Overview
Mochi ("we", "our", or "us") is a sleep-rewiring app that helps you build better sleep habits through gentle wind-down routines, morning sunlight, reflective journalling, and on-device insights. This policy explains what data we collect, how we use it, which third parties we share it with, and your rights.
Mochi is built privacy-first: your AI insights are generated on your device by default, your journal is end-to-end encrypted, and voice dictation is transcribed on your device. We run no advertising; the only analytics are anonymous, content-free usage counts you can switch off (see "Anonymous Usage Analytics" below). A deeper, cloud-based AI reflection is available but is entirely optional and off by default.
Last updated: 11 June 2026
Privacy At a glance
- AI runs on your device by default. Mochi analyses your journal and sleep patterns using Apple's on-device intelligence. This processing never leaves your iPhone — nothing is sent to us or to any AI company.
- Cloud AI is optional and off by default. You can choose to turn on a deeper reflection powered by Claude (Anthropic). Only then — and only for the entries you choose — is text sent securely for that reflection. Your raw Apple Health data is never sent.
- Voice dictation stays on your device. If you dictate a reflection, your speech is transcribed to text on your iPhone and is never recorded, saved, or sent anywhere.
- Your journal is end-to-end encrypted. Brain-dump entries are encrypted on your device before they ever sync. We only store unreadable ciphertext and cannot read your journal.
- Apple Health stays private. If you connect Apple Health, the data is processed only on your device to power your sleep and sunlight features. Your raw Health data never leaves your device; it is never used for advertising, never sold or shared, and never written back with false data.
- No ads, no tracking. Mochi contains no advertising SDKs and never tracks you across other apps or sites. The only analytics are anonymous, content-free usage counts (which features get used) so we can improve the app — you can turn them off any time in Settings → Privacy. We don't profile you or sell your data.
- You're in control. You can delete your account and all its data at any time from Settings → Account → Delete account.
Data We Collect
- Email address — used to create and manage your account. Provided either when you sign up with email and password, or returned to us by Apple or Google when you choose Sign in with Apple or Sign in with Google.
- Account identifier — a unique, opaque user ID is created for your account. This is the only identifier we use to associate your synced data with you.
- Your sleep & wellness entries — the data you create in Mochi: sleep logs (how you rated last night, wake and bedtimes, reflection tags), wind-down missions, your XP, level and streak progress, and your chosen companion. These are stored in your account so they sync securely across your devices.
- Journal (brain-dump) entries — any free-text reflections you write or dictate. These are end-to-end encrypted on your device before syncing; we store only ciphertext and cannot read them (see "Your Journal Is End-to-End Encrypted" below).
- Apple Health data — only if you explicitly connect Apple Health. With your permission, Mochi reads your sleep analysis, Time in Daylight, workouts, and recovery signals (heart-rate variability, resting heart rate, respiratory rate, and overnight wrist temperature) — and, where relevant, cycle data — and writes Mindful Minutes for the sessions you complete (see "Apple Health" below).
- Calendar data — only if you explicitly connect your calendar. Mochi reads upcoming event times to spot early mornings and protect your wind-down, and event titles solely to suggest what you might reflect on. Event titles are used only on your device and are never synced or sent off it (see "Calendar" below).
- Your sleep schedule & time zone — your target wake and sleep times and your time zone are stored in your account so your reminders and your wind-down / wake-up Live Activities can start at the right local time across your devices.
We do not collect your location, contacts, photo library, phone number, or payment card information, and we do not use advertising identifiers. Mochi uses the microphone only while you are actively dictating, and that audio is transcribed on your device and never recorded or stored (see "Voice Dictation" below). If you sign in with Apple or Google, those providers may pass your name during the sign-in handshake, but Mochi does not retain or transmit your name beyond that initial response.
How You Sign In
Mochi offers three sign-in methods. You choose which one to use:
- Email and password — handled by Supabase Auth. Your password is never seen by us in plain text; Supabase stores a salted hash.
- Sign in with Apple — Apple authenticates you and returns an identity token plus your email (which may be a private relay address you control) and, on first sign-in only, your name. Mochi exchanges the identity token for a Supabase session. Apple's relay address means you can revoke our access at any time from your Apple ID settings.
