Legal

Privacy Policy

Last updated: August 23, 2026  · 

The short version: Mochi Slow Café works without an account and stores your game progress on your device. If you choose “Save your café,” Firebase stores your account identifier and a limited progress snapshot so your café can follow you to another device. If you choose “Feedback & ideas,” we store your message and limited app context without attaching your account or device identifiers, then automatically delete the raw submission within 90 days. Purchase services process the limited data needed to provide purchases. PostHog product analytics and Sentry diagnostics are independent choices: each stays off until you explicitly consent, and each can be turned off again in Settings. Turning a choice off stops future collection but does not automatically erase data a provider already received. We never sell your data, show ads, or track you across other apps.

Contents
  1. Who we are
  2. Data stored on your device
  3. Optional account & cloud save
  4. Subscriptions & purchases
  5. Product analytics
  6. Diagnostics & reliability logs
  7. Feedback & ideas
  8. Deep Brew app blocking
  9. Notifications
  10. What we do not do
  11. Third-party services
  12. Data retention
  13. Your choices & rights
  14. Children
  15. International users
  16. Security
  17. Changes
  18. Contact

1Who we are

Mochi Slow Café (“the app,” “we,” “us”) is a cozy focus-timer game published by Kaironos LLC. Kaironos LLC is the data controller for the app data described here. This policy explains what data the app handles and why. It applies to the iOS and Android versions of the app.

2Data stored on your device

Your game progress — focus minutes, matcha rank, coins, owned decorations and their placements, daily-care streak, subscription-derived unlocks, and settings — is stored on your device using the platform’s standard app storage. If you never choose “Save your café,” no Firebase cloud-progress record is created and signed-out progress is not sent to Kaironos cloud services.

Platform backup is separate from optional Firebase cloud save. Android automatic OS backup and device transfer are disabled for the app, so Android does not provide a separate automatic progress-transfer path. On iOS, Apple may include local app data in a device or iCloud backup depending on your Apple settings and platform behavior. We do not operate, receive, control, or guarantee Apple’s backup process. Deleting the app removes its active local data from the device but may not erase an existing Apple-managed backup. Optional Firebase sign-in and cloud save are the supported account-based cross-device path on both platforms.

3Optional account & cloud save

No account is required to play. If you choose “Save your café,” you sign in with Apple or Google on iOS, or Google on Android, through Firebase Authentication. Firebase provides an account user ID and may provide the name and email address associated with that sign-in. We do not receive your password.

For signed-in players, Cloud Firestore stores a limited progress snapshot linked to that user ID: lifetime focus minutes, owned décor and cosmetics, recipe stamps, care streak and last-fed day, and country, venue, room, and mastery progress. Coins, focus-session contents, your focus intent, and the apps selected for Deep Brew are not included in this cloud snapshot.

You can use Settings → Delete account to permanently delete the Firebase Authentication account and recursively delete its cloud-save tree. Apple accounts require one Apple confirmation so the app can revoke Apple’s authorization. Google accounts use the current Firebase session when it is recent enough and ask for Google confirmation only when Firebase requires a recent login. If you are signed out, provider authentication is used solely to locate and delete that account; the app does not merge this device’s café into the cloud. A successful deletion clears this device and restarts onboarding. Settings → Sign out is separate and preserves the local café. See Account & Data Deletion for exact steps and support alternatives.

4Subscriptions & purchases

The app offers an optional paid subscription (“Mochi Slow Café Pro”) and one-time coin packs. Payments are processed entirely by Apple (App Store) or Google (Google Play) — we never see or receive your card or payment details.

To manage purchases and unlock the right features on your device, we use RevenueCat. Before sign-in it uses a random app-specific identifier. If you choose cloud save, that purchase profile is associated with your Firebase user ID so purchases can follow your account. RevenueCat processes purchase receipts, subscription status, and one-time purchase transaction history together with basic device and country information used to validate purchases. We receive purchase status and identifiers, not your payment information. See RevenueCat’s privacy policy at revenuecat.com/privacy.

5Product analytics

Product analytics is an independent optional choice and remains off until you explicitly consent. If you opt in, we use PostHog to record limited app events — for example, whether onboarding was completed or a feature was opened — associated with a random app identifier, not your name or email. That identifier is pseudonymous rather than guaranteed anonymous. On iOS, PostHog does not automatically capture app lifecycle events; the app sends only selected product events after consent. We use this data only to improve the app, never for advertising or cross-app tracking. You can withdraw this consent at any time in Settings → Privacy choices without losing access to the game. Withdrawal stops future collection but does not by itself erase events already retained by PostHog. See PostHog’s privacy policy at posthog.com/privacy.

6Diagnostics & reliability logs

Diagnostics is a separate optional choice and remains off until you explicitly consent. On iOS, if you opt in, we use Sentry for crashes, app hangs, errors, and selected routine reliability logs. Those logs can record app launch; focus-session start and end with an app-generated session ID, chosen duration, whether Deep Brew or cooking was enabled, and the end reason; permission and shield outcomes; RevenueCat configuration state; and network operation, method, and status with an app-generated request ID. Reports and logs may also include the app version and build, device and operating-system type, and exception or stack-trace data. Android diagnostics remain off unless a Sentry project is configured. We configure Sentry not to collect default personal information, account identity, screenshots, view hierarchy, session replay, performance traces, profiles, full request URLs, request or response bodies, purchase receipts, the apps selected for Deep Brew, or user-entered text. You can withdraw this consent independently at any time in Settings → Privacy choices. Withdrawal stops future reports and logs but does not by itself erase diagnostics already retained by Sentry. See Sentry’s privacy policy at sentry.io/privacy.

7Feedback & ideas

If you choose to send Feedback & ideas, we collect the category, message, platform, app version and build, language, submission source, and a random request ID, together with the time the service receives it. We do not attach your account, contact details, device or advertising identifiers, purchases, focus history, screenshots, or logs. Feedback is encrypted in transit, stored in a private Google Cloud bucket, used only to support and improve Mochi Slow Café, and automatically deleted within 90 days. It is not sold, used for advertising, or used for tracking. Please do not include personal or sensitive information in your message. We may retain non-identifying, non-verbatim summaries and aggregate product trends for up to 24 months.

8Deep Brew app blocking

The optional “Deep Brew” mode uses Apple’s Family Controls / Screen Time capabilities so you can block distracting apps during a focus session, strictly at your request. Apple designs these APIs so that the list of apps you choose is never revealed to us — your selection and its enforcement happen entirely on-device through Apple’s frameworks. Deep Brew does nothing unless you turn it on and pick the apps yourself, and the block lifts when your session ends.

On Android, Deep Brew asks you to grant Usage Access so the app can detect which package is currently in the foreground during an active session, and display-over-apps permission so it can show the gentle block screen. The picker lists launchable apps without requesting the restricted all-packages permission. Your selected package names and the foreground-app checks are stored and processed on-device; they are not sent to us. The Android app does not use an Accessibility service for blocking.

9Notifications

If you allow notifications, the app schedules a local notification on your device so Mochi can tell you when a focus session finishes. This never involves a network request or our servers, and you can turn notifications off in your system settings at any time.

10What we do not do

11Third-party services

The app relies on these providers, each under its own privacy policy:

Our legal bases depend on the purpose and applicable law. Purchase processing and an optional cloud save you request are needed to perform those services. Product analytics and diagnostics rely on your consent. Support, security, fraud prevention, and compliance records are handled only as needed for our legitimate interests or legal obligations.

12Data retention

On-device game data persists until you erase it in Settings or delete the app. Android automatic OS backup and device transfer are disabled. On iOS, those actions may not delete an Apple-managed device or iCloud backup, which you manage through your Apple settings; a later restore may return eligible local data. Optional Firebase account and cloud-progress data persists until you delete the account in Settings, submit a verified support request, or it is no longer needed to provide cloud save. In-app account deletion triggers recursive deletion of the linked cloud-save tree. Raw Feedback & ideas submissions are automatically deleted within 90 days. Non-identifying, non-verbatim feedback summaries and aggregate product trends may be retained for up to 24 months. Purchase records held by Apple, Google, and RevenueCat are retained under their policies for as long as needed to provide purchases and meet accounting or legal requirements. If enabled, analytics events, crash reports, and reliability logs are retained according to our configured provider settings for product improvement and reliability, then deleted or aggregated. Turning a privacy choice off stops future collection; it does not guarantee immediate or zero provider retention after collection. Previously received provider data remains subject to the applicable retention period, provider capabilities, legal obligations, and any verified deletion request.

13Your choices & rights

Depending on where you live (including under GDPR or CCPA), you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy, or withdraw consent. You may also complain to your local data-protection or consumer-protection authority. The practical steps are:

14Children

The app is a general-audience wellbeing app and is not directed at children under 13 (or the equivalent minimum age in your country). The optional analytics and diagnostic choices are intended only for a person who can lawfully make those choices; otherwise, continue without sharing. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate deletion steps subject to verification, provider capabilities, and applicable law.

15International users

Our providers (Apple, Google, Firebase, RevenueCat, PostHog, Sentry) may process data in the United States and other countries. Their privacy notices describe where they process data and the transfer safeguards they make available. Kaironos verifies the safeguards required for each supported launch region before release there.

16Security

Network requests to our providers use industry-standard encryption (HTTPS/TLS). No method of storage or transmission is 100% secure, but we keep the data we handle minimal by design.

17Changes

We may update this policy as the app evolves. We will change the “Last updated” date above and provide any additional notice or consent required by applicable law before new optional processing begins.

18Contact

Questions, data-protection requests, or complaints for the controller, Kaironos LLC? Email privacy@kaironosapps.com. For general product support, email support@kaironosapps.com or use our contact form.