Privacy
Last updated 24 August 2026
Mochi is a Mac app that works without an account. Nothing you copy, capture, record or type is sent anywhere — with one exception, the writing help, which sends the sentence you highlighted and keeps none of it. Two other things travel back only because you started them: feedback you write and send, and a crash report if you switch that on. The only personal data that exists is what a purchase creates: an email address, a payment record, and which Macs a licence is running on.
Who is responsible
Mochi is built and licensed by an independent developer, trading without a registered company at present. There is no company name or registered address to give yet; when one exists it will be named here and this paragraph will go. In the meantime the person responsible for the data described on this page can be reached at the address below, and answers it.
Questions about this policy, or a request to exercise any of the rights below, go to privacy@getmochi.app. A person reads them.
What the app on your Mac sends
This is the part worth stating first, because it is unusual. Mochi has no analytics, no telemetry and no account requirement, and it reports nothing about itself on its own initiative. Your clipboard history, your screenshots, your recordings, your snippets and what you type stay on the machine they happened on. Text recognised inside a screenshot is recognised by your own Mac. None of it is uploaded, backed up or synced anywhere, by us or by anyone.
Two things travel back to us, and both are yours to start: feedback you type into Mochi and press Send, and — only if you switch it on — a crash report after Mochi has crashed. Neither is on by default, neither carries anything you wrote or captured, and both are described in full below.
This paragraph is about the app, and it is not weakened by anything further down the page. This website can measure how it is used, if you agree to it on the banner — that is a separate clause and a separate thing. The app contacts none of the companies named in it, whatever you chose here.
There are seven moments when the app talks to a network at all. Here they are, in order of how much they matter. The first five concern you; the last two concern nobody, and are listed because a complete list is the only kind worth printing.
- The writing help — the one that sends your words. It gets a section of its own below.
- The licence check. A paid copy contacts our licence server to activate, and occasionally to confirm the licence is still valid. That exchange carries the licence key and a hashed identifier for the Mac — nothing else, and never anything you wrote. Your Mac verifies its own licence offline in between, which is why it keeps working on a plane.
- Feedback you send.Only when you write something in Mochi’s feedback window and press Send. It carries your message, the email address if you chose to leave one, and — if you leave the box ticked — the short list of version and setting values shown to you in that window before you send it.
- Crash reports, if you turn them on. Off until you say yes. See the clause below.
- Looking up the title of a copied link. Off by default, precisely because turning it on means contacting a third-party website for every URL you copy.
- Exchange rates. So that typing 45 usd in eur can answer, Mochi keeps a table of the rates the European Central Bank publishes, refreshed in the background every few hours from api.frankfurter.app. The request asks for the whole table and carries nothing about you — not what you converted, not that you converted anything, not whether you have ever used the feature. It happens on every Mac running Mochi, paid or free.
- Checking for updates. Mochi asks our own site which versions exist. If you accept an update, the download itself comes from GitHub. Neither request carries anything about you, and both stop entirely if you turn off automatic checks in Settings → General.
That is the complete list. Everything else Mochi does — searching, the clipboard, screenshots, the recorder and its editor, snippets, emoji, and the arithmetic, unit and time-zone answers — never touches a network, and works with the machine in flight mode. Currency is the one calculation that needs the rate table above; without it, Mochi says so rather than guessing.
The writing help, in detail
Pressing ⌥⇧C or ⌥⇧T sends the text you highlighted to Mochi’s writing service, streams it through a language model, and puts the answer back. This is the only feature in the app that sends anything you wrote, and it is worth being exact about it.
What is sent: the selected text, and the settings that describe the job — which action you asked for, the target language, the writing goals in your preferences, and any custom instructions you typed there yourself.
What is not sent: your name, your email address, your licence key, the app you were working in, the document around the selection, the file it came from, or anything else on your Mac. The request carries a hashed machine identifier and a signed licence token so the service knows it is entitled to answer — neither of which identifies you to the model.
How long it is kept: it is not. The text exists in memory for as long as the answer takes, and is then gone. It is never written to disk, never written to a log, and never used to train a model — by us or by anyone we use. Our logs record how many tokens a request used and how long it took; a deliberate rule in the service replaces any field that could contain prose with its length before a line is ever written.
Who touches it on the way: our own service, hosted on Railway in the EU, and Vercel’s AI Gateway, which routes the request to whichever language model answers it — currently models from Google, OpenAI and Anthropic. Both appear in the sub-processor table below. Their terms govern their leg of the journey; ours govern the fact that we keep none of it.
