Privacy Policy

Last updated: September 5, 2026

1. Who we are

mood.cards is a service of Squared Lemon. When we say "we", "us", or "our" in this policy, we mean Squared Lemon, the operator of the mood.cards service.

2. Two roles we play

We act in two distinct capacities under the GDPR:

3. What data we collect

Account data (controller)

When you create an account we collect:

We use this data solely to operate your account, authenticate you, and communicate service-related information.

To look into a problem, we can open your dashboard ourselves and see your projects, your cards, and the feedback in them. That access is read only: nothing can be changed or deleted while we are in there. Every time it happens we record who looked, which team they looked at, and when.

Feedback submission data (processor)

When an end-user interacts with a mood.cards widget on your site, we may receive:

We do not add tracking cookies, fingerprint end-users, or collect data beyond what your integration explicitly sends.

To detect abuse of the widget API we keep a short-lived count of requests per visitor. The visitor's IP address is hashed with a secret key before that count is stored, and the address itself is never written to our database or our logs. The hash expires after one minute.

Website analytics

We use Fathom Analytics (referral link) on our marketing site, our docs and the dashboard. It sets no cookies, so this site has no cookie banner. Section 9 lists what we send to Fathom and what its script picks up on its own.

Fathom describes its own service as collecting no personal data, not tracking individual visitors, and complying with GDPR, ePrivacy, PECR and CCPA. That is their account of their handling, not something we can vouch for on their behalf.

4. How we use data

We use the data we collect to:

We do not sell, rent, or share personal data with third parties for marketing purposes.

5. Where data is stored

All data is stored on servers located in the European Union. Data does not leave the EU unless you explicitly export it.

6. Data retention

7. Your rights (GDPR)

If you are located in the EU/EEA, you have the right to:

Erasure you can do yourself. Deleting your account from the dashboard removes your personal data immediately, as described in section 6. To exercise any of the other rights, contact us at the email address listed below.

For end-users of our customers' sites

If you submitted feedback through a mood.cards widget on someone else's website, that website's operator is the data controller. Please contact them directly to exercise your rights. They may then instruct us to delete or export your data on their behalf.

8. Security

We take reasonable technical and organizational measures to protect data, including:

9. Third-party services

We use the following third-party services:

ServicePurposeData shared
Fathom Analytics Website analytics Page address, referring site, campaign tags on the link you arrived through. No cookies. See below
Bunny Fonts Web font delivery (Quicksand) IP address, browser headers (no logging, GDPR-compliant by design)

What Fathom receives from a dashboard page

Dashboard addresses contain the IDs of your projects and cards. We do not send those. The address we report is the template of the page rather than the page itself, so a card page is sent as /dashboard/projects/:project/cards/:card and the two IDs never leave our servers.

We do not send the query string either, but Fathom's script reads it for itself and picks up a fixed list of campaign tags, utm_source and the like. Those are for links into our marketing pages. None of the filters you set on a dashboard page carry one of those names, and we test for that, so your filters stay here.

Your IP address and browser headers reach Fathom as part of the request, as they do with any third-party service. Fathom states that it uses them to generate an anonymous hash and does not store them.

The widget on a customer's website loads no analytics at all. Fathom is not present there in any form.

10. Cookies and local storage

The mood.cards service uses essential cookies only: a session cookie for logged-in users and a CSRF token. We do not use tracking cookies, advertising cookies, or any third-party cookies. Because of this, we do not display a cookie consent banner.

The mood.cards widget embedded on a customer's site stores small amounts of data on the visitor's device, for functional purposes only. These values are pseudonymous. They are never used to identify anyone, never shared with third parties, and never used to track a visitor from one site to another. Browser storage is scoped to the site you are on, so a value written on one customer's site cannot be read on any other:

KeyStoragePurpose
mc_aid sessionStorage Anonymous per-session ID. Written only when you submit feedback, and used to link a comment to the rating you just gave. Cleared when the tab closes.
mc_seen_<cardId> localStorage Suppresses a card the visitor has already answered, closed, or left unanswered, when the card's visibility is set to "once" or "cooldown". Stores either "1" or a timestamp.
mc_session_<cardId> sessionStorage Suppresses a card for the rest of the visitor's session, when the card's visibility is set to "session".
mc_config_<apiKey> localStorage Caches the customer's card configuration to avoid refetching on every page load. Discarded after 30 days.

These keys fall under the "strictly necessary" exemption in Article 5(3) of the ePrivacy Directive, because each one exists to deliver the feedback service to you, the visitor. The suppression keys are written when a card is answered, when it is closed, or when it fades away unanswered, and their only purpose is to stop the same question being asked again. The session ID is written only when you submit feedback. It lasts until you close the tab, and exists to link your rating to a comment you add straight after it. If you see a card and never answer it, no session ID is created.

None of these keys are meant to outlive the service they support. The widget discards its cached configuration after 30 days, and clears the suppression keys for any card the customer has removed.

The optional proof widget, the embeddable badge that shows a card's average rating on a customer's marketing pages, sets no cookies and writes no data to the visitor's device. It displays aggregate numbers only (an average and a rating count), never individual comments or any personal data. Because it stores nothing and identifies no one, it also requires no cookie banner.

11. Affiliate links

When we link to a recommended third-party service we sometimes use a referral link that earns us a small commission if you sign up. We only recommend services we use ourselves and the commission never affects which tools we choose. Referral links are clearly marked as such inline.

12. Changes to this policy

We may update this policy from time to time. We will notify account holders of material changes via email. The "last updated" date at the top reflects the most recent revision.

13. Contact

For privacy-related questions or to exercise your rights, contact us at:

squeeze@squaredlemon.com