← All documents

Privacy Policy

Information under Articles 13 and 14 GDPR · version 0.9, 27 August 2026

Information under Articles 13 and 14 of Regulation (EU) 2016/679

ControllerMORU-TECH Ltd., UIC 208895389
ProductMoru: web application/PWA and desktop widget
Version and date0.9 / 27 August 2026
StatusPublic document — working draft

Legal framework: Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act, applicable rules on electronic communications, and the national implementing legislation.

1. Who we are

The controller of personal data is MORU-TECH Ltd., UIC 208895389, with registered office and management address at 4001 Plovdiv, Zapaden District, 124 Peshtersko Shose Blvd., Entrance A, Floor 6, Apt. A34, represented by Igor Romanenko.

For questions about the service, contact us at [email protected]. For questions and requests concerning personal data, use [email protected].

This Policy applies to the website and services available at moru-tech.com, app.moru-tech.com and api.moru-tech.com, as well as to the Moru desktop widget for macOS and Windows.

2. What Moru is

Moru is a digital wellness service for exercises, eye care and an indicative assessment of fatigue when working with a screen. The service uses the device camera to temporarily analyse eye movement, blinking, head position and other signals needed for the exercises and assessments.

Wellness, not a medical serviceMoru does not diagnose, provide medical advice, or replace consultation with a doctor. If you have health concerns, seek advice from a qualified medical professional.

3. The most important information about the camera

The video stream is processed temporarily on your device.

Raw frames, photographs, facial landmarks and iris landmarks are not sent to our servers and are not written to disk.

Moru does not use your face for recognition, authentication or identity verification and does not create a biometric template for identification.

Only derived numerical indicators and training data linked to the pseudonymous identifier of your account are sent to the server.

Fatigue indicators, eye-strain indicators and related self-assessments are treated as health data and are processed only after explicit consent.

Separately from camera processing, you may choose to upload a JPEG avatar. The avatar is stored in your profile until you remove it or delete your account.

4. What data we process

CategoryData
Account and loginEmail address, password hash, optional name, UUID/sub, settings, language, account status and history; for Google Sign-In — Google account identifier and email address.
OnboardingScreen time, selected symptoms and intended use. These data are processed only after explicit consent where they reveal health information.
Local videoShort-lived video frames and facial/iris mesh held in RAM and used only to calculate indicators on the device.
Web trainingSession time, exercise type, completion, accuracy, stability, head control, blink rate, tracking quality, screen/device data, session_trace containing estimated gaze direction and head position, and calibration data.
Desktop measurementsPseudonymous device ID, measurement time and window duration, blink rate, PERCLOS, screen distance, head pitch/yaw, confidence and gating flags such as low light, no face detected or camera busy.
Scores and self-assessmentsFatigue score, fixed wellness recommendations, eye-strain/fatigue self-assessments, labels and trends.
Technical dataIP address when communicating with providers and for security, user-agent, browser, operating system, resolution, language, timestamps, access logs, error logs and administrative activity logs.
AnalyticsAfter your choice: screens, sections, clicks, onboarding, training/game events, PWA installation and normalized errors. We do not send health symptoms, measurements or fatigue scores to analytics or advertising providers.
CommunicationsContent of enquiries, feedback, optional email address and files you send to us.
MarketingOnly after separate consent: email/push preferences and limited campaign measurement events via Google Ads and Meta Pixel.
Business enquiriesBusiness email, company, team size, role, country, description of need and UTM parameters when you use the B2B contact form.
PaymentsAs of this version, Moru does not accept payments and does not collect payment-card data. This Policy will be updated before a payment provider is introduced.

5. Why we process data and the legal basis

PurposeLegal basis
Creating and managing an account; providing the core servicePerformance of a contract or steps prior to entering into a contract — Article 6(1)(b) GDPR.
Health-related measurements and assessmentsPerformance of the service — Article 6(1)(b) GDPR, and explicit consent for special categories of data — Article 9(2)(a) GDPR.
Local camera activationExplicit consent and an active action by the user; the operating system/browser camera permission is an additional technical safeguard but does not replace GDPR consent.
Product analytics and diagnostics through non-essential technologiesConsent — Article 6(1)(a) GDPR and the applicable rules on access to or storage of information on the terminal device.
Marketing communications and advertising measurementSeparate consent — Article 6(1)(a) GDPR and the applicable rules on electronic marketing.
Security, abuse prevention, rate limiting and incident investigationLegitimate interests — Article 6(1)(f) GDPR: protecting users, the service and infrastructure.
Responding to enquiries and supportPerformance of a contract or legitimate interests in communication and support — Article 6(1)(b) and/or (f) GDPR.
Business enquiriesSteps prior to a contract and/or legitimate interests in responding to the enquiry — Article 6(1)(b) and/or (f) GDPR. Subsequent marketing is carried out only on a valid legal basis.
Legal obligations and defence of claimsArticle 6(1)(c) and (f) GDPR; where health data are involved, Article 9(2)(f) GDPR only to the extent necessary for legal claims.

6. Explicit consent and withdrawal

Before the first collection of health-related indicators, Moru displays a short notice and requests separate explicit consent. Consent for measurements is separate from consent for analytics and marketing.

You may refuse. The camera and health-related measurements will not start.

You may withdraw consent in the Privacy Center. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

After withdrawal, we stop new measurements, clear the unsent local buffer and stop using the camera for this function.

If you also request deletion of your health history, we delete it from active systems without undue delay and generally within 30 days; backups are overwritten within the ordinary 14-day rotation cycle.

If processing is necessary for a core Moru function, that function will no longer be available after withdrawal. You may keep your account without active measurements or delete it.

