Moziflow
HomePricingFAQ
HomePricingFAQLog in
简体中文繁體中文日本語한국어EnglishFrançaisDeutschItalianoPortuguêsРусскийEspañolहिन्दीالعربيةBahasa IndonesiaTiếng Việtไทย
Log inDownload

Legal

Moziflow Privacy Policy

Version 1.0 · Effective August 1, 2026 · Last updated August 1, 2026

Moziflow respects your privacy. This Policy explains how Moziflow handles information when you visit the Moziflow website, create or use a Moziflow account, download an installer, use the Moziflow desktop software, or contact support.

The Moziflow desktop software is built around a local workspace. Your manuscript, characters, worldbuilding, and creative archive are stored on your device by default. During normal use, Moziflow does not automatically collect or transmit your model API keys and does not upload your work to train Moziflow models. When you use AI features, the instructions, manuscript excerpts, and creative context needed to complete your request are sent directly from the desktop software to the model provider you choose. Information contained in support material that you voluntarily send to Moziflow is an exception.

1. Scope

This Policy applies to:

  • the official Moziflow website and its language versions;
  • Moziflow account, authentication, and session services;
  • Moziflow installers and download services;
  • the Moziflow desktop software; and
  • support requests and diagnostic materials that you voluntarily send to Moziflow.

This Policy does not apply to model providers you choose or other third-party services you access through links. Those services handle information under their own privacy policies.

2. Information Moziflow Handles

2.1 Website Connection and Security Information

When you visit the website or download an installer, website infrastructure may process your IP address, request time, browser or device type, User-Agent, requested path, referring page, downloaded file, and information associated with security events. This information is used to deliver pages and installers, maintain security, prevent abuse, and troubleshoot problems.

2.2 Local Browser Settings

The website stores the following settings in your browser:

  • the language you actively select is stored in local storage until you clear browser data or choose another language; and
  • your theme choice and page position during a language switch are stored in session storage and normally expire when the relevant browser tab or session ends.

Moziflow currently does not use advertising cookies, behavioral analytics cookies, or cross-site tracking technologies. Infrastructure providers such as Cloudflare may set strictly necessary cookies when performing security challenges or abuse-prevention measures.

2.3 Download Information

When you obtain an installer from the download domain, content-delivery and security infrastructure may process the downloaded file, operating system or architecture selection, IP address, request time, and security logs. This information is used to complete the download, protect file distribution, and manage abnormal traffic.

2.4 Support Communications

When you contact Moziflow by email, we process your email address, message content, correspondence history, attachments, and other information you choose to provide. We use this information to respond, diagnose problems, maintain service security, and retain necessary communication records.

Do not include unrelated sensitive personal information, model API keys, access tokens, or other secrets in support messages.

2.5 Diagnostic Exports

Creating a diagnostic export in the desktop software only generates a local file on your device; it does not automatically transmit the file to Moziflow. Moziflow receives the export only if you separately send it through email or another support channel. A diagnostic export may contain application information, redacted runtime configuration, runtime logs, filenames, manuscript chapters, story settings, creative archive data, prompt context, or model-call records. The export process attempts to remove model API keys, access tokens, and some local paths, but it cannot guarantee detection of every sensitive detail that you placed in a manuscript, filename, or log.

Before sending a diagnostic export, inspect its files and remove anything you do not want to provide to Moziflow. Moziflow uses diagnostic material you send only to handle the associated support, security, or troubleshooting matter.

2.6 Account and Authentication Information

When you create or use a Moziflow account, Moziflow processes your account email address, the sign-in method you use, Google account subject identifier when you choose Google sign-in, legal-document acceptance snapshot, session and device records, application version and platform, country or region derived at the infrastructure boundary where available, and security-event records. Moziflow stores keyed summaries of IP addresses, network ranges, User-Agent values, and similar abuse-prevention signals; raw IP addresses are not stored in the account business database.

Email verification codes, OAuth transactions, authorization codes, access tokens, refresh tokens, CSRF tokens, and Desktop handoff data are processed only to authenticate requests, protect sessions, prevent replay, and recover safely from interrupted sign-in. Secrets and plaintext verification codes are not intended to appear in ordinary application logs.

3. Information Kept on Your Device

The following information remains on your device by default and is not automatically uploaded to Moziflow merely because you use the desktop software:

  • novel text and chapters;
  • characters, worldbuilding, plot information, writing rules, and other creative archive data;
  • local workspace files;
  • model API keys; and
  • local desktop settings and runtime records.

Information included in support messages or diagnostic exports that you actively send is an exception. Information sent to your selected model provider when you use AI features is also outside Moziflow's local-storage boundary.

4. Third-Party Model Services

Moziflow lets you configure your own model service and API key. The desktop software sends the information required to complete a task directly to the service address you configure. Depending on the task, that information may include:

  • your instructions and prompts;
  • relevant manuscript excerpts;
  • characters, settings, outlines, and chapter summaries; and
  • other creative information needed to preserve context or perform generation, analysis, or revision.

Model providers may process and retain this information in different countries or regions. Their purposes, retention periods, training policies, and opt-out options are governed by your agreement with the provider and its privacy policy. Moziflow cannot access, correct, or delete this data on a provider’s behalf. Before using a model service, review its terms and privacy policy and select an account type and data settings appropriate for you.

5. Purposes and Legal Grounds

Moziflow handles information only as needed to:

  • provide the website, account, authentication, session, downloads, and support services you request;
  • remember interface settings you actively choose;
  • protect the website, downloads, and software against fraud, attacks, and abuse;
  • diagnose problems, maintain compatibility, and improve stability;
  • establish, exercise, or defend legal claims; and
  • comply with applicable law.

Depending on applicable law, the legal grounds may include performing a service you request, Moziflow’s legitimate interests in operating and protecting the service, compliance with legal obligations, or your choice to submit optional materials. Moziflow does not use information supplied for support to build advertising profiles or train Moziflow models.

6. Disclosure of Information

Moziflow may disclose information:

  • to Google when you choose Google sign-in, for identity authentication under Google's terms and privacy policy;
  • to Cloudflare for website delivery, security protection, abuse prevention, and Turnstile human verification when enabled;
  • to Resend for transactional verification codes and account security notices when email delivery is enabled;
  • to Render for Account application and PostgreSQL hosting if that infrastructure is enabled;
  • to other providers of installer storage and support email, to the extent necessary to provide those services;
  • to comply with applicable law, a court order, or a request from an authority with lawful jurisdiction;
  • to protect the rights, safety, and legitimate interests of Moziflow, users, or the public, or to investigate fraud, attacks, and abuse; and
  • in connection with a business transfer, restructuring, or service succession, subject to reasonable confidentiality and data-protection measures.

Moziflow does not sell personal information, share personal information for cross-context behavioral advertising, or use your manuscript to train Moziflow models.

7. Infrastructure and International Processing

Moziflow uses Cloudflare for website delivery, downloads, and security. When enabled, Moziflow is designed to use Cloudflare Turnstile for human verification, Render for Account application and PostgreSQL hosting, Resend for transactional email, and Google when you choose Google sign-in. These providers may process account, connection, authentication, delivery, and security information in countries or regions where they operate. Support email services may also involve international processing.

Your selected model provider determines its own processing locations under its terms. That model processing is triggered directly by your configuration and request and does not pass through a Moziflow model proxy.

Where required by applicable law, Moziflow uses appropriate contractual, technical, or organizational measures to protect international transfers controlled by Moziflow. Data-protection rules in another country or region may differ from those where you live.

8. Retention

Moziflow retains information as follows:

  • local browser settings are retained by your browser for the periods described in Section 2.2;
  • expired verification-code digests, OAuth transactions, authorization codes, and flow tokens become eligible for deletion 24 hours after expiry; sensitive idempotency responses and handoff ciphertext are destroyed after 60 seconds or terminal use;
  • ordinary idempotency records and rate-limit counters become eligible for deletion after 24 and 25 hours respectively; transactional email delivery status and provider message identifiers become eligible after 7 days;
  • keyed IP or network-range summaries, User-Agent summaries, infrastructure request identifiers, and expired or revoked session metadata become eligible for deletion after 30 days; inactive Desktop device records become eligible after 90 days;
  • ordinary account security events become eligible for deletion after 90 days. Specifically designated high-risk events may be pseudonymized for up to 180 days with an automatic expiry date;
  • routine website, download, and security logs that Moziflow can access or affirmatively exports are normally retained for no more than 30 days; records associated with an attack, fraud, security incident, or dispute may be retained until the matter is resolved and any reasonable limitation period ends;
  • copies retained by infrastructure and email providers are handled under Moziflow’s service configuration, provider agreements, and applicable deletion requirements; provider retention needed for security, backups, or legal obligations may continue longer, and information a provider independently handles under law is also governed by its own policy;
  • support emails and diagnostic material you send are normally deleted or anonymized within 12 months after the support matter closes, unless longer retention is necessary for an ongoing dispute, security incident, or legal obligation;
  • local works and desktop settings remain under your control on your device until you delete them; and
  • model-provider retention is governed by the provider’s terms and your account settings.

Eligible records are removed on the next scheduled maintenance run. Ephemeral authentication cleanup runs every 15 minutes, session and account-deletion cleanup runs hourly, and security-event and transactional-email cleanup runs daily. Actual removal can therefore occur after a stated eligibility time by up to the next scheduled maintenance run. When a retention purpose ends, Moziflow deletes, anonymizes, or otherwise stops using information under its control, except where retention is legally required or necessary to establish, exercise, or defend legal claims.

9. Security

Moziflow uses reasonable technical and organizational measures appropriate to the product’s scale and risks to reduce unauthorized access, disclosure, alteration, and loss. These measures include minimizing server-side data, keeping secrets out of logs where practicable, encrypting data in transit, and redacting diagnostic material.

No storage or transmission method is completely secure. You should protect your device, model accounts, and API keys and maintain an independent backup of local works.

10. Your Rights and Choices

Depending on the law where you live, you may have the right to:

  • know whether Moziflow processes your personal information;
  • request access to or a copy of personal information held by Moziflow;
  • correct inaccurate information;
  • request deletion;
  • restrict or object to certain processing;
  • request data portability where applicable;
  • withdraw consent where processing relies on consent; and
  • complain to a competent data-protection or consumer-protection authority.

To submit a request, email privacy@moziflow.com. To protect your information, Moziflow may ask you to verify your identity through the original communication address or another reasonable method. Rights may be subject to conditions and exceptions under applicable law.

You can request account deletion from the account page after recent identity verification. The request immediately revokes Web and Desktop sessions and starts a 7-day cancellation period. During that period, a restricted recovery session can only view or cancel the deletion. After the period ends, online account, identity, device, session, and ordinary security data is removed by the next hourly account-deletion maintenance run. No production Account backup is enabled as of this Policy version. Before enabling one, Moziflow will configure and disclose a finite backup retention and deletion period. Pseudonymized high-risk security events may remain for the limited period described in Section 8. Account deletion does not delete, upload, or lock books stored in your local workspace.

You manage local works directly on your device. For information held by a model provider, you must exercise your rights with that provider; Moziflow cannot complete the request on its behalf.

11. Children and Minors

Moziflow is not directed to children under 13 and does not knowingly collect their personal information. A person who has not reached the age to consent or contract independently where they live should use Moziflow only with the consent and supervision of a parent or legal guardian. If you believe a child provided personal information to Moziflow without appropriate authorization, contact privacy@moziflow.com.

12. Changes to This Policy

Moziflow may update this Policy as the product, technology, or legal requirements change. An updated Policy will show a new version, effective date, and last-updated date. For changes that materially affect your rights or how information is used, Moziflow will provide a prominent notice on the website or in the software and obtain consent where applicable law requires it.

An update will not retroactively authorize Moziflow to use previously collected information for a purpose materially incompatible with the original disclosure.

13. Contact

  • Privacy requests: privacy@moziflow.com
  • General support: support@moziflow.com
MoziflowFrom brilliant ideas to timeless stories
FeaturesDownloadFAQPrivacyTerms
© 2026 Moziflow