Privacy Policy

Effective date: 2 September 2026

Data controller

Straudo Ventures Korlátolt Felelősségű Társaság

Short name: Straudo Ventures Kft.

Registered office: 1139 Budapest, Pap Károly utca 22. B. ép. V. em. 4. ajtó, Hungary

Company registration number: 01-09-396810

Tax number: 27759484-2-41

Privacy contact: kristof.pongracz@straudo.com

This policy is written to reflect the current Moderion product. Features that are only planned, including WhatsApp support, are not described as active data processing.

1. Scope

This Privacy Policy applies to the Moderion website, web application, connected services, Moderion Agent on Telegram, feedback forms, and subscription management.

Moderion helps users reflect on life areas, set Life Goals and Monthly Goals, connect selected calendar activity to those goals, review progress, and optionally interact with the Moderion Agent.

2. Personal data we process

Account and profile

Passwords and third-party sign-in credentials are handled by the authentication provider and are not available to Moderion in readable form.

Moderion workspace content

This content may reveal personal priorities or circumstances. Users should enter only information they are comfortable storing in Moderion.

Google Calendar information

If a user chooses to connect Google Calendar, Moderion requests read-only access. Moderion cannot create, edit or delete events in the user's Google Calendar.

Moderion may access and process:

Moderion uses this information to:

To provide these functions, Moderion stores connected-account details, authorization tokens, selected-calendar settings, imported event records and the goal links, corrections and interpretations derived from them. Calendar information is retained while needed to provide the user's account history and requested features, unless the user requests deletion or deletes the account. Limited backup or archived copies may remain temporarily where necessary for security, recovery or legal compliance.

Some calendar event details and relevant Monthly Goal context may be processed by hosting, database, authentication and AI service providers acting on Moderion's behalf. AI processing is used to suggest possible links between calendar activity and Monthly Goals. Moderion does not sell Google user data, use it for advertising or credit decisions, or use it for purposes unrelated to the user-facing Moderion features described above. Moderion does not use Google user data to train general-purpose AI or machine-learning models.

A user can stop future Google Calendar access at any time by disconnecting Google Calendar in Moderion or revoking Moderion's access in their Google Account. When disconnected through Moderion, Moderion attempts to revoke Google's authorization and removes the stored connection tokens and calendar selections. Previously imported events and their goal-support history remain in Moderion so existing progress history remains understandable. The user may delete that information by deleting the Moderion account or contacting the privacy address below.

Moderion's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Moderion Agent on Telegram

When Telegram is connected, Moderion may process the Telegram chat identifier, connection and delivery status, messages sent to the Moderion bot, button responses, conversation state, confirmed activity updates and corrections.

Telegram messages are used only to provide the requested Agent interaction and related Daily Focus functionality. WhatsApp is not currently supported and Moderion does not process WhatsApp activity.

User-authorized ChatGPT connection

If you choose to connect Moderion in ChatGPT, the connection lets ChatGPT read your own Life Goals and linked Key Results, Monthly Goals and active, standalone user-confirmed activity reports. It cannot change goals or record activities. Calendar content and derived day assessments, raw Telegram conversations, Monthly Review answers and other people's goals are excluded.

Moderion stores connection identifiers, authorization status and approval/revocation information needed to enforce and manage the connection. Disconnecting in Connected services stops future Moderion reads across your ChatGPT registrations; provider authorization cleanup may require retry. It does not delete information already shared in ChatGPT.

ChatGPT is an external assistant you choose to connect, separate from AI service providers processing requests on Moderion's behalf. Information received by ChatGPT is handled under its terms and your applicable privacy settings. The statements about Moderion's service providers below do not promise ChatGPT's retention or model-training behavior. See OpenAI's Privacy Policy.

Billing information

Moderion may process Stripe customer, subscription, invoice, payment-status and billing-period identifiers required to provide and administer paid access.

Full card details are collected and handled by Stripe. Moderion does not store complete payment card numbers.

Analytics and feedback

Moderion uses two consent categories: Essential, which is always active for authentication, security, saved preferences, drafts and core product operation, and Analytics, which is optional. Analytics covers privacy-minimized product events and the automatically triggered onboarding survey. Until Analytics is chosen, the only measurement is a cookieless count of page visits: the page address is stripped of query values and identifiers before it is counted, no cookie, local value or session value is written in the browser, and no visitor is identified.

When Analytics is enabled, Moderion uses a restricted PostHog (EU) implementation. Analytics events use an internal user identifier and limited properties such as an event type, workspace mode or result category. They do not include goal text, reflections, calendar event text, Telegram messages, feedback answers, record identifiers or exact activity dates.

