Your space. Clearly explained.
Your data, explained.
What Moylo needs to work, what others can see, and how to contact us.
Who is responsible?
Diego Rodriguez, trading as Rodriguez Web, Delftstraße 8, 27474 Cuxhaven, Germany, is the controller. Contact diego@rodriguez-web.de for any privacy question.
Your account and your creative space
We process your email address, account identifier and authentication information to register you and keep you signed in. With Google sign-in, Google also provides your account identifier and basic account information such as your name and profile image. You choose your Moylo handle and display name during onboarding.
We store your profile, uploaded images, post titles, descriptions, alt text, tags, comments, likes, follows and saved works to provide the features you choose to use. The time you last completed your feed lets Moylo show only new works from people you follow. A lowercase copy of your display name makes people search work.
Account and social features are provided under Article 6(1)(b) GDPR. Optional profile details are not required to use the core service. Without authentication details, we cannot create your account.
What is public, and what is private?
Your profile, bio, website and posts are public, including to visitors and search engines. Likes and comments can be read by signed-in users. Follower lists are visible to signed-in users; your following list, saved works and activity are available to you.
Story records are available to signed-in users. Uploaded images use shareable download URLs: someone who receives an image URL can view it. Do not upload confidential images. Other people may retain copies of public content.
Direct messages are available in the app only to the two conversation members. They are not end-to-end encrypted. Authorized service administration may access stored data where necessary to operate the service, handle a support request or investigate abuse. We do not publish your login email on your profile.
Hosting and service providers
Moylo uses Google Firebase for authentication, the database, file storage, server functions and web hosting. Our application database and image storage are configured in Belgium, and web hosting in the Netherlands. This does not mean that every Firebase service processes data only within the EU.
Google may process data internationally. Its Firebase terms include data-processing provisions; Google describes transfer safeguards, including standard contractual clauses and the EU–US Data Privacy Framework, in its Firebase privacy information. Technical connection data such as IP addresses and user agents are processed to deliver and protect the service.
Local storage, cookies and analytics
Firebase stores authentication state in your browser so you stay signed in. Signing out removes the active session from this browser. The installable web app caches a generic offline page; its service worker does not cache your feed or messages. Google may use its own storage during Google sign-in.
Moylo currently includes no advertising pixels or analytics SDK. We use the storage necessary for the functions you request, not an optional advertising or analytics cookie layer.
Safety, support and retention
Reports contain the reported post, your account identifier, a reason and a timestamp. We process reports and support correspondence to address the issue. Preventing abuse and maintaining service security are our legitimate interests under Article 6(1)(f) GDPR; legal obligations may require processing under Article 6(1)(c).
Account data and content remain until removed or an account-deletion request is fulfilled. You can delete your own posts and comments in the app. Stories stop appearing after 24 hours; a scheduled cleanup runs every 15 minutes, so physical deletion can happen later, especially during an outage. Replacing a story schedules its previous image for removal.
Technical logs and provider backups have separate retention periods. Firebase states that authentication information can take up to 180 days to disappear from live and backup systems after account deletion. We may retain information needed to resolve an active dispute, comply with a legal duty or establish legal claims, limited to that purpose.
Your choices and rights
You can change your profile in Settings. To request an account deletion or a copy of your data, use Help & contact. Contact us from your account email and include your handle. We may need to verify ownership before releasing or deleting data. Never send your password.
Subject to the conditions of the GDPR, you can request access, correction, erasure, restriction or portability. You can object to processing based on legitimate interests and withdraw any consent for future processing. You may complain to a supervisory authority, including the Lower Saxony data protection authority.
Moylo does not use automated decision-making with legal or similarly significant effects, or an algorithmic ranking system for your feed.
Last updated: 1 October 2026