent payment fraud. | Performance of a contract; legitimate interest in preventing fraud (Art. 6(1)(f)). |
| Send push notifications you have enabled (journal, journey, reengagement reminders). | Consent (Art. 6(1)(a)); you may withdraw consent at any time in app or OS settings. |
| Measure the effectiveness of Moodscape ads and optimize paid acquisition using limited attribution and subscription-funnel events. | Consent where required, including through Apple's App Tracking Transparency prompt; otherwise legitimate interest in measuring our marketing. |
| Understand feature use and subscription retention through product analytics, and improve app reliability, performance, and user experience. | Legitimate interest in operating and improving the Service. |
| Comply with legal obligations, respond to lawful requests, enforce terms, protect rights. | Legal obligation (Art. 6(1)(c)); legitimate interest. |
| Detect, prevent, and investigate security incidents and abuse. | Legitimate interest in protecting the Service and our users. |
We do not use your personal information for automated decision-making producing legal or similarly significant effects. We use limited, non-sensitive attribution data to measure advertising and optimize paid acquisition. We do not use journal content, moodscape prompts, listening activity, or wellness questionnaire responses for advertising or attribution.
3.1 Journal Privacy, Local Lock, and Safety Controls
Journal entries are encrypted in transit and stored using server-managed encryption controls. Authorized backend services decrypt journal data only when needed to return entries to your authenticated account, save your edits, search entries at your request, or delete entries at your request.
Journal text is not used for analytics, advertising, or AI training, and journal entries are not sent to AI services for moodscape generation.
If you enable the optional journal lock, the app may ask your device to use Face ID, Touch ID, passcode, or an equivalent local authentication method before opening journal screens. Biometric authentication is handled by your device operating system. Moodscape does not receive or store your biometric identifiers.
The app may check journal text before saving to prevent entries containing certain high-risk self-harm language from being stored. If a save is blocked, the blocked journal text remains in the editor on your device and is not saved to our database by the new journal-save path. We may record a non-content safety event, such as that a journal save was blocked, but we do not record the journal text or exact matched term for analytics.
4. AI Processing
Moodscape uses AI-powered personalization to interpret text prompts you submit and prepare moodscape sessions. Your prompt is processed through our backend infrastructure and matched against our private moodscape audio catalog; the selected audio metadata and your prompt are stored so you can replay saved moodscapes.
Before you create a moodscape, the app requests your consent and reminds you not to include sensitive personal, medical, financial, emergency, or identifying information in prompts. If you do not consent, you can still use the rest of the app.
Moodscape prompts are used to provide the feature. They are not sold, used for advertising, or used by us to train AI models.
5. Third-Party Service Providers (Sub-Processors)
We use the following categories of service providers, for the purposes described below. The applicable role and contractual restrictions depend on the service and processing purpose:
| Provider Category | Purpose | Data Processed | Location |
|---|---|---|---|
| Authentication and account management providers | Authentication, identity, and session management. | Email, name, profile image, authentication identifiers, and sign-in request metadata. | United States or global infrastructure. |
| Cloud database, storage, and backend infrastructure providers | Database, private file storage with signed URLs, backend functions, journal encryption, access control, and app reliability. | App data described in Section 2, processed only to provide the Service. | United States or global infrastructure. |
| App store payment and subscription providers | In-app purchases, subscription management, transaction verification, and subscription notifications. | App store account identifiers, transaction receipts, app account tokens, and subscription state. | United States or global infrastructure. |
| Push notification delivery providers | Delivering notifications you have enabled. | Push notification tokens and notification delivery metadata. | United States or global infrastructure. |
| Product analytics providers (Amplitude) | Understand feature use, reliability and subscription retention, and relate acquisition to product use. | Device/account identifiers, feature and listening events, subscription lifecycle and verified monetary events, and campaign metadata. The client SDK is configured not to record the device IP address as an analytics property. No journal text or moodscape prompt text. | United States or global infrastructure. |
| Mobile attribution and advertising measurement providers (AppsFlyer; Meta and Google Ads as advertising recipients) | Measure which paid campaigns result in installs and limited subscription-funnel conversions. | Advertising identifier when permitted, device and app identifiers, IP-derived technical metadata, campaign/referral metadata, app-open and limited conversion events, eligible server-confirmed trial-to-paid conversions and aggregate SKAN revenue measurement. We do not send journal content, moodscape prompts, listening activity, or wellness questionnaire responses. | United States or global infrastructure. |
| Public website, CDN, and security hosting providers | Hosting public legal pages, public assets, secure media delivery, and protection against abuse. | IP address and request metadata when you visit public web pages or request hosted media. | Global infrastructure. |
We use provider agreements and applicable data protection terms. Advertising recipients may have separate responsibilities for their processing. Each provider has its own privacy policy.
6. How We Share Information
We do not sell personal information for money. We disclose limited identifiers and conversion data for advertising measurement as described below. Whether a disclosure is a "sale" or "sharing" under a privacy law depends on the data, purpose and recipient; the absence of a monetary payment does not by itself exclude those definitions.
We disclose personal information only in these circumstances:
- With the providers and recipient categories identified in Section 5, subject to applicable agreements and privacy choices.
- With app store payment providers, to verify, manage, and refund subscriptions.
- With advertising measurement providers and advertising platforms, only as needed to measure Moodscape campaigns and optimize paid acquisition, subject to applicable consent and privacy choices. We do not share journal content, moodscape prompts, listening activity, or wellness questionnaire responses for these purposes.
- For legal reasons, where required by law, subpoena, court order, or to protect the rights, property, or safety of Moodscape, our users, or the public.
- In connection with a business transaction, such as a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, with notice to you to the extent required by law.
- With your consent, or at your direction.
7. International Data Transfers
Moodscape is operated from India and uses service providers located in the United States and other countries. If you are located outside India, including in the EEA, the UK, the United States, or other regions, your information may be transferred to, and processed in, India, the United States, and other countries that may have different data protection laws than your jurisdiction.
When we transfer personal data from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or equivalent mechanisms, executed with each relevant service provider. You may request a copy of these safeguards by contacting us at support@getmoodscape.com.
8. Data Retention
We retain personal information while your account is active and for as long as needed to provide the Service and comply with our legal obligations.
| Data | Retention |
|---|---|
| Account, profile, journal entries, saved moodscapes, activity, achievements, notification preferences. | Until you delete the data in app or delete your account. After account deletion these records are deleted, as described in Section 9. Journal entries blocked by safety controls are not saved by the new journal-save path. |
| AI moodscape prompts and saved moodscape records. | Until you delete the moodscape or your account. |
| Subscription entitlement records held by us. | Until you delete your account. Apple and Google hold the underlying transaction records and retain them under their own policies; we do not process payments and do not keep a separate accounting copy. |
| Cancellation feedback. | Up to 24 months after submission for product improvement, or until you delete your account, whichever is sooner. |
| Diagnostic and security logs. | Up to 90 days for routine operations, longer where needed for investigations or legal hold. |
We may keep limited records longer if required by law or to defend legal claims.
9. Account Deletion, What Happens to Your Data
For analytics deletion or other privacy requests, contact support@getmoodscape.com. Removing data from the app does not by itself confirm that every provider has erased historical analytics.
You can request account deletion at any time from Profile → Delete Account in the app, or by emailing support@getmoodscape.com.
When you delete your account:
- Your authentication identity record (email, password, OAuth tokens, where applicable) is permanently deleted.
- Your account and profile records (name, email, preferences) are deleted, not anonymized.
- Your journal entries and their encryption keys, saved moodscapes, listening progress, streaks, achievements, collections, breathing sessions, push tokens, notification preferences, support and cancellation feedback are deleted from our active databases. Deletion happens in a single database transaction: either all of it is removed or none of it is, so a partial deletion cannot leave records behind.
- Your subscription records held by us (transaction identifiers, period dates, status) are deleted with the rest of your account. We do not process payments ourselves, so these are a copy of what the app store told us about your entitlement, not our book of record. Apple and Google retain their own transaction records under their own policies and retention periods, and deleting your Moodscape account does not affect those or cancel a subscription.
- We keep two things after deletion, and nothing else:
- A one-way SHA-256 hash of your account identifier, so that a delayed or replayed request cannot silently recreate the account you just deleted. It cannot be reversed to identify you and is not linked to any of your content.
- The advertising and analytics identifiers associated with the account (see Section 5), retained only so that we can ask those providers to erase their copies. They are deleted once that erasure is complete.
- Backups may contain residual copies for up to 35 days, after which they are overwritten in the ordinary course.
If you signed in with a third-party sign-in provider, deleting your Moodscape account does not revoke that provider's sign-in link automatically; you can manage it in your device or provider account settings.
10. Security
We use reasonable technical and organizational safeguards designed to protect personal information, including:
- HTTPS/TLS for all network traffic.
- Authentication and session management through a dedicated identity provider.
- Row-level access controls on personal-data tables, enforcing that you can only read and write your own records.
- Encrypted journal storage using server-managed encryption keys and authenticated backend access.
- Private storage buckets with short-lived signed URLs for media access.
- Service-role isolation in Edge Functions; service keys are not exposed to the client.
- Secure device token storage using platform-backed secure storage.
- Principle of least privilege for internal access; audit logging on sensitive operations.
No security system is perfect. You are responsible for keeping your device, platform account, sign-in provider account, and any sign-in credentials secure.
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the appropriate supervisory authorities as required by applicable law.
11. Your Rights
Subject to applicable law, you have the following rights with respect to your personal information:
11.1 Rights for Everyone (in-app controls)
- Update your account and profile information in the app or with your authentication provider.
- Delete individual journal entries and saved moodscapes in the app.
- Manage push notification permissions in iOS/Android settings and notification preferences in the app.
- Manage or cancel your subscription in your Apple App Store or Google Play subscription settings.
- Delete your entire account from Profile → Delete Account.
11.2 Rights under GDPR / UK GDPR (EEA, UK, Switzerland)
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete personal data.
- Erase personal data ("right to be forgotten").
- Restrict processing of your personal data.
- Object to processing based on legitimate interests, including profiling.
- Data portability, receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of prior processing.
- Lodge a complaint with your local data protection supervisory authority. A list of EEA authorities is at https://edpb.europa.eu/about-edpb/about-edpb/members_en. The UK regulator is the ICO (https://ico.org.uk).
11.3 Rights under CCPA / CPRA (California Residents)
You have the right to:
- Know what categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of third parties to whom we disclose it.
- Delete personal information we have collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of "sale" or "sharing" of personal information. You may withdraw tracking permission in iOS Settings and contact support@getmoodscape.com to request that we stop applicable advertising disclosures. Device tracking controls and a legal opt-out request are not interchangeable. See https://getmoodscape.com/privacy-choices for the available controls and request channel. We do not sell personal information for money.
- Limit the use of sensitive personal information to what is necessary to provide the Service. We do not use sensitive personal information for any secondary purpose.
- Non-discrimination, we will not deny service, charge different prices, or provide a different quality of service because you exercised a CCPA right.
For the 12 months preceding the Effective Date, the categories of personal information we have collected, the sources, business purposes, and recipients are described in Sections 2, 3, and 5 of this Policy. We do not sell personal information for money and do not disclose sensitive personal information for purposes other than those listed in Section 3. Advertising attribution practices are described in Sections 2, 3, 5, and 6.
11.4 Rights under India's DPDP Act
If India's DPDP Act applies to you, you may have the right to:
- Access information about the personal data we process about you.
- Correct, complete, update, or erase your personal data, subject to legal exceptions and retention obligations.
- Withdraw consent where processing is based on consent.
- Use grievance redressal by contacting us at support@getmoodscape.com.
- Nominate another person to exercise your rights in the event of death or incapacity, where applicable.
11.5 Rights under Other Laws
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other US states with comprehensive privacy laws have analogous rights to access, delete, correct, and (where applicable) opt out of targeted advertising, sale, and profiling. We will honor those rights subject to verification.
11.6 How to Exercise Rights
Most rights can be exercised directly in the app. For other requests, email support@getmoodscape.com with the subject line "Privacy Request." We will:
- Ask for identity verification where appropriate for access or deletion; do not require account creation or identity verification solely to request an advertising sale/sharing opt-out.
- Respond within the time required by applicable law.
- Handle requests without charge, except where a fee or refusal is expressly permitted by applicable law.
You may authorize an agent to make a request on your behalf with documentation reasonably required to verify the agent's authority.
If we deny your request, you may appeal by replying to our response email. We will respond to your appeal within the time required by law.
12. Children's Privacy
Moodscape is not directed to and is not intended for children under 16, or under 18 where applicable law treats people under 18 as children, including India. We do not knowingly collect personal information from children under these age thresholds. If you are a parent or guardian and believe your child has provided personal information, please contact us at support@getmoodscape.com and we will delete the information promptly.
Where required by law (e.g., GDPR Article 8 or India's DPDP Act), processing of a child's personal data is lawful only with the required consent or authorization of the child's parent or guardian. We do not knowingly track, behaviorally monitor, or target advertising to children.
13. Health and Wellness Disclaimer
Moodscape provides wellness, relaxation, journaling, breathing, and meditation content. It is not a medical device and does not provide medical advice, diagnosis, treatment, therapy, or emergency services.
If you are experiencing a mental health crisis or emergency, contact your local emergency number or a qualified provider.
14. Cookies and Similar Technologies
The Moodscape mobile app does not use cookies. Our public legal and informational web pages may use strictly necessary cookies or logs (e.g., for security and DDoS protection). We do not use advertising or analytics cookies.
15. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app, the App Store metadata, email, or another reasonable method, and update the "Last Updated" date above. Continued use of the Service after the Effective Date constitutes acceptance of the updated Policy.
A previous version of this Policy is available upon request at support@getmoodscape.com.
16. Contact
For privacy questions, requests, or complaints:
Moodscape Email: support@getmoodscape.com Privacy requests subject line: "Privacy Request"