Privacy Policy
Privacy at a glance
- We provide the AI. To answer you, Mochi sends your question, and a picture of your screen when he looks, to OpenAI, which processes it for us as our service provider. You never need an account with OpenAI. Neither we nor OpenAI use what you send to train AI models.
- He listens when you ask. He listens while you hold him or hold ⌥Space, or for his name while his face is open on your phone. His name is recognized on your Mac itself. Talk he overhears stays on your Mac; only the last 30 seconds (at most 300 characters) goes along with a question, as context.
- He sees your screen only when he looks: when your question needs it, while he does a job you asked for, or when you ask for a screenshot.
- Your things stay on your devices. What he remembers about you, your recent chat and your settings live on your Mac; your saved chats live on your phone.
- Our servers pass things along without keeping them. Your questions, screen pictures and phone sound travel through our servers on their way, and we don't store their contents.
- Payments. Our payment processor handles your card. We never see or store your full card number.
- What we never do. We don't sell or "share" your personal information, show you ads, or use your questions, screen, memories or chats to train AI.
- Your choices. Write to hi@usemochi.ai to see, correct or delete what we hold. Section 12 shows how to delete what's on your devices.
This summary is here to help. The full policy below is what counts. For a picture of it all, see Where your data goes.
1Who we are and what this covers
1.1Who we are. Mochi ("Mochi," "we," "us" or "our") provides the Mochi Mac app, the Mochi phone app, the AI features that power them, our relay and other servers, our website at www.usemochi.ai, our waitlist, our emails and Mochi subscriptions (together, the "Services"). This Privacy Policy explains what personal information we collect through the Services, how we use and disclose it, how long we keep it, and the rights and choices you have. Where the EU or UK General Data Protection Regulation applies, Mochi is the controller of the personal information described in this policy. Capitalized terms that are not defined here have the meanings given in our Terms of Service.
1.2What this policy does not cover. This policy does not cover processing by Apple as the maker of macOS, iOS and Safari, which Apple's privacy policy governs; our payment processor's own use of payment information for purposes such as fraud prevention and meeting its legal obligations, which its privacy policy governs; or apps and websites that you visit, or that Mochi opens or operates for you, which have their own privacy practices (Section 15).
1.3Early access. Mochi is in early access. Until subscriptions open, the Mac and phone apps are available only to people we invite, and no one is charged. Some features of those early-access versions work differently from what this policy describes for subscriptions, including how they connect to our AI provider; we explain the differences to testers when we invite them. Everything else in this policy applies to everyone. If you have only visited our website or joined the waitlist, Sections 3.3, 3.4, 3.11 and 3.13 are the parts that apply to you.
2Where your information goes
| Information | Where it's processed | Do we receive it? | How long it's kept |
|---|---|---|---|
| Sound before you ask | Your Mac only (and your phone, if his face is open on it) | Phone sound passes through our relay, unstored | Overheard words: in your Mac's memory for at most 2 minutes |
| Your questions (audio and words) | Your Mac, our AI service and OpenAI | Only passing through our servers, unstored | Mac: in your recent chat. OpenAI: see Section 7.2 |
| Pictures of your screen | Your Mac, our AI service and OpenAI | Only passing through our servers, unstored | Mac: not saved, unless you ask for a screenshot. OpenAI: see Section 7.2 |
| Memory (facts he remembers) | Your Macs, and OpenAI each time he wakes up | Only sealed copies passing between your Macs, which we can't read | Until you delete it |
| Saved chats on your phone | Your phone's browser | No | Until you delete them |
| Account and subscription details | Our servers and our payment processor | Yes | See Section 9 |
| Card and payment details | Our payment processor | Only limited details, never the full card number | See Section 9 |
| Usage counts | Your Mac, and our servers for your account | Yes, counts only, never what was said | See Section 9 |
| Pairing and device details | Your devices and our relay | Yes | Relay: in memory only |
| Server logs | Our host, Railway | Yes, with network and email addresses scrambled | See Section 9 |
| Waitlist email address | Resend | Yes | Until you ask us to delete it (Section 9) |
3Information we collect
3.1Your account and subscription
When you create an account and subscribe, we collect your email address, an identifier for your account, your plan, the dates your subscription started, renews and ends, your billing and cancellation history, the receipts and notices we send you, the country or region we need to calculate taxes, and a record that you agreed to the automatic-renewal terms (which the law requires us to keep). We use your email address to send you receipts, renewal reminders, price-change notices and other messages about your subscription.
