Privacy Policy
Moonray
Last updated: 3 August 2026
In short
Someone tells their life story to Sara, an AI companion, in their own language. We turn it into a printed book and keep the recordings of their voice.
Those stories belong to the person who told them. We encrypt them. We do not sell them, we do not advertise against them, and we do not train AI models on them. If you ask us to delete everything, we delete everything, including the audio and the photographs, and we mean it.
We keep the stories indefinitely unless you ask us to stop, because preserving them is the point of the product.
This policy explains all of that properly.
1. Two people, two roles
Moonray usually involves two people, and the law treats them differently.
The storyteller. The person who talks to Sara, usually an elderly parent. Their stories, their voice, their photographs. In data protection language they are the data subject.
The buyer. The person who pays, usually an adult child. They have an account, an email address, a payment record. They are also a data subject, of much less data.
Sometimes these are the same person, when someone makes a book of their own life.
What the buyer can see. The buyer can read every story as Sara writes it, correct names and dates, add photographs, and remove anything that should not be in the book. They can also download the voice recordings. This is how the product works: the book has to be reviewed before it is printed, and the storyteller is often not the person doing that.
What the buyer cannot see. The conversation itself is never replayed. There is no page, no export and no endpoint anywhere that returns what the storyteller actually said to Sara, message by message. What the buyer reads is the memoir being written, not a transcript.
We say both plainly because both matter. If you are the storyteller, the person who bought this book will read your stories. They will not read your conversation.
What we tell the storyteller. Before her first conversation, Sara tells her that she is an AI, that her stories are kept, that her family can see them, and that she can have everything erased whenever she wants.
2. What we collect
From the storyteller
- The messages she sends Sara, in text or voice.
- The audio of every voice note, kept as a file.
- Photographs she sends.
- Her name, and the name she goes by in her own language.
- Her Telegram user ID, which is how Sara reaches her.
- The language she speaks and the language she wants the book in.
- Timestamps: when she told each story, when she last replied.
We do not ask for her address, her date of birth, her phone number, or any identity document. We do not know her age. Sara does not ask for any of it.
From the buyer
- Email address.
- The storyteller's name and their relationship to her, as typed at checkout.
- The country the book is shipping to, and later the full delivery address.
- Payment records, held by Stripe. We never see or store your card details.
Automatically
- Server logs: which requests were made and when, kept for debugging. They do not contain story text.
- A record of every time we access customer data ourselves, described in section 6.
We do not use advertising trackers or third-party analytics on our website.
3. What we do with it
We use the stories to do the thing you asked for: have a conversation, remember what was said, assemble a book, print it, and keep the recordings.
Specifically:
- Sara's replies. Her messages, and a trimmed portion of the recent conversation, are sent to an AI model so Sara can answer.
- Transcription. Voice notes are sent to a speech recognition service and turned into text.
- Memory. Stories are turned into mathematical representations so Sara can recall related memories later. Names and identifying details are replaced with neutral tokens before this step.
- Assembly. Stories are grouped by life period, lightly corrected for grammar, and typeset into a book. The original wording is always kept, and the corrected version is generated from it, never over it.
- Translation, if an English edition is bought.
- Printing and delivery, through our print partner.
- Email, for the invitation, the receipt, and occasional service messages.
We do not use anyone's stories to train AI models, ours or anyone else's.
Anthropic and OpenAI are contractually barred from training on data sent through their APIs, and both delete it within approximately 30 days. ElevenLabs, who transcribe the voice recordings, are different, and section 5 explains that honestly rather than glossing over it.
4. Legal basis
If you are in the UK or the European Economic Area, we rely on:
- Contract. Most of what we do is necessary to deliver the book you bought.
- Consent. For the storyteller's participation. She is told what happens before she starts and can stop and erase everything at any time.
- Legitimate interests. For security, fraud prevention, and keeping the service working.
Life stories often contain sensitive information: health, religion, politics, ethnicity, family life. We do not ask for it, but people tell their lives as they lived them. Where this happens, we rely on the storyteller's explicit consent, given when she chooses to tell us.
5. Who else sees it
We use other companies to run the service. They only ever get what they need to do their part.
| Who | What they get | Where |
|---|---|---|
| Anthropic | Story text, conversation, and photographs, for Sara's replies and for assembling the book | United States |
| OpenAI | Pseudonymised text for memory, and voice audio only when our main transcription service fails | United States |
| ElevenLabs | Voice audio, for transcription | United States |
| Supabase | The database and file storage, holding everything encrypted | Singapore |
| Railway | Hosting for Sara and our servers | United States |
| Cloudflare | The website and dashboard | Global |
| Stripe | Payment. They handle card details; we never receive them | United States |
| Resend | Sending email | United States |
| Lulu | Printing and shipping the book. They receive the finished book file and a delivery address | United States and Europe |
| Telegram | The messaging app Sara uses. Messages pass through Telegram's own service under their privacy policy | Global |
Three things worth being specific about.
ElevenLabs and the voice recordings. This is the one place where our providers are not equivalent, and we would rather explain it than bury it.