It only happens when you press the key. There is no background processing, no watching what you type, and nothing sitting between you and your keyboard. A selection you never invoke it on is never sent. The free version does not include the feature at all, so a free copy of Mochi never contacts this service in its life.
The legal basis is performing our contract with you: you asked for the sentence to be fixed, and fixing it is what you are paying for. If you would rather no text left your Mac under any circumstances, simply never press those two keys — every other feature is unaffected, and none of them will start.
Feedback and crash reports, in detail
Feedback is a message you wrote and chose to send. Mochi has a window — Settings → General, the menu bar, or typing feedback in the launcher — with a box for what you want to say, an optional email address if you want an answer, and a tick box for a short technical summary. That summary is shown to you, in full, before you send it: the Mochi and macOS versions, which permissions you have granted, whether a handful of features are switched on, and counts such as how many snippets you have. It never contains anything you copied, captured, recorded or typed, and never a file name.
Crash reports are off until you say yes. When macOS notices that Mochi has crashed it writes a report on your own Mac, in the same place it does for every other app. The first time Mochi finds one, it asks — once — whether you would like it sent. If you say no, nothing is sent, then or ever, and it does not ask again. The switch is in Settings → General either way, in both directions.
When it is on, what is sent is the shape of the crash and not the file: which error, which signal, and the list of function names in the thread that failed, along with the Mochi and macOS versions it happened on. File paths are stripped of your account name before the report leaves your Mac. What is deliberately not sent is the rest of that report — the other threads, the list of every program loaded, the command line — and nothing you were working on at the time, because none of it is in what we read.
Both carry the same hashed identifier for your Mac that the licence check uses, so that three reports from one machine can be recognised as one person following up rather than three. It cannot be turned back into your hardware, and it is stored hashed again on our side.
The legal basis for both is consent, given by pressing Send or by answering the crash question — and consent you can withdraw. Write to privacy@getmochi.app and anything you have sent will be deleted.
What we collect, and why
Only what a purchase or a sign-in actually requires:
| What | Why we have it | Legal basis |
|---|---|---|
| Email address, and name if you gave one | To send your licence key, to sign you in, and to answer support | Performing our contract with you |
| Payment records — amount, currency, date, plan, country | Proof of purchase, refunds, and tax | Contract, and a legal obligation to keep tax records |
| Licence records — key, seats, expiry | So the software knows what you bought | Performing our contract with you |
| Several identifiers for each Mac, every one stored only as a keyed hash | To count how many Macs a licence is on, let you move it, and keep the free trial to one per Mac | Contract, and our legitimate interest in stopping one licence covering a hundred machines |
| What kind of Mac it is — model, chip, memory, macOS version, app version, language, time zone, whether it is a virtual machine | Support (“which Mac is that?”), and telling a real Mac apart from one built to look new | Legitimate interests |
| IP address, and the country, region and city it resolves to | Noticing when one connection starts a dozen free trials, and answering “where was this activated?” in support | Legitimate interests, in preventing abuse of the free trial |
| Records of admin actions on your account | So a change to your licence can always be explained | Legitimate interests, and accountability |
The hashed machine identifiers are worth a paragraph of their own. Mochi is free with a paid tier, and the free trial is fourteen days per Mac. Keeping that promise means recognising a Mac it has already met, so the app reads a handful of values that identify the machine — its hardware UUID and serial number, the network card’s built-in address, the boot volume, and when macOS was set up on it. None of them leaves your Mac.Each is turned into a one-way hash on your machine before it is sent, and hashed again with a key on our side. We hold no serial numbers. Every question we can ask of what we store is “is this the same Mac as last time?” — there is no way back from a hash to your hardware, and nothing here can be matched against a list of machines held by anybody else.
More than one value, rather than one, for a reason worth stating plainly: a single identifier is a single thing to change, and a trial that resets when you change it is not fourteen days per Mac, it is fourteen days per person who looks it up. Several independent values make the trial hold without any of them having to be something we could read.
Location is approximate and comes from your address, not from your Mac. Mochi never asks macOS where you are and has no location permission. When the app talks to the licence server, the server sees the IP address of the connection — as every website you visit does — and our host resolves it to a country, region and approximate city. That is what a support answer to “which Mac is this and where was it activated?” is drawn from, and it is what tells us when one connection has started a dozen free trials in a week. Coordinates are rounded to about a kilometre, which puts a dot on a map and not on a street.
