Privacy Policy

Last updated: 2026-08-26

This Privacy Policy explains how Desiderata LLC ("Desiderata," "we," "us," or "our") collects, uses, and shares information when you use Moldable (the "Service").

Capitalized terms not defined in this policy have the meanings given in our Terms of Service.

Moldable is designed as a local-first application—most of your data stays on your machine. This policy describes what limited information we may collect and how we handle it.

TL;DR (friendly summary)

This section is a convenience summary. The full Privacy Policy below controls.

  • Moldable is local-first by default: your apps, data, and configurations are stored on your machine unless you choose a hosted feature.
  • A Moldable account stores basic identity, authentication, session, device, and service records needed to provide account-based features.
  • You can connect a ChatGPT account to use eligible OpenAI-powered features. You complete that sign-in with OpenAI, and Moldable uses the connection only for the features you choose.
  • Bots keep their role, instructions, selected app access, and conversations in your workspace. That information is shared with an AI provider or a connected tool only when it is needed to do the work you ask for.
  • Browser Use has its own workspace-scoped browser profile, separate from your everyday browser. Its site data and sign-ins stay on your Mac unless a website or selected AI provider receives them as part of the task.
  • Computer Use is optional and acts only after you enable it and grant the macOS permissions it needs. It can interact with apps on your Mac, so use it only for work and apps you trust.
  • Voice connects your microphone audio directly to your selected AI provider, such as OpenAI. Moldable Relay carries encrypted session control, not your voice audio.
  • Sync is currently in beta. If you enable it, the files and data covered by your Sync setup are copied to hosted systems so they can be restored and synchronized across your devices. Sync data is encrypted in transit and at rest with server-managed encryption; it is not end-to-end encrypted.
  • Sync can include apps, workspaces, conversations, settings, app data, and other folders you add. Common secrets and machine-only files are excluded where possible, but you remain responsible for what you place in synced locations.
  • We do not currently offer paid services or collect payment information. If that changes, we will update this policy and identify the payment processor before collecting billing information.
  • Moldable Artifacts is a hosted publishing feature. If you publish an Artifact, the Artifact files and metadata are stored online and served at a public, unlisted URL.
  • Our website (moldable.sh) uses Plausible Analytics (cookie-less, privacy-respecting) to understand basic website usage.
  • We don't receive your locally stored apps, code, or personal data unless you choose to transmit them through Sync, another hosted feature, a support request, or a third-party integration.
  • When you connect third-party services (AI providers, MCPs, etc.), those interactions are governed by each service's privacy policy.
  • Google API data (like Google Calendar) is stored locally on your device, not on our servers. Our use of Google data complies with Google's Limited Use requirements.
  • You can contact hello@moldable.sh to exercise privacy rights or ask questions.

1. Who We Are (Data Controller)

Desiderata LLC is the entity responsible for processing personal information described in this Privacy Policy (the "data controller" in some jurisdictions).

2. Local-First Architecture

Moldable is designed to keep your data on your machine:

  • Apps and code you create are stored locally in ~/.moldable/
  • App data (databases, files, etc.) is stored locally
  • Configurations and preferences are stored locally
  • Conversation history with the AI assistant is stored locally

We do not receive this locally stored data by default. It leaves your machine only when you choose or configure a feature that transmits it (for example, enabling Sync, pushing to GitHub, publishing an Artifact, contacting support, or connecting a third-party service).

