Privacy Policy

Mochi (MochiBuddy) · Last updated August 30, 2026

Mochi is a companion-pet to-do app. This policy describes what information the app and this website handle, why, and the choices you have. The short version: your data exists to make the app work for you. We do not run ads, we do not sell your data, and the usage statistics we collect never include the content you create. You can turn them off in the app.

Information we collect

Account information. When you sign in with Apple or Google, we receive an account identifier and, if you choose to share them, your name and email address. Authentication is handled by Firebase Authentication (a Google service). You can also use Mochi as a guest, which creates an anonymous account with no name or email attached.

Your content. The things you create in the app are stored in Google Cloud Firestore so they sync and survive reinstalls: your tasks and lists, your pet's name and adoption date, letters and journal moments the app writes for you, your completion history (including the local time of day tasks were completed, which powers features like Best Hours and suggested times), and your settings such as bedtime, vacation mode, and notification preferences.

Purchase information. Subscriptions are billed entirely by Apple; we never see your payment details. We use RevenueCat to validate App Store receipts and keep track of your subscription status. RevenueCat receives your app account identifier and purchase history for this purpose.

Usage analytics. We use PostHog to understand which features are used and how often, so we can improve the app. This includes events like the app being opened, a task being completed, or an onboarding step being finished, described with coarse labels only. Analytics events never include the content you create: no task titles, list names, letter or journal text, pet names, or completion times. Events are linked to a pseudonymous account identifier, not your name or email. It is the same internal identifier your account has in our database and subscription systems, so analytics are pseudonymous rather than anonymous: they do not name you, but they describe your account's usage. Like most analytics tools, PostHog also receives technical details with each event (device model, OS and app version, language, timezone) and your IP address, from which it derives an approximate, city-level location for the event. Data is processed on PostHog's United States cloud. You can turn analytics off at any time in the app (You tab, "Share usage analytics"), which stops both analytics and crash reporting.

Crash and error reports. If the app crashes or hits an internal error, a report is sent through PostHog so we can find and fix the problem. Reports contain technical details (the type of error, a code-level stack trace, and a trail of the same coarse analytics events leading up to the failure) and are linked to the same pseudonymous identifier. They never contain your tasks, letters, or other content. The analytics toggle in the app turns these off too.

What we do not collect. Mochi contains no advertising, no data brokers, and no cross-app tracking. Analytics do not record your screen or the content you type. We do not collect your precise location, contacts, or browsing activity.

Information that stays on your device

How we use information

That is the whole list. We do not use your data for advertising or sell it to anyone.

Who we share information with

We share data only with the service providers that run the app's infrastructure, and only what each needs to do its job:

We may also disclose information if required by law.

This website

The site you are reading is a static page hosted on GitHub Pages; it sets no cookies and runs no analytics or trackers. Three things on it do talk to other services:

Data retention and deletion

Your data is kept as long as your account exists. You can delete your account at any time in the app (You tab, Delete account). Deletion erases your content from our database, removes your authentication record, and deletes your customer record from RevenueCat. It also resets the analytics identifier on your device. Analytics events collected before deletion contain no content you created; if you would like them erased as well, email us and we will delete them.

Analytics and crash events are otherwise retained in PostHog until we delete them; email us if you want yours erased sooner. Support emails and form submissions are kept as long as needed to resolve the conversation or, for the updates list, until you unsubscribe.

Deleting your account does not cancel an active subscription, because subscriptions are managed by Apple. To stop billing, cancel in Settings on your device (Settings, your name, Subscriptions) before or after deleting your account. If you return later, Restore Purchases will reconnect an active subscription to your new account.

Security

Data is encrypted in transit using HTTPS/TLS and stored on Google, RevenueCat, and PostHog infrastructure. Access to your content is restricted to your own account by server-side security rules.

Children

Mochi is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Most of these you can exercise directly in the app; for anything else, email us and we will help.

Changes to this policy

If we change this policy, we will update the date at the top of this page. Meaningful changes will be called out in the app.

Contact

Questions about privacy or your data: asquared.dev@gmail.com