Moziflow
HomePricingFAQ
EnglishFrançaisDeutschItalianoPortuguêsРусскийEspañolहिन्दीالعربيةBahasa IndonesiaTiếng Việtไทย한국어日本語繁體中文简体中文
Download

Legal

Moziflow Privacy Policy

Version 1.0 · Effective September 9, 2026 · Last updated September 9, 2026

Moziflow respects your privacy. This Policy explains how Moziflow handles information when you visit the Moziflow website, create or use a Moziflow account, purchase or manage a subscription, request a refund, download or update the desktop software, use its features, or contact support.

The Moziflow desktop software is built around a local workspace. Your manuscript, characters, worldbuilding, and creative archive are stored on your device by default. During normal use, your model API keys are not automatically uploaded to Moziflow servers, and Moziflow does not upload your work to Moziflow for model training. When you use AI features, test a model connection, or retrieve model information, the desktop software sends your API key to the model service address you choose, as required by that service for authentication. The instructions, manuscript excerpts, and creative context needed to complete an AI request are also sent directly to that address. If you voluntarily send support material to Moziflow, Moziflow may receive the information contained in that material.

This version describes account, authentication, subscription, payment, refund, public website analytics, and software-update services and the providers that support them.

1. Scope

This Policy applies to:

  • the official Moziflow website and its language versions;
  • Moziflow account, authentication, and session services;
  • Moziflow subscriptions, billing, payment, and refund services;
  • Moziflow installers, downloads, and software-update services;
  • the Moziflow desktop software; and
  • support requests and diagnostic materials that you voluntarily send to Moziflow.

This Policy describes Moziflow’s handling of information, including information shared with service providers. Model providers you choose and third parties that process information for their own legal or business purposes, including payment services, also handle information under their own privacy policies.

2. Information Moziflow Handles

2.1 Website Connection and Security Information

When you visit the website or download an installer, website infrastructure may process your IP address, request time, browser or device type, requested path, referring page, downloaded file, and information associated with security events. This information is used to deliver pages and installers, maintain security, prevent abuse, and troubleshoot problems.

2.2 Local Browser Settings

The website stores the following settings in your browser:

  • the language you actively select is stored in local storage until you clear browser data or choose another language; and
  • your theme choice and page position during a language switch are stored in session storage and normally expire when the relevant browser tab or session ends.

Moziflow uses strictly necessary cookies and session information for sign-in, account access, human verification, and abuse prevention. Blocking these cookies can prevent account and payment features from working. Moziflow does not use advertising cookies, behavioral analytics cookies, or cross-site advertising tracking technologies.

2.3 Download and Update Information

When you download an installer, check for updates, or download an update, content-delivery and security infrastructure may process the requested installer or update file, operating system or architecture selection, IP address, request time, and security logs. This information is used to check release availability, deliver the requested files, protect distribution, and manage abnormal traffic.

2.4 Support Communications

When you contact Moziflow by email, we process your email address, message content, correspondence history, attachments, and other information you choose to provide. We use this information to respond, diagnose problems, maintain service security, and retain necessary communication records.

Do not include unrelated sensitive personal information, model API keys, access tokens, or other secrets in support messages.

2.5 Diagnostic Exports

Creating a diagnostic export in the desktop software only generates a local file on your device; it does not automatically transmit the file to Moziflow. Moziflow receives the export only if you separately send it through email or another support channel. A diagnostic export may contain application information, redacted runtime configuration, runtime logs, filenames, manuscript chapters, story settings, creative archive data, prompt context, or model-call records. The export process attempts to remove model API keys, access tokens, and some local paths, but it cannot guarantee detection of every sensitive detail that you placed in a manuscript, filename, or log.

Before sending a diagnostic export, inspect its files and remove anything you do not want to provide to Moziflow. Moziflow uses diagnostic material you send only to handle the associated support, security, or troubleshooting matter.

