Legal
Privacy Policy
Last updated: October 3, 2026
The short version
- Moonody creates an account for you the first time you open it. There’s no password: it’s identified by a random ID.
- To keep your ritual working, we store your nights, settings, morning answers and what plays during your sessions on our servers in Germany.
- If you connect Spotify, we also receive your Spotify profile, including your email, and we manage one private playlist in your account.
- Moonody doesn’t measure your sleep. No microphone, no motion sensors, no location, no data from the Health app, no ads and no tracking across other apps.
- We don’t sell your personal information.
- You can delete your account in the app. We then delete what identifies you.
- Who we are
- What we collect and why
- What we don’t collect
- What stays on your iPhone
- Spotify and Apple Music
- Who we share data with
- Where your data is processed
- How long we keep it
- Deleting your account
- Your choices and rights
- Legal bases (EU and UK)
- Children
- Security
- This website
- Changes and contact
Who we are
Moonody is made by S.E. Smarters Engineered LTD, a company registered in Cyprus (HE465488), Efesou 9, 5290 Paralimni, Famagusta, Cyprus (“we”, “us”). We are the controller of the personal data described here. You can reach us at [email protected].
This policy covers the Moonody app for iPhone, the Moonody servers it talks to and this website, moonody.com.
What we collect and why
| Data | What it includes | Why we use it |
|---|---|---|
| Account and device | A random account ID and a sign-in key, a random installation ID, your iPhone model, iOS version, app version, language, region and time zone. | To create and secure your account, keep your data in sync and fix problems. |
| Spotify profile (if you connect Spotify) | The profile Spotify shares with us: your Spotify user ID, display name, email, country, subscription level, explicit-content setting, follower count and profile link. | To connect your account, check that Spotify can play Moonody’s mix, recover your account on a new iPhone and, if you turn it on, send you email. |
| Your nights | When each session starts and ends and how long it lasts, whether it was at your usual bedtime, your Ritual Score, whether the Sleep Signal and its soft tail played, the music service used, whether the alarm and Smart Fade were on, how the night ended, and how many times your iPhone was locked and unlocked during the session. An open session is saved about every 15 minutes. Naps and very short sessions are kept but don’t count as nights. | To run the ritual: your seven-night cycles, your Journal, your Ritual Score and the end of the night. We use the lock and unlock times to estimate when your night ended. |
| Morning answers | Your answer to “How long did it take you to fall asleep?”, your cycles and your streak. | To show you, in your Journal, whether the Signal seems to be working for you. |
| Settings | Bedtime and days, target sleep length, reminder, alarm time and days, Smart Fade, your music service and whether it can play. | To remind you, wake you and build the right mix, and to keep your settings if you move to a new iPhone. |
| What plays | For each session, the tracks that played (track, title, artist, position in the mix, source, length and time) and when you pause, resume or skip. | To build each night’s mix so it doesn’t repeat, to plan how long it should last and to understand how Moonody’s music is listened to. |
| App events | Things you do in the app, with the time and app version: for example opening it, finishing setup, connecting a music service, allowing alarms or Apple Music, or viewing and starting a purchase (with the product and price). It also includes technical events, such as data that couldn’t be saved or sent, or a low battery level when you tap Go to Sleep (the percentage). | To understand how Moonody is used and improve it. We do this ourselves, without third-party analytics tools. |
| Crash and freeze reports | If the app crashes or freezes, iOS gives it a technical report, usually the next day. We receive a summary: the kind of problem, the app and iOS versions, the iPhone model and where in Moonody’s code it happened. It contains nothing you wrote or did in the app. | To find and fix problems. If you share analytics with Apple, Apple also sends us its crash reports. |
| Purchases | Whether you have Moonody Plus and the purchase events RevenueCat reports to us, such as product, dates and status. | To unlock Plus and keep it working on your account. Apple handles the payment; we never see your card. |
| Email preference | Whether you turned on “Sleep tips by email” and when. It’s off unless you turn it on. | To send you sleep tips by email only if you asked for them. |
| Calculated by us | The average and the spread of the length of your recent sessions with music. | To decide how long tonight’s mix should be. |
| Technical logs | For each request to our servers: the IP address it came from, the address requested, the time and the response. | Security, abuse prevention and troubleshooting. To limit sign-ups, we also hold IP addresses in memory for about a minute. |
If you use the backup mix that Moonody plays when its own mix isn’t available, we record what plays on your Spotify account during that session.