3. Information We Collect

3.1 Information you provide

  • Contact information: If you contact us for support, we may collect your email address and the content of your communications.
  • Account information: If you create an Account, we collect your name, email address, password hash, Account identifiers, and the information needed to authenticate and administer your Account. We do not store your plaintext password.
  • ChatGPT account connection: If you choose “Sign in with ChatGPT,” OpenAI handles the sign-in flow. Moldable receives the connection information needed to provide the OpenAI features you choose and may receive the connected account's email address or identifier. We do not receive your ChatGPT password.
  • Bot and workspace data: Bot names, role descriptions, standing instructions, user-approved memories, selected app access, channel and conversation history, and related settings are stored locally in the workspace. When you ask a bot to use an AI provider, app, extension, or hosted feature, the relevant portion may be processed by that provider or feature to complete your request.
  • Connected-extension settings: When you install or enable a plugin, MCP server, skill, or other connection, Moldable may store its configuration, enabled state, permission or access settings, connection status, and local logs. Credentials you provide for a connection are intended to remain in your local secure credential store unless the connection's own sign-in flow tells you otherwise.
  • Browser Use and Computer Use data: Browser Use keeps a separate, workspace-scoped browser profile on your Mac, which can include cookies, site storage, downloads, browsing state, and site sign-ins. Computer Use may process information displayed in the apps and windows you direct it to use, and records limited local activity needed to continue or troubleshoot a task. This information is not sent to our servers by default.
  • Voice data: When you start Voice, the app sends microphone audio directly to the selected AI provider to run the conversation. Finalized transcripts and resulting conversation messages are stored locally in the relevant Moldable channel or workspace and may be included in Sync if you choose to sync that location.
  • Sync content and configuration: If you enable Sync, we collect and host Synced Content together with filenames, folder paths, workspace, app and device identifiers, versions, conflicts, storage usage, exclusions, and other information needed to back up, restore, and synchronize it.
  • Future billing information: We do not currently offer paid services. If we introduce them, we may collect the plan, billing period, storage allowance, subscription status, payment-processor customer identifiers, invoice identifiers, amounts, currency, payment status, and transaction history needed to administer the purchase. Payment-card details would be collected by the payment processor; we do not intend to store full payment-card numbers.
  • Feedback: Suggestions or feedback you voluntarily submit.
  • Published Artifact content and metadata: If you publish through Moldable Artifacts, we collect the files, title, artifact type, entrypoint, file manifest, versions, public slug, source app/workspace metadata you provide, and other metadata needed to host and serve the Artifact.
  • Publishing credentials and security data: To authenticate publishing, we may store public keys, key identifiers, labels, request timestamps, nonces, signatures, upload session data, file hashes, and audit or abuse-prevention records.

3.2 Information we may collect automatically

  • Website analytics: Our website (moldable.sh) uses Plausible Analytics to measure aggregate website usage (for example, page views and referrers). Plausible is designed to be cookie-less and to avoid collecting personal data. Learn more: https://plausible.io/data-policy.
  • Download metrics: When you download the application from GitHub or other distribution platforms, those platforms may collect basic metrics (such as download counts).
  • Artifact Service operational data: When you publish, update, unpublish, or access hosted Artifacts, we and our infrastructure providers may process technical and operational information such as IP address or derived approximate location, user agent, request path, timestamps, referrer, response status, bandwidth, rate-limit events, security events, and similar server/CDN or service records.
  • Account and Sync operational data: When you sign in, connect a device, sync, restore, or manage hosted data, we and our infrastructure providers may process IP address, user agent, request and event timestamps, session and device identifiers, token and grant identifiers, file or folder paths, object identifiers and hashes, byte counts, change types, synchronization status, errors, rate-limit events, security events, and similar service records.

3.3 Information we do NOT collect

  • The content of apps you create, unless you sync, publish, or otherwise transmit that content through the Service
  • Your code or generated code, unless you sync, publish, or otherwise transmit it through the Service
  • Your local files or databases, unless you sync, publish, or otherwise transmit them through the Service
  • Your conversation history with the AI assistant, unless you enable a hosted feature that includes it or otherwise choose to share it
  • API keys, ChatGPT passwords, browser cookies, or other credentials you configure locally, except where a hosted feature requires server-side credentials that you intentionally provide to us
  • The contents of your workspace-scoped browser profile, Computer Use activity, bot instructions or memories, or Voice audio by default

3.4 AI providers, ChatGPT sign-in, and Voice

When you use an AI feature in Moldable, the prompts, relevant conversation context, tool results, and files or content you choose to provide may be sent to the AI provider you select or connect. For example, a bot may send the instructions and context needed to perform its role; a browser or Computer Use task may provide relevant page, window, or task information; and Voice sends microphone audio directly to the selected provider. The provider may generate transcripts, responses, or other outputs.

“Sign in with ChatGPT” is an optional OpenAI authorization connection. It does not give Moldable access to your ChatGPT password, and it does not make Moldable a service operated by OpenAI. OpenAI's terms, privacy policy, plan eligibility, and usage limits govern its services and your use of the connected account.

