Early access is opening in small groups · Join the waitlist

Moorhaven Privacy Policy

Effective date: October 11, 2026
Version: 2026-09-29

This policy explains what personal information Chatham Oaks Growth Solutions, which operates Moorhaven ("Moorhaven", "we", "us"), collects when you use the Moorhaven console at moorhaven.ai and the Moorhaven API (together, the "Service") or visit our website at moor-haven.com (the "Website"), what we do with it, and the choices you have. It is published at https://moor-haven.com/privacy.

The short version:

Information we collect

Account information

When you or your organization signs up, or when you are invited to an organization, we collect:

You can also sign in with a Google account. That sign-in is handled by our network provider, Cloudflare Access, and we receive only your email address from it. If that email address is not yet part of an organization, we do not create an account for it; you sign up to create your own organization.

Content you submit

"Content" means the prompts, messages, images, and other input you send to the Service, and the output the models return.

No review and nothing to produce. We do not run classifiers on your content, no person at Moorhaven reads it, and we keep no copy that could be reviewed later. We act on abuse using the records about requests described below and on reports we receive. Because we keep no content, we cannot produce it in response to a subpoena or other legal demand; such a demand can reach only your account, usage, and activity records.

If your content includes personal information about other people, we process it only on your behalf, to provide the Service to you. You are responsible for having the right to share it with us.

Connectors

Connectors let the model call third-party tools you choose (for example Linear or Notion) through the Model Context Protocol. When you add a connector:

When you add or remove a connector or turn one of its tools off, the activity record (see below) names that connector and tool.

Turning a connector off keeps its stored authorization so you can turn it back on. Removing a connector deletes our copy of its tokens. Neither revokes the access you granted at the third-party service; you can do that in that service's settings.

Usage and billing information

Activity records

We keep a record of account and administrative actions — for example creating or revoking an API key, inviting or removing a member, changing a plan, or adding a connector. Each entry records who acted (by email address), what they did, and when.

We also record each time you accept our Terms of Service and this Privacy Policy: your email address, your organization, which version you accepted, how (at signup, when joining by invitation, or when asked at sign-in), and when. We keep these records even after your account is deleted, as evidence of the agreement.

Waitlist

While sign-up opens in stages, you can join a waitlist on the Website. When you do, we store:

We store nothing else from the form: no IP address, no browser details, and no cookies. Cloudflare stores the entry for us in its D1 database service. To slow down automated sign-ups, Cloudflare limits how often one IP address can submit the form; it does that counting on its own network, and we do not receive or store the counts.

We use your entry only to decide when to invite you and to send you that invitation. We send it from support@moorhaven.ai, our support inbox on Google Workspace, and we delete your waitlist entry once you are invited. The invitation email stays in our mailbox, like other email we send. To be removed from the waitlist before then, email privacy@moorhaven.ai.

Joining the waitlist does not create an account; that happens only if you sign up after you are invited.

Technical information

How we use information

We use personal information to:

We do not use your content or personal information to train or improve AI models, sell it, or use it for advertising.

How we share information

We share personal information only with the following:

RecipientWhyWhat they receive
CloudflareNetwork and security: carrying traffic to our servers and handling sign-in; hosting the Website and the waitlistAll traffic to and from the Service and the Website, including content, which Cloudflare decrypts at its edge to carry it to us and run its security checks. It keeps connection and sign-in records (addresses, timestamps, the pages requested, and your email for sign-in) under its own policy. Apart from waitlist entries, which it stores for us in its D1 database, we have not enabled any Cloudflare feature that stores request or response content. It also counts waitlist submissions per IP address to limit abuse.
GoogleSign-in, when you use a Google accountHandled by Google and Cloudflare; we receive your email
Google WorkspaceOur email, including the support and privacy inboxes we answer fromYour email address and the emails we exchange
StripePayments and billingYour email, organization identifier, seat count, and usage charges
ResendSending sign-in, signup, and invitation emails, and notices to our support inboxYour email address and the email's contents
Connector services you chooseCarrying out tool calls you enableTool requests generated from your conversation
Members of your organizationCollaboration and administrationYour email, name, and role; your usage; the API keys you created; and the organization's recent activity entries, which show who acted by email address (including Moorhaven staff)

We may also disclose information:

Where your information is processed

Our servers are in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States. Cloudflare may carry traffic through its network locations in other countries, and the Website and the waitlist are hosted on Cloudflare's network, which may store them outside the United States.

How long we keep information

WhatWhereHow long
Your prompts, images, and the model's responsesMemory, while the request runsNot stored
Prompt cacheThe model server's memory, partitioned per organizationUntil later requests replace it or the model server restarts; never written to storage
Prompt fingerprints (one-way hashes)The gateway's memory, per organizationUp to 30 minutes
Console chat historyYour browserUntil you close the tab
Usage records (sizes, token counts, timing, status — no content)Our usage database and the request log on the inference serverFor as long as your account is active, and afterward as long as we need them for billing, security, legal, or dispute purposes
Per-organization monitoring totalsOur monitoring system30 days
Server logs (no content)Our own serversA short, size-limited period, then overwritten
Account, organization, and billing informationOur database and StripeFor as long as your account is active, and afterward as long as we need it for billing, tax, security, legal, or dispute purposes
Activity recordsOur databaseFor as long as your organization exists, and afterward as long as we need them for security and legal purposes
Records of your acceptance of these documentsOur databaseKept after your account is deleted, as evidence of the agreement
Waitlist entries (email, optional intended use, when you joined)Cloudflare D1Until we invite you or you ask to be removed

Sign-in links, signup links, invitations, and sessions expire: sign-in links after 10 minutes, signup links after 24 hours, invitations after 7 days, and sessions after 12 hours (or 2 hours without activity). An expired link or session cannot be used, although the expired record may remain in our database until it is cleaned up.

Your choices and rights

Depending on where you live, you may have additional rights, such as the right to know what personal information we have about you, to receive a copy of it, or to have it deleted. You can exercise them by emailing privacy@moorhaven.ai. We will not discriminate against you for exercising them.

California residents: we do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics about you.

Sensitive and regulated data

The Service is not designed to receive health information (including health information protected by HIPAA), privileged or confidential legal information, financial account or payment card numbers, government identification numbers, or other data that requires special legal protection, unless your organization has signed a separate written agreement with us that covers it. Please do not submit such data otherwise. See our Terms of Service (https://moor-haven.com/terms).

Names and labels are stored even though content is not, so do not put personal or regulated information in organization names, API key labels, connector names, or messages to support.

Security

We use safeguards designed to protect your information, including encryption in transit, one-way hashing of API keys and sign-in tokens, encryption at rest for connector tokens, and access controls on our systems. No system is perfectly secure. If a security incident affects your personal information, we will notify you as the law requires.

Children

The Service and the waitlist are for people 18 and older. We do not knowingly collect information from children. If you believe a child has given us personal information, contact us and we will delete it.

Changes to this policy

If we make a material change, we will tell you by email or in the console at least 30 days before it takes effect. The effective date at the top shows when this policy last changed. We will not use content we have already received in a materially different way without your consent.

Contact

Chatham Oaks Growth Solutions
PO Box 31, 802 Main St
Chatham, MA 02633
Privacy questions and requests: privacy@moorhaven.ai
Everything else: support@moorhaven.ai
Website: https://moor-haven.com