Skip to content
SignalMoth
Live demo ↓PricingOpen editor

Legal / Privacy

Privacy Policy

This policy explains what SignalMoth handles when you visit the website, use the editor, create an account, request an AI draft, make a one-time purchase, or subscribe to a plan.

Effective: August 10, 2026 · Last updated: August 24, 2026

In short: projects are local-first, SignalMoth does not sell personal information or use it for targeted advertising, and Google identity data is used only for sign-in, account operation, security, support, and legal compliance when you choose Google sign-in.

On this page

  1. Scope and operator
  2. Information handled
  3. Google sign-in
  4. How information is used
  5. Projects and AI
  6. Cookies and local storage
  7. Sharing and providers
  8. Retention and deletion
  9. Security
  10. Your choices and rights
  11. International processing
  12. Children
  13. Policy changes
  14. Contact

1. Scope and operator

This policy applies to the SignalMoth public website at signalmoth.com, the editor at app.signalmoth.com, and the account, billing, and AI services they use. SignalMoth is the sole-proprietor brand under which this service is operated from Ho Chi Minh City, Vietnam. SignalMoth is not a separate legal entity or company. In this policy, “SignalMoth,” “we,” “us,” and “our” refer to the sole proprietor operating under the SignalMoth brand.

The sole proprietor operating under SignalMoth determines why and how SignalMoth processes the personal information described in this policy and is the data controller where applicable law uses that term. Some providers, including Paddle for purchase transactions, act as separate controllers under their own terms. Questions or privacy requests can be sent to admin@signalmoth.com.

2. Information SignalMoth handles

  • Website and security data: IP address, browser or device metadata, request time, requested route, request identifiers, and security or error outcomes may be processed by SignalMoth and its hosting providers.
  • Account data: a stable identity-provider identifier, a normalized email address when supplied, and whether the provider marked that address as verified. SignalMoth does not use email as an automatic account-linking key.
  • Local editor data: projects, recovery checkpoints, presentation preferences, and onboarding or theme choices stored in your browser.
  • AI request data: the prompt or edit instruction and the bounded project context needed to perform an AI action that you explicitly start.
  • Billing data: product, plan, and entitlement status; one-time transaction, checkout, and subscription identifiers; Story Pack balances; billing-period dates; provider event status; and, when Paddle makes it available for an order, buyer name, email, billing address or country, purchase history, and transaction analytics. Paddle receives and processes the payment details entered during checkout; SignalMoth does not receive or store full payment-card details.
  • Usage and support data: content-free product events such as a pricing view, AI operation status, token counts, estimated cost, latency, and quota usage. Minimal activation events may record that a tutorial was completed, the first moment was added, Preview was completed, an export was created, a share link was created, “Explore Pro hosting & branding” interest was recorded, or the browser returned in a later session. Those records are limited to the event name, recording time, source, a random deduplication identifier, and an account identifier when signed in. They do not include project content, project titles, files or filenames, prompts or instructions, or learner choices. Usage and support data also includes any information you choose to send when requesting support.

3. Google sign-in data

If you choose Continue with Google when that option is available, Google sends the identity information you authorize to Auth0, SignalMoth's authentication provider. Auth0 uses that information to authenticate you and returns a verified identity result to SignalMoth so an account can be created or accessed.

SignalMoth's application requests only Auth0's OpenID and email scopes. Depending on the Google connection settings, Google and Auth0 may also process basic profile data such as your name and profile image while authenticating you. SignalMoth's application database retains the provider identifier, an email address when supplied, and whether the provider marked it as verified; it does not retain your Google name or profile image and does not receive or store Google access or refresh tokens.

SignalMoth does not request access to Gmail, Google Drive, Google Calendar, contacts, or offline access. Google identity data is not sold, used for advertising, used to assess credit, or used to train generalized AI models. Its use is limited to authentication, account security, support, and legal compliance.

SignalMoth's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can revoke SignalMoth's Google access from your Google Account and request deletion of SignalMoth account data by contacting us.

4. How information is used

SignalMoth uses information to:

  • authenticate users, maintain secure sessions, and prevent abuse;
  • provide purchases, plan access, AI quotas, checkout, and subscription management;
  • fulfil AI actions that a signed-in user explicitly requests;
  • operate, troubleshoot, secure, and improve the service;
  • answer support, privacy, and billing requests; and
  • comply with law and enforce the Terms of Service.

Depending on where you live, the legal basis may be performance of a contract, legitimate interests in operating and securing the service, consent where required, or compliance with a legal obligation.

5. Projects, exports, review links, and AI

SignalMoth is local-first. Editor projects and bounded recovery history are stored in your browser's IndexedDB by default. Account services do not automatically upload full project documents. Clearing site data or browser storage may remove local projects, so you should keep exports you need.

Files, presentation exports, and review links leave your device only when you choose to download or share them. A review link can contain a project snapshot in its URL fragment; anyone who receives the link may be able to view that snapshot.