These interactions are governed by the applicable third-party provider's policies. We recommend reviewing them, including:

A practical privacy tip: share only what the task needs. Do not include passwords, API keys, financial account numbers, or other highly sensitive information in prompts, browser tasks, Computer Use tasks, or Voice conversations unless you understand and accept the receiving provider's practices.

3.5 Connected extensions, Browser Use, and Computer Use

Plugins, MCP servers, skills, and other connections can extend what Moldable can do. They may be built by us, you, or third parties. Depending on the connection and the permissions you grant, an extension may receive prompts, tool inputs and results, files, account data, or access to a third-party service. A skill may also instruct an AI system to use tools or perform local work. We do not control an independent extension's data practices, security, availability, or content.

Connections are currently enabled at the workspace level unless the Service says otherwise. That means a connection enabled for one bot or task may be available to other permitted work in the same workspace. Use a separate workspace, disable the connection, or remove its credentials when you need a stronger separation.

Browser Use is a separate profile for a workspace, rather than your ordinary browser profile. Websites you visit can collect information under their own policies, just as they would in any browser. If you sign in to a website there, its session can remain available to later work in that workspace until you sign out, clear the profile, or remove the workspace data.

Computer Use is an optional native capability for controlling windows and apps on your Mac. It requires the macOS permissions shown to you when you turn it on. It can view the information necessary to carry out the task and can click, type, or otherwise interact with the apps you direct it to use. Treat it as you would letting a trusted helper use your computer: start with limited tasks, review requests and confirmations, and do not enable it for apps or data you would not want the task to reach.

4. How We Use Information

We use the limited information we collect to:

  • Provide and improve the Service
  • Create and administer Accounts; authenticate users and devices; maintain sessions; and prevent unauthorized access
  • Back up, synchronize, restore, meter, troubleshoot, and secure Sync data across authorized devices
  • If we introduce paid services, administer plans, process purchases, issue invoices, prevent payment fraud, handle cancellations, and maintain financial records
  • Respond to support requests
  • Run the local bot, browser, Computer Use, and Voice features you choose to use; maintain their local settings; and provide the requested conversation, task, or action
  • Authenticate and maintain a ChatGPT account connection you choose, including refreshing its authorization where permitted
  • Connect to and operate third-party extensions at your direction
  • Send important updates about the Service (if you've provided contact information)
  • Host, cache, serve, version, update, unpublish, and secure Artifacts
  • Authenticate publishing requests, prevent replay, enforce limits, troubleshoot, measure basic service usage, investigate abuse, and protect the Service and users

4.1 Legal bases where required

Where a law such as the GDPR requires a legal basis, we generally process information:

  • To perform a contract with you, including providing Accounts, Sync, Artifacts, support you request, and any future paid service you choose to purchase
  • For our legitimate interests, including securing and improving the Service, preventing fraud and abuse, troubleshooting, and understanding basic service usage, where those interests are not overridden by your rights
  • With your consent where we specifically ask for it, in which case you may withdraw consent for future processing
  • To comply with legal obligations and establish, exercise, or defend legal claims

5. How We Share Information

We may share information:

  • With service providers that help us operate the Service (for example, hosting, support tools)
  • With infrastructure providers that host, store, cache, route, secure, or deliver the Service, including Moldable Artifacts
  • Across your authorized devices when you enable Sync, so Synced Content and its current state can be restored and synchronized
  • With a future payment processor such as Stripe if you choose to buy a paid service
  • With an AI provider, website, or connected extension you choose: only the information necessary for the feature or task you request may be sent to that recipient. Their handling is governed by their own terms and privacy policies.
  • Publicly when you publish Artifacts: Artifact content and metadata may be made available to anyone with the Artifact URL and may be copied, shared, indexed, archived, or cached by third parties
  • For legal reasons if required to comply with law, or to protect rights, safety, and security
  • In connection with a business transfer such as a merger, acquisition, or sale of assets

We do not sell your personal information.

