Privacy Policy
Information under Articles 13 and 14 GDPR · version 0.9, 27 August 2026
Information under Articles 13 and 14 of Regulation (EU) 2016/679
| Controller | MORU-TECH Ltd., UIC 208895389 |
|---|---|
| Product | Moru: web application/PWA and desktop widget |
| Version and date | 0.9 / 27 August 2026 |
| Status | Public document — working draft |
Legal framework: Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act, applicable rules on electronic communications, and the national implementing legislation.
1. Who we are
The controller of personal data is MORU-TECH Ltd., UIC 208895389, with registered office and management address at 4001 Plovdiv, Zapaden District, 124 Peshtersko Shose Blvd., Entrance A, Floor 6, Apt. A34, represented by Igor Romanenko.
For questions about the service, contact us at [email protected]. For questions and requests concerning personal data, use [email protected].
This Policy applies to the website and services available at moru-tech.com, app.moru-tech.com and api.moru-tech.com, as well as to the Moru desktop widget for macOS and Windows.
2. What Moru is
Moru is a digital wellness service for exercises, eye care and an indicative assessment of fatigue when working with a screen. The service uses the device camera to temporarily analyse eye movement, blinking, head position and other signals needed for the exercises and assessments.
| Wellness, not a medical serviceMoru does not diagnose, provide medical advice, or replace consultation with a doctor. If you have health concerns, seek advice from a qualified medical professional. |
|---|
3. The most important information about the camera
The video stream is processed temporarily on your device.
Raw frames, photographs, facial landmarks and iris landmarks are not sent to our servers and are not written to disk.
Moru does not use your face for recognition, authentication or identity verification and does not create a biometric template for identification.
Only derived numerical indicators and training data linked to the pseudonymous identifier of your account are sent to the server.
Fatigue indicators, eye-strain indicators and related self-assessments are treated as health data and are processed only after explicit consent.
Separately from camera processing, you may choose to upload a JPEG avatar. The avatar is stored in your profile until you remove it or delete your account.
4. What data we process
| Category | Data |
|---|---|
| Account and login | Email address, password hash, optional name, UUID/sub, settings, language, account status and history; for Google Sign-In — Google account identifier and email address. |
| Onboarding | Screen time, selected symptoms and intended use. These data are processed only after explicit consent where they reveal health information. |
| Local video | Short-lived video frames and facial/iris mesh held in RAM and used only to calculate indicators on the device. |
| Web training | Session time, exercise type, completion, accuracy, stability, head control, blink rate, tracking quality, screen/device data, session_trace containing estimated gaze direction and head position, and calibration data. |
| Desktop measurements | Pseudonymous device ID, measurement time and window duration, blink rate, PERCLOS, screen distance, head pitch/yaw, confidence and gating flags such as low light, no face detected or camera busy. |
| Scores and self-assessments | Fatigue score, fixed wellness recommendations, eye-strain/fatigue self-assessments, labels and trends. |
| Technical data | IP address when communicating with providers and for security, user-agent, browser, operating system, resolution, language, timestamps, access logs, error logs and administrative activity logs. |
| Analytics | After your choice: screens, sections, clicks, onboarding, training/game events, PWA installation and normalized errors. We do not send health symptoms, measurements or fatigue scores to analytics or advertising providers. |
| Communications | Content of enquiries, feedback, optional email address and files you send to us. |
| Marketing | Only after separate consent: email/push preferences and limited campaign measurement events via Google Ads and Meta Pixel. |
| Business enquiries | Business email, company, team size, role, country, description of need and UTM parameters when you use the B2B contact form. |
| Payments | As of this version, Moru does not accept payments and does not collect payment-card data. This Policy will be updated before a payment provider is introduced. |
5. Why we process data and the legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing an account; providing the core service | Performance of a contract or steps prior to entering into a contract — Article 6(1)(b) GDPR. |
| Health-related measurements and assessments | Performance of the service — Article 6(1)(b) GDPR, and explicit consent for special categories of data — Article 9(2)(a) GDPR. |
