Privacy
Moada Privacy Policy
1. Introduction
When you use Moada, you trust us with information about your account and the files you choose to upload. This Privacy Policy explains what information Moada Lab (“we,” “us,” or “our”) collects, why we use it, how we share and protect it, and the choices available to you.
This Policy applies when you use the Moada websites, applications, and services (the “Service”). Moada Lab operates from the Republic of Korea and serves users in multiple countries. This Policy covers account and profile information, technical information generated through use of the Service, and personal information that may be contained in files uploaded to Moada. It does not apply to third-party websites or services that operate under their own privacy policies.
The Korean-language Privacy Policy is provided for users in the Republic of Korea and includes disclosures required under Korean law. This English Policy is maintained independently for other global users rather than as a direct translation. Your rights under applicable law are not limited by the language you use to access the Service.
Moada acts as a controller when we determine why and how account, profile, usage, security, and other service-operation information is processed. When Moada processes personal information contained in files on behalf of an organization, the organization determines the purposes and means of that processing and Moada acts as its processor. The organization determines what it uploads and who may access it, while Moada processes the file content as needed to provide and secure the Service and carry out those instructions.
2. Information We Collect
Information you provide
- Profile information, such as your name or display name.
- Files and file content you upload, including titles, filenames, and any information contained in those files.
- Information processed through our feedback feature, including your member identifier, reply email address, feedback type and content, submission page, browser information, and related handling records.
Information we receive from Google
When you sign in with Google, we receive your Google account identifier, email address, name, profile image, email verification status, and, where available, the organization domain verified by Google. We do not receive or store your Google password.
Information generated when you use Moada
- File metadata, such as file size, media type, share-link identifier, sharing setting, permitted organization domain, processing status, and creation, update, and deletion times.
- Guest session and claim identifiers, session creation and expiry times, and essential cookies.
- Usage events, such as uploads and file views, the relevant account, guest, or content identifier, and the time of the event.
- Request, error, and security records, session information, access times, and a one-way server-side identifier derived from an IP address.
Uploaded files are not necessarily personal information, but they may contain personal information depending on what you choose to upload. You are responsible for ensuring that you have the right to upload and share the contents of your files.
3. How We Use Information
- Provide, operate, and maintain the Service.
- Create and manage accounts, authenticate users, and protect sign-in sessions.
- Verify organization domains and enforce file sharing settings.
- Upload, store, render, manage, share, view, and download files.
- Connect guest files to an account after sign-in.
- Measure usage and apply service limits.
- Diagnose errors, prevent abuse, investigate security issues, and improve reliability.
- Respond to support requests, privacy requests, and disputes.
- Comply with applicable law and enforce our Terms of Service.
We do not use your file content to train AI models. We do not use personal information for targeted advertising.
4. How Information Is Shared
We do not sell personal information. We may disclose information:
- To service providers that process information on our behalf as described below.
- At your direction, including when you make a file available through a share link or to users from an organization domain.
- When required by law, legal process, or a valid government request.
- When reasonably necessary to protect Moada, our users, or others from fraud, abuse, security threats, or harm.
- As part of a merger, acquisition, financing, reorganization, or sale of all or part of our business, subject to appropriate safeguards.
A file shared with “Anyone with the link” may be opened by anyone who receives that link. Organization-restricted files are available only after Moada verifies the viewer’s account against the permitted organization domain.
5. Service Providers
We use the following companies to operate the Service. They process information on our behalf under contractual obligations.
| Provider | Services | Information involved |
|---|---|---|
| Google LLC (Google Cloud Platform) | Application and API hosting, cloud file storage and delivery, and request and error processing | Uploaded files and content, content metadata, and request and error records |
| Supabase, Inc. | Authentication and database infrastructure | Account, profile and organization verification information, guest sessions, content metadata, and usage events |
| Plus Five Five, Inc. (Resend) | Delivery of service-inquiry and feedback emails | Member identifier, reply email address, feedback type and content, submission page, browser information, and email-delivery records |
| Google LLC (Google Analytics) | Consent-based product and website analytics | Page and feature interactions, device and browser information, approximate location derived from an IP address, analytics identifiers, and event times |
6. International Data Transfers
Moada is operated from Korea, while its primary application, database, and file-storage infrastructure is located in Singapore. As a result, your information may be transferred to, stored in, or accessed from Korea and Singapore regardless of where you live. Feedback submitted through the Service is transmitted through Resend and processed in the United States. Google Cloud Platform, Supabase, and Resend may also process limited information from other locations when providing support, security, or operational services under their terms.
We use contractual, organizational, and technical safeguards intended to protect information across borders. Where applicable law requires a specific transfer mechanism, we will use an appropriate mechanism before making the transfer.