3.2Payment information
Payments are handled by our payment processor. You give your card or other payment details directly to it, not to us. We receive only limited information from it, such as the type of card, its last four digits and expiry date, your billing country and postal code, whether a payment succeeded, and the processor's own reference numbers for you and your payments. We never receive or store your full card number or its security code.
3.3The waitlist and our emails
When you join the waitlist, we collect your email address. We send it a confirmation email. Opening the link in that email does nothing by itself: only when you tap Yes, save my spot on the page it opens do we add your address to our list, held by our email provider, Resend, together with the fact that you are subscribed and the dates Resend records. We then send you a welcome email. Resend keeps a record of each email it sends for us, including the address it went to and whether it was delivered, and records it if you leave the list. If you leave, even from a confirmation email before you ever joined, we keep only your address with an "unsubscribed" mark, so that we never email you again unless you ask to join again. You can do that with the Join again button on the page you left from, which sends you a fresh confirmation email (subject to the same daily limits).
The waitlist does not ask your age, your name or anything else. To stop abuse, our server counts sign-up attempts for a short time, in memory only, by network and by inbox (at most three confirmation emails a day to one address). Our server's logs never contain your email address or your network address, only short scrambled codes made from them. The links in our emails carry your address sealed, so that only our server can read it. The confirmation link works for 48 hours; the link to leave works for two years.
3.4Messages you send us
If you write to us, including by replying to one of our emails or by using "Something's wrong? Tell us" in Mochi, we receive your email address, your message and anything you choose to include. A "Something's wrong" report is an email you send yourself from your own mail app, so you can read it first; besides what you write, it contains only basic diagnostics, such as Mochi's version, your type of device, what is connected and switched on, and the last error, and never your chats, memories, codes or anything from your screen.
3.5Device and pairing information
When you pair a phone with your Mac, the Services create identifiers for each device and a secret token for the pairing so that messages reach the right device. Your Mac keeps a list of its paired phones with each phone's name, when it was paired and last seen, and a fingerprint of its token (not the token itself). While your devices are connected, our relay holds in memory your Mac's name, its identifiers and your phones' names, so that it can connect them.
Your Mac also sends our relay a short health report so we can spot problems: Mochi's version, which macOS permissions are on, whether he is set up, how many phones and screens are connected, whether he is awake, and how the last job ended and how long it took (for example "12s, 7 steps, done"), never what the job was. When you hold Mochi's face on your phone and no sound reaches your Mac, the relay notes that too (how long you held, never any sound), so that a broken microphone shows up.
3.6Your voice
- When he listens. Mochi listens to you while you hold the little Mochi on your Mac's screen or hold ⌥Space, using your Mac's microphone, or while you hold his face on your phone, using the phone's microphone. Your Mac's microphone is used only while you hold him. While the Listen for "Mochi" setting is on and his face is awake on a paired phone, he also listens for his name through that phone's microphone.
- Listening for his name. To notice his name, your Mac uses Apple's speech recognition running on the Mac itself, so that sound is not sent to Apple or OpenAI to be recognized. On Macs that cannot recognize speech on the device, Mochi does not listen for his name at all; he listens only while you hold him. Sound from your phone travels through our relay to reach your Mac (see below).
- What he overhears. While he listens for his name, your Mac turns what it hears into words so that it can notice "Mochi." Those words stay on your Mac, in memory only, and are forgotten after two minutes even if nobody says anything else; and are never shown on, saved by or sent to your phone. When you ask a question, only the last 30 seconds of them (at most 300 characters) go to OpenAI with it, as context.