| Local camera activation | Explicit consent and an active action by the user; the operating system/browser camera permission is an additional technical safeguard but does not replace GDPR consent. |
| Product analytics and diagnostics through non-essential technologies | Consent — Article 6(1)(a) GDPR and the applicable rules on access to or storage of information on the terminal device. |
| Marketing communications and advertising measurement | Separate consent — Article 6(1)(a) GDPR and the applicable rules on electronic marketing. |
| Security, abuse prevention, rate limiting and incident investigation | Legitimate interests — Article 6(1)(f) GDPR: protecting users, the service and infrastructure. |
| Responding to enquiries and support | Performance of a contract or legitimate interests in communication and support — Article 6(1)(b) and/or (f) GDPR. |
| Business enquiries | Steps prior to a contract and/or legitimate interests in responding to the enquiry — Article 6(1)(b) and/or (f) GDPR. Subsequent marketing is carried out only on a valid legal basis. |
| Legal obligations and defence of claims | Article 6(1)(c) and (f) GDPR; where health data are involved, Article 9(2)(f) GDPR only to the extent necessary for legal claims. |
6. Explicit consent and withdrawal
Before the first collection of health-related indicators, Moru displays a short notice and requests separate explicit consent. Consent for measurements is separate from consent for analytics and marketing.
You may refuse. The camera and health-related measurements will not start.
You may withdraw consent in the Privacy Center. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
After withdrawal, we stop new measurements, clear the unsent local buffer and stop using the camera for this function.
If you also request deletion of your health history, we delete it from active systems without undue delay and generally within 30 days; backups are overwritten within the ordinary 14-day rotation cycle.
If processing is necessary for a core Moru function, that function will no longer be available after withdrawal. You may keep your account without active measurements or delete it.
7. How the fatigue score is calculated
The current version does not use an LLM and does not send data to an external AI model. The rules-v1 score is calculated using predefined mathematical rules applied to derived indicators. The system displays a numerical value, a qualitative description and a recommendation from a fixed set.
The score is indicative. It may be inaccurate in low light, when wearing glasses, with an unsuitable camera, if the face is obscured, during movement, with an unusual position or when tracking confidence is insufficient. Moru uses confidence and gating flags and may withhold a result when quality is insufficient.
Moru does not make decisions that produce legal effects or similarly significantly affect you. You may request an explanation of the data used and the rules version and may report an incorrect result.
8. Analytics, cookies and similar technologies
Strictly necessary technologies support login, security, settings and operation of the service. Optional product analytics/diagnostics and, separately, marketing measurement may be enabled. Details are set out in the Cookie and Similar Technologies Policy.
PostHog and GA4 are activated only after analytics consent.
Google Ads and Meta Pixel are activated only after separate marketing consent.
Symptoms, health labels, eye-strain, fatigue score, calibration vectors, session_trace, PERCLOS, blink rate and other health/biometric-derived values are not sent to analytics or advertising platforms.
You may change your choices at any time in the Privacy Center.
9. With whom we share data
| Recipient | Role / purpose |
|---|---|
| Hetzner | Hosting, database and backups in Germany. |
| PostHog | Product analytics and diagnostics after consent; EU region; only approved pseudonymised events. |
| Google Sign-In, Google Workspace for service emails, GA4/GTM and Google Ads after the relevant consent; until self-hosting is introduced, delivery of the MediaPipe model from Google Cloud Storage. | |
| Cloudflare | TLS/CDN, security, Turnstile and coarse country determination by IP to block access from Russia/Belarus. According to the current architecture, API traffic is not proxied through Cloudflare. |
| jsDelivr | Delivery of the MediaPipe WASM resource until migration to self-hosting. |
| Meta | Meta Pixel only after marketing consent and only for non-health events. |
| Authorised persons | A limited group of administrators, employees, external developers and legal/accounting advisers where necessary and subject to confidentiality obligations. |
| Authorities and courts | Where disclosure is required by law or necessary to protect rights. |
The current list of suppliers and their roles is maintained in the internal processor register. We do not sell personal data. We do not provide individual results to employers or other organisations under the current B2C model.
