GDPR

Privacy policy

This is a translation. The French version of this document is the one that applies. This English text is provided so you can read what you are agreeing to; where the two differ, the French wording governs.

In short: moula serves ads, so it needs to know which account to pay and which impression to count — and nothing else. It never reads what you write, and it respects your editor’s telemetry setting.

What leaves your machine: one request per display — account key, event id, editor type. Nothing else. No file contents, no file names, no project names, no prompts, no model replies.

Last updated 8 August 2026.

What we collect, and why

The moula extension sends the minimum needed to serve and count an ad. Each item, what it is for, and how long it is kept:

DataPurposeRetention
Account API keyAuthenticate the request and credit the right developerIrreversible fingerprint only, for as long as the account exists
Event id (request)Deduplicate retries, tie a click to its impressionWith the impression record
Impression / click recordsEarnings ledger, advertiser billing, anti-fraudEarnings ledger — exportable as CSV, detached from your identity when the account closes
Editor type (VS Code / Cursor / CLI…)Placement breakdown shown to the advertiserWith the impression record
Coarse network metadataAbuse preventionIP never kept as itself — irreversible fingerprint only, or no log at all

The table above is the complete list, field by field. Nothing else is collected: if it is not there, we do not receive it.

What we never collect

moula does not read, transmit or store your source code, your prompts, your keystrokes, your file names or paths, your open documents, your workspace or project names, your git history, or the list of your other extensions. The extension never asks the editor for any of it, so there is nothing to leak.

IP addresses

We do not keep raw IP addresses. If and when we keep network metadata to prevent abuse, your IP address is never recorded as itself: we keep only an irreversible fingerprint, computed by mixing in a secret value known to us alone. The computation runs one way only — the fingerprint cannot be turned back into your address, cannot be found by trying every possible address, and cannot be used to follow you from one service to another (technically: a salted hash). Our current rate limiting keeps no IP log at all.

Hosting, processors and transfers outside the EU

We rely on a small number of technical providers, acting as processors:

  • Vercel — application hosting.
  • Supabase — database and storage for account, impression and click data.
  • Stripe — collecting from advertisers and paying out developer earnings. Your bank and tax details are entered directly with Stripe and never pass through our servers.

Some of these providers are established outside the European Union, so part of the processing may take place there. Those transfers are covered by appropriate safeguards within the meaning of the GDPR — the European Commission’s standard contractual clauses, included in those providers’ data processing agreements, and where applicable their certification under the EU–US Data Privacy Framework. We never sell or rent your data, and no third-party cookie or advertising tracking pixel is set.

Retention

Impression and click records are kept because they are your earnings ledger — they are what lets you (and the advertiser) audit every cent. You can export your own ledger as CSV at any time. If you close your account, we delete your profile and your API keys and detach your ledger from your identity. API keys are never kept in a usable form: we hold only an irreversible fingerprint, so a database breach cannot reveal working credentials.

VS Code telemetry setting

moula respects VS Code’s global telemetry setting. If you have turned telemetry off (or set it below what moula would report), moula treats that as a ceiling and sends no optional telemetry. The ad request itself always needs your account key and an event id in order to pay you — that is the product, not analytics — but no separate usage telemetry is collected against your wishes.

How to opt out

You can stop all data flow at any time by putting moula to sleep, turning on presentation mode, erasing your API key, or uninstalling the extension. Opting out only suspends your earnings — it is never a breach of our Terms, and there is no penalty of any kind for turning moula off.

Who processes your data

The controller is the site publisher (see the legal notice). Contact for any question about data: dpo@moula.io.

We have not appointed a data protection officer: our activity falls under none of the cases that require one (article 37 GDPR). Requests are handled directly by the publisher, at the address above.

Targeting, profiling and automated decisions

An ad is chosen from three things only: the campaign’s category against the categories you have excluded, the language you accept, and a per-person repeat cap. Nothing else enters the selection.

There is no advertising profile, no behavioural segmentation and no auction. We do not build a picture of you, we do not sort you into an audience, and we neither resell nor share data for advertising purposes. Advertisers receive aggregate counters — impressions, clicks, how many distinct developers were reached — never your identity.

No decision producing legal effects or significantly affecting you is taken automatically within the meaning of article 22 GDPR. Freezing an account on suspicion of fraud is decided by a person, comes with a reason, and is reversible — write to us to contest it.

Cookies and trackers

No advertising cookies, no analytics trackers, no third-party pixels on our pages. We use only the cookies strictly necessary for the service to work: your session once you are signed in. They are exempt from prior consent, which is why you see no banner.

The client installed on your machine (extension and CLI) sets no cookies at all: there is no browser in the loop.

Your rights, and how to exercise them

You have the rights of access, rectification, erasure, restriction, objection and portability set out in articles 15 to 22 of the GDPR, as well as the right to withdraw your consent and to give directions about what happens to your data after your death.

In practice, without having to write to us:

  • Access and portabilityexport all of your data as readable JSON, from your dashboard, at any time.
  • Rectification — your account details can be changed directly in your preferences.
  • Objection — pausing delivery stops all collection of display events, immediately and without penalty.

For erasure and restriction, write to dpo@moula.io. We reply within one month (article 12.3 GDPR). One honest caveat: if a balance is owed to you or payouts have been made, the corresponding accounting records are kept for as long as the law requires — we cannot erase an invoice, and we will tell you precisely what is deleted and what is kept.

Finally, you may lodge a complaint with a supervisory authority. In France, the CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.

Changes to this policy

Any change is dated at the top of this page. If a change widens what we collect or what we do with it, we tell active accounts before it takes effect rather than relying on you to re-read the page.

Historique des modifications

7 July 2026
First publication.
24 July 2026
Transfers outside the EU added (standard contractual clauses and Data Privacy Framework).
5 August 2026
Right to erasure added (article 17): account deletion from the dashboard, and anonymisation of the records that are kept.
8 August 2026
The controller now refers to the legal notice; its identification by name is removed. English version published.