Scope and who we are
This Privacy Policy explains how Workado, LLC, doing business as Moxby ("Moxby," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you use Moxby.
This Policy applies to:
- the Moxby website, account portal, support center, and public tools;
- Moxby browser extensions for Chrome, Firefox, Safari, Edge, and compatible Chromium browsers;
- the optional Moxby Desktop Bridge application;
- Moxby Chat, Mods, Missions, Projects, Marketplace, and related product features; and
- communications, support requests, and other interactions with Moxby.
This Policy does not govern a third-party model, website, connected service, or independently published Mod. Those services may process information under their own policies and agreements.
The short version
We do not sell your personal information or use your browsing activity to build advertising profiles.
Many chats, Mods, Projects, settings, and workflow records are stored on your device. Connected features still send the information needed to the services you choose.
When you use Claude, Codex, OpenRouter, Gemini, or another provider, that provider receives the content needed to answer or act and applies its own terms and privacy practices.
We use standard account, feature, reliability, and performance events. We do not use page contents, prompts, source code, email contents, or tool output as ordinary product analytics.
Information we collect
Account and subscription information
We collect information such as your name, email address, authentication identifiers, account settings, team or workspace membership, plan, trial status, entitlements, and subscription status. If you use a team account, workspace administrators may manage membership, access, and plan information.
Payment information
Payments are processed by Stripe or another disclosed payment processor. The processor collects payment details needed to complete the transaction. Moxby generally receives transaction, customer, subscription, payment status, and limited billing information rather than your complete payment card number.
Product and device information
We may collect browser and operating system type, extension or Bridge version, installation and pairing status, device or app identifiers, IP address, approximate location derived from IP address, dates and times of use, referral source, feature events, performance measurements, errors, crash information, and diagnostics you choose to share.
Browser, chat, project, and workflow content
Depending on what you ask Moxby to do, the Services may process URLs, page text, page structure, selected tabs, network and developer-tool information, screenshots, images, files, prompts, messages, model responses, tool results, Mod code and settings, Projects, Mission goals and KPIs, run history, evidence, schedules, and action recordings. Moxby processes this content when you invoke a feature that needs it, install or run a Mod, attach it to a conversation, or authorize a Mission or browser action.
Marketplace and publisher information
If you browse, install, review, publish, or sell Marketplace content, we may collect your publisher profile, listings, packages, media, categories, permissions, versions, installation and license records, reviews, questions, support and privacy links, moderation information, security scan results, and payout or transaction records where applicable.
Support and communications
We collect the information you provide in support requests, surveys, account communications, feedback, and other messages. This can include attachments and diagnostics you choose to send.
How the extension and Desktop Bridge use data
Moxby needs browser permissions to place its interface beside your work, run the Mods you select, understand pages you ask it to work with, and perform browser actions you request. The exact permissions shown by your browser vary by browser and release.
| Capability | Why Moxby uses it |
|---|---|
| Website and page access | Read the current page, add or change page features, apply URL-scoped Mods, capture user-requested context, and complete approved browser actions. |
| Scripts and styles | Install and run Moxby-authored, Marketplace, or custom Mod behavior on matching websites. These scripts provide the functionality you asked to add to the page. |
| Tabs, side panel, menus, and storage | Show Moxby, organize browser work, remember preferences, store installed Mods and local state, and restore active workflows. |
| Network, debugger, and cookie access | Inspect or reproduce website behavior when you use tools such as app learning, recording, debugging, authenticated browser actions, or site automation. This can expose sensitive session and page information, so use these capabilities only on systems you are authorized to access. |
| Native messaging | Connect the extension to the optional Desktop Bridge for provider authentication, approved file and application access, local services, computer-use actions, and durable workflows. |
| Alarms and background work | Run approved schedules, refresh product state, and maintain extension functionality. |
Some product data is stored locally through browser storage, local application files, or local databases. Local data may include installed Mods, site scopes, settings, chat history, Projects, workflow state, Mission evidence, and usage reports. Removing the extension or Bridge can remove or make local data unavailable, but it does not automatically delete your Moxby account or cloud records.
The Desktop Bridge is optional. When installed and paired, it can access local files, applications, operating-system capabilities, and supported provider authentication only as needed for the features you enable. Supported secrets and provider credentials are stored using operating-system credential storage where available.
Moxby's use and transfer of information received through browser extension permissions complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. You can review that policy in the Chrome for Developers documentation.
AI providers and connected services
When you invoke Moxby Chat, an AI-assisted Mod, a Mission, a public website tool, or another model-powered feature, Moxby may transmit the prompt and the browser, file, image, tool, or workflow context needed for that request to the model provider or connected service you selected or authorized. The information sent depends on the feature, your attachments and instructions, the active page, and the provider route you choose.
Moxby supports provider routes such as Anthropic's Claude and Claude Code, OpenAI's ChatGPT and Codex, OpenRouter, and Google Gemini. A provider may receive inputs and produce outputs directly under its own account, API, consumer, or business terms. OpenRouter may route a request to the model host you select. Provider practices concerning retention, human review, security, model training, regional processing, and deletion are controlled by that provider, not Moxby.
Do not send credentials, regulated data, or other sensitive information to a model or connected service unless you have the right to do so and have confirmed that the provider's terms, settings, and data controls meet your requirements.
How we use information
We use information to:
- provide, operate, maintain, and secure the Services;
- create and manage accounts, authentication, plans, trials, billing, entitlements, teams, and support;
- pair the extension with the Desktop Bridge and keep account state available across Moxby surfaces;
- process model requests and connected-service actions you initiate;
- install, run, update, license, moderate, and support Marketplace packages;
- measure feature adoption, reliability, usage allowances, and performance;
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms;
- debug errors, improve product functionality, and develop new features;
- send service, account, billing, security, and support communications;
- send marketing communications where permitted, with an option to unsubscribe; and
- comply with law, enforce agreements, and protect Moxby, our users, and others.
We may create aggregate or deidentified statistics for product planning, business operations, and reporting. We do not use your private prompts, page contents, source code, email contents, or tool output to train a Moxby-owned general-purpose AI model.
Moxby personnel do not routinely review your private prompts or page content. Human access is limited to cases where it is reasonably necessary to provide support you request, investigate abuse or a security issue, comply with law, or operate the service using aggregate or deidentified information where practical.
How we disclose information
We may disclose information to the following recipients:
- Service providers. Hosting, account, database, payment, customer support, email, security, diagnostics, and infrastructure providers that process information for Moxby.
- Model providers and connected services. Providers you select or authorize to process an AI request, use an integration, or complete an action.
- Marketplace publishers. Information needed to deliver, license, support, or resolve issues with a listing, subject to the listing and publisher's terms.
- Workspace administrators. Account, membership, plan, role, and product-use information available to an organization that manages your workspace.
- Professional advisers. Lawyers, auditors, insurers, and advisers under appropriate confidentiality obligations.
- Authorities and affected parties. Information reasonably necessary to comply with law, respond to valid legal process, prevent harm, investigate fraud or abuse, or protect rights and security.
- Transaction participants. Information connected with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to applicable safeguards.
- Other parties at your direction. A person or service you ask us to share with or connect to.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use the pages you visit to target third-party ads.
Current core service providers include Supabase for account, entitlement, Marketplace, and support infrastructure, and Stripe for payment and billing services. Their own privacy notices explain their independent processing: Supabase Privacy Policy and Stripe Privacy Policy.
Third-party and custom Mods
A Mod can change an existing website, add a workflow, or operate as a focused browser app. Mods may be created by Moxby, an independent Marketplace publisher, you, or another person acting for your organization. Mods can include scripts, styles, API calls, model requests, website actions, and connections to other services.
A third-party Mod may collect or transmit information under the publisher's own privacy policy and terms. Review the listing, publisher, requested permissions, plan requirements, support link, privacy link, and connected data destinations before installing or enabling it. A Moxby review, scan, badge, collection, featured placement, or Marketplace listing does not replace your own review and is not a guarantee that the Mod is error-free or suitable for your use.
Custom Mods, Missions, scripts, and workflows you or your agent create run according to the code, permissions, instructions, and services you choose. You are responsible for ensuring that you have authority to access the affected websites, accounts, systems, and data.
Cookies, local storage, and analytics
The website, portal, extension, and Bridge may use cookies, browser storage, local files, local databases, and similar technologies to keep you signed in, remember preferences, pair product surfaces, store installed packages, protect the service, process referrals, and understand product performance.
Our first-party product analytics record events such as sign-in, onboarding completion, feature activation, upgrade actions, allowance status, entitlement errors, version, and platform. These events help us operate and improve Moxby. You can limit some website storage through browser controls, but blocking essential storage can prevent authentication, pairing, preferences, or other features from working.
Browser "Do Not Track" signals are not interpreted consistently across the industry. Moxby does not sell personal information or use cross-context behavioral advertising. Where applicable law requires recognition of a browser privacy signal for an opt-out right, we will process that signal as required.
Data retention and deletion
We retain cloud account, subscription, entitlement, Marketplace, support, and product records for as long as reasonably necessary to provide the Services, maintain security, resolve disputes, enforce agreements, meet legal and accounting obligations, and support legitimate business operations.
Data stored locally remains on the applicable browser profile or computer until you delete it, clear the relevant storage, remove the associated feature, or uninstall the product. Uninstalling Moxby does not automatically delete your account, subscription, support history, Marketplace activity, or other cloud records. Deleting an account does not automatically erase content held by an independent model provider, connected service, or Marketplace publisher.
When information is no longer required, we delete it, anonymize it, or retain it only as permitted by law. Limited copies may remain in backups for a reasonable period and are protected from ordinary use until overwritten.
Security
We use reasonable technical and organizational safeguards designed to protect information against accidental or unlawful loss, misuse, alteration, disclosure, or access. These measures include transport encryption where appropriate, access controls, scoped product permissions, package validation, and operating-system credential storage for supported secrets.
No system is completely secure. You are responsible for protecting your device, browser profile, provider accounts, API keys, account credentials, local files, backups, and access to any website or system Moxby can operate. Contact us promptly if you believe your Moxby account or product installation has been compromised.
Your choices and controls
You can control Moxby data in several ways:
- disable or remove the extension;
- revoke site access or other browser permissions;
- disable or uninstall a Mod, pause a Mission, or remove a custom workflow;
- disconnect the Desktop Bridge or a model provider;
- clear extension, browser, Project, chat, or local application data using available product and device controls;
- manage your account, plan, communications, and billing settings;
- unsubscribe from marketing messages while continuing to receive required service notices; and
- request access, correction, or deletion by contacting us.
Some choices can reduce or disable product functionality. If you use Moxby through an organization, your administrator may control certain account and workspace settings.
Privacy rights
Depending on where you live, you may have rights to request access to personal information, correction, deletion, portability, restriction, or objection; to withdraw consent; to appeal a denied request; or to receive information about categories of data, sources, purposes, and recipients. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
To submit a request, email [email protected] or use our support center. We may need to verify your identity and authority before completing a request. We may deny or limit a request where permitted by law, including when information must be retained for security, fraud prevention, legal, billing, recordkeeping, or free-expression reasons.
California and other U.S. state disclosures
During the preceding 12 months, Moxby may have collected the categories described in this Policy, including identifiers, account and transaction information, internet or electronic activity, device information, approximate geolocation, professional or organizational information, user content, and inferences limited to product operation and support. We collect these categories from you, your device, your organization, service providers, and services you connect. We use and disclose them for the business purposes described above. We do not sell these categories or share them for cross-context behavioral advertising.
Moxby may process sensitive information that you choose to expose through page contents, files, credentials, precise instructions, or connected services. We use such information only to provide the requested product capability, protect the service, or comply with law. We do not use it to infer characteristics about you for advertising.
EEA, UK, and similar jurisdictions
Where applicable, our legal bases include performing our contract with you, pursuing legitimate interests such as operating and securing Moxby, complying with legal obligations, and consent where required. You may have the right to complain to your local data protection authority.
International data transfers
Moxby is based in the United States. We and our service providers may process information in the United States and other countries that may have different data protection laws than your country. Where required, we use recognized transfer mechanisms or other safeguards for international transfers. A model provider or connected service may use its own transfer mechanisms under its separate policy.
Children
Moxby is a business and productivity tool and is not directed to children under 16. We do not knowingly collect personal information from a child under 16. If you believe a child has provided personal information to Moxby, contact us so we can investigate and take appropriate action.
Changes to this Policy
We may update this Privacy Policy as Moxby, our practices, or legal requirements change. We will post the revised Policy and update the effective date. If a change materially affects how we use personal information, we will provide additional notice when appropriate. Your continued use after the effective date of an update is subject to the revised Policy.
Contact us
Questions, privacy requests, and complaints can be sent to Workado, LLC dba Moxby at [email protected] or through the Moxby support center.
For the rules governing use of Moxby, read our Terms of Service.