6. Third-Party Services

Moldable may integrate with third-party services. When you use these integrations, your data is subject to the third party's privacy policy:

  • AI providers: Anthropic, OpenAI, OpenRouter, or other AI services you configure
  • Infrastructure providers: Cloudflare and other providers we use for hosting, storage, databases, CDN, security, rate limiting, and related infrastructure
  • Future payment processors: Stripe or another processor identified before you purchase a paid service
  • ChatGPT/OpenAI: If you choose to sign in with ChatGPT, use OpenAI-powered models, or start Voice with OpenAI
  • Plugins, MCP servers, and skills: Connections and capabilities you choose to install or enable; some may be developed by third parties
  • Browser websites: Sites you visit through Browser Use, which receive information from that browser profile under their own policies
  • Other services: Any third-party services you choose to integrate (e.g., calendar APIs, databases)

We encourage you to review the privacy policies of any third-party services you use.

7. Moldable Accounts and Sync

7.1 Accounts and authentication

Accounts use email and password authentication. We store a password hash rather than your plaintext password. We also process session cookies, device-bound credentials, authorization grants, and security records to keep you signed in, connect authorized devices, and protect hosted features.

7.2 ChatGPT account connections

You can use local Moldable features without connecting a ChatGPT account. If you choose “Sign in with ChatGPT,” the authorization process takes place with OpenAI. Moldable uses the connection only to provide the OpenAI features you ask it to use. You can disconnect the account in Moldable's provider settings; this stops Moldable's use of the connection, though it does not delete your OpenAI account or data held by OpenAI.

7.3 What Sync stores

When you enable Sync, the Service may host apps, workspace data, conversations, settings, app data, other files or folders you add, and related metadata covered by your Sync configuration. Sync is designed to exclude certain environment files, credentials, certificates, dependencies, caches, logs, temporary files, and machine-specific state, but those rules cannot identify every sensitive file. You remain responsible for reviewing what you place in synchronized locations and avoiding secrets or regulated data unless the Service is expressly designed for them.

7.4 Encryption and access model

Sync encrypts data in transit and at rest using server-managed encryption. Sync is not end-to-end encrypted: our systems and infrastructure providers may be technically capable of processing plaintext when necessary to operate, secure, troubleshoot, restore, or comply with law. Access is limited to authorized purposes and personnel, but no storage or transmission system is completely secure.

7.5 Your choices and deletion

You can use available local features without creating an Account and can choose whether to enable Sync. These choices have different effects:

  • Turn off Sync for a location: Local files are designed to remain on that device. After any undo period shown in the Service, the current Hosted Copy for that location may be permanently removed.
  • Disconnect or sign out a device: Sync stops on that device, but local files already on it and the Hosted Copy in your Account normally remain.
  • Add an ignore or exclusion rule: Matching files normally remain local but may be removed from the current Hosted Copy. That hosted deletion may reach other connected devices.
  • Make a file or folder online-only: Where this feature is available, a verified local copy may be removed while the Hosted Copy remains.
  • Delete your Account or hosted data: You may request deletion at hello@moldable.sh or use an in-product deletion control where available.

Deletion may take time to propagate through limited history, backups, logs, security records, deletion records, and disaster-recovery systems. We may retain limited records where reasonably necessary for legal compliance, fraud prevention, dispute resolution, or security. A retained log or historical record is not a recovery service and may not be available to you.

7.6 Storage limits and incomplete uploads

If a storage or other limit prevents a file or change from being hosted, it may remain only on the device where it was created. We process storage usage, pending-item status, and error information to enforce limits and show Sync status. You should not assume that every local change has a Hosted Copy merely because Sync is enabled.

8. Future Billing and Payments

We do not currently offer paid subscriptions, storage add-ons, or other paid services and do not currently collect payment information for the Service.

If we introduce paid services, we will update this policy before collecting billing information. A payment processor such as Stripe may collect payment-card and billing details directly and provide us with limited customer, subscription, invoice, amount, currency, and payment-status information. We would use and share that information only as needed to administer the purchase, prevent fraud, provide support, maintain financial records, and comply with law. The processor's privacy policy would govern its own collection and use of payment information.

9. Moldable Artifacts

Moldable Artifacts is a hosted feature for publishing static web artifacts such as slides, HTML/CSS/JavaScript prototypes, generated media, reports, and exported static bundles.