- Your question. Once you call him by name or hold him, your Mac sends the audio of your question to OpenAI through our AI service (Section 7.2) so that OpenAI's models can understand and answer it. The words of your question are also kept in your recent chat on your Mac (Section 8).
- Through the phone app. While Mochi is awake on your phone, sound from its microphone travels through our relay to your Mac, encrypted in transit. The relay passes it along as it arrives and never stores it. If his face is left awake on a phone and nothing is said for 30 minutes, he naps and that phone's microphone stops, unless you have asked him to stay awake.
- What we don't do. We don't create voiceprints, identify you by your voice, or keep recordings of you. Mochi answers in written speech bubbles; he does not produce speech.
3.7Pictures of your screen
- When. With your Screen Recording permission, the Mac app takes a picture of your screen only when he looks: when your question needs one (for example "what's this?" or "is this right?"), while he carries out a job you asked for, after each step, to check the result, and when you ask him for a screenshot. It does not watch your screen otherwise.
- What goes with it. Your Mac reads the text in the picture with Apple's on-device text recognition and notes the name of the app in front. During a job, with your Accessibility permission, it also reads the front window's title and the names of its buttons and other controls. The picture and that text are sent to OpenAI, through our AI service, so that its models can understand your screen.
- What it can show. A picture of your screen can include anything visible at that moment, including other people's names, messages or personal information. Please close or hide anything you don't want Mochi to see.
- Where it's kept. Our servers pass pictures of your screen to OpenAI without storing them, and the Mac app doesn't save them, except a screenshot you ask him to take, which he saves in the Mochi folder in your Documents.
3.8Other things you ask Mochi to use
- Calendar and Reminders. If you allow it in macOS and ask what's coming up, your Mac reads your events and reminders on the Mac and sends the short list he reads back to you to OpenAI.
- Documents and the clipboard. If you ask him to read a document or what you copied, its contents are sent to OpenAI.
- Web research. If you ask him to look something up, your request goes to OpenAI, whose web search tool finds the answer.
- Weather and exchange rates. For the weather, your Mac sends the place you asked about (or, for "here," the city of your Mac's time zone) to Open-Meteo, then that place's coordinates. For exchange rates, it sends only the two currency codes to Frankfurter. Neither receives anything you said.
- Sites he opens for you. If you ask him to search a site or start an email, he opens a page (for example a search page or an email draft) in your browser, and that site receives what's in the link.
3.9Memory and your recent chat
Mochi remembers short facts you ask him to remember (up to 50, each up to 200 characters), in a private file on your Mac. He refuses to keep anything that looks like a password, code or card number. He also keeps your recent chat with him on your Mac (Section 8). Each time he wakes up, his memories and your recent chat are sent to OpenAI, before you ask anything, so that he knows you and keeps the thread.
If you use Mochi on more than one Mac, those Macs share his memories through our relay. Each Mac seals its copy with AES-GCM encryption using a key that is created on your Macs and that we do not have; our relay only passes the sealed copy to your other Macs that are online, cannot read it, and does not store it. When you ask him to forget something, your Mac keeps a "forgotten" note of that fact (its words and when it was forgotten) for up to two years, so that it can't come back from another of your Macs; Section 12 shows how to delete everything.
3.10Usage information
On your Mac. To help fix slowness and show you how much he's been used, the Mac app keeps a small log on your Mac of each reply's size in tokens (the units AI models count in), which model answered, how long you waited, and short notes such as why he napped (the last 400 lines), and a total per day of questions, jobs and their estimated AI cost (for 400 days). It never records what was said. This information stays on your Mac.
On our servers. To run subscriptions, apply fair-use limits and keep our costs in check, our servers count how you use the AI features under your account: how many questions and jobs, how much AI processing they used, which features, and when. These counts never include what you said, what was on your screen, or what Mochi answered.
3.11Server logs and network addresses
When your browser or devices connect to our website or servers, our servers necessarily receive your network (IP) address and process technical details such as the page or address requested, the time and your browser type. Our own logs record events such as connections, errors and the health reports in Section 3.5; they replace network and email addresses with short scrambled codes and never contain the contents of your questions or messages, codes, tokens or keys. Our host, Railway, may also keep its own records of requests to our servers, which can include IP addresses.
