Privacy Policy
Last updated 22 August 2026. The short version: the app keeps your cluster data on your machine and sends it nowhere; the website keeps the minimum an account and a subscription need; nobody runs analytics on either.
1. Who is responsible
Moonway Labs, LLC, a Delaware limited liability company, 2810 North Church Street, STE 88324, Wilmington, DE 19802, United States is the controller of the personal data described here. Reach us at support@moonway.io.
2. The desktop app and the daemon
Moonway runs locally. Your kubeconfigs, cluster objects, the journal, metrics, checks, AI conversations and settings live in files on your machine (the permissions page lists the exact paths) and are never sent to us. There is no telemetry, no crash reporting, no analytics, and no usage beacon. Secret values are redacted before they even sit in the daemon’s memory.
The app makes exactly these outbound connections:
- Your clusters, with your credentials — what the product is for.
- The AI provider you configure (Claude, an Anthropic API key, or any OpenAI-compatible endpoint), only if you configure one and only while you are asking it something. What you send goes to that provider under its own privacy terms; we never see it. A local model is an endpoint that never leaves your machine.
- The release feed (
downloads.moonway.io, served by Cloudflare) to check for updates when it starts and periodically while it runs. The request carries the app version and — like any web request — your IP address; it carries no account identifier and we do not log it against you. - moonway.io, only when you click Sign in to get a key: the app opens your browser to your account and receives the key back on a local port. The key contains your email and is stored on your machine.
3. The website and your account
The free tier needs no account. If you buy Pro, Team or a Lifetime license, moonway.io keeps:
- Account data, held by our sign-in provider Clerk: your email address, name and avatar (from the identity provider you sign in with, if any), organization memberships and roles, and the security metadata a sign-in system keeps (sessions, devices, timestamps).
- Entitlement data, stored as metadata on that account: your tier and seat count, your Stripe customer and subscription identifiers, whether you hold a lifetime license, and the timestamps of recent license-key mints (a rate limit).
- Billing data, held by Stripe as merchant of record: name, email, billing address, payment method and transaction history. Card numbers never touch our servers.
- Server logs at our host Vercel: IP address, user agent, requested path and timing, kept briefly for security and debugging. Not used for profiling.
Cookies. moonway.io sets only the cookies sign-in needs (Clerk’s session cookies) and, on the checkout page, the ones Stripe’s payment form requires. There are no advertising or analytics cookies, which is why there is no cookie banner.
4. Why we use it
- To run your account, mint your keys and bill you — performance of our contract with you.
- To keep the service secure, rate-limit abuse and fix problems — our legitimate interest in running it.
- To answer when you write to us, and to send service messages about your subscription (renewals, price changes, receipts). We do not send marketing email without asking first.
- To meet legal obligations, mainly tax and accounting records, which Stripe keeps.
5. Who processes it
We do not sell personal data and we do not share it with advertisers. These providers process it on our behalf, each only what its job needs: Clerk (sign-in and accounts), Stripe (payments, as merchant of record), Vercel (hosting moonway.io), Cloudflare (serving downloads and the release feed) and GitHub (hosting release artifacts). They are based in the United States; where data leaves the EU or UK it travels under their standard contractual clauses. We disclose data otherwise only when the law requires it.
6. How long we keep it
Account and entitlement data stay while your account exists. Delete your account and they go with it; Stripe keeps the billing records tax law requires for as long as it requires. Server logs are short-lived. Anything on your own machine is yours to delete — uninstalling is deleting a few folders.
7. Your rights
Wherever you are, you can ask us what we hold about you, correct it, export it or delete it, and object to or restrict how we use it. Write to support@moonway.io from the email on your account and we will act within 30 days. If you are in the EU, UK or California you have these rights by statute as well, including the right to complain to your supervisory authority. We will never treat you differently for exercising them.
8. Security
The daemon binds to localhost behind a per-session token; secrets are redacted in memory; license keys are signed and verified offline; moonway.io keeps no payment data. No system is perfectly secure, and if a breach ever affects you we will tell you without undue delay.
9. Children
Moonway is a professional tool and not directed at anyone under 16. We do not knowingly collect data from children; tell us if you think we have.
10. Changes
If this policy changes in a way that matters, we announce it on moonway.io and, for account holders, by email, before it takes effect. The date at the top is the one to check.