Privacy Policy
Effective date: 14 May 2026 · Last updated: 20 September 2026
This Privacy Policy explains how Muddy Toes ELC Limited, a company incorporated in New Zealand, trading as MoodSpace ("MoodSpace", "we", "us", or "our"), collects, uses, shares, and protects information when you use the MoodSpace mobile and web applications and related services (collectively, the "Service").
MoodSpace supports personal wellbeing and communication through mood check-ins, journaling, family messaging, and adult Solo accounts with chosen friend connections. Because the Service is intended for use by minors with parental involvement, we treat the information you share with us as sensitive and handle it accordingly.
By using MoodSpace, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
Contents
- Who we are
- Who can use MoodSpace
- Information we collect
- How we use information
- Legal bases (EEA/UK)
- How information is shared
- International data transfers
- Data security and encryption
- Data retention
- Your rights and choices
- Push notifications and communications
- Children's privacy
- Changes to this Policy
- Contact us
1. Who we are
Muddy Toes ELC Limited (trading as MoodSpace) is the agency responsible for your personal information under the New Zealand Privacy Act 2020, and the data controller for the purposes of the GDPR and UK GDPR where those laws apply. If you have questions about this Policy or your data, contact us at the address in Section 14.
2. Who can use MoodSpace
MoodSpace is intended for:
- Teens, used with the knowledge and involvement of a parent or legal guardian.
- Parents and legal guardians of those teens.
- Adults using Solo accounts, including optional connections with other adults.
We do not knowingly create accounts for children under the minimum age required by applicable law in your jurisdiction without verifiable parental consent (for example, under 13 in the United States, or under 16 in parts of the EEA/UK). Where required, a parent or guardian must consent to the creation and use of a teen's account.
If you believe a child has provided us with personal information without appropriate parental consent, contact us and we will delete the relevant data.
3. Information we collect
3.1 Information you provide
- Account information: email address, password (handled by our authentication provider), username, display name, role (teen or parent), and avatar.
- Profile information: birthdate (used to calculate age and tailor the experience), themes, preferences, timezone, notification settings, and check-in reminder time.
- Mood and wellbeing data: mood selections (emoji/category), intensity ratings, optional written notes, and context tags associated with check-ins. Mood categories, intensity and associated metadata are not end-to-end encrypted. Written notes use end-to-end encryption when the required keys are available; see Section 8 for limitations.
- Journal content ("Daily Reflections"): written reflections you save in your private space. Reflection text uses end-to-end encryption when the required keys are available. Word and character counts, dates and account identifiers are stored separately and are not end-to-end encrypted. See Section 8 for legacy records and key-unavailable cases.
- Messages: text messages and mood check-in shares sent within MoodSpace. Chat text uses end-to-end encryption when the conversation has the required keys. Sender and recipient identifiers, timestamps, check-in references and read status are processed separately to operate messaging and are not end-to-end encrypted. See Section 8 for legacy conversations.
- Family connections and invitations: information you provide when inviting or linking family members, such as the invitee's name, email address, phone number, age (for child invitations), invitation codes, and chosen avatar metadata.
- Support communications: information you share when you contact us for help or feedback.
3.2 Information collected automatically
- Authentication tokens and session data: stored securely on your device (using platform secure storage where available) to keep you signed in.
- Service usage data: limited operational logs needed to run the Service, including timestamps, streak and check-in counts, points and rewards activity, and similar in-app metrics.
- Safety and audit logs: where authorized administrative review occurs (for example, when reviewing a reported chat), we may log the reviewer, the time of access, the duration of the review, the reason, and the IP address used to perform that review. We do not routinely log end-user IP addresses for ordinary product features.
- Device and technical information: information necessary to operate the app on your device, such as a basic client identifier sent with API requests (e.g.
moodspace-app). - Crash and diagnostic data: if the app crashes or encounters an error, we collect diagnostic information through our error-reporting provider (Sentry), such as device model, operating system version, app version, and technical details of the error. This reporting is configured to minimize personal information and does not include the content of your messages, reflections, or mood entries.
- Subscription and entitlement data: if you purchase MoodSpace Premium or start a trial, we receive subscription status information from your app store and our subscription-management provider (RevenueCat), such as the product purchased, trial and renewal status and dates, and pseudonymous transaction identifiers. We do not receive your payment card details.
3.3 Information from third-party sign-in providers
If you sign in using Google or Apple, we receive the basic profile information those providers share with us (such as your name, email address, and a unique provider identifier) as permitted by your settings with that provider.
3.4 What we do not collect
- We do not access HealthKit, Google Fit, or other health platform data.
- We do not knowingly collect biometric identifiers.
