Privacy

Mochi for iOS · last updated 28 September 2026

The short version.

Without an account

If you chose "keep it on this phone", everything stays on the device: your app selection, your coins and closet, your counters, your pages, your answers during setup and which Mochi you picked. None of it is uploaded. Mochi will remind you once in a while that a lost phone loses the coins and the pages, and you can sign in later from Settings if you change your mind.

Deleting the app deletes all of it. There is no copy anywhere else to ask us for.

With an account

Sign in with Apple asks Apple for an email address and nothing else — no name — and you can choose Apple's Hide My Email, in which case we only ever see a relay address. That address and a random account id are what the account is made of.

The account then holds a backup of six things, so a new phone or a reinstall gets them back:

Backed upWhy
Coin balanceso it follows you
Cosmetics you own and wearso the closet follows you
Which Mochi you usecosy or bro
Your lifetime pause countfor the milestones
Your pages — text, lists and drawingsso a notebook is not lost with a phone
Your email, from Appleit is how the account exists

Not backed up, ever: which apps you watch (iOS never gives us that), today's counters, and anything about what you do inside other apps.

The backup is stored with Supabase on servers in Mumbai, India, in a database where every row is locked to the account that wrote it: the app can only ever read and write your own. Your pages are stored so that they can be given back to you and for no other purpose — they are not read, analysed, shared, used to train anything, or connected to analytics in any way. The app is built so that page contents structurally cannot reach the analytics or crash-reporting code.

Signing out keeps everything on the phone and stops the backup. Deleting the account (Settings → Backup → Delete account) deletes the account, the backup, and everything on the phone, immediately and permanently. The app warns you first.

Mochi Plus

Plus is an auto-renewing subscription sold and billed by Apple. We never see your payment details. Buying Plus requires the account above, so the subscription and its backup travel together.

We use RevenueCat to know whether a subscription is active. It receives the purchase receipt from Apple, a random identifier generated on your device and — when you are signed in — your account id, so that the two can be matched. It does not receive your name, your email, or anything you do in the app.

The subscription belongs to your Apple ID, not to the Mochi account: signing out or deleting the account does not cancel it. Cancel it in your iPhone's Settings → Apple Account → Subscriptions, or from Mochi's own Settings → Manage subscription.

What Mochi is never given

This is a limit of Apple's Screen Time system, not only a promise from us. When you pick apps to watch, iOS gives Mochi opaque tokens that mean nothing outside your device. Mochi is never told the names of those apps, and could not send them anywhere even if it tried.

Mochi also has no access to your messages, photos, contacts, location, browsing, or anything inside the apps it watches over.

Anonymous usage data

If you leave Share anonymous usage switched on in Settings, Mochi sends product analytics and crash reports. This is on by default and takes one tap to turn off.

Product analytics — a short list of named events, sent to PostHog on their European servers:

SentExample
Which named event happenedpause_taken, reset_completed, paywall_shown
A whole number or twohow many apps you selected; which pause; which plan
Which Mochi you usecosy or bro
A random identifiergenerated on your device, tied to nothing
Device type and OS versioniPhone, iOS 26

Events carry counts only. There is no field in them that could hold a name, an email, an app, or a word from a page. PostHog receives the network address your phone connects from, as any online service does, and uses it to work out an approximate country. We do not use it for anything else.

Crash reports — sent to Sentry on their European servers when Mochi crashes or freezes: the technical stack trace, your device model, OS version, and which Mochi you use. Screenshots and screen contents are switched off, and Sentry is configured not to store your network address.

What is never sent, in either case: your name, your email, an advertising identifier, your location beyond an approximate country, the apps you chose, your pages, or anything you typed or read.

None of this is used for advertising, none of it is sold, and none of it is combined with data from other companies' apps or websites.

Notifications

Mochi's notifications are created on your phone by the app itself. Nothing is sent through a notification server, and no one is told when you receive one.

The waitlist

If you entered your email address on the waitlist page, we store that address, and which Mochi you had selected when you did. It is kept in Google Forms, and used only to tell you when Mochi is available to try.

You can ask to be removed at any time by emailing the address below, and you will be.

Turning it off, and deleting your data

Who processes what

ServiceHoldsWhere
Appleyour Apple ID, the subscription, your Screen Time choicesApple's own terms
Supabasethe account and its backup, only if you sign inMumbai, India
RevenueCatwhether the subscription is activeUnited States
PostHoganonymous usage events, only if the switch is onEuropean Union
Sentrycrash reports, only if the switch is onEuropean Union
Google Formsthe waitlist, only if you joined itGoogle's own terms

Children

Mochi is a tool for managing your own phone use and is not directed at children under 13. We do not knowingly collect anything from them.

Changes

If what Mochi collects ever changes, this page changes first, and the date at the top with it. This version adds the optional account, the backup of pages, and Mochi Plus.

Contact

Questions, deletions, or anything else: ayushshanker23@gmail.com