This is a working draft. Sections marked with a placeholder still need input from woople before this page is final. It is not legal advice.
Woople is a product of Mooning Agency Pty Ltd (ABN 20 656 190 608), located at Level 1, 2 Star Crescent, Docklands VIC 3008, Australia. We make an AI-powered content platform for businesses. Contact us at hello@woople.ai.
This policy tells you how we handle personal information about you: meaning account holders, trial users, website visitors, and prospective customers of woople. It covers information we collect and control ourselves.
What this policy does not cover. When you use the platform to generate content, you submit data about your own business (your website content, your brand materials) to woople. How we handle that data as your service provider is governed by the woople Data Processing Agreement. That data is yours; we process it on your instruction, not for our own purposes.
When you sign up, you provide your name, business name, and email address. We use this to create and manage your account and communicate with you about the service. We retain this for the life of your account and for 7 years after closure.
Payments are processed through a third-party payment provider. We do not store your card number. We retain your billing address, invoice history, and transaction records for 7 years as required by law.
We collect data about how you use the platform: features accessed, content generated, credits used, login times, and error logs. We use this to operate the platform, detect abuse, and improve the product. Retained for 2 years.
When you activate the Brain, you provide the URL of your nominated website. We access that website to build structured Brand Brain context scoped to your workspace. The crawled content is your data, processed on your instruction. It is not used as another workspace's Brand Brain. Relevant content is processed by configured AI providers only when a requested feature needs an AI response. The crawled content is deleted within 90 days of your subscription ending.
Where you use the platform's competitor analysis, channel watchlist, ads research, or AI-visibility features, we collect publicly available third-party content on your instruction (for example public social posts, public ad libraries, and public search results) to inform your generated content. This is processed under the Data Processing Agreement in the same way as other customer data.
When you contact our support team or respond to a survey, we retain records of that correspondence. Retained for 3 years.
If you opt in to marketing communications, we track whether you open our emails and click links. You can opt out at any time by clicking unsubscribe or contacting hello@woople.ai. Engagement data is deleted 12 months after you opt out.
We collect standard analytics data when you visit the woople marketing site, including IP address, browser type, pages visited, and referring URL. See the cookies section below.
We use personal information to:
General craft guidance shared across the platform comes from a separate, research-fed corpus. Customer-derived cross-workspace pattern aggregation is not enabled.
We do not sell your personal information.
We do not sell your personal information. We share it only as described below.
We use third-party service providers to help deliver the platform. These include:
Each provider is bound by contractual obligations that limit their use of your data to delivering services for us. A current list of our sub-processors, including their names and locations, is available on request by contacting hello@woople.ai, and is updated with 30 days' notice when material changes are made.
Legal and regulatory disclosures. We may disclose personal information where required by law, a court order, or a regulatory authority.
Business transfers. If Mooning Agency Pty Ltd is sold, merged, or restructured, personal information may be transferred to the successor entity. We will notify you in advance.
Mooning Agency Pty Ltd is based in Australia. Some of our service providers are based in other countries, including the United States. Your personal information may be transferred to and processed in those countries when we use these providers.
For Australian customers. We comply with Australian Privacy Principle 8 when transferring personal information overseas. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.
For Hong Kong customers. We handle your personal data in accordance with the six data protection principles under the Personal Data (Privacy) Ordinance (Cap. 486) (PDPO). When your personal data is transferred to our overseas service providers, we take contractual and other steps to ensure those providers protect your data to a standard consistent with the PDPO, in line with the PCPD's guidance on recommended model contractual clauses for cross-border data transfers.
| Data type | Retention period | Reason |
|---|---|---|
| Account and registration data | Duration of subscription + 7 years | Tax and legal compliance |
| Payment and invoice records | 7 years | Australian tax law |
| The Brain activation data / crawled website content | Deleted within 90 days of subscription end | Proportionate to subscription term |
| Generated content | 30-day export window after termination, then deleted | Customer export opportunity |
| Usage and analytics data | 2 years | Platform operations and abuse detection |
| Support communications | 3 years | Covers typical dispute limitation period |
| Marketing engagement data | Deleted 12 months after opt-out | Suppression list maintenance |
The retention and deletion timelines above are not yet automated in the product. They are fulfilled manually today; the team owns executing them when a subscription ends.
We use industry-standard security measures to protect personal information, including encryption of data in transit and at rest, access controls, and regular security reviews.
If we become aware of a data breach likely to result in serious harm, we will notify you and the relevant regulator as required by law. Under the Australian Privacy Act, we must notify the OAIC and affected individuals of eligible data breaches within 30 days of becoming aware.
The platform sets only essential cookies. These are a workspace-selection cookie (woople_ws), which stores which workspace is currently active, and a temporary demo-access cookie scoped to a demo route. Authentication session data is handled by our infrastructure provider, Supabase, rather than by cookies we set directly.
We do not use analytics, advertising, or third-party tracking cookies. No consent management platform is deployed, and none is required because only essential cookies are used.
You can block these cookies in your browser settings, but the platform may not function correctly without them.
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Under the Personal Data (Privacy) Ordinance (Cap. 486), you have the right to:
To make a data access or data correction request, contact hello@woople.ai. We will respond within 40 days as required by the PDPO. We may charge a reasonable fee for processing a data access request in accordance with the PDPO.
Submit a request to hello@woople.ai. We will respond within the timeframe required by applicable law.
We will give you reasonable advance notice of material changes via email or in-platform notification. Continued use of the platform after the effective date constitutes acceptance.
Privacy contact: hello@woople.ai
Postal address: Level 1, 2 Star Crescent, Docklands VIC 3008, Australia
If you have a complaint, please contact us first. We will respond within 30 days. If not satisfied:
The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) apply to Mooning Agency Pty Ltd (ABN 20 656 190 608).
Current reform status. The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024. Key provisions now in force include enhanced OAIC enforcement powers, tiered civil penalties (up to $50 million for serious or repeated breaches), a statutory tort for serious invasions of privacy (commenced 11 June 2025), and stronger cybersecurity obligations. Automated decision-making transparency requirements apply from 10 December 2026. A second tranche of reforms is expected to remove the small business turnover exemption and introduce a fair and reasonable test for data handling.
Notifiable data breaches. Under the Notifiable Data Breaches scheme, if we become aware of an eligible data breach likely to result in serious harm, we will notify the OAIC and affected individuals within 30 days of becoming aware.
The Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) governs the collection, holding, processing, and use of personal data of individuals in Hong Kong. woople handles Hong Kong customer data in accordance with the six data protection principles (DPPs):
Cross-border transfers. Section 33 of the PDPO, which would formally regulate cross-border data transfers, is not currently in force. In the meantime, woople takes contractual steps with its overseas service providers consistent with the PCPD's 2022 guidance on recommended model contractual clauses, to ensure personal data transferred outside Hong Kong is protected to a standard consistent with the PDPO.
Complaints. Customers may lodge a complaint with the PCPD at www.pcpd.org.hk or by calling +852 2827 2827.
Draft for review. This document is a working draft for review and completion by Mooning Agency Pty Ltd and by qualified legal counsel. It is not legal advice. Laws change; confirm the current legal position before publishing. Placeholders shown in highlighted text must be resolved before use.