3.12Software updates
While your Mac is connected, our relay tells it about the newest version of the Mac app. When there is one, your Mac downloads it from our server, proving it's a connected Mochi with its private identity code. Our server learns which version your Mac is running.
3.13Cookies and storage in your browser
Our website sets no cookies for visitors and has no advertising, analytics or tracking of any kind; it loads nothing from other companies. It saves a few small preferences in your browser's own storage (for example whether its sounds are on), which never leave your device. If you sign in to manage your account on our website, we use only the cookies strictly necessary to keep you signed in.
The phone app uses up to three cookies that only our own site can read: one that remembers your phone may open the app (for one year); one that backs up your phone's pairing, so that a cleared browser doesn't unpair you (for up to 400 days), which our server only reads back to your phone and never keeps; and one that keeps our own private status page signed in for 12 hours, used only by us.
The phone app also keeps what it needs in your phone's browser storage, which is never sent to us: its pairing, your saved chats, and the little things you tell it or do with it (the name you give, your birthday, countdowns, reminders you set on the phone, focus and pet counts, sound and display settings, and when you last chatted). If you allow location, it saves your spot, rounded to about a kilometre, only to place his sun and moon at your real sunrise and sunset; it's never sent to us, your Mac or anyone else.
3.14What we don't collect
We don't collect your age, phone number, contacts or precise location, and we never receive your full card number. We don't create voiceprints or any other biometric identifiers. The phone app can ask what Mochi should call you and your birthday; they stay in that phone's browser (Section 3.13) and never reach us.
4Where it comes from
We collect personal information (a) directly from you, for example when you create an account, subscribe, join the waitlist or write to us; (b) automatically from your devices when you use the Services; and (c) from our service providers, for example whether a payment succeeded from our payment processor, and whether an email was delivered or you unsubscribed from Resend. We don't buy personal information from data brokers or anyone else.
5How we use it
We use personal information to:
- provide the features you ask for, including answering your questions, looking at your screen, carrying out jobs on your computer, remembering facts, pairing your devices and passing messages between them, and delivering updates;
- create and run your account and subscription, including taking payments, sending receipts, renewal reminders and price-change notices, handling cancellations and refunds, and calculating and paying taxes;
- apply usage limits and keep the AI features available and affordable for everyone;
- run the waitlist, including confirming your address, sending a welcome email, telling you about access, launches and important news about Mochi, and honoring requests to leave;
- protect the Services and the people who use them, including detecting and preventing fraud, abuse and security incidents, and enforcing our Terms;
- find and fix problems, using our logs, health reports and anything you choose to send us;
- answer your questions and requests;
- comply with law, including tax and accounting law, and respond to valid legal process; and
- do anything else we describe when we ask for your consent.
We do not use your questions, the audio of your questions, screen pictures, memories, chats, or Mochi's answers to train AI models, and we do not allow our AI provider to use them to train its models. We do not sell your personal information or use it for advertising. We may create aggregated or de-identified information that can no longer reasonably identify you; we keep it in that form and won't try to re-identify it, except as the law allows.
6Legal bases for processing (EEA and UK)
| Purpose | Information used | Legal basis |
|---|---|---|
| Providing the Services, including the AI features, pairing, relaying messages, memory sharing and updates | Your questions and their audio; screen pictures; memories and recent chat; device identifiers and names; phone sound in transit; health reports | Necessary to perform our contract with you (Art. 6(1)(b)) |
| Your account, subscription, payments and service emails | Email address; account and subscription details; limited payment details; usage counts | Necessary to perform our contract with you (Art. 6(1)(b)) |
| Keeping tax, accounting and consent records | Billing history; tax location; automatic-renewal consent records | Legal obligation (Art. 6(1)(c)) |
| Waitlist emails and product news | Email address; confirmation and subscription status | Your consent (Art. 6(1)(a)), which you can withdraw at any time with the link in any email |
| Fair-use limits, security, fraud and abuse prevention, and troubleshooting | Usage counts; server logs; IP addresses; scrambled codes; health reports | Our legitimate interests in keeping the Services secure, working and affordable (Art. 6(1)(f)) |
| Answering your messages | Your message and contact details | Our legitimate interest in answering you, or performing our contract with you |
| Complying with other laws and legal process | What the law requires | Legal obligation (Art. 6(1)(c)) |
| Business transfers | What the transaction needs | Our legitimate interest in running and reorganizing our business (Art. 6(1)(f)) |
Where we rely on legitimate interests, you have the right to object (Section 12). You need to give us your email address to join the waitlist or create an account, and payment details to subscribe; other information is needed only for the features that use it.
