What changes in iOS 1.15
This section describes the updated advertising measurement behavior in Moji iOS 1.15 builds containing this change. Earlier installed builds may behave differently; the earlier policy versions remain available above.
Trial and subscription events may be sent from RevenueCat to Meta even when you decline Apple App Tracking Transparency permission or have not yet made a choice. Moji supplies a persistent Meta app-scoped identifier, available device and network information, and your actual permission status. The iOS advertising identifier is available only with your permission. Declining permission does not stop all measurement data described below from being sent.
1. Scope and Who We Are
This Privacy Policy explains how Moji ("Moji", "we", "us", or "our") collects, uses, discloses, and protects information when you use the Moji iOS app, Android app, website, or related support services.
Moji is currently operated by Kai Kameyama, who is the controller of personal data described in this policy. You can contact us at the address in Section 15.
The iOS and Android apps do not use data in exactly the same way. The current iOS app does not offer sign-in and normally stores new learning progress on the device. The Android app offers optional Moji accounts and cloud progress sync through Supabase. The platform-specific details are explained below.
2. Information We Collect
Information you provide
- Learning preferences: Japanese experience level, JLPT goal, daily card limit, reminder settings, display settings, onboarding status, and similar preferences
- Android account information: Email address, display name when provided, authentication provider, and an account identifier when you create or use an optional Android account
- Legacy iOS account information: If you signed in with Apple or Google in an older iOS version, we may retain the email address, name, provider, account identifier, and cloud records created at that time until they are deleted
- Support information: Your email address and the content of messages you send to us
- Prior Android waitlist information: The email address, source, request status, and related timestamps submitted before Android launched
Supabase manages Android and legacy authentication credentials. We do not receive or store your plaintext password.
Learning and app data
- Review activity: Kanji reviewed, response rating, review time, repetition state, intervals, ease values, and next review date
- Progress: Streaks, cards learned or due, JLPT progress estimates, milestones, and similar learning statistics
- App activity: Screens or features used, app lifecycle events, learning-session activity, subscription events, app version, operating system, device type, language, and app-scoped identifiers
- Subscription information: Product, entitlement, transaction, renewal, trial, and subscription status received from Apple, Google Play, and RevenueCat
- Advertising measurement on iOS 1.15: Meta may receive app activation and onboarding completion events, plus trial and subscription events sent through RevenueCat, regardless of your Apple tracking-permission choice. Information may include a persistent Meta app-scoped identifier, identifier for vendor, IP address, app and device details, actual permission status, and purchase context. The iOS advertising identifier is available only after you grant permission.
Information stored on your device
- The bundled kanji database and app content
- Learning progress, review history, preferences, streaks, and notification schedules
- Widget state used by the app and its widget on the same device
- Authentication session information if you choose to sign in on Android
3. How Each Platform Uses Supabase
Current iOS app
The current iOS app does not create accounts or offer sign-in. New iOS learning normally remains on the device and is not continuously synchronized to Supabase. On an eligible upgrade from an older signed-in version, Moji may use a saved legacy session once to reconcile matching local and Supabase review records before retiring the saved session. Legacy account and cloud records may remain until a verified deletion request is completed.
Android app
The Android app offers optional account access using supported email, Google, or Apple sign-in methods. If you sign in, Supabase processes the account profile, learning preferences, review events, and calculated SRS progress needed to synchronize supported learning data across sessions or devices. If you do not sign in, learning data that is not otherwise described as analytics or subscription data remains on the device.
