← Back

Privacy Policy

Last Updated: August 26, 2026

1. Scope and Who We Are

This Privacy Policy explains how Moji ("Moji", "we", "us", or "our") collects, uses, discloses, and protects information when you use the Moji iOS app, Android app, website, or related support services.

Moji is currently operated by Kai Kameyama, who is the controller of personal data described in this policy. You can contact us at the address in Section 15.

The iOS and Android apps do not use data in exactly the same way. The current iOS app does not offer sign-in and normally stores new learning progress on the device. The Android app offers optional Moji accounts and cloud progress sync through Supabase. The platform-specific details are explained below.

2. Information We Collect

Information you provide

  • Learning preferences: Japanese experience level, JLPT goal, daily card limit, reminder settings, display settings, onboarding status, and similar preferences
  • Android account information: Email address, display name when provided, authentication provider, and an account identifier when you create or use an optional Android account
  • Legacy iOS account information: If you signed in with Apple or Google in an older iOS version, we may retain the email address, name, provider, account identifier, and cloud records created at that time until they are deleted
  • Support information: Your email address and the content of messages you send to us
  • Prior Android waitlist information: The email address, source, request status, and related timestamps submitted before Android launched

Supabase manages Android and legacy authentication credentials. We do not receive or store your plaintext password.

Learning and app data

  • Review activity: Kanji reviewed, response rating, review time, repetition state, intervals, ease values, and next review date
  • Progress: Streaks, cards learned or due, JLPT progress estimates, milestones, and similar learning statistics
  • App activity: Screens or features used, app lifecycle events, learning-session activity, subscription events, app version, operating system, device type, language, and app-scoped identifiers
  • Subscription information: Product, entitlement, transaction, renewal, trial, and subscription status received from Apple, Google Play, and RevenueCat
  • Advertising attribution on iOS 1.13: Meta receives basic app install, activation, and session information whether or not you grant Apple App Tracking Transparency permission. This basic information includes a persistent Meta app-scoped identifier and app and device details, but does not include the iOS advertising identifier when permission is denied. If you grant permission, limited tutorial, funnel, trial, and subscription attribution information may also be sent.

Information stored on your device

  • The bundled kanji database and app content
  • Learning progress, review history, preferences, streaks, and notification schedules
  • Widget state used by the app and its widget on the same device
  • Authentication session information if you choose to sign in on Android

3. How Each Platform Uses Supabase

Current iOS app

The current iOS app does not create accounts or offer sign-in. New iOS learning normally remains on the device and is not continuously synchronized to Supabase. On an eligible upgrade from an older signed-in version, Moji may use a saved legacy session once to reconcile matching local and Supabase review records before retiring the saved session. Legacy account and cloud records may remain until a verified deletion request is completed.

Android app

The Android app offers optional account access using supported email, Google, or Apple sign-in methods. If you sign in, Supabase processes the account profile, learning preferences, review events, and calculated SRS progress needed to synchronize supported learning data across sessions or devices. If you do not sign in, learning data that is not otherwise described as analytics or subscription data remains on the device.

4. How We Use Information

  • Provide kanji lessons, spaced-repetition reviews, progress tracking, widgets, reminders, and cloud sync where available
  • Create, authenticate, secure, support, and delete optional Android accounts
  • Perform the limited legacy iOS progress transition described above
  • Process purchases, determine entitlement status, restore purchases, and prevent subscription fraud
  • Understand app performance and feature use, troubleshoot problems, and improve Moji
  • Measure basic iOS app installs and activations through Meta, and use the advertising identifier or additional tutorial, funnel, trial, and subscription attribution only when Apple tracking permission has been granted
  • Respond to support, privacy, and account-deletion requests
  • Complete and verify the Android launch communications requested through the former waitlist
  • Protect Moji, enforce our terms, comply with law, and establish or defend legal claims

5. Legal Bases for Processing

Where applicable law requires a legal basis, we rely on one or more of the following:

  • Contract: Processing needed to provide the app, account, cloud sync, support, and subscription features you request
  • Legitimate interests: Securing, maintaining, analyzing, and improving Moji, including basic app install and activation measurement where permitted by law, provided those interests are not overridden by your rights
  • Consent: Processing the iOS advertising identifier and additional advertising attribution, and basic activation measurement where applicable law requires consent; you may withdraw consent through the relevant device setting
  • Legal obligations: Processing needed for accounting, tax, consumer protection, privacy, security, and other legal requirements

6. Service Providers and Disclosures

We disclose information only as needed for the purposes described in this policy, at your direction, or where required or permitted by law. Our main service providers are:

