MoodOrbit logo

MoodOrbit

Home Privacy Terms

MoodOrbit Privacy Policy

Version 1.3.7 (subscription data added — what a purchase records, and what Google holds instead of us) Effective Date: 8 August 2026


Plain-English Summary

At MoodOrbit we care deeply about your privacy while giving you a safe, pseudonymous space to talk with another adult who's feeling something similar to what you're feeling right now. We collect only the minimum information needed to match you for a short voice call, keep the platform safe, and send you push notifications if you opt in. We do not record or transcribe your calls today. We never ask for your real name or photos, and we never sell your data.

You control most of what we hold about you. You can delete your account at any time, see and correct your information, and withdraw consent for optional features like mood tracking or notifications. This policy tells you exactly what we do with your data, why we do it, and what rights you have under EU, UK, and California law.


1. Who We Are

MoodOrbit is operated by Gerald van der Harten, a natural person resident in Romania, acting as the sole operator of the MoodOrbit service and the data controller under GDPR Art. 4(7). Contact address: Strada Cetatea Histria 6, Bloc A4, Sc E, Apt 75, Bucharest, Romania. You can reach us using the details in Section 14.

A note on structure: at the time of this policy's publication, MoodOrbit operates as an individual-developer service, not a registered company. If and when the service grows into a registered legal entity (e.g. a Romanian PFA or SRL), this policy will be re-issued naming that entity as the operator and controller, with the change logged in Section 15.

A note on terminology: throughout this policy we describe users as pseudonymous rather than "anonymous." Your vibe name, mood check-ins, and call history can technically be re-linked to your verified phone number inside our database, which makes them personal data under GDPR Art. 4(1). We minimise this linkage in every screen a user interacts with, but we are transparent that the underlying data is pseudonymous, not fully anonymous.

2. Information We Collect

We collect only what is necessary for the service to function and stay safe.

Account & contact data

You create your account in one of two ways, and we collect only what that method requires:

  • If you sign in with a phone number: your phone number (verified via Vonage SMS one-time password)
  • If you sign in with Google: the email address of the Google account you choose, a Google account identifier, and — where Google includes them — the display name and profile picture link held on that account. We do not request access to anything else in your Google account: no Drive, no contacts, no calendar, no Gmail.
  • AI-generated "vibe name"
  • Chosen language(s)
  • Push-notification token (via Expo / Google FCM) — only if you enable notifications
  • A record of the push notifications we sent you — which kind (a nightly MoodOrbit hour reminder, a match alert, or a "someone is waiting" invitation) and when. We keep this so we can tell how often we are contacting you and stop ourselves contacting you too much. It contains no message content and nothing about how you were feeling.

Whichever method you use, none of it is visible to anyone you talk to. Other users see only your vibe name. Your email address, phone number, real name and profile picture are never displayed in the app, never shown to a match, and never used to suggest people to you.

Preference & session data

  • Mood and energy selections per match
  • Intent (Talk / Listen / Either)
  • Gratitudes sent and received (emoji only — 🙏 💙 🌿)
  • Call metadata: match time, call start/end times, duration, pseudonymous partner pairing, session status
  • Queue metadata: time zone offset (for match-timing fairness)
  • Daily usage counters — conversations, AI conversations, and voice minutes used today. These enforce the daily limits that apply to your account, and they reset each day.

Mental-state data — special category under GDPR Art. 9

  • Before- and optional after-call mood check-ins
  • Free-form mood emoji selections
  • Content of reports you submit that describes another user's behaviour or your own mental state

Safety data

  • Reports (reason category + session reference)
  • Blocks (pair references)
  • Automated report counts, ban status and reason on your profile

Technical / incidental data

  • Our sub-processors (Supabase, Vonage, LiveKit, Expo / Google FCM) receive your IP address as a technical necessity of network communication. We do not persistently store IP addresses in our application database. Sub-processors retain them only per their own retention policies (typically for fraud detection and short-lived hosting logs).