7Who receives it
We disclose personal information only as described below.
7.1Our service providers
These companies help us run the Services. They may use personal information only to provide their services to us, under contracts that restrict how they use it.
| Provider | What it does for us | Information involved | Location |
|---|---|---|---|
| OpenAI | Runs the AI models that understand your questions and screen and write Mochi's answers, and its web search tool | Your questions and their audio; overheard context; screen pictures and their text; memories and recent chat; documents and other material you ask about | United States |
| Our payment processor | Takes subscription payments and handles cards, refunds and payment fraud checks | Email address; payment details; billing country and postal code; payment history | We will name it here, with its location, before we take any payment |
| Railway Corporation | Hosts our website, relay, AI service and update downloads | IP addresses; server logs; account and usage records; device identifiers and names; questions, screen pictures, phone sound, messages and sealed memory copies in transit | Railway's data centers |
| Plus Five Five, Inc. (Resend) | Sends our emails and keeps our waitlist | Email address; subscription status; sending and delivery records | United States |
Email you send to hi@usemochi.ai is received and stored for us by the company that hosts that inbox.
7.2OpenAI, our AI provider
We provide Mochi's AI features using models from OpenAI. When you ask Mochi something, the Mac app sends what's needed to answer (the audio of your question, the overheard context described in Section 3.6, the time, your time zone and the name of the app in front of you, screen pictures and their text, his memories and your recent chat each time he wakes up, and the results of things he looked up) to OpenAI through our AI service: either our servers pass the request on, or your Mac connects to OpenAI using a short-lived pass that our servers issue for that one conversation. Our servers do not store the contents of these requests or OpenAI's answers. To help OpenAI detect abuse, we may send it a coded identifier for your account that does not reveal your name or email address. OpenAI processes this information on our behalf, as our service provider, under our agreement with it.
As of October 2026, OpenAI's API documentation states that:
- data sent to its API has not been used to train or improve OpenAI's models since March 1, 2023, unless the customer chooses to share it (we do not);
- it keeps abuse-monitoring logs, which can contain prompts and responses, for up to 30 days, or longer where the law requires or where needed to protect its services or others, and may keep and have people review content that its systems flag as potentially seriously harmful;
- its real-time voice API, which Mochi uses for conversation, keeps no application state; and
- its Responses API, which Mochi uses for harder questions, jobs on your computer and web research, keeps application state for 30 days unless a request asks it not to store it. Mochi sets
store: falseon every such request.
OpenAI also states, on its business data privacy page, that it encrypts this data at rest and in transit and limits who at OpenAI can access it. These are OpenAI's statements about its own practices, which may change; we will update this section if they change in a way that matters to you.
7.3Apple
The Mac app runs on macOS and uses Apple features such as speech recognition and text recognition. Listening for his name uses Apple's on-device speech recognition only (Section 3.6). If you have turned on iCloud Desktop & Documents, files Mochi saves in Documents may be synced to iCloud under your agreement with Apple.
7.4Weather and exchange-rate services
When you ask, the Mac app contacts Open-Meteo (weather) and Frankfurter (exchange rates) directly, as described in Section 3.8. Like any website, they receive your Mac's network address.
7.5Apps, websites and people you direct Mochi to
When you ask Mochi to open a page or carry out a job, such as drafting an email or filling in a form, the information involved goes to the app, website or person concerned, at your direction.
