Security & Privacy
Last updated June 16, 2026
Moontuck is a personalized bedtime-story service operated by MCD LLC(1890 1st Capital Drive, PO Box 192, St Charles, MO 63302). Because some of what you share with us is about your child, here’s exactly how we handle it — in plain English.
What we collect
From you, the parent:your email address (and, if you use Google sign-in, the basic profile fields Google provides), your timezone, the messages you send us, and any “what happens next” steering you submit for your child’s saga.
About your child:a first name only (never a last name), an age range (never a birthday), and one chosen world (dragons, dinosaurs, knights & castles, etc.) per child. We do not collect their gender — stories use your child’s name throughout rather than gendered pronouns. Up to 4 children per subscription, each with their own first name and chosen world.
Automatically: basic log data (IP address, browser, request timestamps) for security and troubleshooting, and a small number of essential sign-in cookies. We do notuse advertising cookies or third-party analytics. Chapter emails contain our logo image, which most email clients load when rendering the message — we don’t use that or any other tracking pixel to monitor which chapters you’ve opened or read.
What we never collect about your child
No last name. No birthday. No photos, video, or voice recordings. No school. No home address. No location data. No contacts. No device identifiers we don’t need. Just a first name, an age range, and one world they love — the minimum required to make the story theirs.
Moontuck is for grown-ups
The app and website are set up and run by a parent or guardian. Children don’t log in, type into the site, or use the service directly — they’re the audience for the stories, not the users. Every story setting and steering nudge is entered by the parent.
How stories are made — and reviewed before they ship
Each chapter is written by a large language model from a leading commercial AI provider, guided by a tightly-constrained writer prompt with safety rules baked in. Before any chapter reaches your inbox it passes through three layers:
- Automated pre-publish quality check. Each draft is scanned for banned ending patterns, stock phrases, lesson-stating dialogue, and other structural issues. Drafts that fail get rewritten automatically, up to two attempts, before the chapter is even saved.
- Human approval. Every chapter is read and approved by a real person before delivery. The chapter never reaches your inbox until that approval timestamp is set.
- Weekly quality audit. A sample of chapters from each week is scored against a 7-dimension rubric (safety, length, voice band, consistency, comedy density, ending pattern, stock-phrase density). Persistent issues trigger investigation and prompt revisions.
We send the AI only what it needs: your child’s first name, age range, the chosen world, the story’s narrative state, and any steering you submitted. We do not send your email, IP address, payment information, or any other identifying data to the AI provider.
What happens to your data at the AI provider
Our AI provider operates under a commercial-tier API agreement whose policy ensures the text we send and the chapters they generate are not used to train their models.Inputs and outputs are retained briefly for abuse-monitoring and operational purposes, then deleted on their schedule. If you’d like the name of the specific provider we use today, email support@moontuck.comand we’ll tell you.
On our end, we do not train, fine-tune, or sell your child’s information, chapter content, or any conversational data to anyone. Your steering submissions are licensed to us non-exclusively to improve the service (writer prompt tuning, rubric refinement) per Terms section 9.7 — never published or attributed to you. We may change AI providers in the future; whichever provider we use will be on the same commercial-tier non-training basis described above.
Your library and chapter emails
Each delivered chapter arrives as an email in your inbox. Those emails remain in your inbox archive as your family’s personal record of what was received — we don’t ask you to delete them.
Separately, your online libraryon moontuck.com gives you a searchable view of every chapter you’ve received. Library access is part of your subscription: it stays open while you’re a subscriber, plus a 90-day grace window after cancellation so you can come back without losing visibility. After 90 days the library closes.
The stories themselves are Moontuck’s intellectual property; your subscription is a narrow personal-use license to read them aloud at bedtime, not a license to reproduce or redistribute them. The full IP terms are in Terms section 9.
Who we share data with
We share only what’s necessary to run the service, and only with vendors bound to protect it:
- Stripe — payment processing (PCI DSS Level 1)
- Resend — chapter and account email delivery
- Supabase — database storage (encrypted at rest, RLS-enforced)
- Vercel — application hosting (HTTPS-only, auto-renewed TLS)
- A commercial AI provider — generation of the story text (commercial-tier API, non-training policy)
We do not sell your information, and we do not share it with advertisers or data brokers.
Payments
All payments are processed by Stripe. Moontuck never sees, stores, or has access to your credit card number, CVV, or billing details — Stripe handles those directly. Stripe is PCI DSS Level 1 certified, the highest level of payment security.
Technical safeguards
- HTTPS/TLS everywhere — every connection between your browser and our servers is encrypted. Certificates auto-renew.
- Stripe webhook signature verification — every billing event from Stripe is HMAC-verified before our code processes it.
- HMAC-signed tokens — magic-link sign-in tokens, admin sessions, and pause links are cryptographically signed and verified with a timing-safe compare.
- HTTP-only, Secure cookies — sign-in cookies are inaccessible to JavaScript and only sent over HTTPS.
- Rate limiting on signup, checkout, magic-link send, and account updates to prevent abuse.
- Row-Level Security (RLS) on the database — server-side service-role queries never expose the underlying key to your browser.
- Anti-enumeration on magic-link send— the response is identical whether or not the email matches an account, so attackers can’t use the endpoint to discover which emails subscribe.
- DMARC, SPF, and DKIM configured on moontuck.com to prevent spoofed email impersonating us.
What we’ll never do
- Never show your child ads.
- Never sell or rent your family’s data.
- Never feed your child’s identifying information, chapters, or steering into AI training data — by us or by anyone we work with.
- Never ask for sensitive information (a password, Social Security number, or card number) by email. A real Moontuck message will not ask for that — if one appears to, it isn’t us.
- Never let a child log in directly. Moontuck is a parent-operated service; kids are the audience for the stories, not the user of the app.
Data deletion
You can cancel your subscription anytime from your account page in two taps. To delete your account and child profiles entirely (beyond cancellation), email support@moontuck.com. We process deletion requests within 30 days. The chapter emails already delivered to your inbox remain in your personal email archive — those are yours to keep or delete as you wish.
Report a vulnerability
If you discover a security vulnerability in Moontuck, please report it responsibly to security@moontuck.com. Include the affected URL, steps to reproduce, and whether user data may be involved. We take all reports seriously and will respond within 48 hours.
Trust by design
- Minimal child data — first name, age range, chosen world
- No gender required — stories use your child’s name throughout
- Pre-publish quality check + human approval before every send
- Weekly quality audit across all generated content
- Commercial-tier AI API — your data is not used to train any models
- No ads, ever
- We don’t sell your data
- Stripe-powered payments (PCI DSS Level 1)
- Encrypted in transit (TLS) and at rest (Supabase)
- HTTPS everywhere, auto-renewed certificates
- Parent-controlled — children don’t log in or use the app
- COPPA-aware
- Cancel or delete your data anytime
- Clear privacy disclosures
This page is the plain-English summary. For the full details, read our Privacy Policy and Terms of Service.