This policy covers the Moonshot macOS app and moonshot.fyi. “We” refers to 21 Media LLC, the studio that builds Moonshot. It explains what we collect, why, and the controls you have.
01Summary
Moonshot is designed for data minimization. Screenshots and screen recordings stay on your Mac unless you choose to upload them. When you upload a capture, the Moonshot app encrypts the capture before it leaves your device. Moonshot Cloud is designed to store encrypted media rather than readable screenshots or recordings.
We do not sell your data. We do not share your data with anyone for advertising, cross-context behavioral advertising, or third-party marketing, and we do not use your captures, transcripts, or other content to train AI models. We do not use third-party advertising or analytics trackers. The analytics we collect are first-party only: product telemetry that helps us keep Moonshot working, and viewing analytics on share pages that we show to the person who shared the recording, both described below.
To run the Service we store what is needed to operate it for you: your account identifier, the encrypted captures you choose to upload, billing records (handled by Stripe), team and invite records, your comments and transcripts, share-page viewing analytics, product telemetry, and minimal operational logs. The only parties that ever receive your data are the people you send a share link to, your own team members per your settings, and the infrastructure providers we rely on to run the Service (Cloudflare for hosting, storage, and AI processing, and Stripe for payments).
02Information We Collect
- Local app settings, keyboard shortcuts, capture folders, recording preferences, recent capture state, and your local Moonshot identity.
- Encrypted uploaded captures and encrypted cloud library records when you choose to upload.
- Upload metadata such as account identifier, share identifier, storage path, upload time, object size, content type, media kind, visibility setting, team identifier, and related usage counters.
- Team names, memberships, roles, invite email addresses, invite status, comments, reactions, transcript segments, auto-generated chapters, and related timestamps.
- Share-page viewing analytics, described in the next section: view counts, watch progress, which parts of a recording were played, clicks on links the sharer added, and email addresses viewers choose to submit.
- Product telemetry from the Moonshot apps: event names (such as "capture" or "upload"), the app or client type, its version, a random device identifier, and small technical details about the event. Telemetry is designed to exclude the contents of your captures, page URLs, and precise location.
- Stripe customer IDs, subscription IDs, plan status, billing period information, and invoice summaries. Moonshot does not store full card numbers.
- Support messages and standard operational request information needed to provide, secure, debug, and operate the Service.
03Viewing Analytics on Share Pages
When someone opens a share link, the share page records viewing analytics for the person who shared the recording: a view event, how much of the recording was watched, which parts of the timeline were played or replayed, clicks on links or buttons the sharer added, and the day these events happened.
To connect these events, the share page stores two random identifiers in the viewer’s browser: a viewer identifier scoped to the sharer’s account (kept in local storage so return visits can be recognized) and a session identifier for the current visit. These identifiers are random tokens we generate. They are not built from the viewer’s name, email, IP address, or device fingerprint, they do not follow viewers to other websites or other Moonshot users’ shares, and we do not use them for advertising.
If a viewer chooses to submit their email address on a share page (for example an end-screen form), that email is shared with the recording’s owner and their team per workspace settings, and it is associated with that viewer’s watching activity on that owner’s shares so the owner can see who watched.
Viewers can avoid these analytics by not opening share links, and can reset the identifiers by clearing their browser’s local storage for the share domain.
04AI Features
Some features process your content with AI models when you use them: transcription, summaries, auto-generated chapters, and AI actions you run on a recording. For these features, the relevant content (for example a recording’s audio or transcript) is processed by our AI infrastructure provider (Cloudflare) to produce the output you requested, and the output is stored with your capture.
AI features run when you or your app request them, and auto-generated chapters are produced when a transcript is saved for an eligible recording on a plan that includes them. We do not use your content to train AI models, and we do not permit our AI infrastructure provider to use it to train theirs under the terms that apply to our use of their service.
05How We Use Information
- Provide local capture, recording, upload, sharing, dashboard, billing, team, and collaboration features.
- Confirm that app requests are authorized.
- Store encrypted media and encrypted library records.
- Generate and manage share links, private shares, team shares, comments, reactions, transcripts, chapters, and workspace access.
- Show sharers how their recordings are viewed: view counts, watch-through, attention across the timeline, link clicks, and emails viewers submit.
- Run the AI features you request, such as transcription, summaries, chapters, and AI actions.
- Understand feature usage and keep the apps reliable through first-party product telemetry.
- Process subscriptions, invoices, billing portal access, cancellations, storage limits, and plan entitlements.
- Send service messages, team invite emails, storage alerts, and support replies.
- Detect, prevent, and respond to spam, abuse, security incidents, and excessive or automated storage usage.
- Comply with legal obligations and enforce our Terms of Use.
06How We Disclose Information
We may disclose information to service providers that help us operate the Service, to people who receive a share link, to team members and workspace administrators according to product settings, in connection with a business transaction, or if required by law or needed to protect rights, safety, security, and service integrity.
Viewing analytics from a share page, including any email a viewer submits there, are disclosed to the owner of that recording and, per workspace settings, their team.
We do not sell or rent personal information. We do not share personal information for advertising, cross-context behavioral advertising, or third-party analytics.
07Retention
Local captures and settings remain on your device until you delete them or uninstall the app according to your operating system behavior.
Uploaded encrypted captures and cloud library records remain until you delete them, your account or identity is deleted where supported, or we remove them under the Terms of Use or applicable law. Billing, security, abuse-prevention, tax, accounting, and legal records may be retained for longer where reasonably necessary.
Deleting a capture also deletes its viewing analytics, watch history, interactivity settings, chapters, and transcript from our database. Product telemetry contains no capture content and is retained as an operational record.
08Your Choices and Rights
- Keep captures local by not uploading them.
- Delete uploaded media from Moonshot Cloud where the dashboard provides deletion controls.
- Control who receives share links and team access.
- Export your recovery keys from the app.
- Manage or cancel paid plans through Stripe-hosted billing tools where available.
- Contact us to request access, correction, deletion, or other privacy assistance.
Depending on where you live, you may have additional rights. To make a privacy request or any other inquiry, contact us at admin@21media.to. We may need to verify your request before acting on it.
09Security
Moonshot uses reasonable security measures intended to protect data, including encryption for uploaded media content and limited-time dashboard sessions.
No method of storage or transmission is perfectly secure. You are responsible for protecting your device, Moonshot secret access key, recovery file, and share links.
10Children, International Users, and Changes
Moonshot is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
We and our service providers may process information in the United States and other countries.
We may update this Privacy Policy from time to time. Updated policies are effective when posted unless they say otherwise.
11Contact
21 Media LLC
admin@21media.to