Privacy Policy
Version of 29 September 2026
1. Who is responsible for your data
- Mosewi Digital (eenmanszaak / sole proprietorship) (the "Operator", "we", "us")
- Registration number: Dutch Chamber of Commerce (KvK) 73856894
- Contact: through the support option shown inside MD (Settings).
The Operator is the “controller” of your personal data for MD under the GDPR / UK GDPR. When you use MD to publish content that mentions or shows other people, you are responsible for having a lawful basis for that content (see the Content Rules). When a business user puts other people’s data (for example its clients’ data) into MD, that business is the controller of that data and we act as its processor under section 17 of the Terms of Service; questions about that data should go to the business concerned.
Most data comes from you, from the platforms you connect, or is created by your use of MD. Giving account data is needed to create an account; without it we cannot provide the Service. Everything else is optional, but some features need it (for example publishing needs a connected account).
2. The data we process
- Account data: username, optional email, and your password stored only as a bcrypt hash (never in plain text); the date the account was created; plan and usage counters.
- Legal acceptance records: which version of the legal documents you accepted, what you ticked, when, the IP address and browser details from which you accepted.
- Connected-platform data: the access and refresh tokens platforms issue to MD (stored encrypted, AES-256-GCM) and the basic profile the platform returns (account ID, name, handle, avatar) — MD never receives your social password.
- Your content: captions, hashtags, media you upload or link, schedules, approval status, platform-specific settings, brands (workspaces) and their logos.
- Performance data: metrics (such as views, likes, reach) the platforms return about content you published through MD.
- AI data: what you write to the AI features, the AI’s replies, and information from your account (such as your past posts, results and business description) that is included so the AI can answer usefully.
- Activity and security records: a log of important actions (connecting an account, approving or publishing a post, sign-ins that failed, plan changes) and technical counters used to stop abuse (for example number of sign-up or sign-in attempts per network address).
- Payment data (when online payment opens): handled by our payment provider; we receive only the plan, status and identifiers needed to give you the plan. We do not receive your card number.
- Support messages: what you write when you use Help to message the MD team, the subject, the page you were on, and your conversation with the assistant just before it, so we can understand and solve the problem.
- Hosting logs: standard request logs (path, time, status, network address) kept by our hosting provider.
We do not knowingly collect special-category data and do not ask for it. Please do not put such data in prompts or posts unless you are entitled to.
3. Why we use it, and on what legal basis
- To provide MD to you (create and secure your account, store your content, publish what you approve, show analytics, apply your plan, provide AI features) — contract (Art. 6(1)(b) GDPR).
- To connect a platform account and act on it — your consent given on that platform’s own screen, which you can withdraw by disconnecting (Art. 6(1)(a)).
- Security, fraud and abuse prevention, limits and rate-limits, keeping activity logs, enforcing the Terms and keeping proof of your acceptance of them, and defending legal claims — our legitimate interests (Art. 6(1)(f)).
- Tax, accounting and other legal duties — legal obligation (Art. 6(1)(c)).
We do not sell personal data, do not use it for third-party advertising, and do not use your content to train our own AI models. No decision with legal or similarly significant effect on you is made by automated means; AI output in MD is a suggestion that you decide on.
4. Who receives data (processors and recipients)
We share data only with the providers needed to run the features you use, under their data-processing terms:
- Supabase — database hosting (EU region: Frankfurt, Germany).
- Vercel — application hosting (functions run in the EU region, Frankfurt; some logs, and media uploaded before October 2026, are stored in the United States).
- Cloudflare — storage and delivery of the photos and videos you upload (stored in the EU) and the network that serves them quickly.
- Anthropic — AI model provider: receives your AI requests and the account information included with them to produce answers. Under its commercial terms it does not use this data to train its models.
- Meta (Facebook, Instagram), TikTok, Google (YouTube), LinkedIn, Pinterest — only for accounts you connect: receive the posts you approve and return account and performance data. Each platform is an independent controller of the data it holds.
