Controls we can verify today
This page lists controls we can verify today. A certification is listed once it has been issued, never before. For anything not covered here, ask; you get the same answer we put in contracts.
What is collected and why
Each kind of data the product handles, where it comes from, and what it is used for.
- Account data
- Names, work email addresses, workspace names and roles for the people a customer invites. Used to sign you in, send product email and bill the workspace.
- Tracked questions
- The questions you choose to track, per market. Each is sent to the engines in your plan as a plain query. No customer identifier and no other data travels with it.
- Stored answers
- The full text of each answer, the sources it cited, the engine, the market and the collection time. Kept in your workspace for as long as it exists so every rate can be traced back to its answers.
- Customer-supplied API keys
- The Anthropic key an admin enters for Claude collection. Stored encrypted, used only for your workspace, and removable by an admin at any time.
- Billing data
- Handled by Stripe. Bluemoon stores the Stripe customer and subscription identifiers and the invoice status; card numbers never reach our systems.
- Free tool inputs
- The domain you enter into a free tool is used to fetch public pages of that domain while the tool runs. The domain and the results are not stored.
- Contact form
- Name, email, company and message, delivered to our inbox by email and kept to answer you.
Controls
Each control is in place today. Nothing here describes a plan.
Encryption in transit
All traffic between your browser, the product and its API is encrypted with TLS. The same applies to the website and the free tools.
Answers stay in your workspace
Answers are collected for the tracked question and stored in the workspace that owns it. Workspaces do not share stored answers.
Your Anthropic key, encrypted
Claude is collected with an API key you supply. The key is stored encrypted, used only for your workspace’s collection, and never billed by Bluemoon; you pay Anthropic directly.
Payments through Stripe
Card details are entered on Stripe’s forms and never touch Bluemoon’s servers. We keep the Stripe customer and subscription identifiers and the invoice status.
Role-based access
Viewer, editor and admin roles on every plan. Admins manage members, billing and keys; editors change questions and competitors; viewers read.
Deletion on request
Ask and we delete a workspace with its stored answers, questions and keys. We confirm by email once the deletion is complete.
Subprocessors
Every third party that processes customer data on our behalf, and what for. The answer engines receive only the tracked question.
| Provider | Purpose | Region |
|---|---|---|
| Infomaniak | Hosting of the product and its stored data | Switzerland |
| Stripe | Billing and payment processing | — |
| Anthropic | Claude answers, using the API key the customer supplies | — |
| OpenAI | ChatGPT answers; only the tracked question is sent | — |
| Gemini, AI Overviews and AI Mode answers; only the tracked question is sent | — | |
| Perplexity | Perplexity answers; only the tracked question is sent | — |
| Bright Data | Collection of answers from public answer surfaces; only the tracked question and its market are sent | — |
| Resend | Delivery of email: product notifications, and contact and demo requests from this website | — |
| Vercel | Hosting of this website and its free tools | — |
| Google Analytics | Website analytics, only for visitors who allow it | United States |
Documentation available on request
What we can send today. Write to the security address and name the document.
- Security overview, this page
- Subprocessor list, this page, updated when a subprocessor changes
- Data processing agreement, on request
- Deletion confirmation, on request, once a deletion is complete
Report a vulnerability
Write to security@trybluemoon.com with steps to reproduce. We acknowledge every report within 2 working days and keep you informed until the issue is closed.
- What to include
- The affected URL or component, steps to reproduce, what you observed and what you expected. A proof of concept helps; customer data does not, so please stop at the point that proves the issue.
- What we do
- Acknowledge within 2 working days, confirm or ask for detail, fix, and tell you when the fix is live. If you want to be named once the issue is closed, say so.
- What we ask
- Do not access, change or keep data that is not yours, do not degrade the service for others, and give us time to fix before publishing.
Questions we are asked
Where is data stored?
How long is data retained?
How do I have data deleted?
Need more than this page?
Ask for the documents, the hosting details, or a call with the people who run the systems.