Privacy Policy
Mossy is an independent sustainability-communication watchdog. We collect as little as possible, never sell your data, and are transparent about what we do with it.
Last updated: 15 June 2026
What data we collect
- Account information. Email address and password (handled by our authentication provider) when you create an account or sign in.
- Usage data. Scans you run, ratings you leave, and beta codes you redeem. This helps us operate and improve the service.
- Audit content. Text, images, PDFs or URLs you submit to the Mossy Message Scan. We process this to generate the audit report and related scores.
- Technical data. Browser type, device type, and coarse location (country-level) derived from your IP address. We use this for security and performance monitoring.
How we use your data
- To provide the Mossy Message Scan and related services.
- To keep your account secure and send essential account emails (password resets, login alerts).
- To improve the tool — for example, understanding which scan inputs are most common so we can refine prompts and scoring.
- To enforce our terms and prevent abuse or fraud.
We do not use your data for advertising, profiling, or selling to third parties.
Data storage & security
Mossy stores data in Supabase, our backend database provider. Where possible, data is stored in the European Union (EU). All data is encrypted in transit (TLS) and at rest. Access is restricted to authorised team members only.
Text, images, and documents submitted for scanning are used solely for the purpose of generating your scan results. Raw submitted content is automatically deleted from our systems within 30 days of submission. Scan results, verdicts, scores, and improvement suggestions are retained for the duration of your account.
For anonymous (non-signed-in) scans, submitted text is processed for analysis and is not stored in our database after the scan completes.
Mossy is hosted on Lovable Cloud infrastructure, which acts as a data processor under a formal Data Processing Agreement. Submitted content is processed solely on our instructions and is not used for AI model training.
For enterprise clients requiring a formal Data Processing Agreement, please contact hello@mossy.green.
Data retention
- Scan content. Text, images, documents and URLs submitted for analysis are stored for 30 days for registered users and are not stored at all for anonymous users. After 30 days, submitted content is automatically deleted. Scan result summaries (risk score, flags, suggestions) are retained in your account history.
- Evidence files. Files uploaded to support sustainability claims in the evidence module are stored securely in your workspace and are not subject to automatic deletion. These are governance documents you have intentionally saved. You can delete individual evidence files at any time from the claim detail page. If you close your account, evidence files associated with your workspace will be deleted within 30 days.
- Claim register. Claims, version history and audit logs in your claim register are stored for as long as your account is active. These records exist to support your governance and compliance workflow. You can archive or delete individual claims at any time. If you close your account, all claim register data will be deleted within 30 days.
- Workspace data. Workspace settings, team members and invitation records are stored for as long as your workspace is active. If a workspace is deleted, all associated data is removed within 30 days.
Security
All data transmitted to and from Mossy is encrypted in transit using TLS. Data at rest is encrypted by Lovable Cloud and Supabase infrastructure. Mossy does not implement application-level encryption beyond what is provided by the underlying infrastructure. For details on Lovable's security practices, see lovable.dev/security.
AI processing
Mossy uses Google Gemini 2.5 Flash via the Lovable AI Gateway to process submitted content and generate analysis results. Submitted content is not used to train AI models. In compliance with EU AI Act Article 50, all AI-generated outputs are labelled as such — all verdicts, risk scores, flags, and improvement suggestions are generated by an AI model.
When you use the Mossy Message Scan, the text and images you submit are sent to an AI model for analysis. The AI provider receives only the content you upload — no personal identifiers beyond what is in the content itself. AI outputs (audit reports and scores) are stored so you can view your history; the original inputs are not kept permanently and are deleted according to our retention schedule.
Your rights
Under the GDPR and applicable data-protection law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Object to or restrict certain processing.
- Export your data in a portable format.
To exercise any of these rights, email hello@mossy.green and we will respond within 30 days.
Cookies
Mossy only uses essential cookies and local storage needed to run the service, plus a preference cookie that remembers your cookie choice. We do not use advertising, profiling or cross-site tracking cookies.
- Essential — Authentication. Keeps you signed in (session token stored by our auth provider).
- Essential — Security. Helps prevent CSRF and abuse on sign-in and on the Message Scan.
- Preference — Cookie choice. Remembers whether you clicked Accept or Essential only.
- Preference — UI state. Optional settings like your last-used scan input, stored locally on your device.
You can clear cookies and local storage at any time from your browser's privacy settings. You can also reset your Mossy cookie choice below — the banner will reappear on your next visit.
Contact
Questions about this policy or your data? Email hello@mossy.green.
Updates
We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised "Last updated" date. We encourage you to review this page periodically.