Moorhaven Privacy Policy
Effective date: October 11, 2026
Version: 2026-09-29
This policy explains what personal information Chatham Oaks Growth Solutions, which operates Moorhaven ("Moorhaven", "we", "us"), collects when you use the Moorhaven console at moorhaven.ai and the Moorhaven API (together, the "Service") or visit our website at moor-haven.com (the "Website"), what we do with it, and the choices you have. It is published at https://moor-haven.com/privacy.
The short version:
- We do not train AI models on your prompts, outputs, or images.
- We do not store the content of your prompts or the model's responses. They are processed in memory to produce a response and then discarded. We keep records about each request — its size, token counts, timing, which model answered, and whether it succeeded — but never its content. Console chat history stays in your browser, not on our servers.
- We do not sell your personal information, show you ads, or use third-party analytics or advertising trackers in the Service or on the Website.
- The Service is not intended for health, legal, financial, or other regulated data unless your organization has a separate written agreement with us that covers it. See Sensitive and regulated data.
Information we collect
Account information
When you or your organization signs up, or when you are invited to an organization, we collect:
- your email address and, if you provide it, your name;
- your organization's name and identifier, plan, seat count, and the intended-use declaration you make at signup;
- your role in the organization (for example owner, admin, or member);
- records of invitations you send or receive;
- if you contact us about an Enterprise plan, your name, email, organization, and the message you write. That message is emailed to our support inbox and not stored in the Service.
You can also sign in with a Google account. That sign-in is handled by our network provider, Cloudflare Access, and we receive only your email address from it. If that email address is not yet part of an organization, we do not create an account for it; you sign up to create your own organization.
Content you submit
"Content" means the prompts, messages, images, and other input you send to the Service, and the output the models return.
- API and console requests. We send your content to the model, return the response to you, and do not write the content to our databases, logs, or disk. While a request is being processed, and until later requests replace it or the model server restarts, parts of it remain in the model server's memory as a prompt cache that speeds up repeated prompts. That cache is held in memory only, is never written to storage, and is partitioned so that one organization's cached prompts can never be used to serve another's.
- Prompt fingerprints. To measure how well that cache works, our gateway keeps one-way fingerprints (salted hashes) of the beginnings of prompts in memory for up to 30 minutes, separately for each organization. They cannot be turned back into your text and are never saved to storage.
- Console chat history is kept in your browser's session storage so the conversation survives a page reload. It normally clears when you close the tab, although some browsers restore it when they restore a closed session. It is not sent to us except as part of each new message.
- The image demo sends the image you choose to the model and does not store it; images pass through memory only and are never written to disk. Your recent questions in the demo are saved in your browser's local storage. The "random photo" option fetches a stock image from picsum.photos on our server, not from your browser.
No review and nothing to produce. We do not run classifiers on your content, no person at Moorhaven reads it, and we keep no copy that could be reviewed later. We act on abuse using the records about requests described below and on reports we receive. Because we keep no content, we cannot produce it in response to a subpoena or other legal demand; such a demand can reach only your account, usage, and activity records.
If your content includes personal information about other people, we process it only on your behalf, to provide the Service to you. You are responsible for having the right to share it with us.
Connectors
Connectors let the model call third-party tools you choose (for example Linear or Notion) through the Model Context Protocol. When you add a connector:
- we store its name, its address, the list of tools it offers and which ones you have turned off, and the details of the authorization you granted it (the issuing service, scope, and the access and refresh tokens it issued to us). Tokens are encrypted at rest;
- when the model uses a connector, we send that service the tool request the model generates from your conversation. That can include content from your conversation. The service's reply is passed back to the model;
- we do not store tool requests or replies, but the third-party service receives them and handles them under its own terms and privacy policy. Only connect services you trust with that content.
When you add or remove a connector or turn one of its tools off, the activity record (see below) names that connector and tool.
Turning a connector off keeps its stored authorization so you can turn it back on. Removing a connector deletes our copy of its tokens. Neither revokes the access you granted at the third-party service; you can do that in that service's settings.
Usage and billing information
- Usage records. For each request we record the organization, the API key or user, the time, the model tier, the size of the prompt (a character count), the number of prompt and completion tokens, how long the request took, and whether it succeeded. We keep these in our usage database, in a request log stored on the inference server itself, and in our internal monitoring system, which keeps per-organization totals for 30 days. They do not contain your content. We use them for billing, rate limiting, capacity planning, and to show you your usage.
- Payments are handled by Stripe. We give Stripe your email address, your organization's identifier, your seat count, and usage charges, and Stripe collects your payment details directly. Card numbers never pass through our servers. We keep the Stripe customer and subscription identifiers.
- API keys are stored only as a one-way hash, plus a short prefix so you can tell keys apart. We cannot recover a key after it is shown to you.
Activity records
We keep a record of account and administrative actions — for example creating or revoking an API key, inviting or removing a member, changing a plan, or adding a connector. Each entry records who acted (by email address), what they did, and when.
We also record each time you accept our Terms of Service and this Privacy Policy: your email address, your organization, which version you accepted, how (at signup, when joining by invitation, or when asked at sign-in), and when. We keep these records even after your account is deleted, as evidence of the agreement.
Waitlist
While sign-up opens in stages, you can join a waitlist on the Website. When you do, we store:
- your email address;
- if you choose one, what you plan to use Moorhaven for (general use, legal or other regulated work, or health); and
- the date and time you joined.
We store nothing else from the form: no IP address, no browser details, and no cookies. Cloudflare stores the entry for us in its D1 database service. To slow down automated sign-ups, Cloudflare limits how often one IP address can submit the form; it does that counting on its own network, and we do not receive or store the counts.
We use your entry only to decide when to invite you and to send you that invitation. We send it from support@moorhaven.ai, our support inbox on Google Workspace, and we delete your waitlist entry once you are invited. The invitation email stays in our mailbox, like other email we send. To be removed from the waitlist before then, email privacy@moorhaven.ai.
Joining the waitlist does not create an account; that happens only if you sign up after you are invited.
Technical information
- Cookies. The Service sets only the cookies it needs to run: a session
cookie that keeps you signed in, a companion security (CSRF) cookie, and,
during signup, a signup cookie and its security cookie. Cloudflare sets its
own sign-in and security cookies (such as
CF_Authorization), and Stripe's checkout and billing pages set their own cookies. We use no advertising or analytics cookies. Your browser's local storage also holds your theme choice. The Website sets no cookies. - IP addresses are used briefly in memory to rate-limit sign-in and signup attempts, and our application does not write them to its database or logs. Our network infrastructure, including Cloudflare, processes IP addresses to carry traffic to us and may keep standard connection logs. Cloudflare also rate-limits the waitlist form (see Waitlist).
- Fonts and documentation assets. The console loads fonts from Google Fonts, and the API documentation page loads a component from the jsDelivr CDN. When your browser fetches these, Google and jsDelivr receive your IP address and browser information under their own policies. The Website runs no scripts and loads everything, including its fonts, from moor-haven.com itself.
- Error logs. If something fails, our servers may log the error, which can include the email address involved (for example when a sign-in email fails to send, or when someone signs in without an account). Error logs never include your prompts, images, or model responses: our servers log only where an error happened and what kind it was, and we test for this. Logs stay on our own servers and are overwritten after a short, size-limited period.
- Do Not Track. We do not track you across other websites, so we do not respond differently to Do Not Track or Global Privacy Control signals.
How we use information
We use personal information to:
- provide, operate, secure, and maintain the Service;
- sign you in and send you sign-in links, signup links, and invitations;
- keep the waitlist and invite you to the Service when there is room;
- review new organizations before approving them;
- process payments and calculate usage charges;
- enforce limits, prevent abuse and fraud, and keep the Service secure;
- respond to your requests and provide support;
- comply with the law and enforce our Terms of Service (https://moor-haven.com/terms).
We do not use your content or personal information to train or improve AI models, sell it, or use it for advertising.
How we share information
We share personal information only with the following:
| Recipient | Why | What they receive |
|---|---|---|
| Cloudflare | Network and security: carrying traffic to our servers and handling sign-in; hosting the Website and the waitlist | All traffic to and from the Service and the Website, including content, which Cloudflare decrypts at its edge to carry it to us and run its security checks. It keeps connection and sign-in records (addresses, timestamps, the pages requested, and your email for sign-in) under its own policy. Apart from waitlist entries, which it stores for us in its D1 database, we have not enabled any Cloudflare feature that stores request or response content. It also counts waitlist submissions per IP address to limit abuse. |
| Sign-in, when you use a Google account | Handled by Google and Cloudflare; we receive your email | |
| Google Workspace | Our email, including the support and privacy inboxes we answer from | Your email address and the emails we exchange |
| Stripe | Payments and billing | Your email, organization identifier, seat count, and usage charges |
| Resend | Sending sign-in, signup, and invitation emails, and notices to our support inbox | Your email address and the email's contents |
| Connector services you choose | Carrying out tool calls you enable | Tool requests generated from your conversation |
| Members of your organization | Collaboration and administration | Your email, name, and role; your usage; the API keys you created; and the organization's recent activity entries, which show who acted by email address (including Moorhaven staff) |
We may also disclose information:
- when required by law, such as in response to a valid subpoena, court order, or warrant. Where the law allows and it is practical, we will try to notify you first so you can seek to challenge the request;
- to protect rights and safety, for example to prevent imminent harm or to report child sexual abuse material to the National Center for Missing & Exploited Children as the law requires;
- in a business transfer, such as a merger or sale of assets, to the acquiring party, who must honor this policy for the information it receives.