4. How We Use Information
- Provide kanji lessons, spaced-repetition reviews, progress tracking, widgets, reminders, and cloud sync where available
- Create, authenticate, secure, support, and delete optional Android accounts
- Perform the limited legacy iOS progress transition described above
- Process purchases, determine entitlement status, restore purchases, and prevent subscription fraud
- Understand app performance and feature use, troubleshoot problems, and improve Moji
- Measure app activation, onboarding, trials, and subscriptions to understand advertising performance and support campaign optimization where Meta permits it, using the data and permission controls described in Section 6
- Respond to support, privacy, and account-deletion requests
- Complete and verify the Android launch communications requested through the former waitlist
- Protect Moji, enforce our terms, comply with law, and establish or defend legal claims
5. Legal Bases for Processing
Where applicable law requires a legal basis, we rely on one or more of the following:
- Contract: Processing needed to provide the app, account, cloud sync, support, and subscription features you request
- Legitimate interests: Securing, maintaining, analyzing, and improving Moji, including basic app install and activation measurement where permitted by law, provided those interests are not overridden by your rights
- Consent: Processing the iOS advertising identifier, and other advertising measurement where applicable law requires consent; you may withdraw consent through the relevant device setting
- Legal obligations: Processing needed for accounting, tax, consumer protection, privacy, security, and other legal requirements
6. Service Providers and Disclosures
We disclose information only as needed for the purposes described in this policy, at your direction, or where required or permitted by law. Our main service providers are:
Supabase
- Purpose: Optional Android authentication and cloud sync, limited legacy iOS compatibility and deletion, and storage of prior Android waitlist and operational records
- Data: Account identifiers, email and profile fields, authentication provider and session data, preferences, review events, SRS card state, deletion records, and prior waitlist records
- Policy: supabase.com/privacy
RevenueCat
- Purpose: Subscription entitlement, purchase validation, subscription analytics, and purchase restoration on iOS and Android
- Data: App-scoped or account identifier, store, product, transaction, entitlement, trial, renewal, and subscription status
- Meta subscription measurement on iOS 1.15: Moji provides RevenueCat with the persistent Meta app-scoped identifier, available device identifiers such as the identifier for vendor, IP address, and actual Apple tracking-permission status before purchase. RevenueCat may send these fields, a hashed external identifier, and trial, purchase, renewal, product, transaction, value, currency, and store information to Meta through its Conversions API. This delivery is enabled even without authorized tracking permission. A valid iOS advertising identifier is available only with permission. Declining or revoking permission does not clear the Meta app-scoped identifier from RevenueCat or delete information already received by either provider.
- Policy: revenuecat.com/privacy
PostHog
- Purpose: Product analytics, reliability monitoring, and understanding feature use
- Data: App-scoped installation or account identifier, app and device information, screens and features used, lifecycle events, learning-session activity, and purchase events. Older releases may have associated email, display name, or sign-in provider with an analytics identifier.
- Controls: Moji does not use PostHog mobile session replay
- Policy: posthog.com/privacy
Meta App Events on iOS 1.15
- Purpose: App install attribution, activation measurement, and advertising campaign measurement
- Basic activation data: When Moji launches or becomes active, Meta may receive a persistent Meta app-scoped identifier, app bundle identifier, app version and build, iOS version, hardware model, locale, time zone, carrier, screen density, CPU core count, IP or related network information, and app install, activation, deactivation, and session information. Moji sends this basic activation information whether Apple tracking permission is authorized or denied.
- Onboarding and subscription measurement: Moji submits onboarding completion events regardless of tracking-permission status. RevenueCat sends the trial and subscription events described above, including when the app is closed. Meta determines whether received events can be matched to advertising or used for campaign optimization.
- Controls: Automatic Meta event logging and automatic in-app purchase logging are disabled. Moji enables advertising-identifier collection only when Apple tracking permission is authorized and reports your actual permission status. It retains the Meta app-scoped identifier when permission is denied, restricted, undetermined, or revoked. Moji does not supply your email address or learning records to Meta through this integration. Apple may also provide delayed, aggregate advertising measurement through SKAdNetwork without the advertising identifier.
- Policy: facebook.com/privacy/policy
TikTok for Business on earlier iOS versions
- Purpose: Advertising attribution and campaign measurement in iOS versions released before version 1.13
- Data: Only after you grant Apple tracking permission, an advertising identifier and limited install, onboarding, trial, and purchase completion events
- Transition: Updating to iOS version 1.13 or later removes the TikTok SDK. An earlier installed version may continue using it until you update, and data previously received by TikTok remains subject to TikTok's retention practices.
- Controls: Moji does not send your email address, Moji account identifier, or learning records to TikTok. You can deny or revoke tracking permission in iOS settings.
- Policy: tiktok.com/privacy
Apple, Google, and sign-in providers
- Apple App Store and Google Play: Distribute the apps and process purchases under their own privacy policies
- Apple and Google sign-in: Authenticate users who choose those Android account methods and provide the identifiers and profile fields authorized by the user
- Apple policy: apple.com/legal/privacy
- Google policy: policies.google.com/privacy
We may also disclose information to professional advisers, authorities, courts, or other parties when reasonably necessary to comply with law, protect users or Moji, investigate abuse, or establish and defend legal claims.
7. Business Transfers and Change of Control
If Moji, its business, or relevant assets are involved in a proposed or completed financing, reorganization, merger, acquisition, or sale, information may be reviewed by advisers and prospective acquirers and may be transferred to a successor where permitted by law. Any pre-completion disclosure will be limited to information reasonably necessary to evaluate or complete the transaction and will be subject to appropriate confidentiality and security restrictions. We will use aggregated or de-identified information for diligence where reasonably possible.