- Stripe (or another payment provider) — only when online payment opens, to take payments.
- Authorities and advisers — where the law requires it, or for legal claims, or to professional advisers under confidentiality.
- If the business is transferred, the successor will take over the data under this policy.
We will update this list before adding a new provider that processes personal data, so business users can object as described in the Terms.
5. Google / YouTube API data
MD’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use YouTube data only to upload the videos you approve and to show you their performance, do not use it for advertising, do not sell it, and do not allow humans to read it except with your consent, for security, or where the law requires. By using YouTube features you also agree to the YouTube Terms of Service and the Google Privacy Policy. You can revoke MD’s access at security.google.com/settings/security/permissions.
6. International transfers
Some providers (including Anthropic, Vercel, Cloudflare and the social platforms) may process data outside the EEA/UK, including in the United States. Where that happens we rely on adequacy decisions (such as the EU–US Data Privacy Framework where the provider is certified) or the EU Standard Contractual Clauses, as applicable.
7. How long we keep data
- Account content and settings: while your account exists. Deleted by you at any time (Settings → Delete my account) — see the Data deletion page.
- Connected-platform tokens: until you disconnect, they expire, or you delete your account.
- Support messages: until you delete your account.
- Old technical records (rate-limit counters, old activity entries, processed job records) are removed automatically on a schedule.
- Proof that you accepted the Terms and a note that an account was deleted: up to 3 years after deletion, to answer legal claims (longer if a claim is pending or the law requires it).
- Billing and accounting records, including your confirmations of plan changes (with date, time, network address and browser): 7 years, as Dutch tax law requires - also after you delete your account.
- Backups: overwritten on the provider’s normal rotation.
8. Your rights
You have the right to access, correct, delete, restrict and object to processing of your data, to data portability, and to withdraw consent at any time (which does not affect earlier processing). In MD you can download your data and delete your account yourself in Settings → Legal & account, and disconnect any platform in Connections. For anything else, use the support option in Settings; we answer within one month (extendable by two months for complex requests, in which case we tell you). We may ask you to prove your identity first so that nobody else can obtain your data. You may complain to a data protection authority — in the Netherlands the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or the authority where you live or work.
8a. Extra information for people outside the EU
- United States (including California, Colorado, Virginia, Connecticut, Utah, Texas and other states with privacy laws): the categories of personal information we collect, their sources and purposes are described in sections 2–4. We do not sell personal information and do not “share” it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for purposes that require an opt-out. You may request to know, access, correct or delete your personal information, and we will not discriminate against you for exercising these rights. You may use an authorised agent, and we may verify the request. If we refuse a request you may appeal by replying to our answer.
- Global Privacy Control / Do Not Track: because we do not sell or share personal information or use tracking cookies, these signals do not change how MD works.
- United Kingdom, Switzerland, Canada, Brazil, Australia and other countries: you have the rights your local privacy law gives you, which you can exercise in the same way as described in section 8.
9. Cookies and similar storage
MD uses only what it needs to work. We use no advertising or tracking cookies, so no cookie banner is needed. The following are set:
- A session cookie that keeps you signed in, and a security token that protects sign-in against forgery (strictly necessary).
- A short-lived cookie used while you connect a social account, to protect that step against forgery.
- Small preference cookies: the brand you selected and the platform filter you chose (the filter clears when you close the browser).
- Browser storage for your display choices (for example whether the assistant button is shown) and a temporary note that lets the assistant point at something after a page change.
10. Security
Passwords are hashed; platform tokens are encrypted; connections use HTTPS; access is protected by sign-in, rate limits and per-account data separation; and important actions are logged. No system is perfectly secure. If a breach affects your personal data in a way the law requires us to report, we will notify the authority and you as required.
11. Children
MD is for people aged 18 and over. If we learn that a child has an account, we will delete it.
12. Changes and contact
We will update this policy when MD or the law changes, show the new version date, and ask you to accept again when the change is important. Contact: the support option in Settings.