7. How the fatigue score is calculated

The current version does not use an LLM and does not send data to an external AI model. The rules-v1 score is calculated using predefined mathematical rules applied to derived indicators. The system displays a numerical value, a qualitative description and a recommendation from a fixed set.

The score is indicative. It may be inaccurate in low light, when wearing glasses, with an unsuitable camera, if the face is obscured, during movement, with an unusual position or when tracking confidence is insufficient. Moru uses confidence and gating flags and may withhold a result when quality is insufficient.

Moru does not make decisions that produce legal effects or similarly significantly affect you. You may request an explanation of the data used and the rules version and may report an incorrect result.

8. Analytics, cookies and similar technologies

Strictly necessary technologies support login, security, settings and operation of the service. Optional product analytics/diagnostics and, separately, marketing measurement may be enabled. Details are set out in the Cookie and Similar Technologies Policy.

PostHog and GA4 are activated only after analytics consent.

Google Ads and Meta Pixel are activated only after separate marketing consent.

Symptoms, health labels, eye-strain, fatigue score, calibration vectors, session_trace, PERCLOS, blink rate and other health/biometric-derived values are not sent to analytics or advertising platforms.

You may change your choices at any time in the Privacy Center.

9. With whom we share data

RecipientRole / purpose
HetznerHosting, database and backups in Germany.
PostHogProduct analytics and diagnostics after consent; EU region; only approved pseudonymised events.
GoogleGoogle Sign-In, Google Workspace for service emails, GA4/GTM and Google Ads after the relevant consent; until self-hosting is introduced, delivery of the MediaPipe model from Google Cloud Storage.
CloudflareTLS/CDN, security, Turnstile and coarse country determination by IP to block access from Russia/Belarus. According to the current architecture, API traffic is not proxied through Cloudflare.
jsDelivrDelivery of the MediaPipe WASM resource until migration to self-hosting.
MetaMeta Pixel only after marketing consent and only for non-health events.
Authorised personsA limited group of administrators, employees, external developers and legal/accounting advisers where necessary and subject to confidentiality obligations.
Authorities and courtsWhere disclosure is required by law or necessary to protect rights.

The current list of suppliers and their roles is maintained in the internal processor register. We do not sell personal data. We do not provide individual results to employers or other organisations under the current B2C model.

10. International transfers

The main first-party systems and databases are located in Germany. Some providers are US companies or use global infrastructure, so limited data may be accessed or transferred outside the EEA, for example IP address, OAuth data, service emails and non-health analytics/marketing events.

Where data are transferred outside the EEA, we use an applicable mechanism under Chapter V GDPR — an adequacy decision, including the EU–US Data Privacy Framework where the specific recipient is validly certified, and/or Standard Contractual Clauses with supplementary measures. You may request further information and a copy of the applicable safeguards at [email protected].

11. How long we keep data

DataRetention period
AccountWhile active; after 6 months of inactivity — notice and deletion, unless you sign in again or a legal basis requires longer retention.
Measurements, sessions, fatigue score, surveys and calibration6 months from creation, unless you delete them earlier or give separate consent for another lawful purpose.
PostHog/GA4 analyticsUp to 12 months, subject to provider settings and a shorter period where technically possible.
Technical and security logsUp to 12 months; ordinary web/rate-limit logs generally up to 90 days.
BackupsRotating window of up to 14 days.
Local offline queueUntil successful transmission, but no more than 7 days; cleared on logout, withdrawal or deletion.
Enquiries and supportUp to 12 months after closure, unless there is a dispute.
B2B contact dataUp to 6 months after the last meaningful contact, unless negotiations have started or separate consent has been given.
Records of consent, rights requests and incidentsUp to 5 years for demonstrating compliance and defending claims.

The detailed schedule and deletion rules are set out in the Retention and Deletion Policy. When the period expires, data are deleted or irreversibly anonymised unless the law requires otherwise.

12. Your rights

to receive information about and access to your personal data;

to receive a copy and, where applicable, a portable file;

to correct inaccurate or incomplete data;

to request deletion;

to request restriction of processing;

to object to processing based on legitimate interests;

to withdraw consent at any time;

to receive an explanation and challenge an automated assessment;

to lodge a complaint with a supervisory authority.

Send your request to [email protected]. As a rule, we will respond within one month. For complex or numerous requests, the period may be extended by a further two months, and we will inform you of the extension. We may request proportionate information to verify your identity.

You may lodge a complaint with the Bulgarian Commission for Personal Data Protection, 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria, or with the supervisory authority at your habitual residence, place of work or place of the alleged infringement.

13. Age restrictions

Moru is intended for persons aged 16 or over. At registration, we request confirmation of the minimum age. We do not routinely collect a copy of an identity document. If we reasonably establish that an account is being used by a person under 16, we may restrict the service and delete the data unless a lawful parental-consent mechanism applies.

14. Security

We apply measures such as encrypted connections, access controls, multi-factor authentication for administrative accounts, RLS/role-based permissions, separate development and production environments, pseudonymisation, logging, backups, restoration testing and payload restrictions.

No measure can eliminate risk completely. In the event of a security breach, we assess the risk and, where required by the GDPR, notify the competent supervisory authority and affected individuals.

15. Changes to this Policy

We may update this Policy when the service, law, suppliers or purposes change. We publish the new version with its date. Where a material change affects consent or introduces a new purpose for health data, we will request new consent before processing.

16. Contact

QuestionContact
General questions and support[email protected]
Personal data and rights[email protected]

Sources and legal basis

Regulation (EU) 2016/679 (GDPR), in particular Articles 5, 6, 7, 9, 12–22, 24–25, 28, 30, 32–36 and 44–49.

European Data Protection Board Guidelines 05/2020 on consent.

EDPB guidance on data protection impact assessments for high-risk processing.

EDPB Guidelines 9/2022 on personal data breach notification.

EDPB Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive.