Privacy Policy
Mochi (MochiBuddy) · Last updated August 30, 2026
Mochi is a companion-pet to-do app. This policy describes what information the app and this website handle, why, and the choices you have. The short version: your data exists to make the app work for you. We do not run ads, we do not sell your data, and the usage statistics we collect never include the content you create. You can turn them off in the app.
Information we collect
Account information. When you sign in with Apple or Google, we receive an account identifier and, if you choose to share them, your name and email address. Authentication is handled by Firebase Authentication (a Google service). You can also use Mochi as a guest, which creates an anonymous account with no name or email attached.
Your content. The things you create in the app are stored in Google Cloud Firestore so they sync and survive reinstalls: your tasks and lists, your pet's name and adoption date, letters and journal moments the app writes for you, your completion history (including the local time of day tasks were completed, which powers features like Best Hours and suggested times), and your settings such as bedtime, vacation mode, and notification preferences.
Purchase information. Subscriptions are billed entirely by Apple; we never see your payment details. We use RevenueCat to validate App Store receipts and keep track of your subscription status. RevenueCat receives your app account identifier and purchase history for this purpose.
Usage analytics. We use PostHog to understand which features are used and how often, so we can improve the app. This includes events like the app being opened, a task being completed, or an onboarding step being finished, described with coarse labels only. Analytics events never include the content you create: no task titles, list names, letter or journal text, pet names, or completion times. Events are linked to a pseudonymous account identifier, not your name or email. It is the same internal identifier your account has in our database and subscription systems, so analytics are pseudonymous rather than anonymous: they do not name you, but they describe your account's usage. Like most analytics tools, PostHog also receives technical details with each event (device model, OS and app version, language, timezone) and your IP address, from which it derives an approximate, city-level location for the event. Data is processed on PostHog's United States cloud. You can turn analytics off at any time in the app (You tab, "Share usage analytics"), which stops both analytics and crash reporting.
Crash and error reports. If the app crashes or hits an internal error, a report is sent through PostHog so we can find and fix the problem. Reports contain technical details (the type of error, a code-level stack trace, and a trail of the same coarse analytics events leading up to the failure) and are linked to the same pseudonymous identifier. They never contain your tasks, letters, or other content. The analytics toggle in the app turns these off too.
What we do not collect. Mochi contains no advertising, no data brokers, and no cross-app tracking. Analytics do not record your screen or the content you type. We do not collect your precise location, contacts, or browsing activity.
Information that stays on your device
- Apple Reminders. If you grant access, Mochi shows reminders from the lists you choose and can mark them completed. Your Reminders data is read on your device and is never uploaded to our servers.
- Photos. If you save a letter card, Mochi adds the image to your photo library. It cannot read, browse, or modify your existing photos.
- Notifications. Reminders and check-ins are scheduled locally on your device.
How we use information
- To provide the app: syncing your tasks, powering your pet's mood, writing letters and journal entries, and scheduling reminders.
- To manage your subscription and restore purchases.
- To understand which features people use and to find and fix crashes and bugs, using the pseudonymous analytics described above.
- To respond when you contact us for support.
That is the whole list. We do not use your data for advertising or sell it to anyone.
Who we share information with
We share data only with the service providers that run the app's infrastructure, and only what each needs to do its job:
- Google Firebase (authentication, database, configuration). See the Firebase privacy documentation.
- RevenueCat (subscription management). See the RevenueCat privacy policy.
- PostHog (usage analytics and crash reports, hosted in the United States). See the PostHog privacy policy.
- Apple (payments, and sign-in if you use Apple ID).
- Formspree (the contact forms on this website). See the Formspree privacy policy.
We may also disclose information if required by law.
This website
The site you are reading is a static page hosted on GitHub Pages; it sets no cookies and runs no analytics or trackers. Three things on it do talk to other services:
- Hosting and fonts. GitHub (the host) and Google Fonts (the typefaces) receive the standard technical data any web request carries, such as your IP address and browser type. The roadmap board on the home page also fetches its list from the GitHub API when the page loads.
- The feedback and updates forms are processed by Formspree and delivered to our inbox. The feedback form sends the message you write plus an email address only if you choose to give one. The updates form sends your email address, which we use only to send occasional Mochi news. You can leave the list or ask us to delete a submission at any time by replying to any email.
Data retention and deletion
Your data is kept as long as your account exists. You can delete your account at any time in the app (You tab, Delete account). Deletion erases your content from our database, removes your authentication record, and deletes your customer record from RevenueCat. It also resets the analytics identifier on your device. Analytics events collected before deletion contain no content you created; if you would like them erased as well, email us and we will delete them.
Analytics and crash events are otherwise retained in PostHog until we delete them; email us if you want yours erased sooner. Support emails and form submissions are kept as long as needed to resolve the conversation or, for the updates list, until you unsubscribe.
Deleting your account does not cancel an active subscription, because subscriptions are managed by Apple. To stop billing, cancel in Settings on your device (Settings, your name, Subscriptions) before or after deleting your account. If you return later, Restore Purchases will reconnect an active subscription to your new account.
Security
Data is encrypted in transit using HTTPS/TLS and stored on Google, RevenueCat, and PostHog infrastructure. Access to your content is restricted to your own account by server-side security rules.
Children
Mochi is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Most of these you can exercise directly in the app; for anything else, email us and we will help.
Changes to this policy
If we change this policy, we will update the date at the top of this page. Meaningful changes will be called out in the app.
Contact
Questions about privacy or your data: asquared.dev@gmail.com