Supabase

  • Purpose: Optional Android authentication and cloud sync, limited legacy iOS compatibility and deletion, and storage of prior Android waitlist and operational records
  • Data: Account identifiers, email and profile fields, authentication provider and session data, preferences, review events, SRS card state, deletion records, and prior waitlist records
  • Policy: supabase.com/privacy

RevenueCat

  • Purpose: Subscription entitlement, purchase validation, subscription analytics, and purchase restoration on iOS and Android
  • Data: App-scoped or account identifier, store, product, transaction, entitlement, trial, renewal, and subscription status
  • Meta subscription attribution on iOS 1.13: Only after you grant Apple App Tracking Transparency permission, Moji provides RevenueCat with the Meta app-scoped identifier and permitted device identifiers for matching. RevenueCat may then send Meta the Meta app-scoped identifier, iOS advertising identifier, identifier for vendor, IP or related network information, tracking-permission status, a possible hashed external identifier, and subscription lifecycle, product, value, currency, and store context. When tracking permission is denied or revoked, Moji stops new matching-identifier collection, clears the Meta anonymous identifier from RevenueCat where the SDK supports clearing it, and reports the current ATT state. Whether RevenueCat delivers an event to Meta is gated by the current ATT state together with the Meta server integration settings. These steps do not delete data previously received by RevenueCat or Meta.
  • Policy: revenuecat.com/privacy

PostHog

  • Purpose: Product analytics, reliability monitoring, and understanding feature use
  • Data: App-scoped installation or account identifier, app and device information, screens and features used, lifecycle events, learning-session activity, and purchase events. Older releases may have associated email, display name, or sign-in provider with an analytics identifier.
  • Controls: Moji does not use PostHog mobile session replay
  • Policy: posthog.com/privacy

Meta App Events on iOS version 1.13 and later

  • Purpose: App install attribution, activation measurement, and advertising campaign measurement
  • Basic activation data: When Moji launches or becomes active, Meta may receive a persistent Meta app-scoped identifier, app bundle identifier, app version and build, iOS version, hardware model, locale, time zone, carrier, screen density, CPU core count, IP or related network information, and app install, activation, deactivation, and session information. Moji sends this basic activation information whether Apple tracking permission is authorized or denied.
  • Data used only after authorization: If you grant Apple App Tracking Transparency permission, Meta may also receive the iOS advertising identifier and a limited tutorial or funnel completion event. Moji may then let RevenueCat match the Meta app-scoped identifier and report trial or subscription conversion information, such as product and transaction details. RevenueCat may include a hashed external identifier in those authorized conversion events.
  • Controls: Automatic Meta event logging and automatic in-app purchase logging are disabled. Moji does not send your email address or learning records to Meta. When Apple tracking permission is denied or revoked, Moji stops new matching-identifier collection and custom tutorial or funnel events, clears the Meta anonymous identifier from RevenueCat where the SDK supports clearing it, and reports the current ATT state. Meta Conversions API delivery is gated by the current ATT state together with the Meta server integration settings. These steps do not stop the basic activation data described above or delete data previously received by RevenueCat or Meta.
  • Policy: facebook.com/privacy/policy

TikTok for Business on earlier iOS versions

  • Purpose: Advertising attribution and campaign measurement in iOS versions released before version 1.13
  • Data: Only after you grant Apple tracking permission, an advertising identifier and limited install, onboarding, trial, and purchase completion events
  • Transition: Updating to iOS version 1.13 or later removes the TikTok SDK. An earlier installed version may continue using it until you update, and data previously received by TikTok remains subject to TikTok's retention practices.
  • Controls: Moji does not send your email address, Moji account identifier, or learning records to TikTok. You can deny or revoke tracking permission in iOS settings.
  • Policy: tiktok.com/privacy

Apple, Google, and sign-in providers

  • Apple App Store and Google Play: Distribute the apps and process purchases under their own privacy policies
  • Apple and Google sign-in: Authenticate users who choose those Android account methods and provide the identifiers and profile fields authorized by the user
  • Apple policy: apple.com/legal/privacy
  • Google policy: policies.google.com/privacy

We may also disclose information to professional advisers, authorities, courts, or other parties when reasonably necessary to comply with law, protect users or Moji, investigate abuse, or establish and defend legal claims.

7. Business Transfers and Change of Control

If Moji, its business, or relevant assets are involved in a proposed or completed financing, reorganization, merger, acquisition, or sale, information may be reviewed by advisers and prospective acquirers and may be transferred to a successor where permitted by law. Any pre-completion disclosure will be limited to information reasonably necessary to evaluate or complete the transaction and will be subject to appropriate confidentiality and security restrictions. We will use aggregated or de-identified information for diligence where reasonably possible.