9.1 Public unlisted URLs

Published Artifacts are served from public, unlisted URLs. Unlisted URLs reduce casual discovery, but they are not access control. Anyone with the URL may view, download, copy, share, index, archive, or cache the Artifact.

9.2 What is stored

When you publish an Artifact, we may store:

  • Artifact files and asset bytes
  • Artifact title, type, entrypoint, description, social preview metadata, source app identifiers, workspace metadata, public slug, and version information
  • File manifests, file paths, content types, sizes, hashes, upload session records, and publication status
  • Publishing key records, nonces, signatures, timestamps, rate-limit records, and security/audit logs

9.3 What not to publish

Do not publish passwords, API keys, credentials, private keys, confidential business information, regulated data, personal information, or other sensitive information unless you have the right to do so and understand that the Artifact may become public.

9.4 Unpublishing and deletion

When you unpublish an Artifact, we intend to remove it from active public hosting and delete the associated stored files from the Artifact Service. However, unpublishing may not remove copies already downloaded, shared, indexed, cached, archived, or stored by visitors, search engines, browser caches, infrastructure caches, backups, logs, or other third parties. We may retain metadata, security logs, audit records, and abuse-prevention records as reasonably necessary to operate, secure, enforce, or comply with legal obligations.

10. Google API Services

When you connect Google services (such as Google Calendar) to Moldable, we access your Google data only as described below. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

10.1 Google Calendar

When you connect your Google Calendar:

  • What we access: Calendar event data (event titles, times, locations, descriptions, attendees) from calendars you have access to.
  • How we use it: To display your calendar events within the Moldable Calendar app and enable you to create, edit, and delete events.
  • Where it's stored: Calendar data is cached locally on your device in ~/.moldable/. We do not store your calendar data on our servers.
  • How long we keep it: Cached data is refreshed each time you use the app. You can disconnect your Google account at any time to remove stored tokens and cached data.

10.2 Limited Use Disclosure

Moldable's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements:

  • We only use Google data to provide and improve the calendar features visible in Moldable.
  • We do not transfer Google data to third parties except as necessary to provide the service, for security purposes, or to comply with law.
  • We do not use Google data for advertising or to build advertising profiles.
  • Humans do not read your Google data unless you provide explicit consent, it's required for security/abuse investigation, or required by law.

11. Cookies and Tracking

The Moldable desktop application does not use advertising cookies or cross-site tracking. Our Account service uses cookies that are necessary to create and maintain authenticated sessions and protect Account-based features.

Our website (moldable.sh) uses Plausible Analytics, which is designed to operate without cookies and without tracking you across sites. Moldable Artifacts may use standard server/CDN logs, security controls, and rate-limit records to deliver and protect published Artifacts. If we materially change our analytics or tracking practices, we will update this policy.

12. Data Retention

  • Local data: Data stored on your machine is retained until you delete it.
  • Account data: Account profile and authentication records are generally retained while your Account remains active and for a reasonable period afterward where needed for security, legal compliance, dispute resolution, or backup rotation.
  • Current Sync data: Synced Content and synchronization metadata are generally retained while Sync remains enabled for that location or until you delete the hosted data or Account. Turning off Sync for a location may remove its current Hosted Copy after the undo period shown in the Service. Disconnecting or signing out a device does not normally delete the Hosted Copy.
  • Sync history: Older versions may be retained according to current technical or plan limits and may be pruned as those limits are reached. Unless a specific plan says otherwise, history is not kept for a guaranteed period and should not be treated as an independent backup.
  • Sync audit records: Hosted object-action audit records are generally configured to expire after 30 days. Other security, rate-limit, deletion, and operational records may be retained for a reasonable period based on security, fraud-prevention, troubleshooting, legal, and dispute-resolution needs.
  • Local bots, Browser Use, Computer Use, and Voice: These records remain on your device until you delete the relevant workspace, channel, browser profile, local history, or application data, subject to any Sync choices you make. A connected AI provider, website, or extension has its own retention practices.
  • ChatGPT connection data: Connection information remains until you disconnect the account or delete the relevant app data. OpenAI retains information under its own policies.
  • Deleted Sync data: Limited backups, logs, security records, deletion records, and disaster-recovery copies may remain for a reasonable period after active hosted data is removed. Their handling depends on the relevant retention system, and they are not ordinarily available through the Service.
  • Future billing data: If we introduce paid services, subscription and transaction records may be retained while the service is active and afterward as reasonably necessary for accounting, tax, fraud prevention, chargebacks, legal compliance, and dispute resolution.
  • Support communications: We retain support communications for as long as reasonably necessary to provide support and maintain records.
  • Published Artifacts: Published Artifact files and metadata are retained while the Artifact remains published, unless removed earlier by you or us.
  • Historical Artifact versions: Prior versions may remain available while the Artifact is published, depending on the feature's versioning behavior.
  • Unpublished Artifacts: After unpublishing, active hosted files are intended to be deleted, but metadata, logs, audit records, security records, and backups may be retained for a reasonable period.
  • Publishing and operational records: Publishing keys, nonces, request records, rate-limit records, service usage records, security records, and abuse-prevention records may be retained as needed to operate, secure, troubleshoot, and enforce the Service.