- We do not collect or store payment card details. Payments for MoodSpace Premium are processed by your app store (Google Play or the Apple App Store); we receive only the subscription status information described in Section 3.2.
If we add such features in the future, we will update this Policy and obtain any consents required by law.
3.5 Camera, photos, and notifications
With your permission, MoodSpace may access:
- Your camera and photo library, only to let you choose or take a profile photo.
- Push notifications, only to deliver reminders, family activity, and messages you have asked to receive.
You can change or withdraw these permissions at any time in your device settings.
3.6 Optional location sharing and maps
Location sharing is optional and off until you enable it. Eligible teen and adult Solo accounts can choose supported recipients and attach a location to a check-in. We request your device location permission before capturing a position. The snapshot may include precise latitude and longitude, accuracy and the capture time; it is associated with the check-in and your selected recipients.
You can leave location out of an individual check-in, change recipients, or turn sharing off in MoodSpace. You can also withdraw location permission in device settings. Turning device permission off prevents new captures but does not by itself delete locations already shared. A recipient may request a fresh location where the feature is available, but a request does not capture or send your location automatically: you choose whether to respond.
MoodSpace does not continuously track your movements or capture location in the background. A shared pin is a snapshot, not a live position. When you open the map, the app may also request your own position to display a reference marker; that action does not share it with your connections.
Location snapshots are encrypted on the device before being stored or delivered through MoodSpace. Recipients decrypt them on their devices. Our servers store encrypted payloads and operational metadata such as sender and recipient identifiers, check-in or request identifiers, and delivery timestamps. End-to-end encryption does not conceal that metadata.
Maps use Apple Maps on iOS, Google Maps on Android, and OpenStreetMap map tiles on the web. When maps load, the relevant provider may receive technical information such as your IP address and requests identifying the map area viewed. The Google Maps SDK also collects device and SDK metadata, an SDK-specific identifier, IP addresses and crash diagnostics, and may collect map interactions such as panning and zooming, to operate and improve its services. This map-service processing is separate from encrypted delivery of your shared location and is subject to the provider's privacy policy.
4. How we use information
We use the information we collect to:
- Provide, operate, and maintain the Service, including mood check-ins, journaling, messaging, family linking, points/streaks, and notifications.
- Authenticate you, secure your account, and prevent abuse, fraud, and unauthorized access.
- Personalize your experience (for example, themes, reminders, age-appropriate content).
- Enable family features, including sharing mood check-ins, reflections, and messages with linked family members in accordance with permissions you (or, for younger teens, a parent) have configured.
- Send transactional messages, such as invitation emails, password resets, and important service notices.
- Respond to your support requests and feedback.
- Detect, investigate, and respond to safety, security, or policy issues, including reviewing reported content where permitted.
- Comply with legal obligations and enforce our terms.
We do not sell your personal information, and we do not use your mood data, journal content, messages, or shared locations for advertising.
5. Legal bases for processing (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract: to provide the Service you've signed up for.
- Consent: for optional features such as location sharing, push notifications, camera, and (for younger teens) parental consent for account use.
- Legitimate interests: to keep the Service secure, prevent abuse, and improve reliability, balanced against your rights.
- Legal obligation: where we must process information to comply with applicable law.
You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
6. How information is shared
We share information only as described below:
Chosen recipients can receive the check-ins, messages and optional locations you share through family or Solo friend connections. Being connected does not automatically grant location access: location sharing has separate recipient controls. We use location data to provide these requested sharing and map features, not for advertising.
- Within your family on MoodSpace. Mood check-ins, reflections, and messages may be visible to linked parents or family members based on the permissions configured for the account (for example,
parent_can_view_reflections). You and, where applicable, the responsible parent can review and adjust these settings. - Service providers ("processors"). We rely on a small number of vendors to operate the Service. They process information only on our instructions and under appropriate contractual safeguards:
- Supabase — authentication, database, real-time, storage, and edge functions hosting.
- Apple and Google — optional sign-in providers, app distribution, and (where enabled) push notification delivery.
- Resend — sending transactional emails such as invitations.
- Expo (EAS) — building and delivering app updates.
- RevenueCat — subscription management and entitlement status for MoodSpace Premium.
- Sentry — crash and error reporting.
- Legal and safety. We may disclose information if we believe in good faith that it is necessary to comply with law, legal process, or enforceable government request; to protect the rights, property, or safety of users (including minors), MoodSpace, or the public; or to investigate violations of our terms.
- Business transfers. If MoodSpace is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to the protections of this Policy.
We do not share your information with advertisers or data brokers.
