Privacy Policy
Effective date: September 25, 2026 Service: MooStash (moostash.io, including www.moostash.io and related apps) Operator: Sigae Intl LLC (“we,” “us,” “our”)
This Privacy Policy explains how Sigae Intl LLC collects, uses, stores, and shares information when you use MooStash—the web app, phone app, and related APIs that help you browse, organize, and process a personal meme / image library.
1. What MooStash is
MooStash is a library viewer and processing product. You connect an account (for example via Google or another supported sign-in provider) and open libraries that live on your device or in linked cloud storage (for example Google Drive, Dropbox, OneDrive, or Box, when enabled). We run optional analysis jobs on library items (such as OCR/text detection, language, framing, localization, and related AI-assisted features) so the product can search, sort, and display your memes.
2. Information we collect
2.1 Account and sign-in (including Google)
When you sign in with Google (or another supported provider), we collect:
- Account identifiers such as email address, display name, and profile photo / avatar metadata provided by the sign-in provider.
- Provider identity (which OAuth / sign-in providers you have linked) and provider subject identifiers needed to recognize your account on return visits.
- Session data (for example a session cookie such as
moo_session) so you stay signed in. - Limited session / admin audit metadata used for security and support (for example recent session activity visible to administrators of the service).
We do not ask you to create a separate password for MooStash when you use supported OAuth sign-in; authentication is handled by the provider you choose.
Google Sign-In is used to authenticate you and to create or resume your MooStash account. We do not use Google account information for advertising.
2.2 Libraries and content
Depending on how you use the product:
- Library metadata we store to operate the product (library ids, names, source type, pins, categories, flairs, display settings, processing flags, and similar catalog fields).
- Derived text and analysis results we generate or store for your items (for example OCR text, detected languages, framing / layout metadata, classifications, and job status).
- Image bytes when the product needs them to show thumbnails, run jobs, or proxy media from a linked cloud provider. For cloud libraries, the original files generally remain with your cloud provider; we may cache or temporarily process copies as needed to run the service.
- Local / device libraries stay under your control on the device or host you configure; we only process what your client sends to MooStash servers for features that require a server.
2.3 Google Drive and other cloud libraries
If you link Google Drive (or another cloud provider) as a library source, we collect and use:
- OAuth access and refresh tokens needed to call that provider’s APIs on your behalf.
- File and folder metadata (names, ids, paths, mime types, sizes, modified times) for the libraries you open.
- File contents when needed to display media, generate thumbnails, import/export, or run analysis jobs you request.
Drive access is limited to the scopes you grant (for example read-only Drive access, or broader Drive access when you use features that write files). We use that access only to provide MooStash library features you request—not to scan unrelated Drive files for advertising or to sell your content.
2.4 AI and third-party processing
When you use AI-assisted or third-party-backed features (or when an administrator enables providers for the deployment):
- We may send images, crops, or text derived from your library items to model providers you or the deployment have configured (for example Google generative APIs, OpenRouter, or other linked providers), subject to that feature’s design and your account / quota settings.
- Some features use your linked provider quota or keys (including bring-your-own-key arrangements where offered). Others may use operator-configured capacity. The product aims to be clear in-product when a provider is linked or required.
2.5 Technical and usage data
- Standard server logs (IP address, user agent, request paths, error diagnostics).
- Job queue and performance metrics (counts, failures, timing) needed to run workers and show progress.
- Approximate device / client information needed for web and phone clients to function.
We do not sell personal information.
2.6 Cookies and similar technologies
We use essential cookies and similar storage for sign-in sessions and core app function. We do not use advertising cookies. If we add optional analytics later, we will update this policy and, where required, obtain consent.
3. How we use information
We use the information above to:
- Provide, secure, and improve MooStash (sign-in, libraries, browsing, search, jobs, localization, admin tools).
- Operate background workers and queues that process your library items.
- Enforce abuse, quota, and security controls.
- Communicate about the service (for example account or security notices).
- Comply with law and respond to lawful requests.
We do not use your meme library content or Google user data to build advertising profiles, to sell ads, or to train generalized AI models unrelated to providing MooStash features to you.
4. Google API Services User Data Policy (Limited Use)
MooStash’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for data obtained via Google Sign-In and Google Drive APIs:
- We use Google user data only to provide or improve user-facing features that are prominent in MooStash (account sign-in, opening and managing your libraries, displaying and processing your images).
- We do not transfer Google user data to third parties except (a) as necessary to provide those features (for example hosting infrastructure or AI providers you or the deployment configure for analysis you request), (b) for security / legal compliance, or (c) as part of a merger/acquisition with notice where appropriate.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data except with your consent, for security / compliance investigations, or where the data is already public / aggregated as allowed by Google’s policy.
- We do not sell Google user data.
5. How we share information
We share information only as needed to run MooStash:
| Recipient | Why |
|---|---|
| Sign-in providers (e.g. Google) | Authenticate you |
| Cloud storage providers you link (e.g. Google Drive) | Read / write your library as you request |
| AI / inference providers you or the deployment configure | Run opted-in or enabled analysis and generation features |
| Hosting and infrastructure (e.g. cloud VMs, databases, object storage, Redis) | Host the service |
| Service operators / admins | Operate and support the deployment (including admin user views that exclude raw session secrets where designed) |
We may disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset transfer (with notice where appropriate).
We do not sell your personal information or your meme library content for advertising.
6. Retention
- Account and catalog metadata are kept while your account remains on the service and for a reasonable period afterward for backups, disputes, and legal compliance.
- Session tokens last until you sign out, they expire, or an administrator invalidates them.
- Cloud tokens (including Google Drive tokens) remain until you disconnect the provider or the token is revoked / rotated.
- Cached media and job artifacts may be retained for performance and debugging, then deleted or overwritten under normal operations.
- Logs are retained for a limited operational window unless a longer period is required for security investigation.
You may request deletion of your account data as described below; some residual copies may remain in encrypted backups for a limited time.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to / restrict certain processing. To exercise these rights, contact us at the email below.
You can also:
- Sign out (ends the current session cookie).
- Disconnect cloud providers (including Google Drive) from MooStash where the product allows.
- Revoke MooStash’s access from your Google Account security settings (or the equivalent page for other providers).
- Stop using optional AI features or unlink third-party AI providers where the product allows.
If you use MooStash through an organization-operated deployment, contact that organization’s admin for account deletion on that instance.
8. Children
MooStash is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
9. Security
We use industry-reasonable measures appropriate to a small hosted service (access controls, session cookies, secret handling for tokens, least-privilege admin tools). No method of transmission or storage is 100% secure. Protect your cloud and sign-in accounts; MooStash’s access is only as strong as those providers and your device.
10. International transfers
We may process and store information in the United States and other countries where our infrastructure or subprocessors operate. If you access MooStash from another region, you understand that information may be transferred to and processed in those locations.
11. Third-party services
Your use of Google, Dropbox, Microsoft, Box, AI providers, and similar services is also governed by their terms and privacy policies. MooStash is not responsible for those services’ practices.
12. Changes
We may update this Privacy Policy from time to time. We will change the effective date above and, for material changes, provide additional notice (for example in-product or by email) where appropriate. Continued use after the effective date means you accept the updated policy.
13. Contact
Sigae Intl LLC 20 Waterside Plaza #3F New York, NY 10010 United States
Registered in New York State (DOS ID #6274267).
Privacy / data requests: marcelin@sigea.com