10. International transfers
The main first-party systems and databases are located in Germany. Some providers are US companies or use global infrastructure, so limited data may be accessed or transferred outside the EEA, for example IP address, OAuth data, service emails and non-health analytics/marketing events.
Where data are transferred outside the EEA, we use an applicable mechanism under Chapter V GDPR — an adequacy decision, including the EU–US Data Privacy Framework where the specific recipient is validly certified, and/or Standard Contractual Clauses with supplementary measures. You may request further information and a copy of the applicable safeguards at [email protected].
11. How long we keep data
| Data | Retention period |
|---|---|
| Account | While active; after 6 months of inactivity — notice and deletion, unless you sign in again or a legal basis requires longer retention. |
| Measurements, sessions, fatigue score, surveys and calibration | 6 months from creation, unless you delete them earlier or give separate consent for another lawful purpose. |
| PostHog/GA4 analytics | Up to 12 months, subject to provider settings and a shorter period where technically possible. |
| Technical and security logs | Up to 12 months; ordinary web/rate-limit logs generally up to 90 days. |
| Backups | Rotating window of up to 14 days. |
| Local offline queue | Until successful transmission, but no more than 7 days; cleared on logout, withdrawal or deletion. |
| Enquiries and support | Up to 12 months after closure, unless there is a dispute. |
| B2B contact data | Up to 6 months after the last meaningful contact, unless negotiations have started or separate consent has been given. |
| Records of consent, rights requests and incidents | Up to 5 years for demonstrating compliance and defending claims. |
The detailed schedule and deletion rules are set out in the Retention and Deletion Policy. When the period expires, data are deleted or irreversibly anonymised unless the law requires otherwise.
12. Your rights
to receive information about and access to your personal data;
to receive a copy and, where applicable, a portable file;
to correct inaccurate or incomplete data;
to request deletion;
to request restriction of processing;
to object to processing based on legitimate interests;
to withdraw consent at any time;
to receive an explanation and challenge an automated assessment;
to lodge a complaint with a supervisory authority.
Send your request to [email protected]. As a rule, we will respond within one month. For complex or numerous requests, the period may be extended by a further two months, and we will inform you of the extension. We may request proportionate information to verify your identity.
You may lodge a complaint with the Bulgarian Commission for Personal Data Protection, 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria, or with the supervisory authority at your habitual residence, place of work or place of the alleged infringement.
13. Age restrictions
Moru is intended for persons aged 16 or over. At registration, we request confirmation of the minimum age. We do not routinely collect a copy of an identity document. If we reasonably establish that an account is being used by a person under 16, we may restrict the service and delete the data unless a lawful parental-consent mechanism applies.
14. Security
We apply measures such as encrypted connections, access controls, multi-factor authentication for administrative accounts, RLS/role-based permissions, separate development and production environments, pseudonymisation, logging, backups, restoration testing and payload restrictions.
No measure can eliminate risk completely. In the event of a security breach, we assess the risk and, where required by the GDPR, notify the competent supervisory authority and affected individuals.
15. Changes to this Policy
We may update this Policy when the service, law, suppliers or purposes change. We publish the new version with its date. Where a material change affects consent or introduces a new purpose for health data, we will request new consent before processing.
16. Contact
| Question | Contact |
|---|---|
| General questions and support | [email protected] |
| Personal data and rights | [email protected] |
Sources and legal basis
Regulation (EU) 2016/679 (GDPR), in particular Articles 5, 6, 7, 9, 12–22, 24–25, 28, 30, 32–36 and 44–49.
European Data Protection Board Guidelines 05/2020 on consent.
EDPB guidance on data protection impact assessments for high-risk processing.
EDPB Guidelines 9/2022 on personal data breach notification.
EDPB Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive.