Legal
Privacy Policy
Effective date: June 20, 2026
Moat Archive ("we," "us," or "our") operates moatarchive.com and the Moat Archive document-archive service. This Privacy Policy explains what information we collect, how we use it, and your choices.
1. Information We Collect
Demo requests. When you request a demo, we collect the contact and firm information you provide and the page where you submitted the request. We use it to respond and schedule a Moat Archive walkthrough.
Account information. When you are invited to use Moat Archive we collect your email address to create your account. Sign-in is handled via email link (magic link) — we do not store passwords.
Documents and files. When you upload files to your archive we store them in private Google Cloud Storage buckets provisioned for your organization. We also store extracted text, metadata, and key fields derived from your documents in order to provide search and AI-assisted answers.
Usage data. We record the number of pages processed and the number of AI queries made each month. This data is used for billing and service metering.
Audit trail. We log actions taken on documents (upload, review, approve, reject, access, chat) including the user, timestamp, and document identifier. This audit data is stored in Google BigQuery and is available to your organization administrators.
Log and technical data. Our servers automatically record standard request logs (IP address, browser type, pages visited, timestamps). We use these for security monitoring and diagnosing issues.
2. How We Use Your Information
- To provide, operate, and maintain the Moat Archive service
- To send you transactional emails (account invites, sign-in links, service notices)
- To respond to demo requests and schedule product walkthroughs
- To meter usage and calculate billing
- To detect and prevent fraud, abuse, and security incidents
- To comply with legal obligations
We do not use your documents or their contents to train AI models, and we do not sell your data.
3. How We Share Your Information
We do not sell or rent your personal information. We share data only in the following circumstances:
- Service providers. We use Google Cloud (storage, database, OCR, AI processing), Firebase (authentication), and Resend (transactional email) to operate the service. These providers process data on our behalf under their own privacy and security commitments.
- Your organization. Administrators in your organization can view the audit trail, manage users, and access documents you have uploaded to the shared archive.
- Legal requirements. We may disclose information if required to do so by law or in good faith belief that such action is necessary to comply with legal process or protect the rights, property, or safety of Moat Archive, our users, or the public.
4. Data Storage and Security
Your documents are stored in private Google Cloud Storage buckets in the United States. Each organization's data is isolated in its own bucket. We support customer-managed encryption keys (CMEK) so you can control encryption at rest with your own GCP KMS key.
Access to documents is controlled at the user level. Only users your administrator explicitly invites can access your organization's archive. All data is encrypted in transit (TLS) and at rest.
5. HIPAA
Moat Archive supports use cases that may involve protected health information (PHI). If your organization requires a HIPAA Business Associate Agreement (BAA), please contact us at hello@moatarchive.com before uploading any PHI.
6. Data Retention
We retain your account information and documents for as long as your organization's account is active. You can request deletion of your account and associated data at any time by contacting us. Audit trail records may be retained for a longer period where required for compliance purposes.
Demo-request data is retained until you request removal or we convert you to a full account.
7. Cookies and Local Storage
The Moat Archive application uses browser local storage and session cookies solely to maintain your authentication session. We do not use advertising cookies or third-party tracking pixels. The marketing site (moatarchive.com) uses Google Fonts, which may set a cookie; no other third-party tracking is present.
8. Your Rights and Choices
You may request access to, correction of, or deletion of personal information we hold about you at any time. To make a request, email us at hello@moatarchive.com. We will respond within 30 days.
To stop receiving demo follow-up emails, reply to any email we send you with "unsubscribe" or contact us at the address above.
9. Children's Privacy
Moat Archive is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a new effective date. For material changes, we will notify active users by email.
11. Contact
If you have questions about this Privacy Policy, please contact us:
Moat Archive
hello@moatarchive.com