Moorkeep

Moorkeep Privacy Policy

This policy covers our website and the e-mail we exchange with people who write to us or whom we write to. It is short because the business is small: one person, a static site, and a mailbox. Last updated 29 September 2026.

1. Who we are

Moorkeep is run by Eitan Plaks, a sole proprietor in Israel, at Dalia Ravikovitch 5, Rosh HaAyin 4840301. For the personal data described here we are the controller: we decide why and how it is used.

Privacy contact: eitanp214@gmail.com.

2. What this policy covers

Personal data about:

It does not cover the software you run yourself. Moorkeep runs on your own servers; we have no access to your installation and never see what is in it. Nothing is hosted by us, and nothing can be bought on this site today, so there is no payment data.

3. What we collect, why, and our legal basis

DataWhere it comes fromWhy we use itLegal basis (GDPR Art. 6(1))How long we keep it
Website logs: IP address, browser type, pages requested and timesYour browser, through our website hostTo deliver the website and keep it secure; to count visits, from the host's own server-side totalsLegitimate interests (f)As long as our website host retains them
E-mail you send us: your address, your company if you give it, and what you tell us about your Flowise setupYou, in an e-mail you write and send yourself. This site has no form; the two buttons open your own mail program.To reply, to understand demand, and to send you a letter of intent if you ask for oneSteps you ask us to take before a contract (b); legitimate interests in understanding demand (f)12 months after our last contact, unless you become a customer
A first message from us to a business that publicly says it runs Flowise, by e-mail, its own contact form or a LinkedIn message: the contact address or page that business publishesThe business's own website or public profileTo ask, once, whether they run it in production and what they needLegitimate interests (f). We write once; if there is no reply we do not write againThe address is kept only so that we never write to it a second time
Release announcements: your e-mail addressYou, by askingTo tell you when a release ships; nothing elseConsent (a). Reply "stop" to any announcement and it endsUntil you say stop; then only on a do-not-mail list
Customer and prospect contacts: name, business e-mail, role, company, messages, support requests and letters of intentYou or your colleaguesTo provide support, manage the relationship and keep contract recordsContract (b); legitimate interests (f) for contacts at business customersFor the relationship, then for as long as Israeli record-keeping rules require
Security reports: your name or handle, your contact details and the reportYou, through our security-reporting channelTo fix vulnerabilities and, if you want, to credit youLegitimate interests (f)The report, for as long as the fix is published; your contact details, 24 months

We do not sell personal data. We do not use it for advertising. We do not buy lists.

We use an AI assistant. Messages sent to us may be read by an AI assistant (Anthropic's Claude) that helps us log them and draft replies; it also helps us find the businesses we write to and draft that first message. Anthropic handles the text under its consumer terms. Model training is switched off on the account; Anthropic's terms still allow it to use content flagged for safety review or sent to it as feedback, and we send none as feedback. Every reply you receive was read and sent by Eitan Plaks; the assistant drafts, a person decides.

4. Who receives your data

The companies below. Where one acts for us under a contract, the contract is shown; where we use a consumer service under its own terms, we say so. That is the whole list; when it changes, this page changes and says so.

ProviderWhat it does for usWhere it processes dataSafeguard for the transfer
Cloudflare, Inc.Serves this website, answers its DNS, and forwards e-mail sent to our domain to our mailboxUnited States, through a global network of edge locationsCloudflare's Data Processing Addendum, which incorporates the EU Standard Contractual Clauses and the UK Addendum
Google LLC (Gmail)Our mailbox: holds the e-mail you send us and carries our repliesUnited StatesA standard Gmail account under Google's privacy policy. Google handles the mail under its own terms, as a separate company, not as our processor; there is no processor contract for a consumer account. We chose it for its security over a mailbox on a new domain
Anthropic, PBCThe AI assistant that reads messages and drafts replies (section 3)United StatesAnthropic's consumer terms and privacy policy. On a personal subscription Anthropic handles the text under its own terms, as a separate company, not as our processor; we have no contract with it beyond those terms
GitHub, Inc.Hosts our source code, private until the first release; security reports reach us by e-mail until thenUnited StatesGitHub's own terms of service for a personal account. Its Data Protection Agreement covers organisation accounts, so we do not cite it

Others. We may share personal data:

A representative in the EU or the UK. Article 27 requires a controller outside the EU to appoint one unless its processing is occasional, includes no large-scale processing of special categories of data, and is unlikely to risk anyone's rights. Today we answer e-mails people choose to send us and write once to businesses that publicly run Flowise; we read that as occasional, and no lawyer has confirmed it. Before the first release announcement goes to the people who asked for one, we will take advice on whether that list needs a representative, and say so here. If you think we have this wrong, write to us; we would rather be told than be right.

5. International transfers

We are based in Israel. The European Commission has decided that Israel protects personal data adequately, so data can flow from the EU to Israel without further safeguards. If you are in the United Kingdom, your data also reaches Israel; the UK's approved-country regulations carried over the adequacy decisions that were in force when it left the EU, and the decision on Israel is one of them.

The companies in section 4 handle data in the United States. The table shows the safeguard where one exists, and says so where none does.

6. How long we keep data

The table in section 3 gives each period. When a period ends, we delete the data or make it anonymous. We delete data sooner if you ask, unless the law requires us to keep it.

7. Your rights

Depending on where you are, you may have the right to:

Israeli privacy law gives similar rights to inspect and correct information.

To use a right, e-mail eitanp214@gmail.com. We reply within one month. We may need to confirm your identity first.

You can also complain to a data protection authority. In the EU, that is the authority where you live or work. In the UK, it is the Information Commissioner's Office. In Israel, it is the Privacy Protection Authority. We would be grateful for the chance to fix the problem first.

8. Security

The business is one person, a static website and a mailbox, so the honest list is short. We protect personal data by:

No method is perfect. If a breach affects you and the law requires us to tell you, we will.

9. Cookies and analytics

This website sets no cookies and loads no analytics script. We look at our host's server-side request counts, which involve nothing running in your browser. If that ever changes, this section changes first and we ask for consent where required.

10. Children

Our services are for businesses. They are not directed at children, and we do not knowingly collect data about children under 16.

11. Automated decisions

We do not make decisions about you that are based only on automated processing and that have legal or similarly significant effects.

12. The software itself

Moorkeep runs on your own servers and sends no usage data to us or to anyone unless you switch it on yourself. It has a dormant analytics client that only wakes if you set the environment variable POSTHOG_PUBLIC_API_KEY; no key ships with the software. If you set your own, the data goes to your own project, not to us. Unset it and it stops. The software also writes an audit log of its own actions to the storage you configure; that log stays with you.

13. Changes to this policy

When we change this policy, we post the new version here with a new date. If a change is material, we also e-mail customers and the people who asked for release announcements.