Privacy Policy

Effective date: June 8, 2026 · Version 3 (Voice & Journal)

The short version

Mooring is an AI conversational tool, not a human. It's a wellness app for adults 18 and older. We do not use your conversations to train AI models, we do not sell your data, and we do not share individual session content with employers.

Voice sessions: audio is processed live and discarded when the session ends. We don't retain it.

Text journal entries: stored encrypted so you can come back to them. You can delete any entry, or all of your entries, at any time in Settings.

Your rights: you can access, export, correct, or delete your information at any time. Email privacy@trymooring.com for any privacy question.

Notice required by California SB 243 and New York's AI Companion Models law (General Business Law Article 47). The conversation you have with Mooring is generated by artificial intelligence, not a human. The AI may sound conversational and emotionally attuned, but it does not have feelings, awareness, or memory of previous sessions the way a person would. Mooring may not be suitable for some minors and is offered only to users 18 and older.

1. Who we are

Mooring is operated by Daniel Kernan (referred to in this policy as "Mooring," "we," "us," or "our"), an independent iOS developer based in the United States. Mooring is a voice and journal wellness app designed first for trauma-exposed workers and open to anyone who needs a place to set things down at the end of a hard day.

You can reach us at privacy@trymooring.com for any privacy question or request.

2. Scope of this policy

This policy applies to the Mooring iOS app, the trymooring.com website, and any related services we provide. It explains what information we collect, how we use it, who we share it with, how long we keep it, and what rights you have.

Mooring is intended only for users 18 years of age or older. We do not knowingly collect information from anyone under 18. Mooring is currently offered to users in the United States only. If you access Mooring from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your home country.

3. What we collect

3.1 Voice audio (during voice sessions)

When you start a voice session, your microphone audio is streamed in real time to Hume AI's Empathic Voice Interface 3 (EVI 3) to power the conversation. Voice audio is not retained past your session. It is processed live and discarded when the session ends. Audio is not stored on Mooring's servers, in iCloud, or anywhere else once the session ends. This is true whether you start the session inside the app or through CarPlay.

3.2 Session transcripts

During a voice session, a live text transcript is generated so the AI can respond meaningfully. By default, voice transcripts are ephemeral and discarded when the session ends. The only exception is if you tap "Reflect" at the end of a session to generate a post-session reflection — in that case, the transcript is briefly held to generate the reflection and is then discarded. You choose whether to save the reflection itself.

3.3 Text journal entries

When you use Mooring's text journal mode, the messages you type and Mooring's responses are stored encrypted in our database (Firebase, operated by Google Cloud) so that you can come back to your entries whenever you want. You can delete any entry, or all of your entries, at any time in Settings. Deletion is permanent and propagates through our systems within 30 days.

Mooring may send the content of your recent text entries to OpenAI as part of generating a response in a continuing journaling conversation. OpenAI does not use content submitted through its API to train its models (described in Section 5).

3.4 Post-session reflections

If you tap "Reflect" at the end of a voice or text session, your session content is sent to OpenAI's GPT model to generate a short structured reflection. Reflections are saved only if you explicitly tap "Save" after reviewing them. Saved reflections are stored encrypted and remain available to you in the app until you delete them.

3.5 Account information

To use Mooring you need an Apple ID account. From your Apple device we receive an opaque user identifier and your subscription status. We may also collect:

  • Your email address — if you provide one for product notifications or support.
  • Your first name — only if you choose to provide one during onboarding so Mooring can address you naturally. It is stored locally on your device and is included in the prompt sent to the AI during your sessions so it can greet you by name. You can change or remove your name at any time in Settings.
  • Profession context — if you self-identify during onboarding as sworn personnel, a healthcare worker, or another category, Mooring uses this to surface relevant crisis resources. Stored locally on your device.
  • Onboarding acknowledgments — including the timestamp of your SB 243 disclosure acknowledgment and your AI-conversation acknowledgment.

3.6 Subscription and payment information

All payments are processed through Apple's App Store. Mooring does not receive or store your credit card or bank account information. We use RevenueCat to manage and validate subscriptions: when you start, renew, or change a subscription, Apple notifies RevenueCat, which relays your subscription status, plan tier, renewal date, and trial status — keyed to an anonymous app account identifier — to our backend. Neither RevenueCat nor Mooring receives your payment card details.

3.7 Usage analytics

We collect aggregated, anonymized usage information to understand which features are working — for example, how often a mode is used or whether sessions complete successfully. This information is not linked to your individual identity.

3.8 Server logs

Our servers (Firebase Cloud Functions) log basic request information including IP address, timestamp, and request type for security and reliability purposes. These logs are retained for 30 days on a rolling basis and then automatically deleted.

4. How we use your information

  • To provide the conversation service. Voice audio, transcripts, and text journal content are used in real time to enable Mooring's conversation with you.
  • To generate post-session reflections when you request them. When you tap "Reflect," your session content is sent to OpenAI's GPT model (which does not train on data submitted through its API) to generate a structured reflection.
  • To store text journal entries you create, so you can return to them later. Within an active text conversation, the AI may reference your recent messages for continuity. Mooring does not analyze your entries to build a profile of you or track patterns across sessions.
  • To manage your subscription and provide customer support. Subscription status determines your access to Mooring features.
  • To send product notifications. If you sign up for launch notifications, we use your email address to inform you when Mooring launches or about material product updates. You can unsubscribe at any time.
  • To improve the product. Aggregated, anonymized usage patterns help us understand what's working. We do not link this analysis to individual users.
  • To comply with the law. If we are required to disclose information under applicable law (for example, a valid court order), we will do so only to the extent legally required and will notify you when permitted.

5. What we do NOT do

  • We do not use your conversations to train AI models. OpenAI does not train on data submitted through its API, and we have enabled Hume's training opt-out. Your voice, transcripts, text journal entries, and reflections are not used to improve any AI system.
  • We do not sell your personal information. Mooring does not sell or share personal information for cross-context behavioral advertising as defined under the CCPA.
  • We do not share individual session content with employers. If Mooring later offers employer-paid access through B2B partnerships, employers will only receive aggregate anonymized usage signals — never individual session content.
  • We do not use your conversations for advertising. Mooring does not show ads, does not integrate advertising SDKs, and does not provide your information to advertisers, ad networks, or analytics platforms used for advertising.
  • We do not retain voice audio. Audio is transient. It is discarded as soon as the session ends.

6. Third-party services

Mooring uses a small number of carefully chosen third-party services to provide the app. We have enabled the data controls our AI providers offer so your content is not used to train any AI model.

6.1 Hume AI (voice conversation)

Hume AI provides the Empathic Voice Interface 3 (EVI 3) that powers Mooring's voice conversations. Audio and the live transcript are streamed to Hume during your session and processed in real time. Mooring has enabled Hume's training and data-retention opt-outs, so your audio and transcripts are not retained by Hume after your session and are not used to train Hume's models. Hume's privacy policy: hume.ai/privacy.

6.2 OpenAI (text journal conversation and post-session reflections)

OpenAI provides the GPT models that power Mooring's text journaling conversations and generate post-session reflections in both voice and text mode. OpenAI does not use data submitted through its API to train its models. OpenAI's privacy policy: openai.com/policies/privacy-policy.

6.3 Google Cloud / Firebase (backend infrastructure)

Mooring uses Firebase Cloud Functions and Firestore (operated by Google Cloud) for backend infrastructure: minting ephemeral API tokens, storing encrypted text journal entries and saved reflections, and managing subscription state. Firebase's privacy and security details: firebase.google.com/support/privacy.

6.4 Apple (App Store, payments, and platform services)

Apple processes your subscription payments through the App Store and provides platform-level services including push notifications and CarPlay. When you use Mooring through CarPlay, the session runs the same voice pipeline as the app — your audio streams to Hume AI during the session and is discarded when it ends — and CarPlay itself does not collect any additional personal information from you. Apple's privacy policy: apple.com/legal/privacy.

6.5 RevenueCat (subscription management)

RevenueCat processes your App Store subscription events to determine your entitlement — which tier you have and whether it is active. It receives an anonymous app account identifier and your subscription and transaction status from Apple. It does not receive your payment card details or the content of your sessions. RevenueCat's privacy policy: revenuecat.com/privacy.

6.6 Netlify (marketing website)

The trymooring.com website is hosted on Netlify and is informational only — it does not collect personal information from visitors. Netlify does not have access to any of your in-app data.

7. Data retention and deletion

  • Voice audio: not retained past the session. Discarded immediately when the session ends.
  • Voice session transcripts (unsaved): ephemeral. Discarded when the session ends, or after a reflection is generated if you tapped "Reflect."
  • Text journal entries: retained encrypted in our database until you delete them or close your account. You can delete any entry, or all entries, at any time in Settings.
  • Saved reflections: retained until you delete them or close your account.
  • Account information (email, subscription status, optional name): retained while your subscription is active and for 30 days after cancellation, then permanently deleted.
  • Aggregated, anonymized usage analytics: may be retained indefinitely as they are not linked to your individual identity.
  • Server logs (including IP addresses): retained for 30 days on a rolling basis, then automatically purged.

How to delete your data

You can delete your data three ways:

  • Delete individual entries — tap and hold on any text journal entry or saved reflection to delete it.
  • Delete all your entries — in Settings → Data & Privacy → "Delete all my entries."
  • Delete your entire account — in Settings → Data & Privacy → "Delete account." This is irreversible and removes all stored content within 30 days.

You can also email privacy@trymooring.com to request deletion. We will confirm completion within 30 days.

8. Your rights under U.S. privacy laws

8.1 California residents (CCPA / CPRA)

If you are a California resident, you have the following rights with respect to your personal information:

  • Right to know what categories of personal information we collect, how we use it, and to whom we disclose it. This policy provides that information.
  • Right to access the specific pieces of personal information we hold about you. Email privacy@trymooring.com to request a copy.
  • Right to correct inaccurate personal information.
  • Right to delete your personal information. Use the deletion options in Section 7, or email us.
  • Right to data portability — receive your data in a machine-readable format. Email us to request export.
  • Right to opt out of the sale or sharing of personal information. Mooring does not sell or share personal information for cross-context behavioral advertising. There is nothing to opt out of, but we acknowledge the right.
  • Right to limit the use and disclosure of sensitive personal information. See Section 8.2 below.
  • Right to non-discrimination — we will not deny you service, charge you differently, or provide a different level of quality because you exercised your privacy rights.

8.2 Sensitive Personal Information (CCPA)

Under California law, the content of your text journal entries, voice session transcripts (when temporarily processed), saved reflections, and any health-related information you provide are considered Sensitive Personal Information. Mooring uses your Sensitive Personal Information only for the following purposes, all of which are permitted under the CCPA without requiring a separate opt-out:

  • To provide the conversational service you requested.
  • To generate the post-session reflection you requested.
  • To store text journal entries on your behalf so you can return to them.
  • To ensure security and integrity of the service.

Mooring does not use Sensitive Personal Information to infer characteristics about you, for cross-context behavioral advertising, for profiling, or for any purpose outside the four purposes listed above. If we ever wanted to use Sensitive Personal Information for additional purposes, we would request your separate opt-in consent first.

8.3 Health information and the FTC Health Breach Notification Rule

Mooring's text journal entries and voice session content may include information related to your mental health. Under the FTC's updated Health Breach Notification Rule (effective July 29, 2024), Mooring qualifies as a covered health-app provider. If Mooring experiences a breach involving unauthorized access to or disclosure of this information, we will notify affected users, the FTC, and (where required) the media within 60 days of discovery, in accordance with the rule.

8.4 Other state privacy laws

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Indiana, Tennessee, New Jersey, Minnesota, Maryland, and other states with comprehensive consumer privacy laws have rights similar to those described above for California residents. Email privacy@trymooring.com to exercise any of these rights.

9. How to exercise your rights

Email privacy@trymooring.com from the email address associated with your account. We will respond within 45 days. If we need more time, we will notify you of the extension. We may need to verify your identity before processing certain requests; for that, we may ask you to confirm specific information about your account.

If we deny your request, we will explain why. You may appeal a denial by replying to the denial email. We will respond to appeals within 60 days.

10. Security

We take reasonable technical and organizational measures to protect your information, including:

  • Encryption in transit. All communications between the Mooring iOS app, our backend, and our AI providers use TLS 1.2 or higher.
  • Encryption at rest. Text journal entries and saved reflections are stored in Firestore using Google's server-side encryption.
  • Training opt-outs. OpenAI does not train on data submitted through its API, and we have enabled Hume's training and retention opt-outs, so your content is not used to train either provider's models.
  • Ephemeral API tokens. The iOS app never holds long-lived API keys for our AI providers; tokens are minted per session by our backend.
  • Locally stored credentials use Apple's Keychain.
  • Access controls. Only the founder has administrative access to backend systems.

No system is perfectly secure. We cannot guarantee absolute security, but we work to apply industry-standard protections appropriate to the sensitivity of the information involved.

11. Children's privacy

Mooring is intended only for users 18 years of age or older. The onboarding flow includes an age gate that terminates onboarding for users under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a user under 18, we will delete that information immediately. If you believe a minor has provided us with personal information, please contact privacy@trymooring.com.

Consistent with California SB 243, we note that AI companion chatbots like Mooring may not be suitable for some minors. We do not knowingly offer Mooring to minors.

12. AI conversation: what to know

Mooring's conversations are generated by artificial intelligence, not a human. Voice mode is powered by Hume AI's Empathic Voice Interface 3. Text mode and post-session reflections are powered by OpenAI's GPT models. The AI may sound conversational and emotionally attuned, but it does not have feelings, awareness, or memory of previous sessions in the way a human would.

Mooring is not a substitute for licensed mental health care, therapy, counseling, or medical treatment. Mooring does not diagnose, treat, cure, or prevent any disease or medical condition. Mooring does not make automated decisions that significantly affect users (no benefits decisions, no risk scoring shared externally, no employment decisions).

If you are in crisis

Mooring is not a crisis service. If you are experiencing thoughts of self-harm or suicide:

  • 988 Suicide and Crisis Lifeline: call or text 988
  • Crisis Text Line: text HOME to 741741
  • Frontline Helpline (first responders): 1-866-676-7500
  • Safe Call Now (sworn personnel): 1-206-459-3020
  • Emergency: dial 911 if in immediate danger

Mooring's safety protocols include detection of statements suggesting suicidal ideation or self-harm, and the AI is designed to respond with warm acknowledgment and gentle referral to crisis resources rather than abrupt refusal. Details of these protocols are summarized in our Terms of Use.

13. Data breach notification

If Mooring experiences a security breach that compromises the confidentiality, integrity, or availability of your personal information, we will notify affected users without unreasonable delay and within the timeframes required by applicable law. For breaches involving unsecured identifiable health information, we will notify affected users, the FTC, and (where required) the media within 60 days of discovery, as required by the FTC Health Breach Notification Rule.

14. International users and data transfers

Mooring is operated from the United States and is currently offered to users in the United States only. All data is processed and stored in the United States. If you access Mooring from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your home country. Mooring is not designed to comply with the EU General Data Protection Regulation (GDPR) or the UK Data Protection Act 2018, and is not currently offered to users in the EU, UK, or EEA.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app, by email, or both, and we will update the effective date at the top of this policy. We will not retroactively reduce your privacy protections without your consent.

16. Contact us

  • Privacy questions and requests: privacy@trymooring.com
  • General contact: daniel@trymooring.com

← Back to Mooring  ·  Terms of Use  ·  Support

© 2026 Mooring. All rights reserved.