- Sign in with Google — Google authenticates you via the official Google Sign-In iOS SDK and returns an identity token, your email address, and your Google account ID. Mochi exchanges the identity token for a Supabase session. See the Google Privacy Policy for how Google handles your account.
Whichever method you choose, the only piece of identity data we retain on our backend is your email address and an opaque Supabase user ID.
Apple Health
Connecting Apple Health is entirely optional and is requested only when you choose to enable a feature that uses it. Mochi asks for the minimum access each feature needs, when that feature needs it — never all at once, up front.
- What we read (with your permission): your sleep analysis (time in bed and sleep stages, where available from Apple Watch) to auto-fill your nightly sleep log; Time in Daylight to automatically credit your morning-sunlight goal; and, to show how your lifestyle shapes your sleep, your workouts and recovery signals (heart-rate variability, resting heart rate, respiratory rate, and overnight wrist temperature). For users it's relevant to, Mochi can also read cycle data to offer supportive, non-clinical context.
- What we write (with your permission): Mindful Minutes for the breathing and wind-down sessions you complete in Mochi, so they appear in the Apple Health Mindfulness section. We only ever write sessions you actually complete — we never write false or estimated data into Apple Health.
- How it's processed: Health data is read and processed on your device to power the sleep, sunlight, and reflection features inside Mochi. Your raw Apple Health records never leave your device. If you turn on the optional Cloud AI reflection, only a short, plain-language summary derived on your device (for example, "worked out three times this week") may be included — never your raw Health data. Sleep data you choose to keep is stored in your own account (protected by Row Level Security, below).
- What we never do: we never use Apple Health data for advertising, marketing, or any form of data mining; we never sell it or share it with data brokers or third parties; and we never store your health information in iCloud.
- Your control: you can review and revoke Mochi's Health access at any time in the iOS Settings → Privacy & Security → Health screen, or from Settings → Integrations inside Mochi. Revoking access stops all reading and writing immediately.
Calendar
Connecting your calendar is entirely optional and is requested only when you enable a feature that uses it. With your permission, Mochi reads your upcoming events to:
- Event times — to spot an unusually early start and gently protect your wind-down the night before.
- Event titles — used only on your device to suggest what you might like to reflect on (for example, gently asking how a meeting went). Event titles are never synced, never stored on our servers, and are never sent to any third party, including the optional Cloud AI.
You can revoke calendar access at any time in iOS Settings → Privacy & Security → Calendars, or from Settings → Integrations inside Mochi.
AI Processing (On-Device & Optional Cloud)
Mochi's reflective insights — spotting themes in your journal and patterns in your sleep — are generated using Apple's on-device foundation models (Apple Intelligence) by default. This means:
- By default, your data never leaves your device for AI. The analysis runs locally on your iPhone. Your journal text and sleep data are not sent to us, to Apple's servers, or to any third-party AI provider for this processing.
- No on-device AI training on your data. Because nothing is transmitted for on-device analysis, that content is never used to train any AI model.
- Optional Cloud AI (off by default). You can choose to enable a deeper reflection powered by Claude (Anthropic). It is off by default and requires your explicit consent. When enabled, the specific journal entries you choose are decrypted on your device and sent — encrypted in transit, and routed through Mochi's secure server so no AI key is ever in the app — to Anthropic to generate the reflection, together with a short, non-identifying context summary (never your raw Apple Health data). Per Anthropic's terms, your content is not used to train their models and is not retained after the request is processed. You can turn this off at any time in Settings → AI, and a clear consent prompt explains this before anything is sent.
Your Journal Is End-to-End Encrypted
Your brain-dump journal entries are the most personal thing in Mochi, so they get the strongest protection:
- Each entry is encrypted on your device using a key that only you hold. The key is stored in your iCloud Keychain so your entries can sync across your own Apple devices — but the key itself is never sent to our servers.
- Our backend only ever stores the encrypted ciphertext. We cannot read your journal entries, and neither can anyone who might access the database.
- When Mochi analyses your reflections on-device, it decrypts them only on your device. If you have turned on the optional Cloud AI reflection, the entries you choose are decrypted on your device and sent securely for that reflection, as described above.
Voice Dictation
You can dictate a reflection instead of typing it. If you do:
- Mochi uses the microphone only while you are actively dictating.
- Your speech is transcribed to text entirely on your device using Apple's on-device speech recognition. The audio is never recorded, saved, or sent to Apple, to us, or to any third party.
