Legal · Data protection
Mose Privacy Policy
Effective: 26 August 2026 · Version: 1.0
This policy explains how Mose (trymose.com and app.trymose.com) collects, uses, stores and shares personal data.
1. Who we are
Mose is operated by MOZME LLC (30 N Gould St Ste R, Sheridan, WY 82801, USA). For any privacy request: info@trymose.com. We are the data controller (KVKK/GDPR) and "business" (CCPA).
2. What Mose is
Mose is an SEO content automation service for website owners: it reads a connected site, extracts a brand profile, finds content opportunities in Google Search Console data, generates articles and images with AI, publishes them to WordPress or Shopify and measures the results. It is aimed at businesses and not directed at anyone under 18.
3. Data we collect
- Account: name, email, password (hashed only).
- Workspace and site: site URL, brand profile, business facts you approve.
- Connection credentials: WordPress / Shopify access tokens (stored encrypted).
- From connected services: Google Search Console performance data (read-only access);
your site's public content; PageSpeed scores.
- Automatically: server logs (IP, browser, time), session cookie, usage events,
cost records of AI calls.
- Payments: processed by Stripe; your card details never reach our servers. We keep
only subscription status, plan and invoice IDs.
We collect no special-category data and do no advertising tracking.
4. Why, and on what basis
Providing and billing the service (contract), security and debugging (legitimate interest), service notifications (contract), marketing email (consent only, unsubscribe in every email), legal obligations.
5. Google data
Mose's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We request only read access to Search Console; signing in with Google is not required. We use this data to show your search performance, propose content opportunities and measure results after publication. We do not sell it, use it for advertising or use it to train AI models; humans see it only with your consent, in security reviews or when required by law. Tokens are stored encrypted. When you click "Remove connection" in the dashboard or revoke access at https://myaccount.google.com/permissions we delete the tokens; stored data is deleted within 30 days.
6. AI
We use third-party AI providers for content and image generation. They receive the brand profile, the topics and business facts you approved — never passwords, tokens or payment data. We work with providers under API terms that do not use your data for model training. Generated content is yours; reviewing it before publishing is your responsibility.
7. Who we share with
We do not sell your data. Only to provide the service: hosting and database (Hetzner Online GmbH, Germany · Cloudflare, Inc.), payments (Stripe, Inc.), AI providers, email delivery, and the platforms you connect (your WordPress site, your Shopify store, Google). Email info@trymose.com for the current sub-processor list. We may disclose data where required by law or in a company transfer (with prior notice).
8. International transfers
The company is in the U.S. and servers are in the EU, so your data may be transferred abroad. We rely on KVKK Art. 9 and GDPR mechanisms (Standard Contractual Clauses).
9. Retention
Account data: deleted within 30 days of account closure. Connection tokens: immediately on disconnection. Invoice records: for the legally required period. Logs: 90 days. Backups: rolling 30-day cycle.
10. Security
TLS, encrypted token storage, workspace-level data isolation, hashed passwords, regular backups. If a breach occurs we notify within the statutory period (72 hours). Found a vulnerability? info@trymose.com.
11. Your rights
For your rights under KVKK Art. 11, GDPR and CCPA/CPRA (access, correction, deletion, objection, portability, withdrawing consent, non-discrimination; we do not sell personal data) email info@trymose.com; we respond within 30 days after verifying your identity. You may complain to the Turkish Personal Data Protection Board or your EU supervisory authority. You can close your account and remove any connection from the dashboard.
12. Cookies
Only strictly necessary (session, CSRF) and preference cookies; no advertising cookies. You can delete them in your browser; blocking necessary cookies prevents sign-in.
13. Changes and contact
We notify material changes by email at least 14 days in advance; the current version is always at this address. Contact: info@trymose.com · MOZME LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA