MOZEN
FeaturesBlogDocsGalleryPricing
English
English简体中文繁體中文日本語FrançaisDeutschEspañolPortuguês한국어
Get Started
English简体中文繁體中文日本語FrançaisDeutschEspañolPortuguês한국어
FeaturesBlogDocsGalleryPricing Get Started

Privacy Policy

v2.2 · 2026-06-21

1. Scope of Application and Data Controller

This Privacy Policy explains how Mozen (hereinafter "Mozen," "we," or "the Service") collects, uses, discloses, stores, and protects your personal information when you access, register for, or use the Mozen website, web application, desktop or mobile applications, AI features, whiteboard, documents, reader, resource library, import/export, payment, and customer support services.

Mozen is currently provided by an individual independent operator under the name Mozen acting as the data controller / personal information handler. For the operator's personal safety and privacy protection, the operator's residential address is not displayed on public pages; for privacy requests, data rights requests, or complaints, please contact privacy@mozen.ai, and for legal notices or formal service-of-process information requests, please contact legal@mozen.ai. We will handle requests after completing the necessary identity verification and will provide service-of-process information where legally required.

2. Types of Information We Process

To provide a unified knowledge workspace and AI productivity services, we may process the following information:

  • Account and identity information: email address, username, avatar, language, region, login method, authentication session, account status, membership status, deletion request status, security activity records, and support communication records.
  • User Content: notes, documents, whiteboards, canvas objects, database tables, reading annotations, e-book progress, media files, images, audio, video, references, tags, tasks, schedules, habits, goals, Skill configurations, project structures, exported files, and related metadata that you create, upload, import, edit, generate, or share.
  • Collaboration and synchronization data: Y.Doc updates, snapshots, edit timestamps, workspace identifiers, member permissions, sharing links, invitation status, and device synchronization status used for real-time collaboration on documents and whiteboards, offline recovery, version merging, conflict handling, and cross-device synchronization.
  • AI interaction data: the prompts, conversations, reference materials, selected content, related note excerpts, and whiteboard context you submit to the AI, tool-call results, AI-generated text/images/audio/video/fonts/structured content, model routing information, points consumed, task status, and error information.
  • Import and third-party integration data: when you proactively connect or import third-party services, we process materials within the scope of authorization, such as Notion, Zotero, Google Drive, OneDrive, Baidu, WebDAV, social publishing accounts, or other external storage/publishing/material sources.
  • Payment and subscription information: plan, order number, transaction status, subscription cycle, trial status, cancellation status, refund status, information required for tax/invoicing, payment gateway customer ID, and transaction confirmation information. Mozen does not directly store full bank card numbers, CVV, or full payment credentials.
  • Technical and usage information: IP address, browser and device type, operating system, access time, page paths, feature usage, crash logs, performance metrics, error logs, anti-abuse signals, approximate geographic location, and necessary or optional data in Cookies, localStorage, sessionStorage, and IndexedDB.
  • Security and compliance information: login records, abnormal access, permission changes, data export requests, account deletion requests, administrator audit logs, content security interception records, payment risk-control signals, legal requests, and compliance retention records.

3. Sources of Information

  • Provided directly by you: information you provide when registering, editing, uploading, importing, purchasing, contacting customer support, submitting feedback, authorizing AI, or connecting third-party services.
  • Automatically generated or collected: logs, synchronization records, usage records, device information, Cookies, local cache, AI task records, and payment status generated by the system when you use the Service.
  • Third-party sources: necessary information returned to us by login, payment, storage, import, publishing, AI model, anti-fraud, infrastructure, or customer support providers that you have authorized.

4. Purposes of Use and Legal Bases

We process personal information only where there is a legitimate purpose and legal basis, including:

  • Creating and managing accounts, authenticating logins, maintaining sessions, and providing workspace, whiteboard, document, reader, resource library, search, import/export, real-time synchronization, sharing, and collaboration functions.
  • Processing AI requests, model routing, tool execution, points deduction, result persistence, content security, error recovery, and task continuity.
  • Processing payments, subscriptions, trials, renewals, cancellations, refunds, taxes, invoices, financial reconciliation, and the customer portal.
  • Providing customer support, troubleshooting, notifications, product changes, service announcements, and security alerts.
  • Protecting the security of accounts, systems, and the community, and detecting and preventing fraud, abuse, spam, malware, unauthorized access, fraudulent charges, infringement, and conduct that violates the terms.
  • Improving service quality, performance, reliability, availability, model routing, cost control, and user experience, including using aggregated or de-identified data for analysis.
  • Complying with legal obligations, enforcing agreements, responding to lawful requests, resolving disputes, and asserting or defending legal claims.

Where GDPR, UK GDPR, CCPA/CPRA, China's Personal Information Protection Law (PIPL), or other data protection laws apply, we will rely, depending on the specific context, on bases such as performance of a contract, your consent, legal obligations, legitimate interests, protection of vital interests, or legal requests to process data.

Legal bases (GDPR / UK GDPR) mapped to purposes:

  • Performance of a contract (Art.6(1)(b)): creating and managing accounts, providing core services such as workspace/editing/synchronization/AI, and processing payments and subscriptions.
  • Legitimate interests (Art.6(1)(f)): ensuring security and anti-fraud, improving the service and reliability, and necessary de-identified analysis; we balance these against your rights and freedoms.
  • Consent (Art.6(1)(a)): AI features that require sending out User Content, optional analytics/attribution storage, and marketing emails; you may withdraw at any time.
  • Legal obligations (Art.6(1)(c)): tax, accounting, compliance retention, and responding to lawful requests.

Special category data (Art.9): we do not actively collect sensitive personal data; if your User Content, voice, or images may contain special category data, we process it only where you provide it and an Art.9 exception applies (such as your explicit consent), and we require you to process such data through the Service only where a lawful basis exists. Where China's PIPL, CCPA/CPRA, LGPD, and similar laws apply, we process in accordance with their respective requirements (such as separate consent or sensitive-information limits).

5. AI Features and Model Providers

Mozen's AI features may require sending your prompts, selected content, related context, reference materials, media files, or task results to third-party model, inference gateway, embedding, speech-to-text, speech synthesis, image, video, or font generation providers configured by us or an administrator for processing.

  • Authorization mechanism: before you first use an AI feature that requires sending out User Content, we will request AI data authorization. You can withdraw authorization in "Settings → Privacy and Data." After withdrawal, features that rely on third-party models to process User Content may become unavailable.
  • Minimum necessity: we strive to send only the content and context necessary to complete the request. The system supports model routing, context compression, and tool-result trimming to reduce unnecessary outbound data transfer.
  • De-identification and filtering: before sending to model services, the system performs basic de-identification of sensitive tokens such as email addresses, phone numbers, ID card numbers, bank card numbers, and those in URLs, and may block or flag high-risk requests through content security policies.
  • Training restrictions: unless you expressly consent or applicable law permits, we will not use your User Content to train Mozen's general-purpose models; under standard integration paths, we will require model providers not to use User Content sent via API to train their general-purpose foundation models.
  • Provider retention: third-party model providers may retain request data for a short period in accordance with their contracts, privacy policies, abuse monitoring, and security policies. Where enterprise or specific plans offer zero-retention or shorter-retention capabilities, the actual configuration and provider commitments shall govern.
  • Bring-your-own-key or external connections: if we offer BYOK, bring-your-own model keys, or direct third-party account connection capabilities, the relevant data processing will also be subject to the agreement, privacy policy, and account settings between you and that third party; we cannot control how that third party retains or uses your data.
  • Likeness, voice, and sensitive content: when using AI to generate, edit, or transcribe content involving real persons' likenesses, voices, meetings, recordings, identity information, or sensitive personal information, you must have obtained the necessary consent and comply with applicable law.
  • Named providers and international transfers: Mozen's current AI model providers include both providers located in Mainland China (such as DeepSeek, Moonshot AI (Kimi), MiniMax, ByteDance Doubao/Volcengine, Zhipu GLM, and SiliconFlow) and providers located in the United States and other regions (such as Google, OpenRouter, Replicate, fal.ai, Cloudflare, and Azure Speech); the full current list and processing locations are set out in the public Subprocessors list; you may also request supplemental information via privacy@mozen.ai. Depending on the feature and model routing used, your relevant content may be transferred to China, the United States, or other countries/regions for processing, constituting an international transfer subject to the mechanisms described in the "International Transfers and Data Residency" section of this Policy.

