Privacy Policy
Last Updated: January 8, 2026
At Moodzaic, we prioritize your privacy. We collect only the data necessary to provide our AI-powered design services. We do not sell your personal data to advertisers or third parties.
Table of Contents
- Who We Are
- Information We Collect
- How We Use Your Data
- AI Processing & Generated Content
- Third-Party Services
- Cookies & Tracking
- Data Retention
- Your Rights (GDPR & Indonesian UU PDP)
- International Data Transfers
- Security
- Children's Privacy
- Changes to This Policy
- Contact Us
1. Who We Are
Company Name: Moodzaic
Website: https://moodzaic.com
Contact Email: hello@moodzaic.com
Location: Jakarta, Indonesia
Moodzaic is an AI-powered design system generator for designers, developers, and founders.
2. Information We Collect
We collect only the information necessary to operate and improve our Service.
2.1 Information You Provide
- Email address (for account login and communication)
- Name (from Google OAuth)
- Google account ID (for authentication)
- Design project data, including:
- Text prompts describing your project
- Mood and style selections
- Generated outputs (color palettes, typography, design systems)
2.2 Usage & Technical Data
- Generation count
- Feature usage patterns
- Timestamps of activity
- Basic device and browser information
2.3 Payment Information
Important: We do NOT store credit card details on our servers. All payment transactions are processed securely by Midtrans.
We only retain:
- Transaction IDs
- Subscription status (FREE vs PRO)
- Billing records (for tax compliance)
3. How We Use Your Data
We use your information to:
- Provide and operate the Moodzaic service
- Generate AI-powered design systems
- Process payments and manage subscriptions
- Send important service updates and transaction receipts
- Analyze usage patterns to improve features and fix bugs
- Ensure security and prevent fraud
We do not sell your personal data.
4. AI Processing & Generated Content
Moodzaic uses Google Gemini API to generate design systems based on your input.
🤖 AI Training Disclaimer
Your prompts and design data are NOT used to train Google's AI models. Your inputs are processed only to provide you with design system outputs. Your design data remains yours.
We do not use your projects for marketing, public datasets, or any purpose other than generating your requested designs.
5. Third-Party Services
We rely on trusted third-party providers to operate Moodzaic. Each processes data under its own privacy policy:
- Midtrans – Payment processing
Privacy Policy → - Supabase – Database & authentication
Privacy Policy → - Cloudflare – Hosting & CDN
Privacy Policy → - Google Cloud AI (Gemini API) – AI generation
Privacy Policy →
6. Cookies & Tracking
We use minimal cookies strictly necessary for functionality:
- Session management (keeping you logged in)
- Security and fraud prevention
- Basic analytics to understand feature usage
You may disable cookies in your browser, but some features may not function properly.
7. Data Retention
Active accounts: Data retained while your account is active.
Deleted accounts:
- Personal data removed within 30 days
- Billing records retained for 7 years (Indonesian tax compliance)
Backups: Deleted data may persist in secure backup systems for up to 30 days before permanent deletion.
8. Your Rights (GDPR & Indonesian UU PDP)
We comply with UU No. 27 Tahun 2022 (Indonesian Personal Data Protection Law) and GDPR.
You have the right to:
- Access your personal data
- Request data portability (export your data)
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent
- Object to data processing
- File a complaint with a data protection authority
To exercise these rights, contact: hello@moodzaic.com
We will respond within 30 days.
9. International Data Transfers
Your data may be processed on servers located outside Indonesia, including:
- Supabase servers (United States)
- Cloudflare global network
- Google Cloud (United States)
We ensure appropriate safeguards (such as Standard Contractual Clauses) are in place to protect your data during these transfers.
10. Security
We implement industry-standard security measures, including:
- Encrypted connections (HTTPS/TLS)
- Secure authentication
- Limited access to production systems
- Regular security audits
No system is 100% secure, but we continuously improve our safeguards to protect your data.
11. Children's Privacy
Moodzaic is not intended for users under 18 years old.
We do not knowingly collect personal data from children. If you believe we have collected data from a minor, contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email or a prominent notice on our website.
Continued use of the Service after updates constitutes acceptance of the revised policy.
13. Contact Us
Questions about privacy or data protection?
📧 hello@moodzaic.com
Attribution: Adapted from 37signals open-source policies / Licensed under CC BY 4.0