Privacy policy
Privacy policy
Last updated: September 12, 2026
This policy describes how SenTeGuard Inc. (“we,” “us”) processes personal information and other data in connection with the Moyo product website, request forms, online store purchases (including agentic commerce checkout), and authorized assessments. Moyo is a product of SenTeGuard Inc.; it is not a separate legal company.
Store policies: Terms of service · Refund and return policy · Authorized use · Security
How we classify data
Moyo workflows handle different classes of data under different rules. We do not treat them as one undifferentiated pool.
Class A
Marketing contact data
Information you provide to inquire, subscribe, or request a preliminary scan: typically work email, organization name, domain, optional scope notes, and similar form fields. We may also receive technical metadata such as IP address and user agent in server logs.
- · Purpose: qualify leads, respond to requests, deliver preliminary findings by email, product updates if you opt in
- · Example processors: site hosting, CRM / Mailchimp audience, transactional notification email
- · Not the same as: a full assessment corpus or confidential customer uploads
Class B
Public-source scan data
Lawfully accessible information collected during an authorized outside-in review for an organization and domain you specify, e.g. hiring posts, patents, filings, social posts, websites, and other open sources. This material is already public or otherwise lawfully available; it is not confidential data you upload through the website forms.
- · Purpose: map inference paths and initial exposures as described in your request and any later engagement scope
- · Authorization: preliminary scans and external reports run only with the authorization and public-source limits described on Authorized use
- · Not the same as: marketing CRM fields alone, or private documents you provide under a white-box SOW
Class C
Customer-provided confidential data
Non-public materials you deliberately provide under a written white-box or similar engagement: private document corpora, RAG indexes, internal knowledge bases, credentials issued for testing, or other confidential attachments listed in the scope of work. The public website forms, including the preliminary scan form, do not accept confidential document uploads from anonymous visitors.
- · Purpose: only the authorized white-box or enterprise testing described in the SOW
- · Controls: documented retention and deletion rules agreed with you; restricted access; see Security
- · Not the same as: lawful public web material gathered outside-in
Class D
Generated assessment findings
Work product we produce for you: inference maps, confidence and sensitivity scores, source attribution, exposure rankings, mitigation recommendations, and related briefing materials. Findings may reference public-source data, customer-provided data (if authorized), or both, depending on engagement type.
- · Purpose: deliver the engagement; support re-test or follow-on work only as agreed
- · Confidentiality: treated as customer confidential under the engagement agreement unless you authorize other use
- · Not the same as: marketing lists used for general product outreach
Class E
Purchase and payment data
When you buy through our online store or agentic commerce checkout, we and our payment processor receive information needed to complete the transaction: buyer contact details, order contents, and payment status. Card numbers and full payment credentials are handled by the payment processor; we do not store full card numbers on Moyo servers. If you leave Stripe checkout and submit the optional abandonment survey, we also receive the reason you chose, any details you write, and an email only if you provide one.
- · Purpose: process payment, fulfill the order, send receipts and delivery communications, prevent fraud, meet accounting/tax records duties, and (if you submit it) understand why a checkout was cancelled
- · Example processors: Stripe or another checkout provider you complete payment with; site hosting; transactional email
- · Not the same as: confidential assessment corpora (Class C)
How we use information
We use each class only for its stated purposes: lead handling and communications (A); authorized outside-in analysis (B); authorized white-box testing (C); delivering and, where contracted, validating findings (D); and purchase fulfillment, records, and optional checkout-abandonment feedback (E). We may also process data as needed to secure our systems, prevent abuse, and meet legal obligations.
Processors
We may use service providers such as hosting (e.g. Netlify), email/CRM (e.g. Mailchimp), payment processors (e.g. Stripe), advertising measurement (e.g. Google Ads, LinkedIn Insight Tag, Reddit Pixel, TikTok Pixel, X Pixel), and transactional email for notifications. Providers act under our instructions. Customer confidential (Class C) workloads are not mixed into general marketing audiences.
Retention and deletion
Marketing contact data is retained while relationships are active and as required for records. Public-source scan materials and generated findings are retained per engagement terms and then deleted or de-identified. Purchase and payment records are retained as required for accounting, tax, and dispute resolution. Customer-provided confidential data is retained and deleted under the documented rules in your SOW and our authorized-use policy, typically the shortest period consistent with delivery, re-test options, and legal hold duties.
Your choices
Contact us to request access, correction, or deletion of personal information we hold about you, subject to legal exceptions and contractual obligations. Marketing preferences can be updated via unsubscribe links where provided.
Contact
Privacy inquiries: SenTeGuard Inc., Austin, TX, United States. Email david@senteguard.com.