moatid: Privacy Policy
Last updated: July 30, 2026 · Part of the manymoats family. moatid is a curiosity wall plus optional sealed-share tools. not a full product suite yet.
Plain English: we collect as little as the surface needs. We do not sell personal information. Sealed-share keys never leave your browser URL fragment.
What this surface is
- Curiosity wall : a public page explaining identity infrastructure work. No account is required to read it.
- Sealed share (optional) : create a short-lived encrypted note. The decryption key lives only in the URL fragment (after
#). The server stores ciphertext + IV only and cannot decrypt.
- Account chrome (optional) : if you sign in with the manymoats account, the shared auth cookie is the same one used on other family products.
What we collect
- If you only browse the wall : standard web server / host logs (IP, user-agent, path, time) for security and reliability. No advertising trackers.
- If you create a sealed share : ciphertext, IV, TTL, views remaining, optional creator uid if signed in. Never the AES key. Burn is a hard DELETE of the ciphertext row.
- If you sign in : email and auth state via the manymoats account (Supabase / shared auth). See the family privacy policy for that account.
- Product-usage counting (Loop) : if the shared Loop script is present, basic first-party usage events (surface, action, time, random device id). Sync is on by default; Do Not Track / Global Privacy Control is treated as opt-out unless you later choose otherwise. Events do not include sealed plaintext or vault secrets.
Service providers (subprocessors)
- Google Cloud / Firebase : hosting.
- Supabase : auth and server-only sealed_shares storage (RLS on; anon/authenticated revoked).
- Stripe : only if you later buy a paid family product (not required for the wall).
- OpenRouter / fal.ai / Resend : only when a manymoats family product you use explicitly requests AI or mail; not used by the wall itself.
Access, export, and delete
When signed in on a family product, use Account → Your data to export a JSON package or request account erase. Erase is honest about partial stages (billing receipts may be retained for legal duty; biometric weights are purged when that path is fully wired). Sealed-share ciphertext rows you created are deleted when burned, expired, or views are exhausted. You can also email privacy@manymoats.com or support@manymoats.com.
Children
moatid is not directed to children under 13. We do not knowingly collect personal information from them.
Contact
Questions: privacy@manymoats.com · support@manymoats.com
home · seal · open · security