Privacy policy

Effective 12 July 2026 · Last revised 12 July 2026

This page explains how mosADD (the "Service") handles personal data. mosADD is built in the Swiss privacy tradition: our data practices are governed by Swiss data-protection law (FADP / revDSG), and because our infrastructure runs in the EU (Frankfurt) we also honour the GDPR for users in the EU/EEA. If you are in the United States, the U.S. state privacy rights section below describes your CCPA/CPRA and equivalent state rights. For requests related to your data write to privacy@mosadd.com.

1. Who is the data controller

The data controller for mosADD consumer accounts is mosADD Sàrl, Rte de la Galaise 33, 1228 Plan-les-Ouates, Switzerland. If you self-host the open-source mosadd OS, you are your own data controller — this policy then describes only the upstream code, not your deployment. Where you connect mosADD to your own workspace and invite others onto seats you pay for, you act as controller for those members' use within your workspace and we act as your processor for that workspace data.

2. What we collect

Account data

Communications content

AI memory & RAG (your "second brain")

mosADD can build a searchable memory index so you and your agents can recall past context. There are two separate indexes with two different privacy guarantees:

Connectors (USB hub / Composio)

When you connect an external tool or account (for example through the USB connection hub, which uses Composio as an OAuth broker), you authorise a specific data flow between that third-party service and mosADD. We store the connection's authorisation tokens and metadata needed to keep the connector working; the third-party service is governed by its own privacy policy. You can disconnect a connector at any time, which revokes the stored authorisation.

Telemetry & threat radar

Payment & subscription data

What we do NOT collect

3. Legal basis (GDPR Art. 6)

Data categoryBasis
Account, communications contentContract (Art. 6(1)(b)) — needed to provide the service
Server-side RAG / knowledge indexContract (Art. 6(1)(b)) — you asked us to index and recall it
Connectors (Composio / USB hub)Consent (Art. 6(1)(a)) — you authorise each connection
Threat radar eventsLegitimate interest (Art. 6(1)(f)) — account-security defense
TelemetryConsent (Art. 6(1)(a)) — opt-in toggle in settings
Stripe billing & seatsContract (Art. 6(1)(b))

4. Retention

Data categoryRetention
AccountUntil you delete the account
DMs / emails / channel messagesDefault: forever; you can set per-thread TTL
mIRC ephemeral & mTALK contentPer-room TTL (default 24h)
Server-side RAG embeddingsUntil you delete the source item or your account; removing a source removes its embeddings
Connector authorisationsUntil you disconnect the connector or delete the account
Threat-radar device events90 days for routine events; 7 years for NIS2-eligible events
Stripe customer IDs / seat recordsUntil you delete the account; subscription history retained 7 years for tax
Audit log (immutable)7 years (NIS2 minimum)

5. Your rights (GDPR Art. 15–22)

Email privacy@mosadd.com to exercise any of these. We respond within 30 days.

6. U.S. state privacy rights (CCPA/CPRA & equivalents)

If you are a resident of California or another U.S. state with a comprehensive privacy law (e.g. Virginia, Colorado, Connecticut, Utah, Texas), you have the rights below. We honour them regardless of where you live.

To exercise any of these, email privacy@mosadd.com. We will verify your request against your account and respond within the statutory window (45 days for CCPA, extendable once). You may use an authorised agent. Because we do not sell or share personal information, we do not process "Do Not Sell" signals — but we honour Global Privacy Control (GPC) as an opt-out preference where applicable.

7. Sub-processors

ProcessorPurposeLocation
SupabasePostgres + Auth + Storage + Edge Functions + vector indexEU (Frankfurt)
StripeSubscription & seat billingIreland (EU) and US
ComposioConnector / OAuth broker for the USB hub (only for tools you connect)US
ResendOutbound email (mAYL + invites)EU
LiveKitReal-time voice & push-to-talk media routing (mTALK / calls); media is transient and not stored unless you record a sessionGlobal edge + US contracts
VercelWebsite hosting (mosadd.com, mcp.mosadd.com)Global edge + US contracts
CloudflareDNS + WAFGlobal edge
GitHubSource code, releases (public OSS only)US
Sentry (when enabled)Error monitoringEU (Frankfurt)

For US-located processors (Stripe, Composio, LiveKit, Vercel, Cloudflare, GitHub), transfers use Standard Contractual Clauses and, where available, the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework.

8. Breach notification

In the event of a confirmed personal-data breach with risk to your rights and freedoms, we will notify the supervisory authority within 72 hours (GDPR Art. 33) and inform affected users without undue delay (Art. 34). Our process is published at github.com/Hei33enberg/mosADD/docs/security/incident-response.md.

9. Children

mosadd is not intended for users under 16. If you believe a minor has created an account, contact us and we will delete it.

10. Cookies and trackers

We use only first-party cookies strictly necessary for authentication. No analytics, no advertising, no cross-site tracking.

11. Changes

Material changes are announced in the in-app changelog at least 14 days before they take effect. The latest version always lives at mosadd.com/privacy.html. Past versions are kept in git history.

12. Contact & complaints