Mochi & Friends

Your life. Your little friend.

This privacy policy explains the information Mochi & Friends uses to provide your account, habit tracking, pet, shop and friend features.

Effective October 2, 2026 · Operator: Chase Hunter Lee Hammonds
Privacy contact: hunter@outerrange.studio

Account and everyday records

When you make an account, our backend processes your email/sign-in identity, account identifiers, display name, optional username, time zone and settings. Password authentication stores a password hash. Sign in with Apple uses Apple’s service; an encrypted Apple refresh token is retained to support account revocation.

Manual check-ins, goals, optional notes, mood and energy entries, meal details, movement/rest records, ongoing plans, away periods and pet settings are stored on your iPhone and sync to your account when signed in. Coin balances, rewards, purchases made with earned coins and virtual possessions also sync. These records can include health and fitness information. We use them to track your habits, keep your progress available across sessions and shape your pet’s life. Story pages, captures and local story progress stay in account storage on your iPhone unless you choose to share or export them.

Apple Health and photos

With your permission, Mochi reads steps, sleep and workouts from Apple Health. It does not write to Apple Health. Raw readings are read on this iPhone and are not uploaded as Health history or stored in the app’s synced activity records.

Those readings can complete goals and shape your pet. Goal configuration and completion/reward evidence can sync to your account. The pet’s resulting status, score and room effects can be visible to friends according to your sharing settings. Keeping raw readings on the phone does not mean every effect derived from them stays on the phone.

Meal photo files and drafts stay in local account storage in the current version. A record can sync whether it has a local photo; the photo file itself is not uploaded by that sync. If you choose to export or share something, the resulting copy is outside the app’s control.

What friends see

Friendships, invitations, blocks and reports are stored on the backend. Accepted friends can see your display name/username and your pet’s name, appearance, outfit, room and selected status information. Sharing settings control supported optional details. Individual check-in records, nutrition values, notes and raw Health readings are not included in the friend-facing response.

Someone with an active invitation link can see an invitation preview, including the inviter’s name, pet name and selected housewarming gift. Forwarding it can expose the preview; it does not automatically create a friendship. Removing or blocking a friend ends access when their device next connects. We cannot recall screenshots or other copies someone has already made.

Reliability, notifications and support

The app sends short operational events/error codes, a random install identifier, timestamps, app/build information, OS/device model and an account ID while signed in to diagnose problems. Events include account/sync states and story progression. Server diagnostics use a 14-day retention threshold with scheduled cleanup. Detailed MetricKit diagnostics are kept locally unless you choose to share them.

If notifications are enabled, device push tokens and delivery records support notifications through Apple. If you email support, we receive your email address and the information you choose to include so we can answer your request.

Service providers and this website

Convex provides backend/authentication/storage, Apple provides Health/sign-in/push services, Resend processes account email, and Vercel hosts this website. These providers process information needed for those services. Infrastructure may process network information, such as IP addresses, for delivery and security. Data may be processed outside your country, including in the United States.

This website adds no analytics scripts, advertising trackers or cookies. The current app has no advertising or cross-app advertising tracking, and Health information is not used for advertising. Data is shared to operate the features described here, with your chosen friends, when you deliberately share it, or when legally required.

Retention and account deletion

Account records are retained to provide the service until you remove them or delete the account. Begin deletion in Settings → Account → Delete account. Server cleanup removes account data and social access in stages and revokes Sign in with Apple authorization where applicable; failures retry. Deletion is a process, not instant removal of every copy. Signing out alone does not delete the account or its separate local storage.

Moderation reports and deletion-process records can remain after account cleanup. They contain account identifiers and report reasons or deletion status/error information. The current system has no automatic expiry for these records. Contact us to request review or deletion of remaining information; legal obligations or an active safety matter may require retaining some records.

Routine cleanup uses a 90-day threshold for sync receipts, deleted-record markers, completed social actions and inbox items, and a 30-day threshold for terminal push jobs. Unverified password sign-ups use a 7-day threshold. These are scheduled cleanup thresholds, not a promise that every copy disappears at that exact time.

Provider logs and backups may persist under the providers’ retention schedules after active records are removed. Their schedules differ from the app’s cleanup. Contact us for help identifying remaining copies or making a provider-related deletion request. Copies deliberately exported by you or other users can also outlast the active account.

Your choices and rights

You can use manual check-ins without connecting Health, change Health permissions, manage supported sharing settings, remove/block friends, edit records or begin account deletion. Contact hunter@outerrange.studio to request access, a copy, correction or deletion, or to ask about withdrawing permission, restricting processing or objecting where applicable. We may need to verify account ownership to protect your information. You may also contact your local data protection authority.

Audience and policy updates

Mochi is designed for adults and teens. It is not intended for children. The current app does not perform age verification. If you believe a child has provided personal information, contact us to request its removal.

We update this page when our data practices change and revise the effective date. Contact us with any questions about this policy.