A successor may use transferred personal information only for purposes consistent with this policy and the purposes for which the information was originally collected, unless another lawful basis applies. This section does not authorize an acquirer to use personal information for a materially incompatible purpose. We or the successor will provide notice, and obtain consent where required, before any materially different use.

8. Retention

  • Android accounts and cloud learning: Retained while the account is active and then deleted or de-identified after a verified deletion request, subject to limited backup, fraud-prevention, security, and legal records
  • Current iOS learning: Stored on the device until the app or its data is deleted; legacy cloud records remain until deleted or no longer reasonably needed
  • Subscriptions and transactions: Retained as needed for entitlement, accounting, tax, fraud prevention, dispute resolution, and other legal obligations
  • Analytics: Retained according to our provider settings and for as long as reasonably needed for product analysis, security, and troubleshooting, after which it is deleted or de-identified
  • Support and privacy requests: Retained as needed to resolve the request and document compliance
  • Former Android waitlist: The waitlist is closed following the August 19, 2026 Android launch. Existing records are used only to complete or verify the requested launch communications, handle removals, and prevent duplicate sends. They will be deleted or de-identified no later than November 17, 2026 unless a longer period is required by law.

Protected backup copies may remain until normal backup rotation completes. We may retain de-identified or aggregated information that can no longer reasonably identify a person.

9. Your Choices and Rights

Depending on where you live, you may have rights to:

  • Ask whether we process your personal data and request access to it
  • Correct inaccurate or incomplete personal data
  • Request deletion or restriction of processing
  • Receive certain data in a portable format
  • Object to processing based on legitimate interests
  • Withdraw consent without affecting processing that occurred before withdrawal
  • Lodge a complaint with your local data-protection authority

We do not sell personal information for money. Some laws may define advertising attribution as "sharing" even when no money is exchanged. When iOS App Tracking Transparency permission is denied or revoked, Moji stops new matching-identifier collection and custom tutorial or funnel events, clears the Meta anonymous identifier from RevenueCat where the SDK supports clearing it, and reports the current ATT state. Meta Conversions API delivery is gated by the current ATT state together with the Meta server integration settings. These steps do not stop the basic Meta activation data described in Section 6 or delete data previously received by RevenueCat or Meta. You may also contact us to exercise applicable privacy rights.

To exercise a privacy right, contact us using Section 15. We may need to verify your identity before completing a request.

Deleting an Android account

If you are signed in on Android, use the account deletion control in the app. This deletes the Moji authentication account and associated Supabase profile, preferences, review events, and calculated SRS progress, subject to the limited retention described above.

Deleting a legacy iOS account

The current iOS app has no authenticated account screen. If you created a Moji account in an older version, request verified deletion through our account deletion page.

Deleting an account does not cancel an Apple App Store or Google Play subscription. Cancel the subscription separately in the store that processed it. Account deletion also does not erase learning data stored only on a device; delete the app or clear its local data on that device.

10. Security

  • HTTPS/TLS encryption for data transmitted to our service providers
  • Supabase Row Level Security and access controls for account and cloud learning data
  • No public read access to former Android waitlist records
  • Access limited to people and service providers who need it for the purposes in this policy

No system is completely secure. We cannot guarantee absolute security, but we use reasonable technical and organizational safeguards appropriate to the information we process.

11. International Data Transfers

Moji and its service providers may process information in countries other than the country where you live. Where required, we use contractual, organizational, or other safeguards intended to provide an appropriate level of protection for transferred personal data.

12. Notifications

Moji may ask for permission to send local learning reminders, streak alerts, and milestone notifications. These notifications are optional and can be disabled in the app or device settings. Moji does not use learning reminders for third-party advertising.

13. Children

Moji accounts and cloud-sync services are not directed to children under 13 or the applicable minimum age for independent consent in their country. If we learn that we collected personal data from a child without valid authorization, we will take reasonable steps to delete it. A parent or guardian can contact us using Section 15.

14. Changes to This Policy

We may update this policy as Moji, its ownership, or legal requirements change. We will post the updated policy here and revise the date above. If a change materially affects how we use personal data, we will provide additional notice or request consent where required. We will not treat a new policy as retroactive permission for an incompatible use of data collected under an earlier notice.

15. Contact Us

For privacy questions, requests, or complaints, contact:

  • Controller: Kai Kameyama, operator of Moji
  • Email: moji.app.help@gmail.com
  • Service: Moji: Learn Japanese on Your Lock Screen

Please include enough information for us to understand and verify your request. We will respond within the period required by applicable law.

Last Updated: August 26, 2026 · Version 2.1