LuluLabs Inc. (“LuluLabs,” “we,” or “us”) respects the privacy of people who use MOA (the “Service”). This policy explains what information the Service processes, why it is processed, and how you can manage it.
1. Core principles
- Links, images, notes, and organized results are saved on your device first.
- If you enable cloud sync, data syncs to the private iCloud database for your Apple Account. On the upcoming Android version, data syncs to MOA's private app storage in your own Google Drive. LuluLabs does not access either storage location.
- When you run AI organization, required content is sent to our processing service and AI provider. LuluLabs does not retain source scrap content in its database after processing.
- When you ask the AI chat a question, that question and short excerpts of the scraps needed to answer are sent to our processing service and AI provider only at the moment the reply is generated. Conversations are not stored on our servers - they stay on your device (and your own iCloud if you enable sync).
- We do not display advertising, sell user data, or use advertising identifiers or behavioral-tracking SDKs.
2. Information we process
Information stored on your device or in your selected personal cloud
- Saved link addresses and text retrieved from those links
- Images and screenshots you select
- Notes you enter
- AI-generated or user-edited titles, summaries, full text, and classifications
- App settings, backups, and sync status
Information processed temporarily for AI organization
- Link addresses and public text or metadata retrieved from those links
- Processing copies of selected images and text extracted on your device
- Notes you include with an AI organization request
Information used for subscriptions and abuse prevention
- Product, receipt, subscription status, and anonymous app user identifier provided by Apple App Store and RevenueCat
- A one-way hashed IP value, date, and request count used to enforce AI request limits. The original IP address is not stored in the application database.
- A one-way hashed app-user identifier, usage month, link and image organization counts, and a request hash and processing time used to prevent duplicate claims. Original app-user and request identifiers are not stored.
- A one-way hashed random install identifier and minimal product events used to check app quality (app opened, first save, third save, first detail view, search attempted and succeeded, and the number of trimmed pending shares), plus platform, language, and record date. Link addresses, titles, body text, memos, search queries, images, and the original install identifier are not collected.
- Request type (link or image), image count, model name, token counts, and processing time used to measure AI processing cost. These records contain no identifiers and no scrap content.
3. How we use information
- Generate titles, summaries, and classifications for links and images
- Provide scrap storage, search, editing, backup, and selected personal cloud sync
- Verify free usage limits and Premium subscription status
- Prevent abnormal high-volume requests and maintain service reliability
- Check whether the first save and search flows work, and improve app quality
- Measure AI processing cost and plan service operations
- Respond to support requests
4. Storage location and retention
- On-device storage: Data remains on your device until you delete it in the app or delete the app data.
- iCloud: If sync is enabled, data remains in your private iCloud. You can delete that copy with “Delete iCloud Data” in the app.
- AI processing content: Our relay function does not store source scrap content in the LuluLabs database after processing. OpenAI API inputs and outputs are not used for model training by default. OpenAI may retain abuse-monitoring records for up to 30 days under its policies.
- IP rate-limit records: Hashed IP values, dates, and counts may be retained for up to 30 days for abuse prevention and are then deleted.
- Free-usage records: The hashed app-user identifier and monthly link and image organization counts are retained only for the current month and the previous two months. Duplicate-request hashes and processing times are retained for 35 days. Expired records are deleted automatically each day.
- App quality records: The hashed random install identifier and minimal product events are kept for 90 days, after which the server deletes them automatically each day.
- AI cost records: Token usage records, which identify no one, are kept for 180 days and then deleted.
- Subscription records: Apple and RevenueCat process these records for the period needed to provide subscriptions and meet legal obligations.