6. Cookies, Local Storage, and Offline Cache

Mozen uses Cookies, localStorage, sessionStorage, and IndexedDB to maintain core functions:

  • Necessary storage: data required for the authentication session, CSRF/security state, offline editing cache, Y.Doc local persistence, current workspace, upload recovery, error recovery, and service availability. Refusing this storage may prevent the Service from functioning properly.
  • Optional storage: theme, language, layout, tool preferences, recently used items, and experience-optimization data. You can manage optional storage through the storage consent controls or your browser settings.
  • Browser controls: you can delete or restrict browser storage, but this may result in the loss of login status, offline content, preference settings, or unsynchronized edits.

7. Third-Party Services and Sharing

We do not sell your notes, whiteboard, or document content. We may share personal information in the following necessary scenarios:

  • Infrastructure and authentication: database, object storage, edge network, authentication, logging, email, backup, and security providers, such as Supabase, Cloudflare/R2, and similar providers.
  • Payment and tax: Paddle and its parties related to payment, tax, risk control, customer portal, and refund processing. Paddle currently acts as the Merchant of Record / authorized reseller, directly collecting payment information from you and processing receipts, taxes, subscriptions, and refunds.
  • AI and media processing: providers of text, embedding, image, audio, video, transcription, speech synthesis, OCR, search, media compression, and security filtering.
  • Third parties you authorize: services such as external storage, import sources, publishing destinations, OAuth login, calendars, material libraries, social platforms, and WebDAV.
  • Organizations and workspaces: if you join a team, enterprise, or shared workspace, administrators or authorized members may view, export, manage, or delete the content, members, permissions, and usage records within that workspace.
  • Law and security: sharing necessary to comply with the law, court orders, regulatory requirements, law enforcement requests, tax audits, sanctions screening, anti-fraud, investigation of abuse, and protection of the rights and safety of users or third parties.
  • Business transfers: in a merger, financing, acquisition, reorganization, bankruptcy, asset sale, or similar transaction, personal information may be transferred as part of the business assets, but we will require the recipient to continue protecting the relevant information.

8. Payments, Subscriptions, and Financial Records

Mozen's paid subscriptions, trials, points packages, and related transactions are currently processed by Paddle. We do not directly store full bank card information. We store order, plan, subscription, points, transaction status, refund status, tax, and reconciliation records to perform the contract, provide benefits, handle customer support, and for compliance, auditing, anti-fraud, and financial reporting purposes.

Financial, tax, anti-fraud, and dispute-handling records may need to be retained or retained in de-identified form after account deletion, until the expiry of the statutory retention period or dispute-resolution period.

9. Data Security

  • We use encryption such as TLS to protect data in transit, and use cloud providers, databases, object storage, and access control mechanisms to protect stored data.
  • Sensitive configurations such as OAuth tokens, external storage credentials, payment gateway configurations, and administrator keys are stored through server-side secure zones or encryption mechanisms and are displayed in masked form in the management interface.
  • The external backup encryption feature can enable AES-256-class encryption for data exported or mirrored to external storage; this feature is not equivalent to end-to-end encryption of all collaboratively edited content.
  • We restrict access to personal information by employees, contractors, and providers, and process production data on a minimum-necessary basis.
  • No internet transmission or electronic storage can be guaranteed to be absolutely secure.
  • Data security incidents and breach notification: we maintain a security incident response process. In the event of a breach that may affect your personal information, we will notify in a timely manner in accordance with applicable law: under the GDPR / UK GDPR, we will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, and notify affected individuals where a high risk is likely; under applicable U.S. state breach-notification laws, the PIPL, LGPD, PIPEDA, Australia's NDB, Korea's PIPA, Japan's APPI, and Switzerland's FADP, we will notify regulators and/or affected individuals within the timeframes and by the means each requires. Notifications typically include the nature of the incident, likely consequences, measures taken or proposed, and contact details.

10. Data Retention and Deletion

  • Account and content: we retain your account profile and User Content for the duration of the account, unless you delete the content, deactivate the account, or the law requires otherwise retention.
  • Synchronization and backup: Y.Doc updates, snapshots, offline queues, indexes, caches, backups, and audit logs may be retained for a short period after deletion to support recovery, synchronization consistency, security auditing, and disaster recovery.
  • AI records: AI usage records, points transaction records, task status, tool-call summaries, and error logs are retained as needed for service, accounting, anti-abuse, and debugging purposes; long-term retention of original content is minimized as much as possible.
  • Exported files: self-service data export records and temporary download data are subject to a validity period; in the current implementation, export results are typically used for immediate download, and export records record the status, size, and expiry time.
  • Account deactivation: after submitting a deactivation request, a 14-day cooling-off period begins, during which it may be withdrawn. After the cooling-off period ends, the system adds the account to the backend deletion process. Where there is an active subscription, a paid order, an unresolved dispute, or a legal obligation, deletion may be blocked, delayed, or replaced with anonymization.
  • Statutory retention: for tax, accounting, payment disputes, fraud prevention, security, legal requests, or dispute-resolution purposes, we may retain certain records for the necessary period.

