This page supplements our Privacy Policy, which describes what data we collect and why. Read that page first for the full picture.
1. Scope
This policy applies if you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland and use Hi, Moose - the desktop app and the hosted services provided by Farmball, LLC ("Farmball," "we," "us," or "our"). It explains our legal bases for processing, your rights under the GDPR and UK GDPR, and how we handle international data transfers.
Hi, Moose is local-first. Prompts and content processed by the local AI model on your own device are never transmitted to us, so the GDPR concepts below apply only to the personal data involved in the hosted features you choose to use - your account, scheduled monitoring, hosted audio, and any Connected Platform or third-party model you configure.
2. Our role: controller and processor
For account information, billing, and the operation of the Service itself, Farmball acts as a data controller. For content you submit to a hosted feature (for example, an article sent to the audio player, or a URL registered for monitoring), Farmball generally acts as a data processor on your behalf, processing that content only to deliver the feature you requested.
3. Legal bases for processing
We process personal data on the following legal bases:
- Contract - to provide the Service you signed up for, including account access, billing, and hosted features you enable.
- Consent - for optional features and non-essential cookies, which you can withdraw at any time.
- Legitimate interests - to secure accounts against unauthorized access, prevent abuse, and improve the Service, balanced against your rights.
- Legal obligation - where we must retain or disclose information to comply with applicable law.
4. Automated decision-making and AI
Hi, Moose generates audits, scores, and content suggestions using AI models. These outputs are intended to assist your own review and decision-making - we do not use them to make decisions that produce legal effects or similarly significant effects concerning you without your own review and action. You always decide what to do with an audit, score, or draft before it is published or acted on. Because Output can be inaccurate, you should independently verify it, as described in our Terms of Service.
5. International data transfers
Our hosted infrastructure runs in the United States, so personal data you submit to a hosted feature is stored and processed there. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on safeguards such as Standard Contractual Clauses with our service providers, or on the provider's own certified transfer mechanism, to protect it to a standard consistent with the GDPR. If you connect your own third-party model provider or CMS, that provider's own transfer practices govern the data you send it directly.
6. Your rights under the GDPR
If the GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to legal retention requirements.
- Restrict how we process your data in certain circumstances.
- Port your data to another provider in a structured, commonly used format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local supervisory authority.
7. How to exercise your rights
To exercise any of these rights, email [email protected]. We may ask you to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law.
8. Data retention
We retain personal data only for as long as needed to provide the Service or comply with legal obligations, generally deleting or anonymizing hosted-feature data within 90 days of it no longer being needed, as described in our Privacy Policy.
9. Sub-processors
We use a limited set of sub-processors to operate the Service, including Stripe (payments) and Google Firebase (authentication and infrastructure), along with any Connected Platform or model provider you personally configure. Contact [email protected] for our current sub-processor list.
10. Data Processing Agreements
Where we process personal data on your behalf as a processor, we do so only on your documented instructions, with the safeguards described in this policy and our Privacy Policy, in line with Article 28 of the GDPR. Business customers who need a signed Data Processing Agreement can request one at [email protected]; once executed, it forms part of your agreement with us.
11. Breach notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and any required supervisory authority without undue delay, in line with our obligations under applicable law.
12. Contact us
Questions about this policy or how it applies to you? Reach us at [email protected], or write to Farmball, LLC, Austin, Texas.