Bucket 1
What you put in
The data you explicitly entered into Moonshot.
People, accounts, campaign data, queries you asked, files you uploaded, notes you wrote.
The Vault · Privacy as a product
Most software gives you a buried export wizard or a nuclear delete-my-account button. Moonshot gives you The Vault — a live inventory of everything we keep on you, with controls that match how you actually think about your data.
Everything we keep
Every piece of data Moonshot holds falls into one of these. If we ever add a sixth, it goes here too.
Bucket 1
The data you explicitly entered into Moonshot.
People, accounts, campaign data, queries you asked, files you uploaded, notes you wrote.
Bucket 2
The data Moonshot derived, computed, or observed. The stuff most apps hide.
Drift alerts, scores, revenue pulse calculations, behavioral telemetry, AI conversation history.
Bucket 3
Local state Moonshot left on your device. Almost nobody surfaces this.
localStorage, sessionStorage, cookies, IndexedDB caches (including your File Vault).
Bucket 4
Data third-party connections cached on our side when you connected them.
Stripe customer cache, Gmail metadata, Calendar token state, anything an integration left behind.
Bucket 5
Snapshots you explicitly preserved. These survive even when their source data is deleted.
Campaign rollup percentages, weekly scorecards, MedBay results, the files in your File Vault.
What you can do
Every piece of data, in plain English. No JSON dump, no enterprise export wizard — a real live inventory organized by the categories above.
Anything you want, granular. Each delete shows a clear disclaimer about what it affects — cosmetic, resets a feature, breaks a feature, or requires sign-in again.
Before deleting raw data, you can preserve a snapshot — like the rollup percentage of a campaign even if you delete every data point. Snapshots survive deletion of their source and are receipts of a moment, not live projections.
The Vault opens with sign-in. Same data, your controls.
Privacy Policy
Last updated: July 20, 2026
Moonshot OS (“we”, “our”, “us”) is designed to help users understand and act on their work activity. This policy explains exactly what Google data Moonshot accesses, why, and the controls you have over it. Every write capability is optional and happens only when you explicitly initiate it — Moonshot never sends email, changes your calendar, or posts on your behalf in the background. The Vault (above) is the product surface for the commitments documented here.
You choose which Google services to connect. We request the minimum scope for each feature, and we list every scope and its purpose below. Read access is the default; each write capability is separate and is requested only when you explicitly turn it on.
We use this data to:
Access tokens are securely stored and encrypted.
Google user data is processed to generate product insights such as Weekly Operating Reviews, detected activity patterns, and next-step recommendations.
We retain Google-connected data only for as long as it is needed to provide the product experience, operate the service, and support account-level controls such as disconnect and deletion.
We do not sell Google user data or other personal data.
We do not use Google user data for advertising or marketing.
We do not share Google user data with third parties except where needed to provide the service, comply with law, or protect against abuse, fraud, or security issues.
You can:
Reckon is building a shared reference from small operators, for small operators — the kind of local, real-world numbers that have never existed in any public dataset. Contributing is entirely optional and off by default. Nothing about your numbers is shared unless you explicitly choose to share them.
If you opt in, only your own recorded operating numbers are used — never anything that identifies you, your business, or your customers. Before anything is contributed it is anonymized: your name, account, business name, and any free text are removed, and location is coarsened to a broad area, never a precise address.
Contributed numbers are only ever used in aggregate — combined with many other operators to produce a typical benchmark for a kind of business in a broad area. We never surface an aggregate until enough operators have contributed that no single business can be identified from it.
Moonshot OS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is accessed only as needed to provide the Moonshot OS features you have connected.
Gmail is accessed at the metadata (headers) level only — Subject, From, To, and Date — to detect communication patterns, follow-ups, and activity signals. We never read Gmail message bodies or attachments.
Google Calendar is read to detect meetings, scheduling, and deadlines. Calendar events are created or edited only when you explicitly initiate that action inside Moonshot.
Any write capability — sending a Gmail message, creating or editing a calendar event, or posting a Google Business Profile review reply — happens only after an explicit, user-initiated action, and for Gmail send it also requires a separate reconnect and confirmation step.
Moonshot OS integrates with Google APIs, including Gmail, Google Calendar, Google Drive (per-file Sheets import), and Google Business Profile.
Use of Google user data is limited to the practices described in this policy.
We may update this policy. Changes will be reflected on this page.
To request deletion or ask a privacy question, contact support@timelessrobots.com.