Updated 30 September 2026
Who operates these services
Moonwake Society is an independent studio project operated by Michal Grančai. For privacy questions and requests, email [email protected].
Where this policy applies
This policy covers moonwakesociety.com and the private Moonwake Analytics workspace. It does not replace the privacy notices of Roblox, YouTube, TikTok, Instagram, Whop, Cloudflare, or other connected services.
Information we handle
- Website and security: requests and technical details needed to serve pages, protect the site, and diagnose faults. The site itself does not offer a public account or newsletter form.
- Game analytics: instrumented gameplay events and session information from Moonwake experiences, including progression, device category, version and health signals. Reports are used to understand the game and diagnose faults.
- Connected platform accounts: if the authorized administrator connects an account, the workspace may receive account and channel identifiers, profile names, public post metadata, platform metrics and the permissions granted. Connection tokens are kept in protected server storage. The available information differs by platform and permission.
- Content workflow: source links, editorial decisions, draft metadata, media artifacts, approval records and publication receipts created in the private workspace.
- Email operations: addresses, routing configuration, and message content received through a Moonwake Worker inbox. Mail sent to a Moonwake address may be stored so the authorized administrator can read and manage it.
- Contact requests: information you choose to send to the privacy address so we can respond.
Why we use it
We use the information to operate and secure the website and private tools, analyze Moonwake games, manage connected accounts and content, receive mail, and answer requests. The lawful basis depends on the activity and relationship: legitimate interests in operating and protecting the studio, steps requested by a correspondent, and consent where a specific connection or optional processing asks for it. We will identify any further basis required for a specific integration before enabling it.
Google and other platform data
Google account authorization is used only for the functions shown when the authorized administrator connects a YouTube channel, such as reading channel information or using an approved upload capability when separately enabled. We do not sell connected account data or use it for advertising. We do not transfer it to unrelated third parties except service providers needed to run the requested function or where law requires. Revoking a platform grant stops future access; a deletion request can address information already stored locally. TikTok and Instagram access follows the permissions actually granted and each platform's availability.
Storage, recipients and retention
Moonwake's private services run on protected infrastructure. Hosting, access control, email routing and connected platform providers process the information needed for their roles; those providers may apply their own retention policies. The website server records request method, path, response status and duration without deliberately logging the visitor IP address. Our retention targets are 30 days for local website request and error logs, 90 days after receipt for Worker inbox mail, and the duration of an active connection plus 30 days after disconnect for its remaining account identity record. These three automatic deletion rules are still being implemented and are not yet live. Instrumented game events are purged after 90 days. Disconnecting a platform removes locally stored token access and cached observations, but a minimal identity record currently remains pending a verified deletion request. Worker inbox messages currently have no automatic expiry or self-service deletion. Backup retention also requires operator review; the targets above do not describe provider recovery copies or separately exported backups.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent where consent applies. Send requests to [email protected]. We may ask for enough information to verify that a request concerns your data. You may also complain to the relevant data-protection authority. See data deletion instructions for connected accounts.
Changes
We will update this page when the services or handling practices change. The update date above will show the current version.