This page explains how mosADD (the "Service") handles personal data. mosADD is built in the Swiss privacy tradition: our data practices are governed by Swiss data-protection law (FADP / revDSG), and because our infrastructure runs in the EU (Frankfurt) we also honour the GDPR for users in the EU/EEA. If you are in the United States, the U.S. state privacy rights section below describes your CCPA/CPRA and equivalent state rights. For requests related to your data write to privacy@mosadd.com.
The data controller for mosADD consumer accounts is mosADD Sàrl, Rte de la Galaise 33, 1228 Plan-les-Ouates, Switzerland. If you self-host the open-source mosadd OS, you are your own data controller — this policy then describes only the upstream code, not your deployment. Where you connect mosADD to your own workspace and invite others onto seats you pay for, you act as controller for those members' use within your workspace and we act as your processor for that workspace data.
@mosadd/crypto); the operator stores only ciphertext and cannot read themmosADD can build a searchable memory index so you and your agents can recall past context. There are two separate indexes with two different privacy guarantees:
pgvector) scoped to your account, so search works across your devices. This content is server-readable by design and is not end-to-end encrypted. End-to-end-encrypted mDM plaintext is never sent to the server index.When you connect an external tool or account (for example through the USB connection hub, which uses Composio as an OAuth broker), you authorise a specific data flow between that third-party service and mosADD. We store the connection's authorisation tokens and metadata needed to keep the connector working; the third-party service is governed by its own privacy policy. You can disconnect a connector at any time, which revokes the stored authorisation.
| Data category | Basis |
|---|---|
| Account, communications content | Contract (Art. 6(1)(b)) — needed to provide the service |
| Server-side RAG / knowledge index | Contract (Art. 6(1)(b)) — you asked us to index and recall it |
| Connectors (Composio / USB hub) | Consent (Art. 6(1)(a)) — you authorise each connection |
| Threat radar events | Legitimate interest (Art. 6(1)(f)) — account-security defense |
| Telemetry | Consent (Art. 6(1)(a)) — opt-in toggle in settings |
| Stripe billing & seats | Contract (Art. 6(1)(b)) |
| Data category | Retention |
|---|---|
| Account | Until you delete the account |
| DMs / emails / channel messages | Default: forever; you can set per-thread TTL |
| mIRC ephemeral & mTALK content | Per-room TTL (default 24h) |
| Server-side RAG embeddings | Until you delete the source item or your account; removing a source removes its embeddings |
| Connector authorisations | Until you disconnect the connector or delete the account |
| Threat-radar device events | 90 days for routine events; 7 years for NIS2-eligible events |
| Stripe customer IDs / seat records | Until you delete the account; subscription history retained 7 years for tax |
| Audit log (immutable) | 7 years (NIS2 minimum) |
Email privacy@mosadd.com to exercise any of these. We respond within 30 days.
If you are a resident of California or another U.S. state with a comprehensive privacy law (e.g. Virginia, Colorado, Connecticut, Utah, Texas), you have the rights below. We honour them regardless of where you live.
To exercise any of these, email privacy@mosadd.com. We will verify your request against your account and respond within the statutory window (45 days for CCPA, extendable once). You may use an authorised agent. Because we do not sell or share personal information, we do not process "Do Not Sell" signals — but we honour Global Privacy Control (GPC) as an opt-out preference where applicable.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Postgres + Auth + Storage + Edge Functions + vector index | EU (Frankfurt) |
| Stripe | Subscription & seat billing | Ireland (EU) and US |
| Composio | Connector / OAuth broker for the USB hub (only for tools you connect) | US |
| Resend | Outbound email (mAYL + invites) | EU |
| LiveKit | Real-time voice & push-to-talk media routing (mTALK / calls); media is transient and not stored unless you record a session | Global edge + US contracts |
| Vercel | Website hosting (mosadd.com, mcp.mosadd.com) | Global edge + US contracts |
| Cloudflare | DNS + WAF | Global edge |
| GitHub | Source code, releases (public OSS only) | US |
| Sentry (when enabled) | Error monitoring | EU (Frankfurt) |
For US-located processors (Stripe, Composio, LiveKit, Vercel, Cloudflare, GitHub), transfers use Standard Contractual Clauses and, where available, the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework.
In the event of a confirmed personal-data breach with risk to your rights and freedoms, we will notify the supervisory authority within 72 hours (GDPR Art. 33) and inform affected users without undue delay (Art. 34). Our process is published at github.com/Hei33enberg/mosADD/docs/security/incident-response.md.
mosadd is not intended for users under 16. If you believe a minor has created an account, contact us and we will delete it.
We use only first-party cookies strictly necessary for authentication. No analytics, no advertising, no cross-site tracking.
Material changes are announced in the in-app changelog at least 14 days before they take effect. The latest version always lives at mosadd.com/privacy.html. Past versions are kept in git history.