When a user intentionally submits a bug report, feature request or survey response, the submitted answer is processed as feedback. These forms remain available when Analytics is off, and in that case they are submitted without a persistent analytics identifier or stored analytics state in the browser.

Session replay, autocapture, heatmaps, console capture and performance capture are currently disabled.

Technical and security information

Moderion and its service providers may process IP address, browser and device information, timestamps, request metadata, error information and security logs needed to operate, protect and troubleshoot the service.

Shared Spaces

If a user deliberately shares a workspace or selected information, Moderion processes the invitation, access relationship and the content made available to the invited person. Sharing is user-controlled and read-only unless the product explicitly states otherwise.

3. Why we process data

We do not sell personal data.

4. AI-assisted processing

Moderion uses AI-assisted processing for guided goal creation, summaries, calendar-to-goal suggestions, Agent interpretation and similar product functions.

Only the information needed for the specific request is sent to the relevant AI service, such as the user's input, eligible goal context and, for calendar-to-goal suggestions, the relevant calendar event details. AI output may be inaccurate. Where a suggestion affects stored goal relationships or reported progress, Moderion provides confirmation or correction controls where supported.

Moderion does not use data submitted by people using the Moderion application, including Google Calendar data, to train general-purpose AI or machine-learning models. Service providers processing this information on Moderion's behalf are not permitted to use it for their own advertising or general-purpose model training.

Users should not enter passwords, payment card details, government identifiers, medical records or confidential information belonging to another person into AI-assisted fields or Agent messages.

5. Sensitive information

Moderion does not require medical diagnoses, medical records or other regulated records. However, voluntary goals and reflections may reveal information about health, mental wellbeing, relationships, beliefs or other sensitive areas of life.

Users control what they enter and may edit or delete workspace content through available product controls. Moderion is a reflection and goal-support product, not a medical, psychological, legal or financial service.

6. Service providers and recipients

Moderion uses service providers only where needed to operate the product. Current provider categories include:

Providers process data under their own security and privacy terms and, where applicable, data-processing agreements. Data is also shared when required by law, to protect legal rights, or as part of a corporate transaction subject to appropriate safeguards.

7. International transfers

Some providers may process data outside Hungary or the European Economic Area. Where required, Moderion relies on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism.

8. Retention

Moderion keeps account and workspace content while the account is active and for as long as needed to provide the service. After deletion, information is removed or anonymized subject to technical deletion cycles, backup handling, security needs and legal retention duties.

Billing and accounting records may be retained for the period required by applicable law. Provider-level logs and backups follow the applicable provider schedules.

Moderion should not be used as the only copy of information that must be preserved.

9. User controls

Depending on the feature and account state, users can:

Disconnecting a service stops new access through that connection but does not automatically remove information already incorporated into Moderion. Users may use the available deletion controls or contact the privacy address for help.

10. Data protection rights

Subject to applicable law, users may request:

Requests can be sent to kristof.pongracz@straudo.com. Identity verification may be required.

Users may also complain to the Hungarian National Authority for Data Protection and Freedom of Information: NAIH.

11. Security

Moderion uses access controls, authenticated connections, restricted service credentials and other organizational and technical measures intended to protect personal data. No internet service can guarantee absolute security.

Users are responsible for protecting their account, email and connected-service credentials and for notifying Moderion of suspected unauthorized access.

12. Cookies and local storage

Moderion uses two categories. Essential browser storage and technologies are always active and are needed for authentication, security, draft recovery, preferences and product operation. Analytics is optional and covers privacy-minimized PostHog product events and the automatically triggered onboarding survey. Before Analytics is chosen, page visits are counted in cookieless mode only: no analytics cookie, local analytics value or browser identifier is created, and no detailed product event is sent.

The choice is stored in the browser you make it in, so it applies to that browser only and is kept across page loads, browser restarts, signing in and signing out. It is not linked to your account or synchronized across devices.

You can change or withdraw the choice at any time through Cookie settings in the website footer or in Settings → Data & privacy. Withdrawing Analytics stops further analytics and removes the analytics identifier and analytics storage from that browser. Moderion does not use marketing or advertising cookies.

13. Children

Moderion is not intended for children under 16. We do not knowingly collect personal data from children under 16.

14. Changes to this policy

This policy may be updated when Moderion's product, providers or legal obligations change. Material changes will be communicated through the product or another appropriate channel. The effective date at the top identifies the current version.

15. Contact

Privacy questions and requests:

Straudo Ventures Kft.
1139 Budapest, Pap Károly utca 22. B. ép. V. em. 4. ajtó, Hungary
kristof.pongracz@straudo.com