What we don’t collect
- No microphone, camera, motion sensors or location.
- No data from the Health app or any wearable. Moonody doesn’t measure your sleep: it records your sessions, and you tell it how the night went.
- No contacts, photos or files.
- No advertising identifier, no ads and no tracking across other companies’ apps or websites.
- No third-party analytics or crash-reporting tools.
- No payment card details. Apple handles payments.
What stays on your iPhone
Some data is kept only on your iPhone:
- Your Spotify sign-in tokens and your Moonody sign-in key, in the iPhone’s Keychain.
- A local copy of up to 400 nights, your settings and preferences.
- The exact time of each lock during a session. Only the number of locks and unlocks, and the time of the last lock, are sent to us.
Your installation ID is kept in the iPhone’s Keychain, so it stays on the iPhone even if you delete the app. This lets Moonody recognize the iPhone if you reinstall. Apple Music permission is handled by iOS, and we don’t receive an Apple Music token.
Spotify and Apple Music
Spotify
If you connect Spotify, you sign in on Spotify’s own screen and choose to allow Moonody. We never see your Spotify password. Moonody asks Spotify for these permissions:
- Your profile and email (
user-read-private,user-read-email): to connect your account, as described above. - One private playlist (
playlist-read-private,playlist-modify-private,ugc-image-upload): Moonody creates a private playlist called “Moonody · Tonight” in your account, gives it Moonody’s cover and fills it with each night’s mix. To find it again, Moonody reads the list of your playlists, but it doesn’t change any other playlist. - Playback (
user-read-playback-state,user-modify-playback-state,user-read-currently-playing): to start, pause and skip the music, find your iPhone in Spotify’s list of devices and see what’s playing. - Recently played (
user-read-recently-played): to read your last 50 played tracks and record the ones that came from Moonody’s playlist.
When you connect, the app sends your Spotify access token to our server once, so the server can read your Spotify profile. The server doesn’t keep the token. You can remove Moonody’s access at any time at spotify.com/account/apps. The “Moonody · Tonight” playlist stays in your Spotify account until you delete it there.
If you tap Disconnect Spotify in Moonody’s settings, we delete your Spotify profile from your Moonody account and keep only your Spotify user ID, so your nights come back if you connect the same Spotify account again, on this iPhone or another. A different Spotify account counts as a different person, with its own Moonody account. Deleting your account removes the ID too.
Spotify’s own handling of your data is covered by the Spotify Privacy Policy.
Apple Music
If you choose Apple Music, Moonody uses Apple’s MusicKit to check that you have an Apple Music subscription and to play music from the Apple Music catalog in its own player. It doesn’t read your library or create playlists. You can turn this permission off in Settings › Privacy & Security › Media & Apple Music.
Who we share data with
We use a few service providers. They process data for us and only as needed to provide their service:
- Hetzner Online GmbH (Germany) hosts our servers and database.
- Cloudflare, Inc. provides the network and security for this website and for Moonody’s servers. It processes IP addresses and the traffic that passes through it.
- BunnyWay d.o.o. (Slovenia, bunny.net) delivers Moonody sleep sounds and the app’s settings file through its content delivery network. It processes the IP address of each iPhone that downloads them; every copy of the app checks the settings file when it opens.
- RevenueCat, Inc. manages subscriptions. It receives your Moonody account ID and the purchase information Apple provides. See the RevenueCat Privacy Policy.
- Apple handles App Store purchases, Apple Music and the alarms and reminders on your iPhone. See the Apple Privacy Policy.
- Spotify, if you connect it, as described above.
We don’t sell your personal information and we don’t share it for targeted advertising. We may disclose data if the law requires it, to protect our rights or users’ safety, or as part of a merger or sale of the business, in which case this policy would continue to apply to your data.
Where your data is processed
Our servers and database are in the European Union, in Germany. Some providers, such as Cloudflare, BunnyWay and RevenueCat, may process data in the United States or other countries. When personal data leaves the European Economic Area, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or the EU–U.S. Data Privacy Framework.
How long we keep it
- While your account exists, we keep your data so Moonody keeps working: your history, your cycles and mixes that don’t repeat. There’s no automatic expiry.
- Technical logs are kept for a short time and deleted automatically as they rotate.
- After you delete your account, we keep a de-identified copy of your history, as explained below.
- Data can remain in backups for a limited time.
Deleting the app doesn’t delete your account. To delete it, use the option in the app first.
Deleting your account
In the app, go to Profile and settings › Account › Delete Account. You need an internet connection. When you confirm:
- We delete your email, your Spotify connection and profile, your installation ID and devices, and your sign-in keys.
- We keep your history in a separate record that no longer contains your email, name, Spotify ID or device IDs. That includes your nights, morning answers, plays, settings, app events and purchase status. We use it for statistics.
- The app deletes its data, keys and Spotify tokens from your iPhone and starts over with a new, empty account.
Deleting your account doesn’t cancel a Moonody Plus subscription. Cancel it in your iPhone’s Settings › [your name] › Subscriptions. It also doesn’t remove the playlist from your Spotify account or Moonody’s access to Spotify, which you can manage as described above.
Your choices and rights
- Email tips are off by default. You can turn them on or off at any time in the app.
- Permissions for notifications, alarms and Apple Music can be changed at any time in your iPhone’s Settings.
- Spotify access can be removed at spotify.com/account/apps.
Depending on where you live, you may have the right to access the data we hold about you, correct it, delete it, get a copy in a portable format, restrict or object to how we use it, and withdraw consent where we rely on it. To use any of these rights, write to [email protected]. We may ask you for information from the app to confirm the account is yours. We won’t treat you differently for using your rights.
If you’re in the EU, you can also complain to a data protection authority, such as the Commissioner for Personal Data Protection in Cyprus (dataprotection.gov.cy) or the authority where you live.
If you’re in the United States, the same rights are available to you, and we honor them wherever you live. We don’t sell personal information, and we don’t share it for cross-context behavioral advertising.
Legal bases (EU and UK)
- Contract: to provide Moonody. This covers your account, your nights, your settings, building and playing tonight’s mix, and Plus.
- Legitimate interests: to keep Moonody secure, fix problems and improve it, using app events, technical logs and statistics. You can object at any time.
- Consent: for sleep tips by email and for the permissions you allow on your iPhone. You can withdraw it at any time.
- Legal obligation: to keep records we are required to keep, such as purchase records.
Children
Moonody isn’t directed to children under 13, and we don’t knowingly collect personal data from them. If you believe a child has given us personal data, write to us and we’ll delete it.
Security
Connections to our servers use HTTPS. Each account has its own sign-in key, and we store only a scrambled (hashed) version of it. Sign-in keys and Spotify tokens are kept in the iPhone’s Keychain, and access to our servers is limited. No system is perfectly secure, but we work to protect your data and will act quickly if something goes wrong.
This website
moonody.com doesn’t use cookies, analytics or trackers, and it doesn’t load fonts or scripts from other companies. Like any website, it’s delivered through servers that process your IP address. In our case those servers are Cloudflare’s and ours, and they use your IP address only to deliver and protect the site. The morning question on our home page is a demo: nothing you tap there is sent anywhere.
Changes and contact
If we change this policy, we’ll update this page and the date above. If a change is significant, we’ll also tell you in the app.
Questions or requests: [email protected] · S.E. Smarters Engineered LTD, Efesou 9, 5290 Paralimni, Famagusta, Cyprus.