7. International data transfers
Your information may be processed in countries other than the one you live in, including in the United States and other regions where our service providers operate. Where required, we use appropriate safeguards (such as the European Commission's Standard Contractual Clauses) to protect international transfers. For New Zealand users, we take reasonable steps to ensure that information disclosed overseas is subject to safeguards comparable to those in the Privacy Act 2020, consistent with Information Privacy Principle 12.
8. Data security and encryption
We take the security of your information seriously, particularly given the sensitive nature of mood, journal, and family communications.
- All connections between the MoodSpace app and our servers are protected with TLS (HTTPS) encryption in transit.
- Authentication tokens are stored using your device's secure storage (such as iOS Keychain / Android Keystore) where available.
- Access to data is restricted using row-level security policies, JWT-based authentication, and least-privilege controls on the backend.
- End-to-end encryption and its limits. MoodSpace supports end-to-end encryption for chat text, daily reflection text and written check-in notes. Encrypted content is encrypted and decrypted on user devices; our servers cannot read that encrypted content. This is not a guarantee that every stored record is end-to-end encrypted: older plaintext records may remain, legacy conversations without the required keys can use plaintext, and reflections or notes may be stored without end-to-end encryption when their required keys are unavailable. Such records remain subject to our access controls and infrastructure encryption. Shared location snapshots require encryption and are not sent through a plaintext fallback. Account information, mood categories, intensity, reflection counts and operational metadata are not covered by content encryption.
- Recovery and reports. If you lose access to your keys, recovery depends on the recovery options available and previously set up for your account, such as a recovery code or an eligible linked person. We cannot guarantee recovery without the necessary keys or recovery material. If a user reports content to us, a readable copy of the reported content may be included with the report so that we can review it.
- Other personal data is encrypted at rest on our infrastructure in accordance with industry-standard cryptographic practices.
No security measure is perfect. If we become aware of a security incident affecting your information, we will notify you and the appropriate authorities as required by law.
9. Data retention
We keep your personal information only for as long as is necessary to provide the Service and for the purposes described in this Policy.
Shared check-in locations can remain available as part of check-in history; they do not all expire after 24 hours. Fresh locations shared in response to a request are shown on the map for up to 24 hours after the response. Expiry from the map is not a promise of immediate deletion from storage or backups. Turning sharing off or removing a recipient withdraws their access through the location feature. This cannot erase a screenshot or other copy a recipient has already kept. The account and content retention rules below also apply to encrypted location records and associated metadata.
- Active accounts: information is retained while your account is active.
- Deleted or inactive accounts: when an account is deleted (by you, a parent, or due to prolonged inactivity), associated personal data is removed or anonymized within a reasonable period, subject to backups and to limited records we are required to keep for legal, security, or audit purposes (for example, abuse investigation logs).
- Soft-deleted records: some content is initially marked as deleted before permanent removal, so that accidental deletions can be recovered for a limited time.
10. Your rights and choices
Depending on where you live (including under the New Zealand Privacy Act 2020, the GDPR/UK GDPR, and similar laws), you may have the following rights regarding your personal information:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your account and associated personal information.
- Export a copy of your data in a portable format.
- Restrict or object to certain processing.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority — in New Zealand, the Office of the Privacy Commissioner (privacy.org.nz).
For teen accounts, a parent or legal guardian may exercise these rights on the teen's behalf where appropriate.
To exercise any of these rights, contact us at the address in Section 14. We will respond within the timeframes required by applicable law. You can also manage many settings directly in the app (profile information, family links, notification preferences, and visibility settings).
11. Push notifications and communications
If you enable push notifications, MoodSpace may send you check-in reminders, family activity alerts, and other in-app updates. You can disable notifications at any time from your device settings or from the in-app notification preferences.
We may send you transactional emails (such as account verification, password reset, and invitations) that are necessary to operate your account. We do not send marketing emails without your consent.
12. Children's privacy
MoodSpace is designed with minors in mind and includes parent-managed features. We:
- Require parental involvement for younger teen accounts in line with applicable law.
- Do not knowingly collect more personal information from children than is necessary to provide the Service.
- Do not use children's data for behavioral advertising or sell it to third parties.
- Provide controls so that parents and teens can manage what is shared and with whom within their family.
If you are a parent or guardian and believe your child has provided personal information to MoodSpace without your consent, please contact us so we can review and, where appropriate, delete that information.
13. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you through the app, by email, or by other appropriate means, and update the "Last updated" date at the top of this Policy. Your continued use of the Service after the changes take effect means you accept the updated Policy.
14. Contact us
If you have questions, concerns, or requests about this Policy or your personal information, contact:
Muddy Toes ELC Limited (trading as MoodSpace) — Privacy Team
New Zealand
Email: privacy@getmoodspace.app
We will do our best to respond promptly and resolve any concerns you have.