What we do NOT collect or store

  • Voice audio content or call recordings
  • Call transcriptions or voice-derived text
  • Text-chat message content (see next paragraph)
  • AI companion conversation content — transmitted to our AI sub-processor to generate replies, but not stored in our database (see the AI companion paragraph below)
  • Real names or photographs
  • Precise location
  • Your contacts
  • Browsing history

Text chat sessions — Phase 5.5 addition. MoodOrbit now also offers an optional text-chat mode as a secondary matching track, in which two pseudonymous users exchange written messages for up to 5 minutes (with the option to mutually upgrade to a voice call). Text message content is transmitted in real time via our realtime infrastructure and is never persisted to our database. When the session ends, the content is gone — we cannot produce a transcript, respond to a message-level DSAR, or recover the content ourselves. The same rule applies as to voice: if we ever introduce server-side processing or retention of text content (for example, automated moderation that stores flagged messages for review), we will update this policy, notify you in advance, and obtain your explicit consent before any such processing applies to you. We will not retroactively process historical text content.

AI companion sessions — Phase 6 addition. When no human match is available in your selected mood, MoodOrbit may offer you the option to talk to an AI companion (a guided, text-based listener) instead of waiting. This feature is optional and off by default: it runs only after you give separate, explicit in-app consent, and you can always decline and keep waiting for a human. When you use it, the messages you write during the session are sent in real time to Anthropic, our AI sub-processor, which operates the Claude model that generates the companion's replies. Those messages can include special-category mental-state content, so we process them only under your explicit Art. 9 consent (see Section 4). We do not store the content of AI companion conversations in our application database, and Anthropic does not use data submitted through its commercial API to train its models. Anthropic operates from the United States; this transfer is covered by the safeguards in Section 6. Anthropic retains API inputs and outputs for a limited period under its commercial terms for trust-and-safety purposes, after which they are deleted. If we later introduce server-side storage or monitoring of AI session content (for example, the safety-monitoring layer planned for a future release), we will update this policy and obtain renewed explicit consent before that processing begins.

Subscription data — Phase 11 addition. If you buy a paid plan, the purchase itself is made through Google Play, which is the merchant of record. We never receive, see, or store your card number, bank details, billing address, or any payment credential — those stay with Google. What we store is the minimum needed to know which plan you hold and until when: the plan name, its state (active, in grace after a failed payment, cancelled, expired), the start and end dates of the current period, an opaque Google Play purchase token, and the Google order identifier. Our payments partner RevenueCat processes the purchase event on our behalf and tells us that the purchase is valid; Google also sends us real-time notifications about renewals, cancellations and refunds so that your plan reflects reality without us polling. We keep these records for as long as you hold the plan and afterwards only as long as tax and accounting law requires (see Section 7). A purchase record contains no mental-state data of any kind — it says which plan you bought, never what you talked about.

If we introduce any voice-based safety feature in the future (for example, real-time crisis keyword detection as part of our AI Safety Layer), we will update this policy, notify you in advance, and obtain your explicit consent before processing any voice content. We will not retroactively apply such a feature to past calls.

3. How We Use Your Personal Data

  • To create and manage your account and to match you with other users
  • To verify that you are a real person signing in — by SMS one-time password, or by Google sign-in if you choose it — which is how we keep automated accounts and banned users out
  • To deliver the voice call via WebRTC
  • To maintain your personal mood journal and display mutual saved connections
  • To offer an optional AI companion to talk to when no human match is available (only if you give explicit consent)
  • To send push notifications (only if you opt in)
  • To detect and prevent abuse, enforce blocks, investigate reports, and protect platform safety
  • To comply with legal obligations (for example, responding to lawful requests from authorities)
  • To generate aggregated, anonymised statistics for service improvement

4. Lawful Bases for Processing (GDPR & UK GDPR)

For each category of data we process, we rely on a specific lawful basis:

  • Contract (Art. 6(1)(b)) — the sign-in method you choose (phone number, or the Google account identifier and email address described in Section 2), account creation, matching, call delivery. Without these, we cannot provide the service you requested.
  • Consent (Art. 6(1)(a)) — push notifications, optional mood-tracking, any future optional analytics.
  • Explicit consent (Art. 9(2)(a)) — processing of mental-state / special category data (mood check-ins, mental-state content inside reports, mental-state content you may communicate in a text chat session). We collect this consent through a dedicated in-app prompt at onboarding that is separate from general terms acceptance, is granular (you can use the app without enabling mood tracking, and without using the text-chat mode), and can be withdrawn at any time in Settings. Text-chat content itself is not stored (see Section 2), so this basis applies only to any such content that a user voluntarily includes in a Report they submit. We separately rely on explicit Art. 9 consent — collected through a dedicated, just-in-time prompt shown before your first AI companion session — for the mental-state content you choose to share with the AI companion, which is transmitted to our AI sub-processor Anthropic to generate replies (see Section 2 and Section 5).
  • Contract (Art. 6(1)(b)) — subscriptions. If you buy a paid plan, we process the purchase token, order identifier, plan, state and period dates in order to give you the plan you paid for, to honour the remainder of a period you have cancelled, and to withdraw it on refund. This is ordinary contract data under Art. 6(1)(b): it is not special-category data and is never combined with your mood or session content.
  • Legal obligation (Art. 6(1)(c)) — responding to lawful authority requests, tax / corporate record-keeping.
  • Legitimate interests (Art. 6(1)(f)) — platform safety (blocks, reports, automated abuse detection), fraud / abuse prevention, aggregated anonymised analytics for service improvement. We balance these interests against your rights and freedoms; you may object at any time (see Section 9).

You may withdraw consent at any time for any consent-based processing. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.

5. Sharing and Third-Party Processors

We share your personal data with the following sub-processors only to the extent necessary for them to provide their service to us, and under written data-processing agreements that bind them to GDPR/UK GDPR standards:

Payments (Phase 11). Google (Google Play) acts as the merchant of record for every purchase and as an independent controller of the payment itself — its own privacy policy governs the card details you give it, which we never receive. RevenueCat, Inc. (United States) processes purchase events on our behalf as a sub-processor: it receives your pseudonymous MoodOrbit account identifier, the product purchased, and Google's purchase token, and it does not receive your name, phone number, email address, mood data, or anything you say in the app. This transfer is covered by the safeguards in Section 6.

  • Supabase — database, authentication, realtime messaging, Edge Functions. Region: European Union (West EU — Ireland, eu-west-1). Personal data is stored and processed within the EEA.
  • Vonage — SMS one-time password delivery
  • LiveKit — WebRTC voice call infrastructure (voice audio is not recorded by us or by LiveKit on our instruction)
  • Expo / Google FCM — push notification delivery (only if you enable notifications)
  • Anthropic — AI companion: operates the Claude model that generates replies in optional AI listener sessions, and receives the messages you write during such a session, only after you have given explicit consent. Anthropic does not train its models on data submitted via its commercial API. Region: United States (transfers covered by the SCCs — see Section 6).
  • Sentry — crash and error reporting: if the app crashes or malfunctions, technical data (stack trace, screen name, device model, OS version) is sent to Sentry so we can find and fix the bug. A scrubbing layer on your device removes phone numbers, verification codes, message content, and mood values before anything is sent — Sentry never receives conversation or mental-state content. Region: European Union (Frankfurt).
  • Cloudflare — website and email infrastructure: DNS, TLS, and hosting for moodorbit.app (including the legal pages this policy lives on), and email forwarding for our @moodorbit.app addresses — if you email us, your message transits Cloudflare's Email Routing on its way to our inbox. Covered by Cloudflare's standard DPA.

Sign in with Google — a separate relationship, not a sub-processor. If you choose to sign in with Google, Google authenticates you and returns the data listed in Section 2. For that authentication step Google acts as an independent controller under its own privacy policy, not as a processor acting on our instructions — we do not send it your data; it sends us the result of a sign-in you asked it to perform. Our handling of what it returns is additionally governed by the Google API Services User Data Policy, including its Limited Use requirements. If you sign in with a phone number instead, Google receives nothing.

A current, maintained list of our sub-processors — including name, location, purpose, and the date of the most recent change — is available on request by contacting us at privacy@moodorbit.app. We will update that list before adding or changing any sub-processor.