Where your information is processed
Our servers are in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States. Cloudflare may carry traffic through its network locations in other countries, and the Website and the waitlist are hosted on Cloudflare's network, which may store them outside the United States.
How long we keep information
| What | Where | How long |
|---|---|---|
| Your prompts, images, and the model's responses | Memory, while the request runs | Not stored |
| Prompt cache | The model server's memory, partitioned per organization | Until later requests replace it or the model server restarts; never written to storage |
| Prompt fingerprints (one-way hashes) | The gateway's memory, per organization | Up to 30 minutes |
| Console chat history | Your browser | Until you close the tab |
| Usage records (sizes, token counts, timing, status — no content) | Our usage database and the request log on the inference server | For as long as your account is active, and afterward as long as we need them for billing, security, legal, or dispute purposes |
| Per-organization monitoring totals | Our monitoring system | 30 days |
| Server logs (no content) | Our own servers | A short, size-limited period, then overwritten |
| Account, organization, and billing information | Our database and Stripe | For as long as your account is active, and afterward as long as we need it for billing, tax, security, legal, or dispute purposes |
| Activity records | Our database | For as long as your organization exists, and afterward as long as we need them for security and legal purposes |
| Records of your acceptance of these documents | Our database | Kept after your account is deleted, as evidence of the agreement |
| Waitlist entries (email, optional intended use, when you joined) | Cloudflare D1 | Until we invite you or you ask to be removed |
Sign-in links, signup links, invitations, and sessions expire: sign-in links after 10 minutes, signup links after 24 hours, invitations after 7 days, and sessions after 12 hours (or 2 hours without activity). An expired link or session cannot be used, although the expired record may remain in our database until it is cleaned up.
Your choices and rights
- Access and correction. You can see your account details in the console. To correct information you cannot edit there, contact us.
- Deletion. To delete your account or your organization, email privacy@moorhaven.ai. Within 30 days we will delete or de-identify your personal information, except records we must keep for billing, security, or legal reasons. We may need to verify your identity first.
- Chat history is in your browser; closing the tab normally clears it.
- Connectors can be removed at any time from the Connectors page.
- Waitlist. To be removed from the waitlist, email privacy@moorhaven.ai and we will delete your entry.
- Email. We send only emails needed to operate the Service and, if you join the waitlist, your invitation. We do not send marketing email.
Depending on where you live, you may have additional rights, such as the right to know what personal information we have about you, to receive a copy of it, or to have it deleted. You can exercise them by emailing privacy@moorhaven.ai. We will not discriminate against you for exercising them.
California residents: we do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics about you.
Sensitive and regulated data
The Service is not designed to receive health information (including health information protected by HIPAA), privileged or confidential legal information, financial account or payment card numbers, government identification numbers, or other data that requires special legal protection, unless your organization has signed a separate written agreement with us that covers it. Please do not submit such data otherwise. See our Terms of Service (https://moor-haven.com/terms).
Names and labels are stored even though content is not, so do not put personal or regulated information in organization names, API key labels, connector names, or messages to support.
Security
We use safeguards designed to protect your information, including encryption in transit, one-way hashing of API keys and sign-in tokens, encryption at rest for connector tokens, and access controls on our systems. No system is perfectly secure. If a security incident affects your personal information, we will notify you as the law requires.
Children
The Service and the waitlist are for people 18 and older. We do not knowingly collect information from children. If you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy
If we make a material change, we will tell you by email or in the console at least 30 days before it takes effect. The effective date at the top shows when this policy last changed. We will not use content we have already received in a materially different way without your consent.
Contact
Chatham Oaks Growth Solutions
PO Box 31, 802 Main St
Chatham, MA 02633
Privacy questions and requests: privacy@moorhaven.ai
Everything else: support@moorhaven.ai
Website: https://moor-haven.com