13. Security

We implement reasonable security measures to protect information we collect. However, no method of transmission or storage is 100% secure.

Your local data is protected by your device's security measures. We recommend:

  • Keeping your operating system and software updated
  • Using strong device passwords/encryption
  • Being thoughtful about which apps, plugins, MCP servers, and skills you install or enable
  • Using Browser Use as a separate workspace profile and signing out of sensitive sites when you are finished
  • Enabling Computer Use only when you need it, and reviewing the macOS permissions it requests
  • Reviewing what an AI provider, website, or connected extension may receive before starting a sensitive task
  • Reviewing Artifacts before publishing and avoiding publication of secrets or sensitive information

14. Your Rights and Choices

14.1 Local data

You have full control over your local data. You can:

  • View, modify, or delete any data in ~/.moldable/, including bots, conversations, local browser-profile data, Computer Use history, and Voice transcripts
  • Export your data at any time
  • Uninstall the application and delete all local data

14.2 Accounts and Sync

You may choose not to create an Account, turn Sync off, disconnect devices, change exclusions, or request deletion of your Account and hosted Sync data. Turning Sync off is designed to preserve local files but may remove the Hosted Copy; disconnecting a device normally preserves both. Contact hello@moldable.sh if an in-product control is unavailable.

14.3 Published Artifacts

You can unpublish Artifacts through the Service where that feature is available. You may also contact us at hello@moldable.sh for help with Artifact deletion or privacy requests. Unpublishing does not guarantee removal of copies already shared, cached, indexed, downloaded, archived, or stored by third parties.

14.4 Future telemetry

If we add anonymous telemetry in the future, it will be opt-in and you will be able to control it in Moldable settings.

14.5 Privacy rights

Depending on where you live, you may have rights to:

  • Access information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your information
  • Request a portable copy of certain information
  • Ask us to restrict certain processing
  • Object to certain processing
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at hello@moldable.sh.

14.6 EEA/UK residents

If you are in the European Economic Area or United Kingdom, you may have additional rights under applicable data-protection law, including the right to lodge a complaint with your local data protection authority. Providing Account, Sync, Artifact, or future paid-service information may be necessary for us to provide the feature you request; without it, the feature may not work.

14.7 California residents

If you are a California resident and the California Consumer Privacy Act (CCPA) applies to us, you may have rights to know, access, correct, or delete personal information and to receive information about how it is used and disclosed. We do not sell personal information or share it for cross-context behavioral advertising, and we do not discriminate against you for exercising applicable privacy rights.

15. International Transfers

We are based in the United States, and our service providers may process information in the United States and other countries. Those countries may have different data-protection laws than your country. Where applicable law requires a transfer mechanism, we take the steps required by that law, which may include using an adequacy decision, standard contractual clauses, or another lawful safeguard.

16. Children's Privacy

The Service is not directed to children under 18, and we do not knowingly collect personal information from children.

17. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date indicates when changes were made. We will take reasonable steps to notify you of material changes.

18. Contact

Desiderata LLC
4607 Library Road, Ste 220 PMB 630
Bethel Park, PA 15102
United States

Email: hello@moldable.sh