5. Processors and international transfers
We use the following processors and transfer information only as needed to perform our contract with you. Information is transmitted over encrypted networks when you choose to use AI organization, personal cloud sync, or subscription features.
| Provider and contact | Country, timing, and method | Purpose, information, and retention |
|---|---|---|
| OpenAI OpCo, LLC Privacy contact |
United States · When AI organization is requested · Encrypted network transfer | AI summarization and classification of links, images, and notes · Not stored in our database; security and abuse-monitoring records up to 30 days |
| Supabase, Inc. Privacy contact |
Seoul, Republic of Korea region (provider headquartered in the United States) · When AI organization is requested or a minimal product event occurs · Encrypted network transfer | Relay AI requests, enforce usage limits, and check app quality and cost · Source scraps are not stored; IP rate-limit records for 30 days, duplicate-request records for 35 days, monthly usage records for the current and previous two months, minimal product events for 90 days, and cost records for 180 days |
| Apple Inc. Privacy contact |
Countries determined by your Apple Account settings and Apple data location · When sync or payment is used · Encrypted network transfer | Private iCloud sync, in-app purchases, and subscription management · Retention under Apple Account settings and policies |
| RevenueCat, Inc. Privacy contact |
United States · When subscriptions are viewed, purchased, or restored · Encrypted network transfer | Anonymous app user identifier, product, receipt, and subscription status · Until no longer needed for subscriptions, contract closure, and legal obligations |
You may decline an international transfer by not using the related optional feature. If you do not want content transferred for AI organization, do not use AI organization. If you do not want personal cloud or subscription processing, do not enable sync or purchase a subscription. You can continue to view, search, and edit scraps on your device and use manual backups.
6. Third-party disclosure and automatic collection
- We do not sell personal information or disclose it to unrelated third parties, except where required by law.
- The providers listed above process information only to perform the requested service under our instructions and may not use it for their own advertising.
- The app and our website do not use personalized advertising, advertising identifiers, analytics cookies, or behavioral-tracking cookies.
7. Your choices and rights
- View, edit, and delete scraps and notes in the app.
- Turn off iCloud sync or delete MOA data stored in iCloud.
- Export or restore a manual backup from Settings.
- Change photo access in iOS Settings.
- Manage or cancel subscriptions in Apple Account subscription settings.
- Request access, correction, deletion, restriction or suspension of processing, or withdrawal of consent by email or phone.
We may verify your identity before acting on a request. We respond within the period required by applicable law. If a lawful restriction prevents us from completing a request, we explain the reason and available review process. Privacy requests are generally free of charge.
8. Children’s privacy
MOA is a general productivity app for organizing links and screenshots and is not directed to children under 14. We do not knowingly collect personal information from children under 14.
9. Deletion
We delete information without undue delay when its retention period ends or the processing purpose is complete. Electronic files are deleted using methods designed to prevent recovery. You can delete scraps and personal cloud data using the controls provided in the app.
10. Security measures
- Encrypted transmission using HTTPS
- AI API keys managed in server environments rather than embedded in the app
- Request limits based on one-way hashed values instead of stored source IP addresses
- A local-first architecture that does not store source scraps on LuluLabs servers
11. Changes to this policy
If this policy changes, we will post the effective date and a description of the change on this page or in the app. We will provide notice before applying a material change that affects user rights.
Change history
- August 27, 2026 — added how AI chat transmits and stores data (questions and scrap excerpts are sent only while generating a reply; conversations stay on your device).
- August 12, 2026 — clarified that Android personal cloud sync (Google Drive) is upcoming, and removed the event items for the discontinued resurfacing feature.
- August 11, 2026 — added minimal product events for app quality and AI cost records, including their purpose and retention periods.
- August 9, 2026 — clarified minimal usage records and their retention periods.
12. Privacy contact and requests
Privacy officer: Nae Jin Hyeon, Chief Executive Officer
Email: privacy@lululabs.ai
Phone: +82 70-8064-4177
Operator: LuluLabs Inc.
Address: F2, J801, 47 Gangnam-daero 112-gil, Gangnam-gu, Seoul 06121, Republic of Korea
Contact us to request access, correction, deletion, suspension of processing, or withdrawal of consent. We respond under applicable law.
If you are not satisfied with our response, you may also contact the Korean Privacy Portal, the Privacy Infringement Report Center, or the Personal Information Dispute Mediation Committee.