Mozzy
Terms Privacy Contact
Back to sign in

Legal / Data

Privacy Policy

A clear explanation of the information Mozzy handles, why it is needed, and the choices available to you.

Version
2026-08-01
Effective
1 August 2026

On this page

1. Scope 2. Information collected 3. How information is used 4. Workspace content 5. Cookies and local storage 6. Service providers and sharing 7. Overseas processing 8. Security and retention 9. Access and correction 10. Complaints and contact
01

Scope and responsibility

This policy explains how Mozzy, currently operated by William Thomas, handles personal information in connection with its website, accounts, workspaces, bug reports, attachments, and Assistance connections.

Workspace owners and members decide what they submit. An organisation using Mozzy may have its own privacy obligations for content concerning its customers, staff, or users.

02

Information we collect

  • Account information: name, email address, password hash, verification status, sign-in activity, role, and Terms acceptance.
  • Workspace information: workspace and project names, membership, invitations, settings, and project URLs.
  • Report evidence: issue descriptions, reproduction steps, device and browser details, URLs, screenshots, files, logs, console output, and status history.
  • Assistance information: connection configuration, health status, response time, software versions, and technical events submitted by authorised connected systems. WordPress events may include fatal PHP errors, database error messages, email failures, and supported scheduled-task failures.
  • Contact information: the name, email address, topic, message, account association, delivery status, and resolution status of enquiries sent through the Contact form.
  • Technical and usage information: essential session and security data, page views, successful sign-ins, active time by Mozzy section, recognised automated-agent name and category, and approximate country or Australian state codes.
  • Abuse-prevention information: the result and timing of session-based maths challenges, hidden bot fields, and network information temporarily processed to apply submission rate limits.

Some report evidence may incidentally contain personal or sensitive information. Submit only what is reasonably necessary to diagnose the issue.

For Mozzy Work extension usage totals, we record the member account ID, browser type and calendar date of successful authenticated extension requests, including automatic refresh while connected. These daily records are retained for 90 days and shown as aggregate counts to Super Admins. This counter does not collect browsing history, website content, passwords or access tokens.

03

Why we use information

We use information to create and secure accounts, provide isolated workspaces, store and organise reports, process attachments, deliver transactional email, operate Assistance connections, export selected reports, understand aggregated platform usage, prevent misuse, diagnose faults, and communicate about the service.

Contact and registration submissions are checked automatically for a correct session-based maths answer, an unfilled hidden field, a plausible completion time, and applicable rate limits. A submission that fails these checks is rejected rather than stored. A person can retry with a new challenge or contact support if a legitimate submission continues to fail.

We do not currently sell personal information or use workspace evidence for third-party advertising.

04

Who can see workspace content

Workspace content is available to authorised members of that workspace. Workspace owners control invitations and membership. Super Admin access is used for platform administration and account management, including protected access to generated maintenance invoices and maintenance logs when billing or support administration requires it.

Contact enquiries are available to authorised Super Admins and may be emailed to active Super Admins so they can respond. Assistance events and the readable reports created from them are available to members of the connected workspace.

Exported files leave Mozzy’s access controls. The person exporting or sharing them is responsible for protecting the resulting copy.

05

Cookies and device storage

Mozzy uses essential session and security cookies for sign-in and request protection. Interface preferences such as theme, sidebar mode, and visual-effects quality are stored locally in your browser.

The anti-spam maths answer and form start time are held in the essential session. Hidden bot-field contents and challenge answers are not stored as Contact messages or account information when a submission is rejected.

Mozzy uses first-party Platform Analytics to measure page views and engaged time while a signed-in page is visible, focused, and recently used. Approximate country and Australian state codes may be supplied by the network provider. Platform Analytics does not store precise coordinates or raw visitor IP addresses.

Mozzy does not use third-party advertising cookies.

06

Service providers and disclosure

If you connect Google Drive through Mozzy, we process Google authorization codes, store an encrypted refresh token and your selected destination folder ID and name, and provide short-lived access tokens to your authenticated WordPress website. Backup contents upload directly from your website to Google Drive. Disconnecting in WordPress removes that website’s saved Mozzy grant without deleting Drive files. You can also revoke Mozzy access in your Google account. Advanced setup using your own Google application keeps its authorization credentials on WordPress.

Information may be processed by providers used to operate Mozzy, such as hosting, backups, transactional email, DNS, security, or private tunnelling. Depending on deployment, these providers may include Brevo for email and Cloudflare for network or security services.

When Contact notifications are enabled, the sender’s name, email address, selected topic, and message are included in transactional email sent to active Super Admins. The enquiry remains stored in Mozzy even if email delivery fails.

We may also disclose information where required by law, to protect users or the service, or as part of a business transfer with appropriate safeguards. Providers should receive only the information reasonably needed for their function.

07

Overseas processing

Some service providers may process or store information outside Australia. The countries involved depend on the providers and regions configured for the deployment. Reasonable steps should be taken to assess provider privacy and security practices before enabling them.

08

Security and retention

We use access controls, workspace separation, password hashing, verified accounts, and other reasonable technical and organisational safeguards appropriate to the service. No internet-connected system can be guaranteed completely secure.

Assistance access tokens are generated for individual connections. Mozzy stores a one-way hash for authentication and a separately encrypted copy so authorised workspace members can retrieve the token from the connection actions. The shared WordPress plugin stores its token in the connected website’s options after a short-lived, one-time pairing exchange; Mozzy does not place the permanent token in the browser return URL.

The WordPress connector is designed not to send passwords, cookies, form contents, database records, WordPress users, or visitor IP addresses. Error messages, affected URLs, and file paths can still contain incidental personal or confidential information, so connector events should be reviewed and the connected website configured appropriately.

Account and workspace information is generally retained while needed to provide Mozzy, meet legal obligations, resolve disputes, or protect the service. Done-report retention can be configured before reports move to Archive. Deleted information may remain for a limited period in backups before normal rotation removes it.

Contact enquiries and Assistance events are retained while reasonably needed to respond, maintain incident history, protect the service, or meet applicable obligations. They may be removed or de-identified when no longer required.

Closing an account disables access immediately and starts a 14-day recovery period. Signing in during that period restores the account. After the recovery period, the account and any solely owned workspaces scheduled with it are permanently deleted from the active service; limited backup copies may remain until normal rotation.

If you discover a security concern, contact us promptly and do not include secrets in the initial message.

09

Access, correction, deletion, and exports

You may request access to personal information about you and ask for inaccurate, out-of-date, incomplete, irrelevant, or misleading information to be corrected. You may also ask about deletion or obtain available workspace exports, subject to the rights of other people and applicable legal requirements.

Regular members can close their account from Settings. Shared workspaces must be transferred before closure so another member’s access and content are not unexpectedly removed. Super Admin accounts cannot be closed through Settings and require direct administrative handling so platform administration is not unintentionally disabled.

Use the contact form with enough detail to identify your account and request. We may need to verify your identity before disclosing or changing information.

10

Privacy questions and complaints

Send privacy questions or complaints through the contact form. We will acknowledge the concern and aim to investigate and respond within a reasonable period.

If Australian privacy law applies and a complaint remains unresolved, you may be able to contact the Office of the Australian Information Commissioner. Visit oaic.gov.au for current guidance.

Material policy changes will be shown through an updated version and effective date.

Mozzy · Catch bugs. Keep moving. Questions? Contact the Mozzy Team