Privacy Policy
Last updated: March 1, 2026
Introduction
MoodStead ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, store, and share information when you use the MoodStead application, website, and related services (collectively, the "Service").
We understand that the data you entrust to MoodStead is deeply personal. Mental health information deserves the highest level of protection, and we have designed our systems and policies with that principle at the forefront. By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Information We Collect
Account Data
When you create an account, we collect your email address and a password (stored in hashed form). You may optionally provide a display name. We do not require your real name, date of birth, or any other identifying information to use the Service.
Health Tracking Data
The core function of MoodStead involves recording health-related information that you voluntarily provide. This may include mood ratings, sleep logs, medication records, symptom reports, weight entries, exercise logs, journal entries, voice recordings, thought records, behavioral activation plans, safety plans, and related wellness data. All health tracking data is encrypted and stored securely.
Usage Data
We collect anonymized usage data to understand how people interact with MoodStead and to improve the Service. This includes information such as which features are used most frequently, session duration, and general interaction patterns. This data is aggregated and cannot be used to identify individual users.
Device Information
We may collect basic device information including device type, operating system version, and app version. This information is used solely for providing technical support, ensuring compatibility, and improving the Service.
How We Use Your Information
Providing the Service
Your health tracking data is used to power the features of MoodStead, including displaying your mood trends, generating insights and reports, and making your data available across your devices. We process this data solely to provide you with the Service you have requested.
Improving the Service
Anonymized, aggregated usage data helps us understand which features are most valuable and where we can improve the user experience. We do not use individual health data for product development or research purposes.
Communication
We may use your email address to send you important service-related notices, such as security alerts, account notifications, and changes to our terms or policies. You may also opt in to receive product updates and tips, which you can unsubscribe from at any time.
Analytics
We use privacy-focused analytics to understand overall usage patterns. These analytics do not track individual users and do not access any health data. We do not use analytics for advertising, profiling, or any purpose beyond improving MoodStead.
Data Storage & Security
We take the security of your data extremely seriously. The following measures are in place to protect your information:
- Encryption at rest: All health data stored on our servers is encrypted using AES-256 encryption.
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.3.
- Secure servers: Our infrastructure is hosted on reputable cloud providers with SOC 2 Type II compliance and regular security audits.
- Access controls: Access to user data is strictly limited to authorized personnel who require it to provide technical support. All access is logged and monitored.
- Regular audits: We conduct regular security assessments and penetration testing to identify and address potential vulnerabilities.
Data Sharing
We Do Not Sell Your Data
We will never sell, rent, lease, or trade your personal information or health data to any third party. This is a core principle of MoodStead that we will never compromise.
Service Providers
We work with a limited number of trusted service providers who help us operate the Service, such as cloud hosting providers and payment processors (Lemon Squeezy). These providers are contractually obligated to protect your data and may only use it to perform services on our behalf.
Legal Requirements
We may disclose your information if required to do so by law, such as in response to a valid court order, subpoena, or government request. We will make reasonable efforts to notify you of such requests unless prohibited by law. We will challenge requests that we believe are overly broad or legally insufficient.
Your Rights
You have the following rights regarding your personal information:
- Access: You may request a copy of all personal data we hold about you at any time.
- Correction: You may update or correct your personal information through the app settings or by contacting us.
- Deletion: You may delete individual entries or your entire account at any time. Account deletion permanently removes all associated data from our servers within 30 days.
- Export: You may export all of your data in standard formats (PDF, CSV) at any time.
- Withdraw consent: You may withdraw your consent to data processing at any time by deleting your account. Certain features may not be available if you withdraw consent for specific types of processing.
To exercise any of these rights, you may use the in-app settings or contact us at support@moodstead.com.
Cookies & Tracking
MoodStead uses minimal cookies and tracking technologies. We use essential cookies required for the Service to function properly (such as session management and authentication). We use privacy-focused analytics that do not rely on cookies to track individual users.
We do not use advertising cookies. We do not run retargeting or remarketing campaigns. We do not participate in ad networks or share browsing data with advertising platforms. Your use of MoodStead will never result in targeted ads elsewhere on the internet.
Children's Privacy
MoodStead is not intended for use by children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children under these ages. If we become aware that we have collected personal information from a child under the applicable age, we will take steps to delete that information promptly.
If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at support@moodstead.com so we can take appropriate action.
International Data Transfers
MoodStead is operated from the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
We ensure that any international transfers of personal data are conducted in compliance with applicable data protection laws, including the use of Standard Contractual Clauses or other approved transfer mechanisms where required by the General Data Protection Regulation (GDPR) or similar legislation.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email and/or by posting a prominent notice within the Service at least 30 days before the changes take effect.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of those changes.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
MoodStead Privacy Team
Email: support@moodstead.com
We will respond to all privacy-related inquiries within 30 days.