Privacy Policy

How Moned processes personal information and the choices available to people who use the service.

Version
2026-07-27.2
Effective
Updated

Controller and contact

Moned UG, Schedestraße 7, 20251 Hamburg, Germany, is the controller for the Moned public website and marketplace services described here.

Privacy questions and rights requests can be sent to privacy@moned.ai or submitted through the governed privacy request form. Moned does not claim a Data Protection Officer unless one is formally appointed.

Information Moned processes

Account and profile information; expert application and review evidence; service, availability, booking, payment, communication, review, and support records when those features are used; AI-search and conversational-discovery wording, bounded structured criteria, typed results, and derived continuity state; consented microphone-audio transcripts and summaries when enabled; browser consent records; security and operational records.

For enabled tax workflows, Moned may process legal and trading names, tax residence, establishments, performance locations, billing and business status, tax and business identifiers, registrations, evidence, forms, confirmations, expiry dates, transaction tax decisions, documents, settlement, withholding, seller-reporting, exposure, reconciliation, approval, correction, and audit records.

Professional review evidence is private. Government identity documents are not collected by default for expert review. Conversational discovery asks for the kind of help needed, not payment details or sensitive personal case facts.

Why information is used

To operate accounts, public profiles, discovery, reviewed services, authoritative pricing, bookings, payments, communication, safety, support, fraud prevention, legal compliance, and product reliability.

AI-assisted processing

Moned may send bounded search, recent conversational context, compact public marketplace facts, or session inputs to configured cloud AI providers for discovery interpretation and wording, consented transcription, or session summaries. Moned's backend controls expert facts, availability, prices, and every permitted operation; rich cards and selectors are application-owned. Recognizable payment credentials and first-person sensitive-category disclosures are rejected before assistant persistence or provider use, but users should still enter only a general help need. See the AI Policy.

Service providers

Current provider categories include cloud hosting and AI processing, authentication, payment processing, video communication, email delivery, storage, malware scanning where configured, and error monitoring where enabled. Stripe, Google services, LiveKit, and Sentry are used only by the relevant product surfaces and configuration.

Google does not use Moned's prompts to train or fine-tune models without permission. Under the standard Google Cloud terms, a prompt flagged by automated safety classifiers for suspected abuse may be retained in the selected region or multi-region for up to 90 days and reviewed by authorized Google staff for policy enforcement. Moned has requested an exception from this provider logging.

Tax-data safeguards and sharing

Raw tax identifiers and identity payloads are encrypted using the private credential-vault path. Product surfaces display only masked values and non-sensitive verification status. Tax admins receive role-scoped access; payment operators receive only payout reason projections rather than raw tax identity. Sensitive changes and exports require MFA step-up and, where specified, a different proposer and approver.

Moned may share the minimum required information with tax authorities, reporting authorities, payment processors, filing or validation providers, professional advisers, or other recipients where an approved workflow and legal basis apply. Stripe Tax is the selected initial transaction-tax calculator and the European Commission's VIES service is the selected EU VAT-ID source, but both remain inactive in disabled and shadow modes. Filing remains provider-neutral. Provider results are minimized and do not replace Moned's retained decision and audit record.

Retention and deletion

Retention follows purpose and record type rather than one blanket period. Anonymous legacy AI-search records are eligible for seven-day cleanup. When conversational guidance is enabled, anonymous free-form turns are retained for up to 24 hours and their bounded structured conversation for up to seven days. For signed-in users, free-form conversation wording is retained for up to 30 days and bounded structured history, typed results, and summaries for up to 90 days. Raw consented discovery events are retained for up to 90 days and aggregate totals for up to 13 months. Browser consent records are scheduled for deletion after approximately three years.

Closed general support and feature cases are scheduled for deletion after two years; product bugs after 18 months; conduct, booking/payment, privacy, and appeal cases after three years; and coordinated security disclosures after five years. Private support evidence is deleted earlier where it is no longer needed. Legal holds pause deletion. Invoices, booking and payment evidence, tax identity and decision records, seller-reporting snapshots, filings, corrections, and commercial correspondence follow the applicable statutory recordkeeping and restriction periods rather than the support-case schedule.

Authenticated users can remove individual assistant conversations, clear assistant history, remove supported search history, and use account-deletion controls. Deletion does not remove records that Moned must retain for tax, accounting, reporting, payment, fraud-prevention, dispute, or legal-hold purposes. Access is restricted after the ordinary product purpose ends.

Choices and rights

Depending on location, people may have rights to access, correct, delete, restrict, object, withdraw consent, or receive a copy of personal information. Submit a request through the privacy request form or email privacy@moned.ai. Identity confirmation occurs after intake and does not request government ID by default.

Security

Moned uses access control, encryption, audit, private storage, and governed administrative patterns appropriate to the relevant system. No internet service can promise absolute security. Vulnerabilities should be reported to security@moned.ai or through the dedicated disclosure form.

Privacy Policy | moned