When you request an AI draft or edit, SignalMoth sends the request and necessary bounded project context to OpenAI. Requests set OpenAI's store option to false, so SignalMoth does not ask OpenAI to retain the response for later retrieval; that setting does not by itself determine any provider security or abuse-monitoring retention. SignalMoth's AI operation database records usage and cost metadata but deliberately excludes prompts, instructions, full diagrams, project documents, and provider response bodies. OpenAI still processes the submitted content to return the requested result under its own data terms.

6. Cookies and browser storage

SignalMoth uses temporary login-transaction and session cookies that are necessary for authentication and security. Production session cookies are Secure, HttpOnly, and scoped to the SignalMoth application. Auth0 and an identity provider may set their own cookies to operate their sign-in flows.

The marketing site stores a theme choice in local storage. The editor uses IndexedDB, local storage, and session storage for local projects, recovery, and interface preferences. It also stores bounded activation markers and random deduplication identifiers so an activation event is not repeatedly sent during the same browser session and a return in a later session can be recognized. These markers do not contain project content or titles, files or filenames, prompts or instructions, or learner choices. SignalMoth does not use the public marketing site for targeted-advertising tracking.

7. Sharing and providers

SignalMoth does not sell personal information. Depending on the features you use, companies and services that receive or process data include:

  • Cloudflare for website delivery and security;
  • Render for application, database, and rate-limit storage hosting;
  • Auth0, operated by Okta for authentication;
  • Google when you choose Google sign-in, and Google Workspace when you email SignalMoth;
  • OpenAI when you explicitly use an AI feature;
  • Paddle, SignalMoth's authorized reseller and Merchant of Record, for checkout, payment, taxes, receipts, subscription management, refunds, and buyer payment support. Paddle acts as a separate controller for the transaction. SignalMoth and Paddle share order, buyer, transaction, product, and account-support data controller-to-controller where needed to complete and administer the purchase, provide entitlements, prevent fraud, comply with law, or resolve support and refund requests. Paddle explains its processing in the Paddle Privacy Policy.

SignalMoth may also disclose information when you direct it to, when reasonably necessary to protect users or the service, to comply with law, or as part of a transfer of SignalMoth or its assets to another operator, with appropriate notice and safeguards.

8. Retention and deletion

  • Local projects and preferences remain in your browser until you delete them, clear site data, or the browser removes them.
  • Login transactions are valid for up to 10 minutes. Sessions expire after one hour of inactivity or 24 hours in total, or are revoked when you log out. Security records for expired or revoked sessions may remain until they are deleted under operational and legal retention criteria.
  • Account and entitlement records are kept while the account is active and then only as needed for deletion processing, fraud prevention, security, dispute resolution, backup rotation, and legal obligations.
  • Billing and tax records may be retained for the periods required by applicable law and Paddle's obligations. Content-free operational and AI usage records are retained as needed to enforce quotas, investigate incidents, and account for service costs.

SignalMoth does not currently provide self-service account deletion. To request account-data deletion, email admin@signalmoth.com. SignalMoth will verify and assess the request under applicable law. When eligible data is deleted or de-identified, some records may still be retained for the purposes above. Changes to SignalMoth account data do not automatically clear projects stored locally in your browser or records held independently by a provider.

9. Security

SignalMoth uses measures designed to protect data, including encrypted transport, security-scoped cookies, hashed session credentials, restricted database roles, bounded requests, provider-secret isolation, and data minimization. No service can guarantee absolute security, and you should protect your device, account, and exported files.

10. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of personal information, or to receive a portable copy. You may also withdraw consent where processing relies on consent and complain to your local privacy authority.

You can clear local project and preference data through your browser, revoke Google access through your Google Account, log out to revoke a SignalMoth session, and contact admin@signalmoth.com for an account request. SignalMoth does not discriminate for exercising applicable privacy rights.

11. International processing

SignalMoth and its service providers may process information in countries other than your own, including locations where those providers operate. Their privacy notices and contractual terms describe their processing locations and transfer safeguards. Contact SignalMoth if you need information about a specific provider used for your data.

12. Children

SignalMoth is a general-audience productivity tool and is not directed to children under 13. SignalMoth does not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us so it can be reviewed and deleted where required.

13. Changes to this policy

SignalMoth may update this policy as the service or law changes. The effective date will be revised, and material changes will be announced on the site or in the application when appropriate. If a change materially expands how Google user data is used, SignalMoth will notify affected users and obtain consent where required before using that data for the new purpose.

14. Contact

For privacy questions, requests, or complaints, email admin@signalmoth.com. Please do not include passwords, access tokens, payment-card details, or sensitive project content in your message.

SignalMothMotion makes cause visible.

Explore

PricingEditor

Legal

PrivacyTermsRefund Policy

Contact

admin@signalmoth.comQuestions & support