Anthropic and OpenAI both delete API data within approximately 30 days and neither trains on it. ElevenLabs, who transcribe the voice notes, operate under different default terms: they may use voice data to improve their models, and may retain voice-derived data for up to three years. Their zero-retention option exists but is only available on enterprise accounts, and we are not on one. We have asked them about it.
We stay with them for a specific reason, which we tested rather than assumed. We compared them directly against the alternative on real recordings in Persian. The alternative misheard names, misheard family relationships, and turned words into different words. Those errors go into a printed book that a family keeps. We judged that a memoir with the wrong aunt's name in it is a worse outcome than the retention terms, and we chose accordingly.
If that trade is not one you want made with your parent's voice, tell us and we will delete the recordings, or not keep them at all.
Photographs. These are sent to Anthropic alongside the story text, without pseudonymisation, so Sara can see and respond to them. The pseudonymisation described in section 3 applies to memory and internal classification, not to Sara's conversation.
Because our providers are outside Malaysia and the EEA, personal data is transferred internationally. We rely on the providers' own standard contractual clauses and data processing terms for these transfers.
We do not sell personal data. We have never sold personal data. We will not sell personal data.
6. How we protect it
Encryption. Every story, message, photograph, caption and voice recording is encrypted before it is stored, with a key unique to that family. If someone stole our database, they would have unreadable ciphertext.
Audited access. When we access customer data ourselves, for support or debugging, it is written to a tamper-evident log. We can prove what we looked at and when. That log records the account, not the content.
Minimised sharing. We send our AI providers the minimum needed to make Sara work, and we trim conversation history rather than sending everything.
Encrypted transport. All connections use HTTPS.
Who has access. Moonray is currently run by one person. Only he has access to production systems.
No system is perfect and we will not claim otherwise. If a breach affects your data, we will tell you and the relevant regulator, within 72 hours where the law requires it.
7. How long we keep it
We keep stories, recordings and photographs indefinitely.
This is deliberate. The point of the product is that these things outlast the person who told them. A family who bought this for a grandmother should not lose her recorded voice because a subscription lapsed on an anniversary they were not watching.
When a subscription ends, Sara stops asking for new stories. Everything already told stays, and stays downloadable.
If you would rather we did not keep it, tell us, and we will delete it. See the next section.
Other data:
- Account and payment records are kept for as long as needed for tax and accounting, typically seven years.
- Server logs are kept for a short period for debugging.
- The audit log is permanent, including the record that a deletion happened. It stores identifiers, not names or story content.
8. Deleting everything
If you are the storyteller and you speak Persian, tell Sara you want everything erased. She will ask you to confirm twice, once by agreeing and once by typing a word she gives you. Then it is gone. You do not need anyone's permission, and nobody is asked to approve it.
If you speak English, this conversational flow is not yet available in your language. Email hi@moonray.life and we will do it. We are working on making it available in every language we support, and we would rather say this than pretend otherwise.
If you are the buyer, email hi@moonray.life. We do not give buyers a delete button, deliberately. The stories belong to the person who told them, and one person permanently erasing another adult's memoir is not something a button should do without a human looking at it. We will confirm the request and, where the storyteller is still active, make sure she knows before anything is erased.
What deletion actually does. Every story, message, photograph, caption, voice recording, generated book file and cover is deleted from our database and from our file storage. Not marked as deleted, actually removed.
What survives, and why.
- A record that a deletion happened, holding an identifier and the counts, no name and no content. This is what lets us prove deletion took place.
- The buyer's account and payment records, because they belong to a different person and are needed for accounting.
Our AI providers. When you ask us to delete, we stop sending anything immediately, and we record a formal deletion obligation for each provider with a 30-day deadline. None of them offers a self-service way to delete API records programmatically.
Anthropic and OpenAI delete API data within approximately 30 days as a matter of course, and neither trains on it. So for them, we can guarantee deletion from our systems immediately and from theirs within about 30 days.
ElevenLabs is the exception, as section 5 explains. Under their default terms voice-derived data may persist for up to three years. We record the deletion obligation and pursue it, but we will not claim a guarantee we cannot enforce.
We are seeking zero-retention agreements with all three, which would mean nothing identifiable is retained at all. When that is in place, this section will say so.
9. Your rights
Wherever you live, you can ask us to:
- See what we hold about you.
- Correct anything wrong. The book is designed to be corrected: every story can be edited before it prints.
- Delete everything, as described above.
- Export your data, in a readable format.
- Object to how we use it, or ask us to restrict it.
- Withdraw consent at any time. For the storyteller, this means telling Sara to stop.
Email hi@moonray.life. We will reply within 30 days.
If you are unhappy with our answer, you can complain to your data protection authority. In Malaysia that is the Personal Data Protection Commissioner. In the EEA or the UK, your national authority.
10. Children
Moonray is for adults telling their life stories. We do not knowingly collect data from anyone under 16. If a storyteller is under 16, tell us and we will delete everything.
11. Changes
If we change this policy in a way that matters, we will email account holders and update the date at the top. We will not quietly broaden what we do with your data.
12. Contact
hi@moonray.life
Moonray PLT (Registration No. 202304002831), T2A-18-12, 3 Towers, Jalan Ampang, 55000 Kuala Lumpur, Malaysia