7.6Legal and safety reasons
We may disclose information if we believe in good faith that it's reasonably necessary to comply with law or valid legal process; to protect the safety, rights or property of anyone, including Mochi; to detect, prevent or address fraud, security or technical issues; or to enforce our Terms.
7.7Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business, information may be disclosed to the parties involved and transferred as part of that transaction, subject to this policy or one at least as protective.
7.8With your consent
We may disclose information for other purposes with your consent.
7.9No sale and no sharing for advertising
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law and similar state laws, and we have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16. We use no advertising pixels or trackers. We use sensitive personal information only to provide the Services you request and for the other purposes that California law permits without a right to limit, so we do not offer a "Limit the use of my sensitive personal information" choice.
8What stays on your devices
The following is kept on your own devices, not by us.
On your Mac (mostly in ~/Library/Application Support/Mochi, in files only your user account can read):
- the sign-in that connects the Mac app to your account, and your Mac's private identity code for our relay;
- his memories of you, and the "forgotten" notes described in Section 3.9;
- your recent chat with him (the last 20 lines, each up to 400 characters; lines older than 12 hours are no longer used and are removed the next time a line is saved), so he keeps the thread after a nap, the dates you talked (up to 120), so he can notice a streak, and the time you last talked (only the time, never what was said), so his first hello of the day and his "Welcome back!" are right;
- your timers and focus sessions;
- your paired phones (Section 3.5);
- the usage log and daily totals (Section 3.10), and a note of which permissions are on;
- your settings, including any personality you wrote for him, in
~/Library/Preferences/com.mochihq.mochi.mac.plist; - temporary files macOS keeps for the app in
~/Library/Caches/com.mochihq.mochi.mac,~/Library/HTTPStorages/com.mochihq.mochi.macand~/Library/WebKit/com.mochihq.mochi.mac; Mochi doesn't save OpenAI's answers there or anywhere else on disk; and - files he makes for you, and screenshots you ask for, in
~/Documents/Mochi.
On your phone (in your browser's storage for our site): the items in Section 3.13, including up to 60 saved chats (what you asked and his replies). Talk he overheard is never saved on your phone.
9How long it's kept
| Information | How long |
|---|---|
| Account and subscription details | While your account is open. After you close it, we delete them, except the billing and consent records below and anything we need to resolve a refund, chargeback or dispute. |
| Billing records and automatic-renewal consent records | As long as tax, accounting and consumer-protection laws require us to keep them. |
| Payment details at our payment processor | Under the payment processor's own retention rules, as described in its privacy policy. |
| Usage counts on our servers | While your account is open, and afterwards only as part of the billing records above. |
| Your questions, screen pictures and answers passing through our servers | Not stored. Passed on as they travel; OpenAI keeps them as described in Section 7.2. |
| Waitlist address and status (Resend) | Until you ask us to delete it. If you leave the list (even before you ever joined), your address is kept only with an "unsubscribed" mark, so that we never email you again unless you ask to join again; ask us and we'll delete it completely within 30 days. |
| Sign-ups never confirmed | Never added to the list. The confirmation link expires after 48 hours, and opening it without tapping Yes, save my spot saves nothing. |
| Email sending and delivery records (Resend) | As long as Resend keeps them under its own retention settings. |
| Messages you send us | Until we've dealt with them, and then only as long as we need them to follow up with you, unless they're needed for a legal claim. Ask us and we'll delete them sooner. |
| Sign-up counters on our server | In memory only, for at most a day, and gone whenever the server restarts. If a welcome email can't go out right away, the address waits in memory until it's sent or the server restarts. |
| Messages through the relay | Not stored. Passed on as they arrive; if a phone's connection drops, up to 40 messages (256 KB) for it are held in memory for a few seconds so it can catch up. |
| Pairing codes and device details on the relay | In memory only. Pairing codes last 5 minutes and one-time handoff codes 30 minutes; device names and health reports are kept while devices are connected and for a while after, until the server restarts. |
| Server logs (Railway) | As long as Railway keeps them under its own log retention settings, unless needed longer to investigate a security incident. |
| Information on your devices | Until you delete it (Section 12) or uninstall Mochi. |
We may keep information longer where the law requires it, or to establish, exercise or defend legal claims.