7. Data Retention and Deletion
| Information | Retention |
|---|---|
| Account, profile, and organization verification information | Permanently deleted when account deletion is completed. |
| Active files and their metadata | Until you delete the file or complete account deletion. |
| Unclaimed guest sessions and files | Up to 7 days after creation or until they are connected to an account. |
| Essential cookies and browser storage | Until the relevant session or feature expires, or until you delete them. A guest's analytics-cookie choice is stored for up to 3 months. |
| Deleted files | Permanently deleted from Cloud Storage when deletion is completed. |
| Incomplete or failed uploads | Cleaned up after 24 hours. |
| Upload and view usage events | 12 months. |
| Ordinary request and error records | 30 days. |
| Separate security records | Up to 90 days. |
| Service inquiries and feedback | One year after the inquiry is resolved. |
| Google Analytics event data | 14 months from collection. Where the retention reset applies to an analytics identifier, 14 months from the last relevant activity. |
When you request account deletion, Moada immediately blocks access and permanently deletes account and profile information, files, and related metadata. Account deletion cannot be reversed. We may keep limited records only where required by law or necessary to prevent reuse of deleted share links.
8. How We Protect Information
We use administrative and technical safeguards designed to protect personal information. These include access controls, private cloud storage, encryption in transit, short-lived signed upload and viewing links, one-way storage of guest credentials, and isolated rendering of user-provided files. No online service can guarantee absolute security.
For more information about Moada’s security model, see our Security page.
9. Your Privacy Controls and Rights
You control who can open a file through its sharing setting. You can also review or update certain account information, delete individual files, and request deletion of your account from the Service. Deleting your account permanently removes the account and its files and cannot be reversed.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information; object to or restrict certain processing; or withdraw consent where processing is based on consent.
You can exercise certain rights directly through your profile. For other requests, contact privacy@moada.io. We may verify your identity or an authorized agent’s authority before completing a request. Some requests may be limited where permitted by applicable law.
If your request concerns personal information contained in a file uploaded by another user or organization, you should contact that user or organization first. Where Moada processes that information on its behalf, we may refer the request to it and provide reasonable assistance as required by applicable law.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. If we introduce such decision-making, we will explain the logic involved, its significance and consequences, and the rights available to you before it is used.
11. Sensitive Information in Shared Files
A file may contain sensitive personal information, such as health information. If you share such a file, that information may become available to others according to the sharing setting you choose. Upload sensitive information only when necessary, review the sharing setting before sharing, and use a private setting or delete the file if you do not want the information disclosed.
12. Third-Party Resources in Files
Files may contain scripts, images, fonts, links, or other resources provided by third parties. When a file is opened, those third parties may receive information directly from the viewer’s browser, such as an IP address, browser information, or request time. Their handling of that information is governed by their own privacy policies. A user who includes personal information or tracking code in a file is responsible for providing any required notice and obtaining any required permission.
13. Children’s Privacy
Moada is not designed for or directed to anyone under 16, and we do not knowingly collect personal information from anyone under 16. If we learn that we have processed personal information belonging to someone under 16, we will restrict or terminate the associated account and take appropriate steps to delete the information without undue delay.
14. Additional Rights Under EEA and UK Data Protection Laws
If European Economic Area or United Kingdom data protection law applies to our processing, we generally rely on the following legal bases:
- Contract: to create your account and provide uploads, storage, sharing, viewing, and account features.
- Legitimate interests: to secure the Service, prevent abuse, diagnose errors, and improve reliability, where those interests are not overridden by your rights.
- Legal obligations: where we must retain or disclose information to comply with law.
- Consent: where we specifically ask for consent. You may withdraw it at any time without affecting earlier processing.
When personal information is transferred outside the EEA or UK, we use safeguards as described in Section 6 (International Data Transfers), where required by applicable law. Where applicable, you may request access, correction, deletion, restriction, objection, or data portability, and you may complain to your local supervisory authority. Contact privacy@moada.io to exercise these rights.
15. Additional Rights Under U.S. State Privacy Laws
Depending on where you live and whether the relevant law applies to Moada, you may have the right to access or obtain a copy of your personal information, correct inaccurate information, request deletion, and receive information about how personal information is collected, used, or disclosed. Some U.S. state laws may also provide rights to opt out of the sale of personal information, targeted advertising, or certain profiling. We will not discriminate against you for exercising a privacy right that applies to you.
Moada does not sell personal information and does not share personal information for cross-context behavioral advertising. We do not use personal information for targeted advertising or to make decisions based solely on profiling that produce legal or similarly significant effects.
You or an authorized agent may submit a request at privacy@moada.io. We may request information needed to verify the request and the agent’s authority. If you disagree with our response, you may ask us to reconsider it by replying to our response.
16. Changes to This Privacy Policy
We may update this Policy as the Service or applicable law changes. We will provide advance notice of the effective date and details of a change. We will provide reasonable advance notice of a material change that adversely affects users and may also notify users by email.
17. Contact Us
- Controller
- Moada Lab
- Privacy contact
- privacy@moada.io
- Company
- View company information