We do not sell your personal data. We also do not "share" your personal data for cross-context behavioural advertising within the meaning of the California Privacy Rights Act (CPRA).

6. International Data Transfers

Some of our sub-processors — for example Anthropic, which operates the AI companion from the United States — are based in, or have sub-processors in, the United States. Where your personal data leaves the European Economic Area or the United Kingdom, we rely on an approved transfer mechanism with applicable supplementary measures (encryption in transit and at rest, access controls, audit rights): either the European Commission's 2021 Standard Contractual Clauses (SCCs), or — where the recipient is self-certified under it — the EU-U.S. Data Privacy Framework and its UK Extension. Expo relies on the Data Privacy Framework; our other United States processors rely on the SCCs. We conduct transfer-impact assessments where required by case law (including Schrems II).

7. Data Retention

  • Auth / profile data (including a phone number or Google-supplied email address and account identifier, whichever you signed in with): anonymised at user-initiated account deletion; hard-deleted (including removal from our authentication system) within 30 days. Deleting your MoodOrbit account does not delete your Google account; you can additionally revoke MoodOrbit's access at myaccount.google.com under Third-party apps.
  • Operational / session / mood check-in / gratitude data: up to 12 months after the last activity, then either deleted or aggregated into anonymous statistics.
  • Moderation / safety data (blocks, reports, ban records): retained as long as necessary for platform safety and legal defence, up to a maximum of 2 years from the date the record was created, unless a specific legal obligation requires longer.
  • Record of notifications sent to you: up to 12 months, then deleted. Deleted immediately with your account.
  • Aggregated anonymous statistics: may be retained indefinitely as they do not constitute personal data.

Limits on erasure. The right to erasure is not absolute. We may retain specific records beyond the periods above when necessary to (a) establish, exercise, or defend legal claims, (b) comply with a legal obligation, or (c) preserve moderation history needed to protect other users from an abusive actor. Where we retain any such record, we limit the retention to the minimum data and period necessary.

8. Security and Data Breach Response

We use industry-standard technical and organisational measures — including encryption in transit and at rest, row-level database security, access controls, and regular review — to protect your data. No system is 100% secure.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Romanian supervisory authority (ANSPDCP) within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by GDPR Art. 34.

9. Your Data Rights

Under GDPR / UK GDPR (and, where applicable, CCPA / CPRA) you have the right to:

  • Access — ask us for a copy of the personal data we hold about you
  • Rectification — correct data that is inaccurate or incomplete
  • Erasure ("right to be forgotten") — subject to the limits in Section 7
  • Restriction — ask us to stop or limit processing in certain circumstances
  • Portability — receive your data in a structured, machine-readable format, or ask us to transmit it to another controller where technically feasible
  • Objection — object to processing based on legitimate interests (Art. 6(1)(f))
  • Withdraw consent — for any consent-based processing, at any time, without giving a reason
  • Not be subject to solely automated decisions with legal or similarly significant effects (see next paragraph)
  • Lodge a complaint with the Romanian supervisory authority ANSPDCP (www.dataprotection.ro) or your local supervisory authority

Automated processing and decision-making. Our matching algorithm uses only your self-reported mood, energy, intent, and language preferences to propose compatible pseudonymous partners. You can always decline a proposed match and start a new one, so this algorithm does not produce a legal or similarly significant effect on you within the meaning of Art. 22 GDPR.

We do, however, operate one automated decision that has a meaningful effect: when a user accumulates a threshold number of valid reports from distinct other users within a short window, our system automatically suspends their account pending review. A user affected by an automated suspension has the right to request human review of the decision by contacting us using the details in Section 14; we will review promptly and restore the account if the suspension is not warranted.

California residents (CCPA / CPRA) additionally have the right to know the specific categories and sources of personal information we have collected, to request deletion, to correct, and to opt out of any "sale" or "sharing" of personal information. We do neither. We honour the Global Privacy Control (GPC) signal when detected, treating it as a valid opt-out request. We do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects.

