If you are in the EEA, UK, or Switzerland, our GDPR Policy explains your rights in more detail. Our Terms of Service cover account security and AI-generated output.
1. Overview: local-first by design
Hi, Moose is a desktop application. When you write prompts, review drafts, or run a local AI model inside the App, that activity happens on your own device and is not sent to Farmball, LLC unless you use a hosted feature described below.
This policy covers the information we collect when you create an account, use a hosted feature, visit our website, or contact us. It applies to the App and to the hosted services we operate at himoose.com and console.himoose.com (together, the "Service"), which are provided by Farmball, LLC ("Farmball," "we," "us," or "our").
2. What stays on your device
Prompts, drafts, context, and output produced by the local AI model never leave your machine, and we never see them, unless you explicitly do one of the following: connect a BYOK (bring-your-own-key) third-party model provider, enable a hosted feature such as scheduled monitoring or hosted audio, or connect and publish to a third-party CMS. Features that send data off your device are opt-in and labeled in the App.
3. Information we collect
Depending on how you use the Service, we may collect:
- Account information - name, email address, and password or authentication credential you provide when you create an account.
- Billing information - handled directly by our payment processor, Stripe. We do not store your full card number.
- Content you submit to a hosted feature - for example, an article you send to the hosted audio player, or a site or URL you register for scheduled AI-visibility monitoring.
- Connected Platform credentials - access tokens or API keys you provide to connect a CMS or model provider, stored encrypted and used only to carry out the actions you request.
- Usage and diagnostic data - basic technical information such as App version, operating system, and error logs, used to keep the Service running and to fix bugs.
- Website visit data - standard server logs when you visit himoose.com or console.himoose.com, such as IP address, browser type, and pages requested, kept briefly for security and troubleshooting.
- Audio analytics - for the listen-to-this-article player, we temporarily process the listener's IP address to create a one-way hashed identifier for playback tracking; we do not retain the original IP address.
- Communications - anything you send us through the contact form, email, or support channels.
4. How we use information
We use the information above to provide and maintain the Service, process payments, respond to support requests, secure accounts against unauthorized access, and improve the product. We do not sell your personal information, and we do not use content you submit to the Service to train AI models.
6. BYOK and third-party AI models
If you connect your own API key or account for a third-party AI model provider, the prompts and content you send through that connection are transmitted directly to that provider under your own agreement with them. We are not a party to that agreement and are not responsible for how the provider processes, stores, or uses your data. Review the provider's own privacy policy before connecting it.
7. Third-party service providers
We rely on a small number of third parties to operate the Service, including Stripe for payment processing and Google Firebase for authentication and hosting infrastructure. If you connect a CMS (such as WordPress, Webflow, or Grav) or a model provider, that platform also processes the data involved in that specific connection, only because you asked it to. Our hosted infrastructure runs in the United States.
8. Data retention and deletion
We keep account and hosted-feature data for as long as your account is active and as needed to provide the Service. Diagnostic logs and hosted content are generally deleted or anonymized within 90 days unless a feature you use requires longer retention, or we need to keep information to comply with law, resolve disputes, or enforce these policies. Hashed audio-analytics identifiers may be retained for up to one year. You can request deletion of your account and associated data at any time by contacting us.
9. Security
We use reasonable administrative, technical, and physical safeguards designed to protect the information we hold, including encrypting stored Connected Platform credentials. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
You are responsible for keeping your own login credentials, provider keys, and Connected Platform tokens secure, and for using a strong, unique password and multi-factor authentication where we offer it. Our Terms of Service explain how account-security responsibility is shared between you and us.
10. Your choices and rights
You can access, update, export, or delete much of your account information directly in the App or console. California residents have rights under the CCPA/CPRA, including the right to know what personal information we hold, to request deletion or correction, and to opt out of certain uses; we do not sell or share personal information as those terms are defined in California law. Residents of the EEA, UK, and Switzerland should also see our GDPR Policy. To exercise any of these rights, contact us at [email protected]; we may need to verify your identity before acting on a request.
11. Children's privacy
The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product evolves. When we make a material change, we will update the date at the top of this page and, where appropriate, notify you in the App or by email.
13. Contact us
Questions about this policy or your data? Reach us at [email protected], or write to Farmball, LLC, Austin, Texas.