2.6 Account and Authentication Information

When you create or use a Moziflow account, Moziflow processes your account email, sign-in method and identifier, records of your acceptance of legal documents, session and device information, application version and platform, approximate country or region where available, and security records. Network and device information is also processed to secure sign-in and prevent abuse.

Verification codes and session credentials are used to authenticate sign-in, protect account access, and prevent unauthorized or repeated use of a sign-in request.

2.7 Subscription, Payment, and Refund Information

When you purchase or manage a subscription, Moziflow processes your account identifier, account email, selected plan, billing period, checkout language, order and transaction identifiers, subscription status, and paid-through date, as well as the statuses, amounts, currencies, applicable tax amounts, and dates and times of orders, payments, and refunds. We use these records to complete checkout, activate and maintain paid access, handle renewals, cancellation, and refunds, prevent duplicate processing, reconcile accounts, and resolve billing disputes.

Moziflow uses Waffo Pancake for hosted checkout and payment processing. To create checkout, we send Waffo Pancake your account identifier, account email, selected product, currency, checkout reference, language, and payment-return address. Waffo Pancake collects the payment-method, billing, and tax information required to complete your transaction and sends Moziflow the subscription, order, payment, and refund records needed to provide the service, reconcile accounts, and handle disputes, including the relevant statuses, transaction identifiers, amounts, currencies, applicable tax amounts, and dates and times. Moziflow does not receive or store full payment-card numbers or card security codes.

When you request a refund or dispute a charge, we process the account email, order or transaction ID, payment date, reason, correspondence, and supporting information you provide. Necessary transaction references and request details are shared with Waffo Pancake to verify and process the refund or resolve the dispute. Waffo Pancake also handles payment information under its own privacy policy and applicable payment, tax, and recordkeeping requirements.

2.8 Public Website Analytics

Moziflow uses Cloudflare Web Analytics on public marketing pages to understand page views and website performance. Your browser sends page-load and performance information to Cloudflare. For this purpose, Cloudflare may process page addresses, referring websites, browser and device information, connection information, and timing metrics. This analytics service is used only on public home, pricing, download, and FAQ pages, not on sign-in, account-management, or legal-document pages.

Cloudflare Web Analytics does not use analytics cookies or track individual visitors across websites. Moziflow does not send account identifiers, email addresses, manuscript content, or payment records to this analytics service. Moziflow uses aggregate statistics to understand visits to its public website and does not use those statistics to identify individual visitors.

3. Information Kept on Your Device

The following information remains on your device by default and is not automatically uploaded to Moziflow merely because you use the desktop software:

  • novel text and chapters;
  • characters, worldbuilding, plot information, writing rules, and other creative archive data;
  • local workspace files;
  • model API keys; and
  • local desktop settings and runtime records.

Information included in support messages or diagnostic exports that you actively send is an exception. Information sent to your selected model provider when you use AI features is also outside the scope of the local storage described here.

4. Third-Party Model Services

Moziflow lets you configure your own model service and API key. The desktop software sends your API key to the service address you configure, as required for authentication when making model requests, testing connections, or retrieving model information. Your configuration determines the provider and address that receive the information. If you configure a third-party proxy address, that proxy also receives the relevant information. Information sent to complete AI tasks may also include:

  • your instructions and prompts;
  • relevant manuscript excerpts;
  • characters, settings, outlines, and chapter summaries; and
  • other creative information needed to preserve context or perform generation, analysis, or revision.

Model providers may process and retain this information in different countries or regions. Their purposes, retention periods, training policies, and opt-out options are governed by your agreement with the provider and its privacy policy. Moziflow cannot access, correct, or delete this data on a provider’s behalf. Before using a model service, review its terms and privacy policy and select an account type and data settings appropriate for you.

5. Purposes and Legal Grounds

Moziflow handles information only as needed to:

  • provide the website, account, authentication, session, subscription, download, update, and support services you request;
  • process purchases, renewals, cancellation, refunds, and billing disputes and maintain accurate paid-access records;
  • remember interface settings you actively choose;
  • protect the website, downloads, and software against fraud, attacks, and abuse;
  • understand public website usage through aggregate statistics, diagnose problems, maintain compatibility, and improve stability;
  • establish, exercise, or defend legal claims; and
  • comply with applicable law.

Where applicable law requires a legal basis for processing to be identified, Moziflow relies on the following bases for the corresponding purposes:

  • Processing information necessary to provide accounts, authentication, subscriptions, checkout, updates, and related support is based on performing our contract with you or taking steps at your request before entering into a contract.
  • Processing information to secure the service, prevent fraud and abuse, troubleshoot problems, understand aggregate usage of the public website, or establish, exercise, or defend legal claims is based, where permitted by law, on the relevant legitimate interests, taking your rights and interests into account.
  • Processing information necessary to meet applicable accounting, tax, recordkeeping, or other statutory requirements is based on compliance with the relevant legal obligations.
  • Where applicable law requires consent, processing is based on your consent. You may withdraw consent as described in Section 10. Withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn.

Voluntarily submitting support material means only that you are asking us to handle the associated matter; it does not mean you consent to other uses. Moziflow does not use information supplied for support to build advertising profiles or train Moziflow models.

6. Disclosure of Information

Moziflow may disclose information:

  • to Google when you choose Google sign-in, limited to information necessary for authentication and subject to Google's terms and privacy policy;
  • to Cloudflare, limited to information necessary for website and download delivery, security protection, abuse prevention, Turnstile human verification, and the public website analytics described in Section 2.8;
  • to Resend, limited to information necessary to send transactional verification codes and account security notices;
  • to Render, limited to information necessary for account services and data hosting;
  • to Waffo Pancake, limited to information necessary for checkout, payment processing, subscription management, refunds, and billing disputes, as described in Section 2.7;
  • to other providers of installer storage and support email, to the extent necessary to provide those services;
  • to comply with applicable law, a court order, or a request from an authority with lawful jurisdiction;
  • to protect the rights, safety, and legitimate interests of Moziflow, users, or the public, or to investigate fraud, attacks, and abuse; and
  • in connection with a business transfer, restructuring, or service succession, limited to necessary information and subject to reasonable confidentiality and data-protection measures.

Moziflow does not sell personal information, share personal information for cross-context behavioral advertising, or use your manuscript to train Moziflow models.

7. Infrastructure and International Processing

The website infrastructure, account-hosting, authentication, email, and payment providers listed in Section 6 may process information needed to provide their services in countries or regions other than your own. Public website analytics and support email may also involve international processing.

Your selected model provider determines its own processing locations under its terms. The relevant requests are sent directly from your device to the model service address you configure and are not routed through Moziflow servers.

Where required by applicable law, Moziflow uses appropriate contractual, technical, or organizational measures to protect data under Moziflow’s control that is processed across borders. Data-protection rules in another country or region may differ from those where you live. You can use the contact details in Section 13 to learn about international processing arrangements involving your personal information and the safeguards that apply.

8. Retention

Moziflow retains information for the following purposes and periods:

  • local browser settings are retained by your browser for the periods described in Section 2.2;
  • account details, subscription-management records, and checkout-session records are kept while your account exists and are removed when account deletion is completed, except for necessary financial records and the statutory or dispute-related retention described below;
  • short-lived sign-in verification data expires after use or the end of its validity period and is removed through routine cleanup; related verification-email records are normally retained for up to 7 days;
  • network and expired or revoked session records are normally retained for up to 30 days; inactive device records and ordinary account security records are normally retained for up to 90 days;
  • limited records needed to investigate high-risk security events or prevent duplicate payment processing may be retained for up to 180 days;
  • routine website, download, and security logs accessible to Moziflow are normally retained for no more than 30 days;
  • support emails, refund correspondence, and diagnostic material you send are normally deleted or anonymized within 12 months after the matter closes;
  • payment and tax records held by Waffo Pancake are retained under its privacy policy and applicable recordkeeping obligations; copies held by other infrastructure and email providers are subject to the applicable service configuration, provider agreements, and legal requirements;
  • local works and desktop settings remain under your control until you delete them; and
  • model-provider retention is governed by the provider’s terms and your account settings.

We delete or anonymize information when it is no longer needed for these purposes. Routine cleanup can occur after a record expires. Records needed for an unresolved dispute, security incident, or legal obligation may be retained for the time necessary to handle that matter. These exceptions do not authorize unrelated use of the retained information.

Necessary order, payment, and refund records may be retained after account deletion for accounting checks, reconciliation, refunds, dispute handling, and compliance with applicable recordkeeping obligations. Retention periods are determined by the relevant legal requirements and the time needed to handle those matters. Once no longer needed, the records are deleted or anonymized as described in this Section. Retention is limited to necessary information such as transaction identifiers, amounts, currencies, tax amounts, statuses, and dates and times. These records are not used for advertising or unrelated profiling. Account deletion does not mean that all of these transaction records have been anonymized.

For the website analytics described in Section 2.8, Moziflow stores and updates aggregate page-view statistics. These statistics do not contain individual visit records, visitor identifiers, or IP addresses. Cloudflare handles the underlying analytics data under its own privacy policy and service retention settings.

9. Security

Moziflow uses reasonable technical and organizational measures appropriate to the product’s scale and risks to reduce unauthorized access, disclosure, alteration, and loss. These measures include minimizing server-side data, keeping secrets out of logs where practicable, encrypting data in transit, and redacting diagnostic material.

No storage or transmission method is completely secure. You should protect your device, model accounts, and API keys and maintain an independent backup of local works.

10. Your Rights and Choices

Depending on the law where you live, you may have the right to:

  • know whether Moziflow processes your personal information;
  • request access to or a copy of personal information held by Moziflow;
  • request correction of inaccurate information;
  • request deletion;
  • request restriction of processing or object to certain processing;
  • request data portability where applicable;
  • withdraw consent where processing relies on consent; and
  • complain to a competent data-protection or consumer-protection authority.

To submit a request, please see the contact details below. To protect your information, Moziflow may ask you to verify your identity through the original communication address or another reasonable method. Rights may be subject to conditions and exceptions under applicable law.

After verifying your identity, you can submit an account-deletion request through the self-service process on the account page. That process requires you to cancel any subscription that is still in effect and wait until it ends before submitting the request. Once your request is accepted, your website and desktop sessions are signed out, and a 7-day period begins during which you can withdraw the deletion request. After that period, we process the deletion of your account and associated information, subject to the limited retention described in Section 8. Account deletion does not delete, upload, or lock your local works. The conditions of the self-service process do not limit your right to submit a personal-information deletion request or other rights request directly under applicable law. You may still submit such requests using the contact details in Section 13, and we will handle each request in accordance with applicable law.

You manage local works directly on your device. For information held by a model provider, you must exercise your rights with that provider; Moziflow cannot complete the request on its behalf.

11. Children and Minors

Moziflow is not directed to children under 13 and does not knowingly collect their personal information. A person who has not reached the age to consent or contract independently where they live should use Moziflow only with the consent and supervision of a parent or legal guardian. If you believe a child provided personal information to Moziflow without appropriate authorization, please see the contact details below.

12. Changes to This Policy

Moziflow may update this Policy as the product, technology, or legal requirements change. An updated Policy will show a new version, effective date, and last-updated date. For changes that materially affect your rights or how information is used, Moziflow will provide a prominent notice on the website or in the software and obtain consent where applicable law requires it.

An update will not retroactively authorize Moziflow to use previously collected information for a purpose materially incompatible with the original disclosure.

13. Contact

Email: [email protected]

MoziflowFrom brilliant ideas to timeless stories
DownloadFAQPrivacyTerms
© 2026 Moziflow
Contact:support@moziflow.com