A free copy of Mochi creates none of this. A trial creates the hashed identifiers, the description of the Mac, the address it was started from and a date, with no email address attached and no account anywhere.
We can block an individual Mac from using Mochi. It is for one situation — somebody manufacturing machines to farm free trials — it is recorded with a reason whenever it is done, and if you think it has happened to you wrongly, write to us and we will undo it.
Who else can see it
Nine companies process data on our behalf, and no others. Two exist only because of the writing help and see only what that section describes; the last three exist only if you agreed to them on this website, never touch the app, and can be switched off again at any time. Two further hosts are contacted by the app itself without receiving any of your data; they are listed below the table.
| Who | What for | What they get | Where |
|---|---|---|---|
| Dodo Payments | Merchant of record — takes the payment, issues the invoice, handles tax | Name, email address, billing address, payment method details | United States and processing partners worldwide |
| Supabase | Database and sign-in | Email address, licence records, hashed machine identifiers, sign-in timestamps | Frankfurt, Germany (eu-central-1) |
| Vercel | Website hosting | IP address and request metadata, in ordinary server logs | Frankfurt region, with a global edge network |
| Resend | Sending email — licence keys and sign-in links | Email address and the contents of those messages | United States and the EU |
| Railway | Hosting the writing service that corrections and translations pass through | The selected text, in transit only, for as long as the answer takes | European Union |
| Vercel (AI Gateway) | Routing each correction or translation to a language model | The selected text and the instructions for what to do with it | United States, and the regions its model providers operate in |
| Google (Analytics & Ads) | Counting visits to this website, and telling whether an advertisement worked | A random identifier for the browser, pages viewed, country, and — for a purchase — the amount | United States, and Google's global infrastructure |
| Meta (Facebook Pixel & Conversions API) | Telling whether an advertisement we paid for led to a download or a purchase | A random identifier for the browser, which advertisement was clicked, and — for a purchase — a one-way hash of the email address and the amount | United States and Ireland |
| PostHog | Product analytics for this website — which pages lead to a download | A random identifier for the browser and the named events on this page | Frankfurt, Germany (EU cloud) |
Dodo Payments is the merchant of record: legally, they sell you the subscription, take the payment and issue the invoice. Card details go to them and never reach us — we could not show you your own card number if you asked.
Customer records live in the EU (Frankfurt), and the writing service runs in the EU (Netherlands). Some of the companies above are based in the United States, so some data reaches there; those transfers rely on the European Commission’s standard contractual clauses, and on the EU–US Data Privacy Framework where the company is certified under it — Google and Meta both are.
We do not sell personal information and never have. Under California law, sharing is a separate thing from selling: showing you an advertisement based on what you did here counts as sharing, and that is exactly what the advertising category covers. It is off unless you switch it on, switching it off again takes one click on the cookie page, and a browser sending a Global Privacy Control signal is treated as having switched it off already — wherever in the world it is.
Nothing you write is used to train a model, by us or by anyone we use.
Two hosts the app contacts by itself
These are not sub-processors and they receive none of your data. The app asks each of them for a file, and the only thing either learns is that a request arrived from an IP address — which is true of loading any web page on any machine. They are named here because “nothing leaves your Mac” is a claim worth checking, and a claim like that is only worth anything if the exceptions are volunteered rather than found.
| Who | What Mochi asks for | When | What they get |
|---|---|---|---|
| api.frankfurter.app | The table of exchange rates published by the European Central Bank | Refreshed in the background every few hours, on any Mac running Mochi | Nothing about you, and nothing about what you converted. It is a request for the whole table. |
| GitHub | The download for an update, once you accept one | Only when you install an update | Nothing beyond the request itself. The list of available versions comes from getmochi.app, not from GitHub. |
The link-title lookup in the clipboard is the third case and behaves differently, which is why it is off by default: with it on, the app contacts whichever website you copied a link to. That is not a fixed list of hosts, so it cannot be tabulated here. It refuses localhost, .local addresses and bare IP addresses, and it stays off until you turn it on in Settings → Clipboard.