10Security
We use administrative, technical and organizational safeguards suited to the information we handle, including:
- encryption in transit (TLS) between your devices, our servers, OpenAI and our other providers;
- keeping Mochi's files on your Mac readable only by your macOS user account;
- sealing the memories shared between your Macs with a key we never have (our servers can technically see the questions, screen pictures, sound and messages they pass along, so we describe those as encrypted in transit, not end to end);
- secret tokens for each paired phone, which your Mac checks on every connection;
- leaving card details to our payment processor, so that we never hold full card numbers;
- updates installed only if they're signed with the same developer key as the copy you have; and
- collecting and keeping as little as we can.
No method of transmission or storage is completely secure, and we can't guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you and the authorities as the law requires. To report a security problem, write to hi@usemochi.ai.
11International transfers
Mochi is based in the United States, and our service providers process information in the United States and may process it in other countries (see Section 7.1). If you are in the European Economic Area, the United Kingdom or Switzerland, your information will be processed in the United States, which may not offer the same level of data protection as your home country. Where the law requires, we rely on appropriate safeguards for transfers, such as the European Commission's Standard Contractual Clauses (and their UK and Swiss equivalents) offered in our providers' data processing terms. You can ask us for more information about these safeguards.
12Your choices and rights
12.1Choices for everyone
- Your subscription. Cancel at any time, online or by email, as our Terms describe.
- Your account. To close your account and delete the information we hold about it, write to hi@usemochi.ai from the address on your account. We keep only what Section 9 says we must.
- Leave the waitlist. Every waitlist email has a link to leave: open it and press the button on the page. Your email app's own "Unsubscribe" button works too. We stop sending you waitlist and news emails right away. (While you have a subscription, we still send receipts and other notices about it.)
- Delete your waitlist address completely. Email hi@usemochi.ai from that address and we'll delete it within 30 days. You can also ask for a copy of what we hold, or to correct it.
- His memories. Ask him to forget something, or choose Clear His Memory… in Mochi's menu on your Mac (also in Settings), which also clears his recent chat and the days you talked, and makes your other Macs forget too.
- Listening and computer use. Turn off Listen for "Mochi" or Let Him Use the Computer in Mochi's Settings at any time.
- Your phone. Delete saved chats from Mochi's menu on the phone. When you unpair the phone, it offers to erase the chats saved on it too, along with the personal things you told it, like your name and birthday. Clearing our site's data in your browser settings removes everything the phone app saved.
- Your Mac's permissions. Turn off Microphone, Speech Recognition, Screen Recording, Accessibility or Calendar access for Mochi at any time in System Settings > Privacy & Security.
To delete everything Mochi keeps on your Mac: remove your phones in Setup & Phones… and choose Clear His Memory… (so your other Macs forget too), quit Mochi, then delete these folders and files:
~/Library/Application Support/Mochi~/Library/Caches/com.mochihq.mochi.mac~/Library/HTTPStorages/com.mochihq.mochi.mac(and the file next to it ending in.binarycookies)~/Library/WebKit/com.mochihq.mochi.mac~/Library/Preferences/com.mochihq.mochi.mac.plist~/Documents/Mochi, if you don't want to keep the files he made- Mochi itself, from your Applications folder
In Finder, choose Go > Go to Folder… and paste each path. Then turn off Mochi's permissions in System Settings > Privacy & Security. Deleting Mochi from your Mac does not cancel your subscription; cancel it separately.
12.2EEA and UK residents
Subject to the conditions and exceptions in the law, you have the right to access your personal information; to correct it; to erase it; to restrict our processing of it; to receive it in a portable format; to object to processing based on our legitimate interests; and to withdraw your consent at any time, without affecting processing that took place before you withdrew it. You may complain to your local data-protection authority. If you are in the UK, you may complain to us first and then to the Information Commissioner's Office.