A successor may use transferred personal information only for purposes consistent with this policy and the purposes for which the information was originally collected, unless another lawful basis applies. This section does not authorize an acquirer to use personal information for a materially incompatible purpose. We or the successor will provide notice, and obtain consent where required, before any materially different use.
8. Retention
- Android accounts and cloud learning: Retained while the account is active and then deleted or de-identified after a verified deletion request, subject to limited backup, fraud-prevention, security, and legal records
- Current iOS learning: Stored on the device until the app or its data is deleted; legacy cloud records remain until deleted or no longer reasonably needed
- Subscriptions and transactions: Retained as needed for entitlement, accounting, tax, fraud prevention, dispute resolution, and other legal obligations
- Analytics: Retained according to our provider settings and for as long as reasonably needed for product analysis, security, and troubleshooting, after which it is deleted or de-identified
- Support and privacy requests: Retained as needed to resolve the request and document compliance
- Former Android waitlist: The waitlist is closed following the August 19, 2026 Android launch. Existing records are used only to complete or verify the requested launch communications, handle removals, and prevent duplicate sends. They will be deleted or de-identified no later than November 17, 2026 unless a longer period is required by law.
Protected backup copies may remain until normal backup rotation completes. We may retain de-identified or aggregated information that can no longer reasonably identify a person.
9. Your Choices and Rights
Depending on where you live, you may have rights to:
- Ask whether we process your personal data and request access to it
- Correct inaccurate or incomplete personal data
- Request deletion or restriction of processing
- Receive certain data in a portable format
- Object to processing based on legitimate interests
- Withdraw consent without affecting processing that occurred before withdrawal
- Lodge a complaint with your local data-protection authority
We do not sell personal information for money. Some laws may define advertising measurement as "sharing" even when no money is exchanged. You can deny or revoke Apple tracking permission in iOS Settings to prevent access to the advertising identifier. This does not stop the app activation, onboarding, or RevenueCat subscription measurement described in Section 6, remove the Meta app-scoped identifier, or delete previously received data. Contact us using Section 15 to request access, deletion, or exercise applicable rights to object to or opt out of processing.
To exercise a privacy right, contact us using Section 15. We may need to verify your identity before completing a request.
Deleting an Android account
If you are signed in on Android, use the account deletion control in the app. This deletes the Moji authentication account and associated Supabase profile, preferences, review events, and calculated SRS progress, subject to the limited retention described above.
Deleting a legacy iOS account
The current iOS app has no authenticated account screen. If you created a Moji account in an older version, request verified deletion through our account deletion page.
Deleting an account does not cancel an Apple App Store or Google Play subscription. Cancel the subscription separately in the store that processed it. Account deletion also does not erase learning data stored only on a device; delete the app or clear its local data on that device.
10. Security
- HTTPS/TLS encryption for data transmitted to our service providers
- Supabase Row Level Security and access controls for account and cloud learning data
- No public read access to former Android waitlist records
- Access limited to people and service providers who need it for the purposes in this policy
No system is completely secure. We cannot guarantee absolute security, but we use reasonable technical and organizational safeguards appropriate to the information we process.
11. International Data Transfers
Moji and its service providers may process information in countries other than the country where you live. Where required, we use contractual, organizational, or other safeguards intended to provide an appropriate level of protection for transferred personal data.
12. Notifications
Moji may ask for permission to send local learning reminders, streak alerts, and milestone notifications. These notifications are optional and can be disabled in the app or device settings. Moji does not use learning reminders for third-party advertising.
13. Children
Moji accounts and cloud-sync services are not directed to children under 13 or the applicable minimum age for independent consent in their country. If we learn that we collected personal data from a child without valid authorization, we will take reasonable steps to delete it. A parent or guardian can contact us using Section 15.
14. Changes to This Policy
We may update this policy as Moji, its ownership, or legal requirements change. We will post the updated policy here and revise the date above. If a change materially affects how we use personal data, we will provide additional notice or request consent where required. We will not treat a new policy as retroactive permission for an incompatible use of data collected under an earlier notice.
15. Contact Us
For privacy questions, requests, or complaints, contact:
- Controller: Kai Kameyama, operator of Moji
- Email: moji.app.help@gmail.com
- Service: Moji: Learn Japanese on Your Lock Screen
Please include enough information for us to understand and verify your request. We will respond within the period required by applicable law.
Last Updated: September 6, 2026 · Version 2.2