How long we keep it
| What | How long | Why |
|---|---|---|
| Account and licence records | While the licence is live, then two years | So a lapsed customer who comes back still has their key and their history. |
| Payment and invoice records | Seven years | Tax and accounting law requires it. This is the one thing an erasure request cannot remove. |
| Activation records (hashed machine id, machine name, macOS version) | While the licence is live | It is how the licence knows which Macs it covers, and how you move it to a new one. |
| Device records (hashed hardware identifiers, what kind of Mac it is, the country and city its address resolves to) | Two years from the last time that Mac was seen | It is how the free trial stays one per Mac rather than one per reset. The row has to outlive the trial it granted, or the second attempt looks like a first one — which is the whole of what it is for. |
| Sign-in records | Managed by Supabase; sessions expire | Security — noticing sign-ins that should not have happened. |
| Support email | Three years from the last message | So a follow-up question does not start from nothing. |
| Feedback you sent from the app | Three years, or until you ask | A feature request is answered by shipping it, and that can be two releases away. Ask and it goes; if you left an address, that is the part we delete first. |
| Crash reports, if you turned them on | One year | Long enough to tell a crash that came back from one that never left, and short enough that a fault fixed last spring is not still on file. There is nothing in one that identifies you. |
| Text sent to the writing help | Not kept at all | It exists in memory for the length of one request, is never written to disk and is never logged. There is nothing to delete, because nothing is stored. |
| Website measurement, if you accepted it | 14 months in Google Analytics, 12 in PostHog, 90 days at Meta | The shortest window each of them offers that still lets a year be compared with the year before. Withdrawing consent stops it and deletes the identifiers from your browser, but does not reach back into what was already counted — ask us and we will delete that too. |
| Your cookie choice | 6 months, then we ask again | Consent is consent to a particular set of things at a particular moment, and it should not be assumed to hold for ever. A refusal is remembered for exactly as long as an acceptance. |
The honest caveat: a request to erase everything cannot remove the payment records. Tax law requires them to be kept, and that obligation outranks a deletion request. Everything else can go.
Your rights
Wherever you live, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete what we hold, subject to the tax records above;
- hand your data to you in a portable form, or send it somewhere else;
- stop processing it, or object to processing based on legitimate interests.
Email privacy@getmochi.app and we will answer within 30 days. We will not charge you, and we will not make you explain why.
If you are in the EU or UK and you think we have handled this badly, you can complain to a supervisory authority — [the authority in your country]. If you are in California, the CCPA and CPRA rights to know, delete, correct and opt out of sale or sharing are covered by the same list above — and the opt-out of sharing is the cookie choice on this site, which you can change at any moment without asking us. We do not sell data in any sense, and we do not use sensitive personal information to infer anything about you.
This website, and what it measures
Separate from the app, and worth keeping separate in your head: the app on your Mac still has no telemetry of any kind. This clause is about these web pages.
If — and only if — you agree to it on the banner, this site measures how it is used. There are two categories and they are independent:
- Measurement (Google Analytics, PostHog): how many people read a page, how many press Download, and where in the process people give up.
- Advertising (Meta Pixel, Google Ads): whether an advertisement we paid for led to a download or a purchase.
What is recorded is a short list of named moments, not everything you do: a page being viewed, the download button being pressed, a plan being chosen, a sign-in link being asked for, a search of the manual and the length of what was typed into it, and a purchase. There is no session recording, no heatmap, and no automatic capture of clicks or keystrokes — those are switched off in the configuration, not merely unused.
A purchase is reported from our server rather than your browser, because most people never return to the thank-you page. That report carries the amount, the plan, and — to Meta only, and only if you accepted advertising — a one-way SHA-256 hash of your email address. Meta cannot read an address from a hash; they can only check it against one they already hold. If you accepted measurement but not advertising, Meta is not contacted at all.
Until you answer, nothing loads. Not a script, not a cookieless ping. Refusing is one button the same size as accepting, and a browser sending a Global Privacy Control signal has advertising refused for it automatically. Every cookie is listed by name here, along with the button that changes your mind.
The lawful basis is your consent, under Art. 6(1)(a) and the ePrivacy Directive. You can withdraw it at any time, and withdrawing is as easy as giving it was: one click, which also deletes the identifiers those companies stored in your browser. It does not reach back into what was already counted — write to us for that and we will delete it.
Children
Mochi is a professional tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has bought a licence, write to us and we will refund it and delete the record.
Changes to this policy
If this policy changes in a way that matters — a new sub-processor, a new kind of data — we will email everyone with a licence before it takes effect. Small corrections get a new date at the top and nothing more.