Only data available to the current account is selected
Privacy Policy
Account, business and industry-network data is handled around isolation, opt-in sharing, limited use, portability and human decision-making.
Version date: September 10, 2026 · Operator details and legal review required before production launchNo business-data sale and no shared customer pool
The deployer controls the database and infrastructure
AI cannot send messages or make commitments automatically
1. Scope and controller
This policy applies to the MooYeah website, authenticated workspace and backend APIs. Before production launch, the operator’s legal name, registered address and privacy contact must be completed here. For a self-hosted deployment, the server operator is the relevant data controller.
2. Information we process
Account data includes name, workspace name, email, irreversible password hash, sessions and membership. Business data includes companies, contacts, products, communications, tasks, AI prompts and outputs. Industry-network data includes the professional profile, contact details, buyer/seller/visitor role, MBTI, birthday, avatar choice, product/application/market tags, connections, posts and city-level location. Birthday is returned only to its owner; contact details are returned only to accepted connections. Technical data may include security logs, request times, errors, IP addresses and browser information. We do not request precise GPS, identity documents, card data or payment credentials.
3. Purposes and legal basis
Data is used only for authentication, user isolation, lead and follow-up management, AI-assisted analysis, import and export, membership entitlements, security, troubleshooting and legal compliance. Business data is not sold and is not placed in a shared customer pool. Users must have a lawful business-contact basis for uploaded contact data.
4. AI and prompt desensitization
AI features read only workspace data available to the signed-in user. When prompt desensitization is enabled, known company, product and price values are replaced with symbols before context is sent to an external AI provider. Free text can still contain identifying information, so users should not submit unauthorized personal data or trade secrets. AI may be inaccurate; prices, regulations, delivery, quality conclusions and external commitments require human review.
5. Cookies and sessions
MooYeah uses necessary cookies for the HttpOnly login session and language preference. The login cookie authenticates the account and is unavailable to browser JavaScript. The locale cookie retains the Chinese or English selection. Advertising tracking cookies are not used unless separately disclosed with any required consent.
6. Storage, isolation, network and retention
Workspace business data is isolated by workspace and user. The industry network is a separate opt-in feature: profiles are undiscoverable and locations hidden by default. A location can only be selected by the user from MooYeah's bundled city directory; automatic device location and precise GPS are not used. The map shows posts only, not friend locations. Users can disable discovery and location sharing, delete posts or remove connections; social posts are automatically deleted 30 days after publication. Deleted leads enter a recoverable 90-day archive by default; AI request logs, audit logs and backups use separate default periods of 180, 365 and 30 days.
7. Processors and international transfers
Data may be sent to an AI, email, payment, map or integration provider only when that feature is enabled. Opening the map requests resources from Mapbox. Professional-profile city selection uses MooYeah's bundled directory and does not call a third-party location service. MooYeah does not send workspace leads, birthdays, contact details or AI prompts to the map provider. Provider, purpose, storage region and transfer mechanism must be disclosed before launch. The project contains no Cloudflare functionality.
8. Security
Controls include password hashing, HttpOnly sessions, server-side authorization, user and workspace isolation, input validation, audit records and human approval boundaries. Future payment integration must use signed, idempotent server callbacks and server-side order status. No internet service can guarantee absolute security; incidents will be handled and notified as required by applicable law.
9. User rights
Users may access, correct, export or request deletion of their information, withdraw optional processing and object to automated recommendations. In the industry network, users can disable profile discovery and location sharing, delete their posts, decline requests and remove connections. Full account and social-data deletion can be requested from the operator and will be handled after identity verification within the applicable legal period.
10. Children, updates and contact
MooYeah is intended for business professionals and not children. Material policy changes should be prominently notified with a revised effective date. This version is a project configuration template and must be legally reviewed before launch for the operator’s location, target markets and actual third-party services.
Please email info@mooyeah.com.