Last updated: 2026-07-14. Effective: 2026-07-14.
This is the Privacy Policy for Moonwake, an iOS application published by Cloud Motion Lab LLC ("we", "our", "us"). It explains what we collect, why, who we share it with, how long we keep it, and the rights you have. We try to keep this readable. If a section is unclear, write to dev@slyapp.co.
We collect the following categories of personal information when you use Moonwake: identifiers (Apple-issued anonymous user IDs), commercial information (purchase history within the app), internet or other electronic network activity (in-app usage signals), and any inputs you voluntarily provide to in-app features, such as the question you ask for a reading or a dream you ask to have read. We use this information to deliver the app, generate the readings you request, process purchases through Apple, prevent fraud and abuse, and improve features. Retention is described in the Retention section below. We do not sell your personal information and we do not share it for cross-context behavioral advertising. A summary of your California privacy rights and the link to exercise them appear in the State Privacy Rights section below.
Moonwake is built to collect as little as possible. There are no user accounts, no logins, and no profile pages.
Moonwake generates readings by sending the input you provide, together with a fixed instruction prompt, to a third-party AI model provider. For a tarot reading, that input is the question you type. For a dream reading, it is the text of the dream telling you ask to have read, together with the symbols the app found in it. The provider returns generated text, which the app displays as your reading and stores locally on your device. A dream reading happens only when you explicitly request one; keeping a dream in your journal never sends it anywhere. We do not use your questions, dreams, or readings to train any model of our own, and we do not maintain a server-side copy of your reading history or your dream journal. The AI provider's handling of the data we transmit is governed by its own terms and privacy policy, and its retention of the data we send is summarized in the Subprocessors table below.
| AI subprocessor | Purpose | Region | What is sent |
|---|---|---|---|
| OpenRouter (and the underlying model provider it routes to) | Generate the text of a tarot reading from your question, or of a dream reading from a dream you ask to have read | United States | Your typed question, or the dream telling you asked to have read and the symbols found in it, plus a fixed instruction prompt; no name, email, or account identifier |
| Category | Purpose | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Anonymous usage analytics | Operate and improve the app | Legitimate interest, Art. 6(1)(f) |
| Subscription state | Deliver paid features you bought | Performance of contract, Art. 6(1)(b) |
| AI reading inputs (your question, or a dream you ask to have read) | Generate the reading you requested | Performance of contract, Art. 6(1)(b) |
| Fraud, abuse, and security monitoring | Protect users and the service | Legitimate interest, Art. 6(1)(f); legal obligation, Art. 6(1)(c) |
The third-party services that process data on our behalf are listed below. Where data crosses borders, the legal basis for the transfer is identified in the table.
| Subprocessor | Purpose | Region | Transfer mechanism (EU and UK) |
|---|---|---|---|
| TelemetryDeck | Anonymous usage analytics | European Union (Germany) | Adequacy, no transfer needed for EU and UK; GDPR direct application |
| RevenueCat | Subscription state management, anonymized user IDs only | United States | EU-US Data Privacy Framework, with 2021 SCCs as backstop |
| OpenRouter and underlying AI model provider | Generate reading text from your question | United States | EU-US Data Privacy Framework where certified, with 2021 SCCs as backstop |
| Apple App Store, StoreKit, iCloud | App distribution, subscription processing, anonymous receipt | Global, governed by Apple | Apple's own Data Privacy Framework certification and SCCs, see Apple Privacy Policy |
For transfers from the EU, UK, or Switzerland to the United States, we rely first on the EU-US Data Privacy Framework where the recipient is certified, and on the 2021 Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable) as a backstop. We monitor regulatory changes to the Data Privacy Framework and are prepared to switch to SCCs as the primary mechanism if the Framework is invalidated.
We do not sell personal information for money or other valuable consideration, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended. We honor the Global Privacy Control browser signal where it reaches us. Because Moonwake runs on iOS and does not use a website signup, the practical effect is that no opt-out signal is needed to stop a sale or share that we are not doing.
If you live in a U.S. state with a comprehensive consumer privacy law, you have the rights below. The current list of states is California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia.
To exercise any right, email dev@slyapp.co with the words "Privacy Request" in the subject line and tell us which app and what you want. We respond within 45 days, with one 45-day extension where reasonably needed. If we deny a request, you may appeal by replying to the same thread within 60 days. We will respond to the appeal within 45 days. If you are not satisfied, California residents may contact the California Privacy Protection Agency, and other state residents may contact their state Attorney General. Texas, Maryland, Oregon, and other state laws apply regardless of any revenue threshold; we treat all U.S. residents the same.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights of access, rectification, erasure, restriction of processing, portability, objection, and not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. We do not engage in such automated decision-making. To exercise a right, email dev@slyapp.co. You may also lodge a complaint with your local supervisory authority. The lead authority for users in the EU is the data protection authority of the country where you are habitually resident. UK users may complain to the Information Commissioner's Office. We will respond within one month of receipt and may extend by two further months for complex requests, with notice.
Moonwake is rated 17+ and is not directed to children under 13. Under the Children's Online Privacy Protection Act Final Rule amendments, biometric identifiers including fingerprints, faceprints, voiceprints, retina or iris patterns, gait, and DNA are personal information when collected from a child under 13. We do not knowingly collect any personal information, biometric or otherwise, from a child under 13. If we learn that we have, we will delete it within 30 days. If you believe a child has provided us with personal information, contact dev@slyapp.co and we will delete it promptly. For users between 13 and 16 in jurisdictions that require parental consent for personal-data processing, we rely on the Apple platform's Declared Age Range signal where it is available.
Moonwake requests three permissions, each tied to one feature. You can grant or revoke any of them at any time in iOS Settings, and the app works without them.
When you record a dream, Moonwake uses your microphone to capture what you say and Apple's Speech framework to turn it into text.
You can put your own photo behind an affirmation card, and you can save a finished card to your photo library.
Dream transcripts and everything in your dream journal are stored in a file on your device. As journal data they are not uploaded, not synced to any cloud, and not backed up to our servers. If you delete the app, they are gone. One exception, and it only happens when you ask for it: if you request a dream reading, the text of that dream telling is sent to the AI subprocessor listed above to generate the reading, exactly like a tarot question. Your voice audio is never sent or stored in any case, and a dream you never ask to have read never leaves your phone.
All purchases in Moonwake are processed by Apple under Apple's Media Services Terms. We never see your credit card number, billing address, or Apple ID. We receive an anonymous receipt confirming an active subscription or purchase, which the app uses to unlock paid features. Payment data is governed by the Apple Privacy Policy.
We use commercially reasonable administrative, technical, and physical safeguards to protect personal information. No system is perfectly secure. If we determine that a personal-data breach affecting your information has occurred, we will notify you and applicable regulators in accordance with applicable law. For users in the EU and UK, our notification window is 72 hours after we become aware, in line with GDPR Article 33. For U.S. users, we follow the notification rules of your state.
Data on your device is stored using standard Apple frameworks (UserDefaults, SwiftData, Keychain). Data we send to subprocessors is stored on their infrastructure; the location and retention are listed in the Subprocessors table. We do not operate our own user-data servers for Moonwake.
We may update this Privacy Policy. For material changes, including expansion of categories collected, new subprocessors that change data flow, new regions, or changes to dispute-resolution rules referenced here, we will give at least 30 days' advance notice through an in-app banner and, where available, the email address associated with your Apple ID, and will update the effective date at the top of this page. Minor changes such as typographical or formatting fixes may be made without separate notice. Continued use of the app on or after the effective date of an updated version constitutes acceptance.
For privacy questions, complaints, or rights requests: dev@slyapp.co. Our registered postal address is Cloud Motion Lab LLC, 30 N Gould St Ste R, Sheridan, Wyoming 82801, United States. We currently process EU and UK personal data at a scale below the threshold that requires a designated GDPR Article 27 or UK GDPR representative. If your processing is in scope of those requirements, the same contact email is the route to a response. We will appoint and publish a representative if and when our processing reaches that threshold.