1. Scope and Who We Are
This Privacy Policy explains how Moji ("Moji", "we", "us", or "our") collects, uses, discloses, and protects information when you use the Moji iOS app, Android app, website, or related support services.
Moji is currently operated by Kai Kameyama, who is the controller of personal data described in this policy. You can contact us at the address in Section 15.
The iOS and Android apps do not use data in exactly the same way. The current iOS app does not offer sign-in and normally stores new learning progress on the device. The Android app offers optional Moji accounts and cloud progress sync through Supabase. The platform-specific details are explained below.
2. Information We Collect
Information you provide
- Learning preferences: Japanese experience level, JLPT goal, daily card limit, reminder settings, display settings, onboarding status, and similar preferences
- Android account information: Email address, display name when provided, authentication provider, and an account identifier when you create or use an optional Android account
- Legacy iOS account information: If you signed in with Apple or Google in an older iOS version, we may retain the email address, name, provider, account identifier, and cloud records created at that time until they are deleted
- Support information: Your email address and the content of messages you send to us
- Prior Android waitlist information: The email address, source, request status, and related timestamps submitted before Android launched
Supabase manages Android and legacy authentication credentials. We do not receive or store your plaintext password.
Learning and app data
- Review activity: Kanji reviewed, response rating, review time, repetition state, intervals, ease values, and next review date
- Progress: Streaks, cards learned or due, JLPT progress estimates, milestones, and similar learning statistics
- App activity: Screens or features used, app lifecycle events, learning-session activity, subscription events, app version, operating system, device type, language, and app-scoped identifiers
- Subscription information: Product, entitlement, transaction, renewal, trial, and subscription status received from Apple, Google Play, and RevenueCat
- Advertising attribution on iOS: If you grant Apple App Tracking Transparency permission, the device advertising identifier and limited onboarding, trial, or subscription events may be sent to TikTok for attribution measurement
Information stored on your device
- The bundled kanji database and app content
- Learning progress, review history, preferences, streaks, and notification schedules
- Widget state used by the app and its widget on the same device
- Authentication session information if you choose to sign in on Android
3. How Each Platform Uses Supabase
Current iOS app
The current iOS app does not create accounts or offer sign-in. New iOS learning normally remains on the device and is not continuously synchronized to Supabase. On an eligible upgrade from an older signed-in version, Moji may use a saved legacy session once to reconcile matching local and Supabase review records before retiring the saved session. Legacy account and cloud records may remain until a verified deletion request is completed.
Android app
The Android app offers optional account access using supported email, Google, or Apple sign-in methods. If you sign in, Supabase processes the account profile, learning preferences, review events, and calculated SRS progress needed to synchronize supported learning data across sessions or devices. If you do not sign in, learning data that is not otherwise described as analytics or subscription data remains on the device.
4. How We Use Information
- Provide kanji lessons, spaced-repetition reviews, progress tracking, widgets, reminders, and cloud sync where available
- Create, authenticate, secure, support, and delete optional Android accounts
- Perform the limited legacy iOS progress transition described above
- Process purchases, determine entitlement status, restore purchases, and prevent subscription fraud
- Understand app performance and feature use, troubleshoot problems, and improve Moji
- Measure iOS advertising attribution only when the required tracking permission has been granted
- Respond to support, privacy, and account-deletion requests
- Complete and verify the Android launch communications requested through the former waitlist
- Protect Moji, enforce our terms, comply with law, and establish or defend legal claims
5. Legal Bases for Processing
Where applicable law requires a legal basis, we rely on one or more of the following:
- Contract: Processing needed to provide the app, account, cloud sync, support, and subscription features you request
- Legitimate interests: Securing, maintaining, analyzing, and improving Moji provided those interests are not overridden by your rights
- Consent: Processing such as iOS advertising attribution where consent is requested; you may withdraw consent through the relevant device setting
- Legal obligations: Processing needed for accounting, tax, consumer protection, privacy, security, and other legal requirements
6. Service Providers and Disclosures
We disclose information only as needed for the purposes described in this policy, at your direction, or where required or permitted by law. Our main service providers are:
Supabase
- Purpose: Optional Android authentication and cloud sync, limited legacy iOS compatibility and deletion, and storage of prior Android waitlist and operational records
- Data: Account identifiers, email and profile fields, authentication provider and session data, preferences, review events, SRS card state, deletion records, and prior waitlist records
- Policy: supabase.com/privacy
RevenueCat
- Purpose: Subscription entitlement, purchase validation, subscription analytics, and purchase restoration on iOS and Android
- Data: App-scoped or account identifier, store, product, transaction, entitlement, trial, renewal, and subscription status
- Policy: revenuecat.com/privacy
PostHog
- Purpose: Product analytics, reliability monitoring, and understanding feature use
- Data: App-scoped installation or account identifier, app and device information, screens and features used, lifecycle events, learning-session activity, and purchase events. Older releases may have associated email, display name, or sign-in provider with an analytics identifier.
- Controls: Moji does not use PostHog mobile session replay
- Policy: posthog.com/privacy
TikTok for Business on iOS
- Purpose: Advertising attribution and campaign measurement
- Data: Only after you grant Apple tracking permission, an advertising identifier and limited onboarding, trial, and purchase completion events
- Controls: Moji does not send your email address, Moji account identifier, or learning records to TikTok. You can deny or revoke tracking permission in iOS settings.
