Privacy policy
Draft. Last updated 2026-09-07.
Who we are
Moonspool is an outbound sales service for startup founders, operated at moonspool.com. Contact: hello@moonspool.com.
Data about founders (our customers)
- Account: your email address, sign-in links, and the workspace you create.
- Mailbox and calendar access: OAuth tokens for the Google Workspace or Microsoft 365 mailboxes you connect. Tokens are encrypted at rest with a key specific to your workspace. You can revoke them from Settings at any time; revocation makes every stored token unreadable.
- Mail: messages sent from and received by the connected mailboxes in threads the service started, and warmup messages it exchanges between connected mailboxes. We do not read or store other mail in those mailboxes.
- Calendar: free/busy information used to propose times, and the events the service creates.
- Business information you provide during onboarding: product facts, proof points, objections, writing samples, and companies you do not want contacted.
- Billing: credit and usage ledgers. We do not store payment card details.
Google API Services
Moonspool's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail access only to send mail from your mailbox, read replies in threads the service started, move misfiled warmup mail and mark it read, and calendar access only to read availability and create meetings. We do not use this data for advertising and do not sell it.
Data about prospects (people the service contacts)
- Source: public web pages only. Each stored fact records the page it came from and when it was fetched, and is deleted after a retention period.
- Content: name, title, company, work email address, and observations drawn from those pages.
- Rights: prospects can ask to stop or to be deleted by replying to any message. Stop requests take effect immediately; deletion removes every record except a hashed suppression entry that prevents further contact. In jurisdictions that require it, the first message states where the details came from.
Processors
Hosting on OVHcloud; model inference through OpenRouter; page fetching through scrape.do; transactional email through Cloudflare. Each receives only what its function needs.
Retention and deletion
Prospect facts are kept for 12 months from fetch. Conversation history is kept while your workspace exists. Closing a workspace deletes its data; backups are retained for 14 days.
Security
Encrypted transport, encrypted tokens, per-workspace data isolation enforced in the database, and audit logs of every automated decision.