Mochi, the illustrated ginger cat

Privacy Policy

A little clarity about your data.

How Mochi, its widgets and this website handle information.

Effective 27 September 2026

Who is responsible

SIA “Agile Mind” (Sabiedrība ar ierobežotu atbildību “Agile Mind”), registration number 50203366961, is responsible for Mochi’s data handling. Our registered address is Ropažu iela 14B–107, Rīga, LV-1039, Latvia. For privacy questions or requests, email mira@eisenstein.win.

Mochi is an iPhone app with widgets that show a daily card. It works with bundled content when offline. When a network is available, the app and widgets request published phrases and quotes from our content service. You do not need an account to use Mochi.

Data kept on your device

Mochi stores downloaded published content, the choices that keep your daily card stable, and your optional reminder settings in storage shared by the app and its widgets. The app does not send those settings or your card history to our content service. iOS schedules reminders locally after you opt in to notification permission. Removing the app removes its local data under normal iOS app storage behavior; an iOS backup may have its own retention rules.

If you choose to share a card, the iOS share sheet sends the image to the destination you select. Mochi does not upload the shared image to our content service. The destination’s privacy terms apply to anything you share there.

Online requests

To fetch a current card, the app or widget sends an HTTPS request to api.mochi.eisenstein.win with your device’s IANA time-zone name. Later requests may include a content revision tag (If-None-Match) so unchanged content need not be downloaded again. The time-zone name is used to choose the right local date and time period; Mochi does not ask iOS for precise location.

When you visit this website, your browser also sends a request to mochi.eisenstein.win to load the page and its stylesheet. The page uses no analytics script, advertising tracker, account sign-in, or form.

Cloudflare receives a source IP address and request metadata when it delivers or protects these requests. Its Security Analytics shows a sample of individual requests for our API host, including request time, source IP address, host and path. Requests for this website may appear in the same zone’s security records. We use these records only to protect the service and diagnose technical problems. We do not use them to analyze Mochi’s audience or reader behavior, build advertising profiles, or track people across apps and websites. We do not sell this data. The sampled records may be associated with a person or device through the IP address. The reviewed dashboard did not establish whether the time-zone query value or revision header is retained in those records; both are transmitted to serve the app’s request.

We process request metadata under our legitimate interest in providing, protecting and troubleshooting a reliable content service and website (GDPR Article 6(1)(f)). Providing this data is not a legal requirement. You can use Mochi’s bundled card without sending a new content request by keeping the device offline; online updates will then be unavailable. There is no separate switch in Mochi to disable online refresh while the device is connected. We do not use this data for automated decisions with legal or similarly significant effects.

Provider, location and retention

Cloudflare hosts the content API and this website and helps protect their requests. Its Data Processing Addendum forms part of its customer service terms and describes data-transfer safeguards, including EU standard contractual clauses where applicable. Cloudflare may process service data outside the European Economic Area. We will make information about applicable safeguards available on request.

We do not enable persistent Workers Logs or Logpush export for the production Mochi Workers, and we do not keep our own copy of sampled request records. On our current Cloudflare Free zone, Security Analytics makes sampled records available in its dashboard for up to seven days; after that period, they are no longer available to us through that feature. This is the documented dashboard history, not a verified deletion time across all Cloudflare systems.

The content database stores published phrases and quotes, not reader accounts. Our private publishing editor is separate from the reader app and is protected by Cloudflare Access. Editor sign-in records can include an editor’s email address and IP address. We use these records to restrict and diagnose editor access under our legitimate interest in protecting the publishing service. The current Zero Trust Free plan has a standard 24-hour Access authentication-log dashboard history.

Your choices and rights

You can turn reminders off in Mochi or in iOS Settings. To remove data stored by the app on your device, delete Mochi; iOS backups are managed through your Apple settings. There is no reader account to close.

You may contact us at mira@eisenstein.win to request access, correction, deletion or restriction of personal data, or to object to processing based on legitimate interests. You may also have a right to data portability where the law applies. Because requests are anonymous and security records are sampled and short-lived, we may need the approximate time and network details of a request to locate a record, and we may have no matching record. We will not ask for more information than needed to handle a request. You can also complain to the Latvian Data State Inspectorate or another competent supervisory authority.

Changes

We will update this policy when Mochi’s data practices change and show the new effective date here. We will review the App Store privacy answers at the same time.