- Only the resulting text becomes part of your journal entry — which is then end-to-end encrypted like any other entry.
You can manage microphone and speech-recognition permission at any time in iOS Settings → Privacy & Security.
Anonymous Usage Analytics
To understand which parts of Mochi people actually use (and which need work), the app sends a small number of anonymous, content-free usage events — for example "a reflection was created" or "the Progress tab was opened" — to PostHog, our analytics processor, hosted in the EU.
- Anonymous: events carry a random per-install identifier only. We never attach your email, account ID, name, or any other identity to them.
- Content-free: your journal text, Apple Health data, calendar, schedule times, and anything you write or dictate are never included — only event names and small labels like which tab was opened.
- Not tracking: these events are not used to track you across other apps or websites, and are never used for advertising.
- Your choice: you can turn analytics off at any time in Settings → Privacy → "Share anonymous usage analytics" inside Mochi, and the change applies immediately.
How We Use Your Data
- To provide the core features of the app (sleep logging, wind-down missions, streaks, XP and levels, your companion, and reflective insights).
- To securely store and sync your data so it persists across sessions and devices.
- To schedule the gentle reminders and start the wind-down / wake-up Live Activities you opt into (see "Notifications" below).
- To understand — in aggregate and anonymously — which features are used, so we can improve the app (see "Anonymous Usage Analytics" above; opt-out in Settings → Privacy).
We do not use your data for advertising, profiling, or any purpose beyond app functionality.
Third-Party Services
- Supabase — secure cloud database and authentication. Your account data is stored in Supabase and protected by Row Level Security, meaning only you can access your own data. Supabase Privacy Policy
- Apple — Sign in with Apple & Apple Health — Sign in with Apple is used only when you choose it. Apple Health is used only if you connect it. Both are provided by Apple under its own privacy terms. Apple Privacy Policy
- Google Sign-In — used only when you choose to Sign in with Google. Google's iOS SDK handles the sign-in flow and returns an identity token, your email, and your Google account ID, which we exchange for a Supabase session. Google Privacy Policy
- Anthropic (Claude) — used only if you turn on the optional Cloud AI reflection. When enabled, the entries you choose are sent (via Mochi's secure server) to Anthropic to generate a deeper reflection. Anthropic does not train on your content and does not retain it after processing. Anthropic Privacy Policy
- PostHog — anonymous, content-free usage analytics, hosted in the EU (see "Anonymous Usage Analytics" above). You can opt out any time in Settings → Privacy. PostHog Privacy Policy
Mochi uses no advertising networks. Analytics are limited to the anonymous, opt-out usage events described above.
Data Storage & Security
Your account data is stored with Supabase and protected by Row Level Security, so no other user can access your data. All data is transmitted over HTTPS. Your journal entries are additionally end-to-end encrypted, as described above. Your sign-in session is stored securely in the device Keychain, and is never written to ordinary app storage.
Data Retention & Deletion
Your data is retained for as long as you have an account. You can delete your account at any time from Settings → Account → Delete account inside the app. Deleting your account permanently removes all your data from our servers and cannot be undone. Any Mindful Minutes Mochi wrote to Apple Health remain in Apple Health under your control — you can remove those in the Health app.
Notifications
Most of Mochi's reminders (such as morning encouragement and sunlight nudges) are scheduled locally on your device. To start your wind-down and wake-up Live Activities at the right local time, Mochi may use Apple's Push Notification service; for this, your target wake/sleep times and time zone are stored in your account and a push token is registered with Apple. Notification and Live Activity content is kept generic — it never includes your journal text or other sensitive personal data on your lock screen. You can turn notifications off at any time in iOS Settings.
Your Rights
You have the right to:
- Access the data we hold about you.
- Delete your account and all associated data at any time, directly in the app.
- Withdraw consent for Apple Health or Calendar access at any time in iOS Settings or in Mochi.
- Turn off the optional Cloud AI at any time in Settings → AI.
- Turn off anonymous usage analytics at any time in Settings → Privacy.
- Contact us with any privacy-related questions.
Children's Privacy
Mochi is not directed at children under 13. We do not knowingly collect data from children.
Changes to This Policy
We may update this policy from time to time. Any changes will be reflected on this page with an updated date. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact
If you have any questions about this privacy policy, please contact us at:
contact@meliolabs.io