- Policy: tiktok.com/privacy
Apple, Google, and sign-in providers
- Apple App Store and Google Play: Distribute the apps and process purchases under their own privacy policies
- Apple and Google sign-in: Authenticate users who choose those Android account methods and provide the identifiers and profile fields authorized by the user
- Apple policy: apple.com/legal/privacy
- Google policy: policies.google.com/privacy
We may also disclose information to professional advisers, authorities, courts, or other parties when reasonably necessary to comply with law, protect users or Moji, investigate abuse, or establish and defend legal claims.
7. Business Transfers and Change of Control
If Moji, its business, or relevant assets are involved in a proposed or completed financing, reorganization, merger, acquisition, or sale, information may be reviewed by advisers and prospective acquirers and may be transferred to a successor where permitted by law. Any pre-completion disclosure will be limited to information reasonably necessary to evaluate or complete the transaction and will be subject to appropriate confidentiality and security restrictions. We will use aggregated or de-identified information for diligence where reasonably possible.
A successor may use transferred personal information only for purposes consistent with this policy and the purposes for which the information was originally collected, unless another lawful basis applies. This section does not authorize an acquirer to use personal information for a materially incompatible purpose. We or the successor will provide notice, and obtain consent where required, before any materially different use.
8. Retention
- Android accounts and cloud learning: Retained while the account is active and then deleted or de-identified after a verified deletion request, subject to limited backup, fraud-prevention, security, and legal records
- Current iOS learning: Stored on the device until the app or its data is deleted; legacy cloud records remain until deleted or no longer reasonably needed
- Subscriptions and transactions: Retained as needed for entitlement, accounting, tax, fraud prevention, dispute resolution, and other legal obligations
- Analytics: Retained according to our provider settings and for as long as reasonably needed for product analysis, security, and troubleshooting, after which it is deleted or de-identified
- Support and privacy requests: Retained as needed to resolve the request and document compliance
- Former Android waitlist: The waitlist is closed following the August 19, 2026 Android launch. Existing records are used only to complete or verify the requested launch communications, handle removals, and prevent duplicate sends. They will be deleted or de-identified no later than November 17, 2026 unless a longer period is required by law.
Protected backup copies may remain until normal backup rotation completes. We may retain de-identified or aggregated information that can no longer reasonably identify a person.
9. Your Choices and Rights
Depending on where you live, you may have rights to:
- Ask whether we process your personal data and request access to it
- Correct inaccurate or incomplete personal data
- Request deletion or restriction of processing
- Receive certain data in a portable format
- Object to processing based on legitimate interests
- Withdraw consent without affecting processing that occurred before withdrawal
- Lodge a complaint with your local data-protection authority
We do not sell personal information for money. Some laws may define consent-based advertising attribution as "sharing" even when no money is exchanged. On iOS, you can opt out by denying or revoking App Tracking Transparency permission in device settings.
To exercise a privacy right, contact us using Section 15. We may need to verify your identity before completing a request.
Deleting an Android account
If you are signed in on Android, use the account deletion control in the app. This deletes the Moji authentication account and associated Supabase profile, preferences, review events, and calculated SRS progress, subject to the limited retention described above.
Deleting a legacy iOS account
The current iOS app has no authenticated account screen. If you created a Moji account in an older version, request verified deletion through our account deletion page.
Deleting an account does not cancel an Apple App Store or Google Play subscription. Cancel the subscription separately in the store that processed it. Account deletion also does not erase learning data stored only on a device; delete the app or clear its local data on that device.
10. Security
- HTTPS/TLS encryption for data transmitted to our service providers
- Supabase Row Level Security and access controls for account and cloud learning data
- No public read access to former Android waitlist records
- Access limited to people and service providers who need it for the purposes in this policy
No system is completely secure. We cannot guarantee absolute security, but we use reasonable technical and organizational safeguards appropriate to the information we process.
11. International Data Transfers
Moji and its service providers may process information in countries other than the country where you live. Where required, we use contractual, organizational, or other safeguards intended to provide an appropriate level of protection for transferred personal data.
12. Notifications
Moji may ask for permission to send local learning reminders, streak alerts, and milestone notifications. These notifications are optional and can be disabled in the app or device settings. Moji does not use learning reminders for third-party advertising.
13. Children
Moji accounts and cloud-sync services are not directed to children under 13 or the applicable minimum age for independent consent in their country. If we learn that we collected personal data from a child without valid authorization, we will take reasonable steps to delete it. A parent or guardian can contact us using Section 15.
14. Changes to This Policy
We may update this policy as Moji, its ownership, or legal requirements change. We will post the updated policy here and revise the date above. If a change materially affects how we use personal data, we will provide additional notice or request consent where required. We will not treat a new policy as retroactive permission for an incompatible use of data collected under an earlier notice.
15. Contact Us
For privacy questions, requests, or complaints, contact:
- Controller: Kai Kameyama, operator of Moji
- Email: moji.app.help@gmail.com
- Service: Moji: Learn Japanese on Your Lock Screen
Please include enough information for us to understand and verify your request. We will respond within the period required by applicable law.
Last Updated: August 19, 2026 · Version 2.0