Skip to main content

The Vault · Privacy as a product

Your data. Visible. Deletable. Yours.

Most software gives you a buried export wizard or a nuclear delete-my-account button. Moonshot gives you The Vault — a live inventory of everything we keep on you, with controls that match how you actually think about your data.

Everything we keep

Five buckets. No hidden one.

Every piece of data Moonshot holds falls into one of these. If we ever add a sixth, it goes here too.

Bucket 1

What you put in

The data you explicitly entered into Moonshot.

People, accounts, campaign data, queries you asked, files you uploaded, notes you wrote.

Bucket 2

What we noticed

The data Moonshot derived, computed, or observed. The stuff most apps hide.

Drift alerts, scores, revenue pulse calculations, behavioral telemetry, AI conversation history.

Bucket 3

What's in your browser

Local state Moonshot left on your device. Almost nobody surfaces this.

localStorage, sessionStorage, cookies, IndexedDB caches (including your File Vault).

Bucket 4

What integrations stored

Data third-party connections cached on our side when you connected them.

Stripe customer cache, Gmail metadata, Calendar token state, anything an integration left behind.

Bucket 5

What you saved

Snapshots you explicitly preserved. These survive even when their source data is deleted.

Campaign rollup percentages, weekly scorecards, MedBay results, the files in your File Vault.

What you can do

See it. Delete it. Save what matters.

See it

Every piece of data, in plain English. No JSON dump, no enterprise export wizard — a real live inventory organized by the categories above.

Delete it

Anything you want, granular. Each delete shows a clear disclaimer about what it affects — cosmetic, resets a feature, breaks a feature, or requires sign-in again.

Save what matters

Before deleting raw data, you can preserve a snapshot — like the rollup percentage of a campaign even if you delete every data point. Snapshots survive deletion of their source and are receipts of a moment, not live projections.

The Vault opens with sign-in. Same data, your controls.

Privacy Policy

Privacy Policy — Moonshot OS

Last updated: July 20, 2026

Moonshot OS (“we”, “our”, “us”) is designed to help users understand and act on their work activity. This policy explains exactly what Google data Moonshot accesses, why, and the controls you have over it. Every write capability is optional and happens only when you explicitly initiate it — Moonshot never sends email, changes your calendar, or posts on your behalf in the background. The Vault (above) is the product surface for the commitments documented here.

You choose which Google services to connect. We request the minimum scope for each feature, and we list every scope and its purpose below. Read access is the default; each write capability is separate and is requested only when you explicitly turn it on.

  • Gmail — headers only (Subject, From, To, Date). We read message metadata to detect conversations, follow-ups, and activity signals. We never read message bodies or attachments. (scope: gmail.metadata)
  • Gmail send — optional. If you send an email from inside Moonshot (for example, a follow-up from the Desk), we request permission to send that message on your behalf. We never send email in the background. (scope: gmail.send)
  • Google Calendar — read. We read your events to detect meetings, scheduling, and deadlines for your operating week. (scope: calendar.readonly)
  • Google Calendar — create/edit, optional. When you explicitly create or edit an event from inside Moonshot, we use calendar write access to make exactly that change. We never create, edit, or delete events in the background. (scope: calendar.events)
  • Google Sheets / Drive — per-file only. When you import a spreadsheet into Reckon, we access only the specific file you pick with Google’s file picker — never your full Drive. We read it to import its data. (scope: drive.file)
  • Google Business Profile — optional add-on. If you connect it for the Reputation automation, we read your business locations and reviews and, when you choose, post review replies on your behalf. (scope: business.manage)
  • Account email — we read your Google account email address to label the connected account. (scope: userinfo.email)

We use this data to:

  • detect missed follow-ups, stalled conversations, and activity patterns
  • generate a Weekly Operating Review
  • recommend next steps and workflows
  • keep live issues, proof loops, and operating history visible inside Moonshot OS
  • Your data is used only to provide these features inside Moonshot OS.

Access tokens are securely stored and encrypted.

Google user data is processed to generate product insights such as Weekly Operating Reviews, detected activity patterns, and next-step recommendations.

We retain Google-connected data only for as long as it is needed to provide the product experience, operate the service, and support account-level controls such as disconnect and deletion.

  • We use industry-standard security practices to protect your data.
  • We do not claim that any system is perfectly secure, but we work to limit access and reduce unnecessary retention.

We do not sell Google user data or other personal data.

We do not use Google user data for advertising or marketing.

We do not share Google user data with third parties except where needed to provide the service, comply with law, or protect against abuse, fraud, or security issues.

You can:

  • disconnect any Google service at any time — Moonshot revokes the access token with Google and deletes the stored credential
  • delete stored Google data from Moonshot — handled through The Vault when signed in
  • delete all stored Moonshot workspace data for your account
  • preserve a snapshot (the rollup, the percentage, the receipt) before deleting underlying data
  • revoke Moonshot OS access from your Google account security settings

Reckon is building a shared reference from small operators, for small operators — the kind of local, real-world numbers that have never existed in any public dataset. Contributing is entirely optional and off by default. Nothing about your numbers is shared unless you explicitly choose to share them.

If you opt in, only your own recorded operating numbers are used — never anything that identifies you, your business, or your customers. Before anything is contributed it is anonymized: your name, account, business name, and any free text are removed, and location is coarsened to a broad area, never a precise address.

Contributed numbers are only ever used in aggregate — combined with many other operators to produce a typical benchmark for a kind of business in a broad area. We never surface an aggregate until enough operators have contributed that no single business can be identified from it.

  • We never sell your data, and we never use it for advertising.
  • We never share your individual numbers with anyone — including other operators or competitors. Only anonymized aggregates, above a minimum-contributor threshold, are ever shown.
  • You can change your choice at any time. Turning sharing off stops any future contribution, and you can request deletion of previously contributed data at support@timelessrobots.com.
  • The purpose is singular: give the next small operator a better shot with real numbers — never to advantage a larger competitor.

Moonshot OS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is accessed only as needed to provide the Moonshot OS features you have connected.

Gmail is accessed at the metadata (headers) level only — Subject, From, To, and Date — to detect communication patterns, follow-ups, and activity signals. We never read Gmail message bodies or attachments.

Google Calendar is read to detect meetings, scheduling, and deadlines. Calendar events are created or edited only when you explicitly initiate that action inside Moonshot.

Any write capability — sending a Gmail message, creating or editing a calendar event, or posting a Google Business Profile review reply — happens only after an explicit, user-initiated action, and for Gmail send it also requires a separate reconnect and confirmation step.

  • We do not send, modify, or delete emails in the background — only when you explicitly send one from Moonshot.
  • We do not create, edit, or delete calendar events in the background — only when you explicitly initiate the change from Moonshot.
  • We do not sell Google user data, and we do not use it for advertising or marketing.
  • We do not transfer Google user data to others except as needed to provide and secure the service, comply with law, or with your consent.
  • We do not use Google user data to train, develop, or improve generalized/non-personalized AI or machine-learning models.
  • Moonshot OS does not provide humans access to Google user data except with your consent (for example, support you request), where necessary for security or to comply with law, or on data that has been aggregated and anonymized.

Moonshot OS integrates with Google APIs, including Gmail, Google Calendar, Google Drive (per-file Sheets import), and Google Business Profile.

Use of Google user data is limited to the practices described in this policy.

We may update this policy. Changes will be reflected on this page.

To request deletion or ask a privacy question, contact support@timelessrobots.com.

Privacy — Visible. Deletable. Yours. · Moonshot OS