Privacy Policy

This policy describes what MoonStart collects when you use this website and the MoonStart application, why we collect it, and the choices you have.

Last updated 27 July 2026

Who we are

MoonStart (https://moonstart.in) is operated by Rahul Chauhan, an independent developer. For anything in this policy, contact support@moonstart.in.

Information we collect

Account information. MoonStart uses GitHub to sign you in. When you authorise it, we receive and store your GitHub account identifier, username, display name, email address and avatar URL. We never receive your GitHub password, and we do not store your GitHub access token after sign-in completes.

Content you create. Projects, screenshots and images you upload, the copy you write, icons you design, and any assets you generate are stored so the application can show them back to you.

Usage and technical data. When you sign up or sign in, and when certain product events occur, we record the event, a timestamp, your IP address, a country derived from it, and your browser's user-agent string. This is first-party analytics stored in our own database — we use it to understand which features are used and to investigate abuse and errors.

Error reports. If a page crashes, the browser sends us the error message, a stack trace, the page URL and your user-agent so the bug can be fixed.

Cookies and similar technologies

Essential cookies. We set one cookie, ls_session, which holds a signed token identifying your signed-in session. It is httpOnly and SameSite=Lax, and the site cannot keep you logged in without it. A short-lived cookie is also used during GitHub sign-in to protect against cross-site request forgery.

Advertising cookies. This site uses Google AdSense. Google and its partners may set and read cookies on your device to serve and measure ads. Google uses these to serve ads based on your prior visits to this and other websites. Where required, ad personalisation is subject to your consent.

  • You can opt out of personalised advertising in Google's Ads Settings at adssettings.google.com.
  • You can opt out of third-party vendors' use of cookies for personalised advertising at aboutads.info.
  • Most browsers let you block or delete cookies; blocking essential cookies will prevent sign-in from working.

Third parties we share data with

We do not sell your personal information. We share only what is necessary with the following processors:

  • GitHub — authentication, when you choose to sign in.
  • Google AdSense — advertising on public pages of this website.
  • Stripe — payment processing, if and when you purchase a paid plan. Card details go directly to Stripe; we never see or store them.
  • AI providers (such as Google Gemini) — only when you actively use an AI feature. The prompt and any image you submit for that specific request are sent to the provider to produce a result.
  • Our hosting provider — which necessarily processes traffic to run the site.

We do not use your uploaded screenshots, icons or project content to train machine learning models, and we do not provide them to anyone for that purpose.

Legal bases and your rights

Where the GDPR or UK GDPR applies, we process account and content data to perform our contract with you, analytics and error data under our legitimate interest in keeping the service working and secure, and advertising cookies on the basis of consent where consent is required.

You have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to withdraw consent at any time. To exercise any of these, email support@moonstart.in — see the contact page for what to include. We respond within 30 days. If you are in the EEA or UK and are unhappy with our response, you may complain to your local data protection authority.

Retention

Account and project data is kept for as long as your account exists. Deleting a project moves it to trash, where you can restore it; emptying the trash removes it permanently. When you ask us to delete your account, we remove your account record, projects and uploaded assets. Analytics event rows and server logs, which contain IP addresses, are retained for a limited period for security and debugging and then discarded.

Children

MoonStart is a tool for app developers and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

International transfers and security

Our providers may process data outside your country, including in the United States. Data is transmitted over HTTPS, session tokens are signed and stored in httpOnly cookies, and access to the production database is restricted. No system is perfectly secure, so we cannot guarantee absolute security.

Changes to this policy

If we make material changes we will update the date at the top of this page and, where the change significantly affects you, notify you in the application. Continuing to use MoonStart after a change means you accept the updated policy.