Legal · Privacy
Your information, handled with care.
Last updated · September 14, 2026
Moudgil Labs LLC (“Moudgil Labs,” “we,” “us”) builds custom software and AI for small businesses. This policy explains what we collect through this website, our consultations, and the client portal, how we use it, and the choices you have. We keep it in plain English, and we keep it short on purpose.
The short version
- We collect only what we need to answer you and do the work you ask for.
- We never sell your personal information, and we don't run advertising trackers on this site.
- Your data is yours, and so is every account that touches money. The software we build for you runs on infrastructure we operate and maintain — and you can ask for your data, or a copy of the code, whenever you like.
- If you're a client, your portal uses a sign-in and a session cookie. Paying an invoice happens on Stripe's secure page — we never see or store your card details.
- You can ask us what we hold, correct it, or have it deleted at any time.
Who we are
Moudgil Labs LLC is a New York City company. For any privacy question, or to exercise the rights described below, contact us at hello@moudgillabs.ai or +1 (917) 384-7082. We are the party responsible for the personal information described in this policy.
Information we collect
Information you give us
When you submit the consultation form or contact us, we collect what you choose to share — typically your name, your business name, your email address, your phone number, and the message you write about your operations. If you email or call us, we keep that correspondence so we can help you. If you have a client-portal account, what you send through it — support requests and uploaded files — also comes to us; the portal section below describes exactly how.
Information collected automatically
Like most websites, our host records basic technical information when you visit — your IP address, browser and device type, and the pages you request — for security, reliability, and aggregate understanding of how the site is used. We do not use this to build advertising profiles.
We also count a few things you do on the public pages, so we can tell which pages are useful and where the consultation form gives people trouble: that a call to action was pressed and where on the page it sat, that the form was started, that a field or the spam check refused a submission, and that a request was received. These counts carry no free text and nothing about you — only values from a short fixed list, such as "hero" or "form started", together with the address of the page you were on. Nothing you type is ever included.
When you first arrive we also keep, for the life of that browser tab only, a note of how you got here — a category such as "search", "social", or "an AI assistant" — and the page you landed on. The site or search you came from is reduced to that category immediately and is never stored, and neither is anything you searched for. If you go on to send us a consultation request, that category travels with it, so we can tell which pages bring people who want to work with us. It is cleared when the tab closes.
Payments
The public website doesn't take payments. If you're a client, your portal may show invoices with a Pay button — that button sends you to Stripe's secure, hosted payment page to complete payment. Moudgil Labs never sees, collects, or stores your card or bank details; Stripe processes the payment under its own terms and tells us only whether the invoice was paid. We store the invoice, the amount, and its paid or unpaid status — never the payment instrument.
How we use your information
- To respond to your inquiry and schedule a consultation.
- To provide, maintain, and improve the services you engage us for.
- To operate your client portal, if we've set one up for you, and to act on what you send us through it.
- To send you information you asked for, and important notices about work in progress.
- To issue and collect invoices, and keep accurate business records.
- To secure the site, prevent abuse, and comply with our legal obligations.
We use your contact details to reply to you and to carry out an engagement you've asked for. We do not send marketing email you didn't request, and there is no newsletter to unsubscribe from.
How we share information
We do not sell your personal information. We share it only with the service providers that help us run the business, and only to the extent they need it to do their job for us:
- Hosting & analytics — the website runs on a cloud hosting provider (Vercel), which also provides our cookieless, aggregate analytics.
- Database & sign-in — our database and sign-in system are hosted by Supabase, in the United States. What you send through the consultation form is stored there so we can read and respond to it, and so are client-portal accounts and the operational records that power the portal — projects, invoices, documents, and the files you upload. Supabase stores the data on our behalf under its own privacy terms; it does not use it for its own purposes.
- Spam protection — the consultation form uses Cloudflare Turnstile to tell people from bots. Cloudflare receives technical signals about the submission (including your IP address) for that check alone.
- Payments — invoice payments happen on Stripe's secure, hosted pages. Stripe processes them under its own terms and tells us only whether the invoice was paid — card and bank details never reach us.
- Email — when we send transactional email, such as an invoice or renewal notice, it goes through Resend, which handles the address and the message in order to deliver it.
These providers are bound by their own agreements and privacy commitments. We may also disclose information if required by law, to protect our rights or safety, or in connection with a business transfer — in which case we'll notify you as required.
Client data during an engagement
This policy covers the website, your inquiries, and the client portal. When you become a client, the way we handle your business's data is governed by the written engagement agreement we sign with you. Our standing practice, stated plainly: your data is yours. We hold it on your behalf and for nothing but the work you've asked us to do, we reach into it only as far as that work requires, and you can have a copy of it — or have it removed — whenever you ask. Every account that touches money stays in your name. We use business-grade services under proper data agreements — never random consumer tools — and we tell you where every piece of data goes before anything ships.
