Mochi for iOS · last updated 28 September 2026
The short version.
If you chose "keep it on this phone", everything stays on the device: your app selection, your coins and closet, your counters, your pages, your answers during setup and which Mochi you picked. None of it is uploaded. Mochi will remind you once in a while that a lost phone loses the coins and the pages, and you can sign in later from Settings if you change your mind.
Deleting the app deletes all of it. There is no copy anywhere else to ask us for.
Sign in with Apple asks Apple for an email address and nothing else — no name — and you can choose Apple's Hide My Email, in which case we only ever see a relay address. That address and a random account id are what the account is made of.
The account then holds a backup of six things, so a new phone or a reinstall gets them back:
| Backed up | Why |
|---|---|
| Coin balance | so it follows you |
| Cosmetics you own and wear | so the closet follows you |
| Which Mochi you use | cosy or bro |
| Your lifetime pause count | for the milestones |
| Your pages — text, lists and drawings | so a notebook is not lost with a phone |
| Your email, from Apple | it is how the account exists |
Not backed up, ever: which apps you watch (iOS never gives us that), today's counters, and anything about what you do inside other apps.
The backup is stored with Supabase on servers in Mumbai, India, in a database where every row is locked to the account that wrote it: the app can only ever read and write your own. Your pages are stored so that they can be given back to you and for no other purpose — they are not read, analysed, shared, used to train anything, or connected to analytics in any way. The app is built so that page contents structurally cannot reach the analytics or crash-reporting code.
Signing out keeps everything on the phone and stops the backup. Deleting the account (Settings → Backup → Delete account) deletes the account, the backup, and everything on the phone, immediately and permanently. The app warns you first.
Plus is an auto-renewing subscription sold and billed by Apple. We never see your payment details. Buying Plus requires the account above, so the subscription and its backup travel together.
We use RevenueCat to know whether a subscription is active. It receives the purchase receipt from Apple, a random identifier generated on your device and — when you are signed in — your account id, so that the two can be matched. It does not receive your name, your email, or anything you do in the app.
The subscription belongs to your Apple ID, not to the Mochi account: signing out or deleting the account does not cancel it. Cancel it in your iPhone's Settings → Apple Account → Subscriptions, or from Mochi's own Settings → Manage subscription.
This is a limit of Apple's Screen Time system, not only a promise from us. When you pick apps to watch, iOS gives Mochi opaque tokens that mean nothing outside your device. Mochi is never told the names of those apps, and could not send them anywhere even if it tried.
Mochi also has no access to your messages, photos, contacts, location, browsing, or anything inside the apps it watches over.
If you leave Share anonymous usage switched on in Settings, Mochi sends product analytics and crash reports. This is on by default and takes one tap to turn off.
Product analytics — a short list of named events, sent to PostHog on their European servers:
| Sent | Example |
|---|---|
| Which named event happened | pause_taken, reset_completed, paywall_shown |
| A whole number or two | how many apps you selected; which pause; which plan |
| Which Mochi you use | cosy or bro |
| A random identifier | generated on your device, tied to nothing |
| Device type and OS version | iPhone, iOS 26 |
Events carry counts only. There is no field in them that could hold a name, an email, an app, or a word from a page. PostHog receives the network address your phone connects from, as any online service does, and uses it to work out an approximate country. We do not use it for anything else.
Crash reports — sent to Sentry on their European servers when Mochi crashes or freezes: the technical stack trace, your device model, OS version, and which Mochi you use. Screenshots and screen contents are switched off, and Sentry is configured not to store your network address.
What is never sent, in either case: your name, your email, an advertising identifier, your location beyond an approximate country, the apps you chose, your pages, or anything you typed or read.
None of this is used for advertising, none of it is sold, and none of it is combined with data from other companies' apps or websites.
Mochi's notifications are created on your phone by the app itself. Nothing is sent through a notification server, and no one is told when you receive one.
If you entered your email address on the waitlist page, we store that address, and which Mochi you had selected when you did. It is kept in Google Forms, and used only to tell you when Mochi is available to try.
You can ask to be removed at any time by emailing the address below, and you will be.
| Service | Holds | Where |
|---|---|---|
| Apple | your Apple ID, the subscription, your Screen Time choices | Apple's own terms |
| Supabase | the account and its backup, only if you sign in | Mumbai, India |
| RevenueCat | whether the subscription is active | United States |
| PostHog | anonymous usage events, only if the switch is on | European Union |
| Sentry | crash reports, only if the switch is on | European Union |
| Google Forms | the waitlist, only if you joined it | Google's own terms |
Mochi is a tool for managing your own phone use and is not directed at children under 13. We do not knowingly collect anything from them.
If what Mochi collects ever changes, this page changes first, and the date at the top with it. This version adds the optional account, the backup of pages, and Mochi Plus.
Questions, deletions, or anything else: ayushshanker23@gmail.com