To exercise any right, contact us using the details in Section 14. We respond within one month, extendable by a further two months in complex cases with notice to you.

10. Children's Privacy

The service is strictly for adults 18 or older. At signup, users must affirmatively confirm they are 18 or older.

We plan to introduce stronger age verification (age-estimation via the Yoti SDK or equivalent liveness-based estimation) in an upcoming release. Until that feature is live, our age check relies on user self-declaration, which we recognise is a limitation.

If we discover that a user is under 18, we will:

  1. Immediately suspend the account
  2. Delete all personal data associated with the account within 30 days (subject to the limits in Section 7)
  3. Not permit the same person to create a new account until they are 18

If you are a parent or guardian and believe your child has created an account, please contact us at the details in Section 14.

11. Digital Services Act (EU DSA)

MoodOrbit is an "online platform" facilitating user-to-user interaction and is therefore subject to Regulation (EU) 2022/2065 (Digital Services Act). In line with the DSA we:

  • Maintain a clear acceptable use policy and content-moderation policy (see our Terms of Service)
  • Offer every user an accessible report and complaint mechanism (the in-app Report feature)
  • Allow users to contest moderation decisions by contacting us using the details in Section 14
  • Publish any transparency reports that become applicable as the service scales
  • Engage with trusted flaggers as required

We are currently below the Very Large Online Platform (VLOP) threshold (45 million monthly active EU users) and the additional VLOP obligations do not apply.

12. Cookies and Similar Technologies

MoodOrbit is a native mobile application and does not use browser cookies. The application uses standard mobile platform identifiers (for example, a push notification token from Expo / Google FCM) solely for the purposes described in Section 3. We do not use advertising identifiers (Android Advertising ID, iOS IDFA) and we do not integrate any advertising SDKs or cross-app tracking.

13. Changes to this Privacy Policy

We may update this policy from time to time.

Non-material changes (clarifying wording, formatting, contact updates): we will update the effective date and note the change in the Changelog.

Material changes (new processing purposes, new sub-processors, new categories of data, changes affecting your rights): we will notify you in-app and / or by email at least 30 days before they take effect.

Material changes affecting special category data (Art. 9) — for example, if we introduce any feature that processes your voice content, text content, or expands mental-state inference: we will request fresh explicit consent from you in-app. If you do not grant the new consent, the new feature will not be enabled for your account, and your existing use of the service will continue under the terms you have already consented to.

14. Contact Us

Email: privacy@moodorbit.app

Postal address: Strada Cetatea Histria 6, Bloc A4, Sc E, Apt 75, Bucharest, Romania (Gerald van der Harten operates MoodOrbit as an individual; no registered office yet.)

Data Protection Officer: We have not currently appointed a formal Data Protection Officer because our present scale of processing does not meet the large-scale threshold under Art. 37(1)(c) GDPR. Given that our core activity includes the processing of special category data (mood and mental-state information), we reassess this obligation quarterly and on reaching 10,000 monthly active users, whichever comes first, and will appoint a DPO if the assessment indicates the threshold has been met.

All privacy queries are handled by our privacy team at the email above and are responded to within one month.

15. Changelog

  • v1.3.7 — 2026-08-31 — Subscription data described, ahead of the first sale. Section 2 now sets out exactly what a purchase records — plan, state, period dates, Google's opaque purchase token, order identifier — and states plainly what we never receive: card number, bank details, billing address, any payment credential. Section 4 adds the lawful basis (contract, Art. 6(1)(b)); a purchase record is ordinary contract data, is not special-category, and is never combined with mood or session content. Section 5 names Google Play as merchant of record and independent controller of the payment, and RevenueCat as a sub-processor that receives a pseudonymous account identifier, the product and Google's token — and no name, phone number, email, or mental-state data.