Worth being precise about where it sits. The software we build for you runs on infrastructure we operate and maintain — that's what lets us keep it patched, monitored, and one phone call away — so while we're running it for you, some of your business data lives there rather than on a server you administer. That changes who does the maintenance, not who owns the data. It stays yours, it goes with you, and the terms for it are in your engagement agreement, alongside what we own and what you're licensed to use.
One further distinction, so nothing is blurred. Everything above is about your business's own data. Separately, we keep our own operational records to run the working relationship — your contact details, the projects we are doing for you, invoices, documents, and notes — and those live in our systems, not yours, in the Supabase-hosted database described above. They are ours to maintain and protect, we do not sell them or use them for advertising, and you can ask us what we hold, correct it, or have it deleted, as set out below. Your client portal is a window onto some of those records — the next section explains it.
Your client portal and account
If we've set up a client portal account for you, here is exactly how it works:
- Accounts. We create accounts only for the specific people at your business you ask us to — there is no public signup. Signing in uses an email address and a password. We never see your password — it's set and stored by our authentication provider (Supabase), not by us. Sign-ins are recorded.
- What the portal shows you. Your projects and their status, your documents, your invoices and their payment status, your scope approvals, and — where enabled on your account — a summary of usage. The portal is built to show you your data and no one else's, and it deliberately hides our internal notes, our internal cost figures, and every other client's information.
- Cookies in the portal. Staying signed in requires a session cookie. It is strictly necessary for the portal to work, it is not used for advertising or cross-site tracking, and it is separate from the cookieless public site.
- Permissions. Each person you invite gets only the permissions you grant — for example, viewing projects, approving scope, viewing or paying invoices, downloading documents, or uploading files. You can ask us to change or remove anyone's access at any time.
- Uploads and requests. Files you upload and support requests you send through the portal come to us so we can act on them, and are recorded on your account's history. We accept a fixed set of file types — documents, images, spreadsheets, and plain text — cap uploads at about 1 MB, and check each file's actual contents before storing it. Stored files sit under your account, only Moudgil Labs staff can retrieve them, retrieval links expire within minutes, and every retrieval is logged.
Cookies and tracking
Browsing the public pages of this site sets no cookies of ours. Light or dark appearance simply follows your device's own system setting. We do not use advertising or cross-site tracking. We use privacy-friendly, cookieless analytics (Vercel Web Analytics) that record aggregate page views and the handful of interaction counts described above — no individual visitor is identified, and nobody is tracked across sites.
The one thing the public site keeps in your browser is the arrival note described above: a category and a page address, held in the tab's own temporary storage. It is not a cookie, it is never sent anywhere on its own, it cannot follow you to another site, and it disappears when you close the tab.
The one exception is signing in. If you have a client-portal account, signing in sets a session cookie so you stay signed in — it is strictly necessary, and it is described in the portal section above. The private, staff-only area we use to run Moudgil Labs works the same way. If you have not signed in to either, nothing in this paragraph applies to you.
How long we keep it
We keep inquiry and correspondence data for as long as needed to help you and to keep reasonable business records, then delete or anonymize it. Records tied to a paid engagement are kept as long as required for legal, tax, and accounting purposes. Client-portal account records, and the operational records tied to an engagement, are kept for the life of the engagement and as long as those same legal, tax, and accounting purposes require, then deleted or anonymized. You can ask us to delete your information sooner (see below), and we will unless we're required to keep it.
How we protect it
We use reputable providers, encrypted connections, and access controls to protect your information, and we limit who can see it to those who need to. Portal accounts are protected by passwords held by our authentication provider, access is scoped so each client sees only their own data, and administrative access to our systems is limited to Moudgil Labs staff. No method of transmission or storage is perfectly secure, but we work to hold your data to the standards our clients and their industries require — and if a security incident ever affects your information, we will investigate it, contain it, and notify you as applicable law requires.
Your rights and choices
You can ask us to show you the personal information we hold about you, correct it, or delete it — and you can opt out of any non-essential email at any time. Depending on where you live (for example, California and other U.S. states with privacy laws), you may have additional rights, including the right not to be discriminated against for exercising them. To make a request, email hello@moudgillabs.ai. We'll verify your request and respond within the time the law requires.
Children
This site and our services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16.
Third-party links
Our site may link to other websites. We aren't responsible for their content or privacy practices; please review their policies when you visit them.
Changes to this policy
We'll update this policy when our practices change, and we'll revise the “last updated” date above. If the change is significant, we'll make that clear.
Contact
Questions about this policy or your information? Email hello@moudgillabs.ai or call +1 (917) 384-7082. We read every message.