๐
Moona Fit
Privacy Policy
Last updated: March 14, 2026 ยท Effective: March 14, 2026
Moona Fit ("Moona", "we", "our", or "us") is an
AI-powered fitness and wellness coaching application delivered through Telegram. This Privacy Policy describes how we
collect, use, store, share, and protect information about you when you use our services, including our Telegram bot,
website (moona.fit), and any integrations with third-party platforms such as Meta's
Threads and Instagram.
By using Moona Fit, you agree to the practices described in this policy.
1. Information We Collect
We collect the following categories of information:
Information you provide directly:
- Telegram user ID, username, and first name (provided by Telegram upon bot interaction)
- Health and fitness data you voluntarily share: fitness goals, activity level, menstrual cycle data, health conditions, dietary preferences, weight, height, and age
- Workout logs, check-in responses, and feedback you submit within the app
- Payment information processed securely through third-party payment providers (Stripe, Lava.top, Telegram Payments) โ we do not store raw card data
- Messages you send to our bot, including voice messages (transcribed for processing)
Information collected automatically:
- Usage data: features accessed, commands used, timestamps of interactions
- Technical data: device type, browser language, screen size (for web onboarding)
- UTM and referral parameters from landing pages
- Error and performance logs for debugging
Information from third-party platforms (Meta Threads/Instagram):
- When we use the Threads API, we may access public post data (post text, engagement metrics, public profile information such as username, follower count, and public bio) to identify relevant fitness content for engagement
- We do not collect private messages, financial information, or sensitive personal data from third-party platforms
- We access only publicly available content and data explicitly authorized by Meta's platform permissions
2. How We Use Your Information
- To deliver personalized workout plans, nutrition guidance, and coaching
- To track your fitness progress and provide insights
- To send workout reminders, check-in prompts, and streak notifications via Telegram
- To process payments and manage subscription status
- To analyze product usage and improve our services
- To discover relevant fitness content on Threads for community engagement purposes, using only publicly available data via authorized API access
- To respond to your support requests
- To comply with legal obligations
We use data from the Meta Threads API solely to:
- Search for and identify publicly available posts relevant to fitness and wellness topics
- Engage with public content by posting AI-generated replies, reviewed and approved by our team before posting
- We do not use Threads API data for advertising, reselling, or any purpose beyond community engagement for Moona Fit
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and UK, we process personal data under the following legal bases:
- Contract performance โ to provide the fitness coaching service you signed up for
- Legitimate interests โ to improve our service, prevent fraud, and ensure platform security
- Consent โ for optional features such as health data processing; you may withdraw consent at any time
- Legal obligation โ where required by applicable law
4. Data Sharing and Disclosure
We do not sell your personal data. We share data only in the following circumstances:
- Service providers: We use third-party service providers including Telegram (messaging), Stripe and Lava.top (payments), Railway (hosting), Supabase/PostgreSQL (database), Redis (session storage), Airtable (CRM and content management), Apify (web automation), Anthropic Claude and Google Gemini (AI processing), and Google BigQuery (analytics). Each provider is contractually required to protect your data
- Meta Platforms: When posting replies to Threads, the reply content and our account identifier are shared with Meta as part of normal API use. We do not share your personal data with Meta
- Legal requirements: We may disclose data if required by law, court order, or to protect the rights and safety of our users
- Business transfers: In the event of a merger or acquisition, your data may be transferred to the successor entity
5. Data Retention
- Account and profile data is retained for as long as your account is active plus 12 months after deletion
- Workout and health data is retained for as long as you use the service to provide you with progress history
- Payment records are retained for 7 years as required by financial regulations
- Logs and analytics data are retained for 90 days
- Data obtained via the Threads API (public post text, engagement metrics) is retained in our CRM for no more than 90 days and is not linked to individual end users
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Portability: Request your data in a machine-readable format
- Objection: Object to certain types of processing
- Restriction: Request that we limit how we use your data
- Withdrawal of consent: Withdraw consent for optional processing at any time
To exercise any of these rights, contact us at privacy@moona.fit.
7. Data Deletion
How to delete your data:
Send the command /delete_account to our Telegram bot, or email
privacy@moona.fit with the subject "Data Deletion Request".
We will process your request within 30 days and confirm deletion via email or Telegram.
For data processed through Meta's platforms, you may also submit a deletion request through
Meta's Data Deletion Request form.
8. Cookies and Tracking
Our Telegram bot does not use cookies. Our website (moona.fit) uses:
- Essential cookies for session management on web onboarding flows
- Analytics (aggregated, non-identifying) to understand how users find and use our landing pages
We do not use advertising cookies or cross-site tracking technologies.
9. Children's Privacy
Moona Fit is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect
personal data from children. If you believe we have inadvertently collected data from a child, please
contact us immediately at privacy@moona.fit.
10. Security
We implement industry-standard security measures including encryption in transit (TLS), encrypted storage
for sensitive data, access controls, and regular security reviews. However, no system is completely secure.
We encourage you to use a strong Telegram account password and enable two-factor authentication.
11. International Data Transfers
Moona Fit operates internationally. Your data may be processed in countries outside your own, including the
European Union, United States, and others where our service providers operate. We ensure appropriate
safeguards are in place (such as Standard Contractual Clauses for EEA transfers) to protect your data
regardless of where it is processed.
12. Third-Party Platform Policies
Our use of the Meta Threads API is governed by the Meta Platform Terms and the Threads Supplemental Terms. We comply with all applicable Meta platform policies, including restrictions on data use, user privacy, and prohibited content.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a
notice in our Telegram bot or on this page. The "Last updated" date at the top of this page reflects the
most recent revision. Continued use of Moona Fit after changes take effect constitutes your acceptance of
the updated policy.
14. Contact Us
For EU/EEA residents: If you believe we have not handled your data in accordance with applicable law,
you have the right to lodge a complaint with your local supervisory authority.