12.3US state residents
Depending on where you live, you may have the right to know what personal information we've collected about you and to access it; to correct it; to delete it; to receive a portable copy; to opt out of the sale or sharing of your personal information, of targeted advertising, and of certain profiling (we do none of these); to limit certain uses of sensitive personal information (we make none of those uses); and not to be treated differently for using your rights. If we decline your request, you may appeal by replying to our decision.
12.4How to use your rights
Email hi@usemochi.ai, from the email address on your account or the one your request is about.
- Verification. To protect you, we'll check your request, normally by confirming that you control the email address involved, and ask only for what we need to do that. Much of what Mochi keeps is on your own devices, where only you can reach it; we can't see or delete it for you, but Section 12.1 shows how.
- Authorized agents. You may use an authorized agent. We may ask for proof of the agent's authority and ask you to confirm your identity directly.
- Timing. We'll confirm receipt within 10 business days and respond within 45 days, or within one month where the GDPR applies. Where the law allows, we may extend this and will tell you if we do.
- No charge. We won't charge you for a request, except where the law allows a fee for requests that are clearly unfounded or excessive.
12.5Do Not Track and Global Privacy Control
Our website doesn't track you across other websites and has no ads or analytics, so it treats browsers that send Do Not Track or Global Privacy Control signals the same as all others: there is no tracking, sale or sharing for those signals to stop.
13Notice at collection for California residents
This notice describes the categories of personal information we collect, the purposes for which we use them, whether we sell or share them, and how long we keep them. We collect this information from you and your devices, and from our service providers as described in Section 4, and we disclose it only as described in Section 7.
| Category (as defined in the CCPA) | Examples | Purposes | Sold or shared? | How long |
|---|---|---|---|---|
| Identifiers | Email address; account identifier; IP address; device and pairing identifiers; device names | Accounts and subscriptions; waitlist emails; pairing; relaying messages; security | No | Section 9 |
| Customer records and commercial information | Plan, billing and cancellation history; limited payment details from our payment processor; tax location; renewal consent records | Running your subscription; payments, receipts, refunds and taxes; legal records | No | Section 9 |
| Internet or other electronic network activity | Server logs; usage counts; health reports; update checks; email delivery and unsubscribe records | Operating, securing and fixing the Services; fair-use limits | No | Section 9 |
| Audio, electronic and visual information | The audio of your questions; sound from your phone's microphone passing to your Mac; pictures of your screen when Mochi looks | Providing the features you ask for | No | Not stored by us; OpenAI as in Section 7.2 |
| Sensitive personal information | The contents of emails, texts or other messages that appear on your screen when Mochi looks, or that you ask him to read or write | Only to provide the feature you ask for | No | Not stored by us; OpenAI as in Section 7.2 |
We do not collect your precise location or biometric identifiers. Your memories and recent chat are kept on your own devices; they reach OpenAI when Mochi wakes up, and only sealed copies we can't read pass through our relay. This notice is part of this Privacy Policy.
14Children
The Services are not directed to children under 13, and we don't knowingly collect personal information from children under 13. People aged 13 to 17 may use the Services only with a parent's or guardian's permission, and only adults may buy a subscription. Our waitlist doesn't ask your age; if we learn that we have collected personal information from a child under 13, we'll delete it promptly. If you believe a child under 13 has given us personal information, please write to hi@usemochi.ai.
15Other apps and websites
The Services link to, and can open or carry out jobs in, apps and websites that we don't operate. Information you give them, directly or through something you ask Mochi to do, is governed by their privacy practices, not this policy. Please read their policies before you let Mochi act on them.
16Changes to this policy
We may update this policy from time to time. We'll post the new version with a new "Last updated" date, and we'll send you any earlier version on request. If we make a material change, we'll tell you by email or in the Mac app at least 30 days before it takes effect, unless the law requires a different period or we must act sooner to address a security issue. We won't use personal information we've already collected for a materially different purpose than the ones described when we collected it without first asking for your consent where the law requires it.
17Contact us
Privacy questions and requests: hi@usemochi.ai
If you are in the EEA or the UK, you also have the right to complain to a data-protection supervisory authority.