Privacy Policy
Last updated 21 August 2026
Digital Native Co. ("we") operates Mochi. This policy explains what personal information the app handles, why, and what you can do about it. It is written to describe what the app actually does. Where a feature is not yet active, we say so rather than describing it as if it were running.
1. The short version
Your photos, albums, routines and notes are stored on your own device. We do not collect them.
Two things leave your device, and only when you choose: a photo you deliberately publish to the community, and your sign-in details if you create an account.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
2. What we collect
Account information, if you sign in: your email address, display name, profile image URL and a Firebase user identifier, received from Google. Purpose: to authenticate you and associate any cloud data with your account. Legal basis: performance of our agreement with you.
Published content, if you publish: the photo file, its caption, tags and the date you recorded, plus your likes and comments and the account they came from. Purpose: to operate the community feature. Legal basis: your consent, given by the act of publishing.
Subscription status, if you buy a plan: a store receipt or purchase token and the resulting plan and expiry. Purpose: to give you what you paid for and to prevent fraudulent entitlement. We never receive your card details.
Server logs: IP address, request path and timestamp, kept transiently by our hosting providers for security and debugging.
3. What we do not collect
Photos, videos, albums, routines, completions, captions and notes that you have not published. These stay in the app’s private storage on your device.
Your device photo library. The app reads only the specific images you select, and copies them into its own storage.
Location data. The app does not request or record location, and does not read location from photo metadata.
Contacts, calendar, microphone or health data.
4. Advertising
Advertising is not currently enabled in the app. No advertising SDK is integrated and no advertising identifier is collected.
If we enable advertising in future, it will appear only in the public community parts of the app and never inside your private album, and we will update this policy and seek any consent the law requires before it starts.
5. Who processes data for us
Google (Firebase Authentication, Cloud Firestore, Cloud Storage) for sign-in and, for subscribers, cloud storage. Processed in Google data centres, which may be outside the Republic of Korea.
Railway Corp. for hosting our application server, and Vercel Inc. for hosting this website. Both may process data outside the Republic of Korea.
These providers act on our instructions and may not use your information for their own purposes. We do not otherwise disclose personal information to third parties, except where required by law or legal process.
6. Cross-border transfer
Because the providers above operate globally, information may be transferred to and stored in countries other than the Republic of Korea, including the United States. Transferred items are those listed in section 2, transferred for the purposes stated there, and retained for the periods in section 7. You may refuse this transfer by not creating an account and not publishing content, in which case the app continues to work entirely on your device.
7. How long we keep it
Account information: until you delete your account, then removed without undue delay.
Published content: until you unpublish it or delete your account.
Subscription records: for the period required by tax and commercial law, which in Korea is generally five years for records of transactions.
Server logs: a short operational period, ordinarily no more than 90 days.
Anything kept only on your device is under your control and is removed when you delete it or uninstall the app.
8. Your rights
You may ask to see the personal information we hold about you, to have it corrected, to have it deleted, to have its processing suspended, and to withdraw consent.
You can delete your account and everything associated with it yourself, from within the app or at /delete-account on this site. We do not make you ask us to do it.
To exercise any other right, write to contact@digitalnative.vip. We respond within the period the law requires, which in Korea is ten days for an access request.
If you are unsatisfied, you may complain to the Personal Information Protection Commission (privacy.go.kr, 118) or the Korea Internet & Security Agency.
9. Children
The app is not intended for children under 14. We do not knowingly collect personal information from a child under 14 without the consent of a legal guardian. If you believe we have, contact us and we will delete it.
10. Security
Data in transit is encrypted with TLS. Stored files are held in access-controlled storage, scoped so that one account cannot read another’s. Access to production systems is limited to those who need it.
No system is perfectly secure. If a breach occurs that is likely to harm you, we will notify you and the Personal Information Protection Commission as the law requires.
11. Person responsible
Personal information protection officer: the representative of Digital Native Co..
Contact: contact@digitalnative.vip
12. Changes
If we change this policy we will post the updated version here and change the date above. Where a change materially affects how we handle your information, we will give notice in the app at least seven days before it takes effect, or thirty days where the change is to your disadvantage.