11. Your Rights and Choices

Within the scope of applicable law, you may exercise the following rights:

  • Access, correct, update, or delete your account profile.
  • Export your personal data through "Settings → Privacy and Data."
  • Request to deactivate your account and withdraw the request during the cooling-off period.
  • Withdraw AI data authorization, optional storage authorization, or marketing email subscription.
  • Request restriction of processing, object to processing, or request a portable copy of your data.
  • Under applicable U.S. state privacy laws, opt out of the sale/sharing of personal information or cross-context behavioral advertising; Mozen does not sell User Content. If targeted advertising or cross-site tracking is used in the future, we will provide the corresponding choice mechanisms.
  • Lodge a complaint with the data protection authority in your jurisdiction.

To protect account security, we may need to verify your identity before processing rights requests. Certain requests may be restricted due to security, legal, financial, others' rights, technical limitations of backups, or service availability.

12. International Transfers and Data Residency

Mozen provides services to users worldwide, and your information may be processed outside the country or region where you are located. We disclose the principal processing locations candidly:

  • Primary database: hosted in Singapore (region ap-southeast-1).
  • Object storage and edge network: Cloudflare R2 / CDN, distributed across global edge locations.
  • AI model processing: third-party model providers include both providers located in Mainland China and providers located in the United States and other regions; depending on the feature and model routing used, the relevant content may be processed in China, the United States, or other countries/regions (the full current list is set out in the public Subprocessors list).
  • Payments: processed by Paddle as Merchant of Record.

For transfers subject to the GDPR / UK GDPR / Swiss FADP to countries without an adequacy decision (including Singapore, the United States, and others), we use the corresponding transfer mechanisms and safeguards: the EU Standard Contractual Clauses (SCC, 2021/914) together with necessary transfer impact assessments and supplementary measures; for transfers subject to the UK GDPR, the UK International Data Transfer Addendum (UK Addendum) / IDTA; and for those subject to the Swiss FADP, the Swiss-adapted SCC.

Cross-border provision for Mainland China users: where China's Personal Information Protection Law (PIPL) applies, because the primary database and some AI processing are located outside China, when we provide your personal information abroad we will, in accordance with the PIPL, obtain your separate consent, inform you of the overseas recipient, and perform a personal information protection impact assessment and other corresponding obligations, using a lawful cross-border route.

You may request copies of, or information about, the applicable transfer safeguards through privacy@mozen.ai. Our designated EU / UK / China representative details (where appointed) are set out on the Legal Notice / Imprint page.

13. Children and Minors

Mozen is not directed to children under 13 years of age. Users under 18 years of age or who have not reached the legal age of majority in their jurisdiction should use the Service with the consent and supervision of a parent or legal guardian. If we discover that we have collected a child's personal information without the necessary consent, we will delete it or take other necessary measures in accordance with the law.

14. Third-Party Websites and Public Sharing

Content that you proactively make public through sharing links, public pages, exported files, social publishing, or third-party integrations may be viewed, saved, copied, or further disseminated by others. Third-party websites, services, models, payment pages, browser extensions, or external storage are not controlled by this Policy; please read their respective privacy policies and terms.

15. Policy Updates

We may update this Policy due to changes in features, providers, law, or operations. For material changes, we will provide notice through reasonable means such as in-app notifications, email, or website announcements. If you do not agree with the updated Policy, you should stop using the relevant services; your continued use indicates that you accept the updated Policy, except where applicable law requires that consent be separately obtained.

16. Contact Us

For privacy-related questions, data rights requests, or complaints, please contact: privacy@mozen.ai. For account support, you may contact: support@mozen.ai, and for payment and refund support, you may contact: billing@mozen.ai. To protect your account security, we may need to verify your identity before processing the relevant request.

MOZEN

Technology bearing the weight of ink, Space granting the spirit of Zen.

Product Features Pricing Changelog
Resources Docs Blog
Legal Privacy Terms Refund Policy Cookie Policy
© 2026 Mozen Designed for Flow