MOAT / LEGAL
Privacy Policy
What we access, why we use it, and the choices you have.
Effective date: 24 September 2026
1. Who operates Moat
Moat, available at moat.one, is operated by Dev Vora, based in India (“Moat”, “we”, “us”). Dev Vora is responsible for the handling of personal information described in this policy. For privacy, access or deletion requests, email devvora08@gmail.com.
2. What is available today
The current public release is an interactive demonstration. Office reports, customer examples, messages and metrics are synthetic. The demo does not connect to Google Analytics, Google Search Console, email services or payment accounts; it does not send email or collect payment. Typing into demo fields changes the local demo state and is not submitted to a Moat backend. Do not enter confidential or personal customer information in demo fields.
The Google integration described below is planned for the optional Observatory department. It is not active in this release. We will update this policy with the actual storage, retention and processing arrangements before enabling live Google access, and request authorization before accessing Google data.
3. Information used by the current website
- Website requests: our hosting provider, Vercel, processes technical information needed to deliver and protect the site, such as IP address, requested URL, browser information, timestamps and diagnostic logs. Hosting may involve processing outside your country, including outside India.
- Local preferences: the demo uses browser local storage to remember music preferences. You can remove this information through your browser’s site-data settings. Demo activity and edited sample messages are kept in memory and reset when the page is reloaded.
- Support correspondence: if you email us, we receive your email address, message and any information you choose to include. We use it to respond, investigate issues and manage your request. Email is processed by our email provider, Google.
We have not added advertising trackers, behavioral advertising cookies or a third-party visitor analytics integration to this release. Visiting moat.one does not authorize access to your Google account.
4. Planned Google Analytics and Search Console access
When the Google connection becomes available, it will be optional and initiated by you. We intend to request these read-only permissions:
https://www.googleapis.com/auth/analytics.readonly— to read GA4 property information and reports, including users, sessions, acquisition sources, pages, engagement and key events, so the Observatory can display your website’s traffic trends.https://www.googleapis.com/auth/webmasters.readonly— to read your authorized Search Console site information and search-performance reports, including queries, pages, clicks, impressions, click-through rates and average position.
Google permissions can cover more than one property you can access. Moat’s intended workflow is to let you choose the properties used in your workspace and to query those selected properties. The requested permissions do not allow Moat to modify your Analytics configuration or Search Console properties. These permissions do not grant access to Gmail messages, Google Drive files, contacts or your Google password.
The integration will need OAuth authorization tokens and selected property identifiers to maintain the connection. The current demo neither requests nor stores those tokens. Google data will be used for the user-facing Observatory reports and related analysis you request, not for unrelated purposes.
5. Google data, AI and Limited Use
Moat will not sell Google user data or use it for advertising, profiling for advertisements, credit decisions, or training, fine-tuning or improving AI or machine-learning models. We do not currently send Google data to any AI provider because no Google connection exists. Any future use of a processing provider for a requested report will be disclosed before activation and must follow these restrictions.
Moat’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Access to Google data by people will be restricted to circumstances permitted by that policy, such as your affirmative permission for support, investigating security issues or complying with law. Google data will not be shared with unrelated third parties.
6. Sharing and security
We use hosting and email providers to operate the current website and respond to correspondence. We may disclose information when legally required or necessary to investigate abuse and protect users. We do not sell personal information. We do not publish private support correspondence.
We use HTTPS on the production website and restrict access to operational accounts. No transmission or storage system is completely secure. Do not send passwords, OAuth tokens or payment information to our support inbox.
7. Retention and deletion
Local browser preferences remain until you clear site data. Temporary demo state is discarded on reload. We keep support correspondence only as reasonably necessary to handle the request, maintain relevant records or comply with legal obligations. Hosting and email providers may retain operational logs and backups under their service retention schedules.
To request deletion of information you have sent us, email devvora08@gmail.com from the relevant address and describe the request. We may need to verify your identity. We will act within applicable legal time limits and explain any information we must retain by law.
No GA4 reports, Search Console reports or Google authorization tokens are stored by the current demo. Specific retention periods and a working disconnect/deletion process for the Google connection will be published before it is enabled. Removing authorization from your Google Account connections stops future authorized access; it does not by itself erase information already held by an application.
8. Your choices and rights
You can use the demo without connecting an account, clear browser preferences, and choose not to provide information by email. Depending on applicable law, you may have rights to access, correct, delete or restrict processing of your personal information, withdraw consent, or complain to a relevant data-protection authority. Contact us to exercise those rights.
9. Children
Moat is a tool for adult website operators and businesses. It is not directed to children under 18. If you believe a child has provided personal information, contact us so we can address it.
10. Changes to this policy
We will update this page and its effective date when our practices change. Material changes to Google-data use will be disclosed before the changed processing begins, with renewed consent where required. See also our Terms of Service.