Privacy policy

How this website, the free tools and the Bluemoon product handle personal data. Written to be read, not skimmed; if anything here is unclear, write to us.

Last updated 2026-09-21

Who this covers

This policy covers the Bluemoon website at trybluemoon.com, the free tools published on it and, in outline, the Bluemoon product that customers sign in to. Bluemoon is operated from Switzerland. For the product, the customer agreement and the data processing terms that come with it add detail and take precedence where they differ from this page.

What this website collects

Server logs

Like any website, our servers and hosting provider record requests: the page requested, the time, your IP address, your browser type and the page you came from. We use these logs to keep the site running, to detect abuse and to fix errors. They are kept for a short period and then deleted. We do not use them to build profiles.

Cookies and analytics

Nothing is set in your browser until you answer the analytics question. If you allow analytics, Google Analytics 4 loads and sets two first-party cookies (_ga and _ga_ followed by our property ID) so that we can count visits and see which pages are read. Google processes this data for us, including in the United States; IP addresses are anonymised and advertising features are off. If you decline, nothing from Google loads at all.

Your answer is kept in your browser’s local storage, not in a cookie, so we do not ask again on every page; a refusal is remembered for six months. If your browser sends a Global Privacy Control signal, we treat it as a refusal. You can change your answer at any time with “Privacy choices” in the footer: withdrawing stops the measurement straight away and removes the Google Analytics cookies.

The contact form

If you write to us through the contact form, we receive your name, email address, company, the reason you chose and your message. The message is delivered to our inbox by an email delivery provider and kept for as long as we need it to answer you and follow up. You can ask us to delete it at any time.

Demo requests

If you book a demo, we receive your name, business email address, company size, how you heard about us and whether you work for an agency. We use them to prepare the demo and arrange a time, and keep them as long as we are in contact about it.

The free tools

The free tools read public pages of the domain you enter, such as its robots.txt, homepage, sitemap and llms.txt, at the moment you run the tool, and show you what they found. The domain you enter and the results are not stored. Requests are rate-limited per IP address for a few minutes, in memory, to prevent abuse; that counter is not written anywhere.

What the product collects for customers

When a company signs up for Bluemoon, we process the following inside its workspace:

  • Account data: names, work email addresses, roles and sign-in records for the people the customer invites.
  • Tracked questions: the questions the customer chooses to track, per market. These are sent to the answer engines as plain queries; no customer identifier and no other data travels with them.
  • Stored AI answers: the full text of each answer, the sources it cited, the engine, the market and the time of collection. Answers come from public answer surfaces and may name people, for example a founder or a reviewer, if the engine named them.
  • Customer-supplied API keys: the Anthropic API key a customer supplies for Claude collection is stored encrypted and used only for that customer’s collection.
  • Billing data: handled by Stripe. We keep the Stripe customer and subscription identifiers and the invoice status; card numbers never reach our systems.

For this data the customer decides what to track and who has access. Bluemoon processes it on the customer’s behalf under the customer agreement.

Legal basis

Bluemoon is subject to the Swiss Federal Act on Data Protection (FADP). Where the EU or UK General Data Protection Regulation (GDPR) applies, for example when we offer the product to customers in the European Economic Area, we rely on the following bases:

  • Performance of a contract, for the product and for answering a request you send us.
  • Legitimate interests, for server logs, security, abuse prevention and improving the site. We weigh these against your interests and keep the data minimal.
  • Consent, for website analytics. You can withdraw it at any time with “Privacy choices” in the footer.

Who receives data

We do not sell personal data and we do not share it with advertisers. Data is processed by a small number of service providers on our behalf; they are listed with their purpose on the security page. The answer engines receive only the tracked question, never customer data. Where a provider processes data outside Switzerland or the European Economic Area, we rely on the safeguards recognised by Swiss and EU law, such as an adequacy decision or standard contractual clauses.

How long we keep data

  • Server logs: a short period, then deleted.
  • Contact messages and demo requests: as long as needed to answer and follow up, then deleted on request or once the conversation is closed.
  • Product data: for as long as the customer’s workspace is active, so that every rate stays traceable to its answers. When a workspace closes, its data is deleted on request and in any case after the period set in the customer agreement.
  • Billing records: as long as Swiss accounting law requires.

Your rights

You can ask us what personal data we hold about you, have it corrected or deleted, restrict or object to its processing, and receive a copy in a portable format where the law provides for it. Write to the address below and we will answer within the time the law allows, normally within 30 days. You can also complain to the Swiss Federal Data Protection and Information Commissioner or, if the GDPR applies to you, to the supervisory authority in your country.

If you use Bluemoon inside a customer’s workspace, that customer decides how your data is used there. Contact them first; we support them in answering you.

Security

The controls we apply, the subprocessors we use and how to report a vulnerability are described on the security page. That page lists only what we can verify today.

Changes to this policy

When we change this policy, we update the date at the top. For changes that matter to customers, we also notify workspace admins by email before the change takes effect.

Contact

Questions about this policy, or a request about your data: sales@trybluemoon.com. Security matters: security@trybluemoon.com. You can also use the contact form.