  • v1.3.6 — 2026-08-30 — §2 accuracy fix. The daily-match line named a specific number ("enforces our 5-per-day wellness cap"). That number is configuration, not policy: it is set per account and changes without a policy revision, so naming it guaranteed this document would eventually describe a limit the service does not have. It now describes the counters and their purpose without pinning a figure, and names the two additional daily counters (AI conversations, voice minutes) alongside the existing one. No new data category — these are operational counters already covered by the "Operational / session" retention rule in §7 — no new sub-processor, no new legal basis, no change to any Art. 9 basis, and nothing here concerns payments. (v1.4 remains reserved for the legal-entity-name substitution.)

  • v1.3.5 — 2026-08-28 — Adds Sign in with Google as an alternative to phone verification. §2 now lists what Google returns (email address, Google account identifier, and any display name or profile picture link) and states plainly that no sign-in identifier is ever shown to other users; §3 names authentication as a purpose; §4 extends the Art. 6(1)(b) contract basis to whichever sign-in method you choose; §5 records that Google acts as an independent controller for the sign-in itself, not as our sub-processor, and that signing in by phone sends Google nothing; §7 covers deletion of Google-supplied identifiers and points to Google's own revocation page. No new special-category processing, no new sub-processor, no change to any Art. 9 basis. (v1.4 remains reserved for the legal-entity-name substitution.)

  • v1.3.4 — 2026-08-25 — Expo supplied and countersigned a Data Processing Agreement, so the §5 qualification added hours earlier in v1.3.3 is removed and the unqualified statement restored. §6 corrected: transfers do not all rest on the Standard Contractual Clauses — Expo relies on the EU-U.S. Data Privacy Framework and its UK Extension, so §6 now names both mechanisms. No new processing, no new sub-processor, no new data category, no change to any legal basis.

  • v1.3.3 — 2026-08-25 — Accuracy correction to §5. The previous wording stated that written data-processing agreements were in place with all sub-processors. That was not accurate for Expo, which relays push notifications and does not make such an agreement available to us. §5 now says so plainly, states that we are replacing the Expo relay with a direct Google Firebase Cloud Messaging connection, and notes that we are minimising the data carried in notifications in the meantime. No new processing, no new sub-processor, no new data category, no change to any legal basis.

  • v1.3.2 — 2026-08-08 — Disclosure correction: adds Sentry (crash/error reporting, EU-Frankfurt, on-device PII scrubbing) and Cloudflare (website hosting + email forwarding) to the §5 sub-processor list. Both services have been in use since April 2026; this release corrects their omission from the list. No new processing, no new data categories, no change to any legal basis. Reviewed structure passed external legal review 2026-08-08 (clean pass, pre-correction).

  • v1.3.1 — draft 2026-06-28 — Phase 6 AI companion disclosure: documents the optional AI listener feature, adds Anthropic as an AI sub-processor (§5), describes the data flow and US transfer (§2, §6), and extends the Art. 9 explicit-consent basis to mental-state content shared with the AI companion (§4). (v1.4 remains reserved for the legal-entity-name substitution once a PFA or SRL is formed.)

  • v1.3 — draft 2026-04-24 — Launch-structure correction: operator / data controller changed from "MoodOrbit SRL" to "Gary (natural person)" throughout. Reflects the actual launch reality: individual developer, no legal entity yet. A v1.4 will reinstate a legal-entity name once a PFA or SRL is formed.

  • v1.2 — draft (TBD) — Phase 5.5 addition: text-chat mode paragraph in Section 2 making explicit that text content is transmitted via realtime infrastructure and never persisted; Section 4 explicit-consent basis extended to cover user-contributed mental-state content in text-chat reports (though content itself is not stored).

  • v1.1 — draft (TBD) — Incorporates internal review fixes 1–16 from 2026-04-21: DPO reassessment language, explicit consent mechanism described, sub-processor list link, IP address transparency, pseudonymous terminology, gratitudes re-categorised out of Art. 9, automated ban acknowledged under Art. 22, 72-hour breach commitment, DSA section added, CCPA / GPC language, material-change re-consent requirement, cookies section, erasure limits, voice-feature future-proofing.

  • v1.0 — April 21, 2026 — Initial internal draft.


© 2026 MoodOrbit · Operated by Gerald van der Harten · Bucharest, Romania
Home· Privacy Policy· Terms of Service· support@moodorbit.app