Privacy Policy
1. Introduction
This Privacy Policy (“Policy”) describes how Naidžels Naglāzs (Nigel Naglazs) and Mihails Fedurcja (Michael Fedurcja), operating as Mochi: Walk Buddy (“Mochi,” “we,” “us,” or “our”), collect, use, disclose, and otherwise process information when you use the Mochi mobile application and related services (collectively, the “App” or “Services”).
Mochi is developed in Latvia and offered worldwide. By downloading, accessing, or using the App, you acknowledge that you have read and understood this Policy. If you do not agree, do not use the App.
Data controllers: Naidžels Naglāzs (Nigel Naglazs)
and Mihails Fedurcja (Michael Fedurcja), operating as Mochi: Walk Buddy
Country of establishment: Latvia
Contact:
steppet.support@gmail.com
2. Scope
This Policy applies to information processed through:
- the Mochi mobile application (Android and iOS);
- account registration and cloud backup features;
- customer support communications you initiate with us.
This Policy does not apply to third-party websites, app stores, or services that we do not control (including Google, Apple, Firebase, and your device’s health platform), except as described regarding our use of those services.
3. Summary
Mochi is a virtual pet app that uses daily step counts and activity you log in the App to power gameplay. In summary:
- Most data stays on your device by default.
- If you create an account, we store a backup copy of your game progress in Google Firebase (Firestore) so you can restore it.
- We read step count data only from your device’s health platform (where available) or from your device’s motion sensors as a fallback. We do not collect GPS/location data, workout routes, or continuous location tracking.
- We do not sell your personal information.
- We do not use third-party advertising networks.
- If you add friends, we store your friend connections and a public buddy card so friends can see the details you share.
- Optional Premium purchases are processed by Apple or Google. We use RevenueCat to confirm subscription status and unlock features.
- We do not currently integrate third-party advertising or crash-reporting SDKs in the App.
- You may delete your account in Settings, which deletes your cloud backup and removes your authentication account, subject to certain technical limitations described below.
4. Information we collect
We collect information in the categories below depending on how you use the App and which permissions you grant.
4.1 Account and authentication information
If you create an account, we collect:
- email address;
- authentication identifiers (such as a Firebase user ID);
- authentication method used (email/password or Google Sign-In);
- account creation and last sign-in metadata maintained by our authentication provider.
If you sign in with Google, Google may share with us basic profile information associated with your Google account (such as your email address and name), according to your Google account settings and Google’s policies.
An account is required to complete initial setup in the current version of the App.
4.2 Health and fitness information
With your permission, the App accesses daily step count data to power core gameplay features.
- On Android: the App may read step data through Health Connect (READ_STEPS permission).
- On Android (fallback): if Health Connect is unavailable or not granted, the App may use your device’s motion or activity sensors (including activity recognition where required by the operating system) to estimate daily steps.
- On iOS: the App may use your device’s motion or pedometer capabilities to estimate daily steps. HealthKit integration may be added in future versions; if added, we will update this Policy and request any required permissions before access.
We collect aggregate daily step totals relevant to gameplay. We do not intentionally collect precise geolocation or GPS data, workout routes or maps, or heart rate, sleep, or other clinical health measurements unless you separately provide related information through optional in-app logging features described below.
Important: Mochi is not a medical device and is not intended to diagnose, treat, cure, or prevent any disease. Step and nutrition information is for motivation and entertainment only.
4.3 App content, gameplay, and wellness logging data
We process information you create or generate in the App, including:
- virtual pet state (health, mood, evolution, cosmetics, coins, quests, achievements);
- display name and pet name;
- daily step goals and progress summaries used in the App;
- nutrition logs (food names, calories, and macronutrients you enter or save);
- water intake logs;
- optional profile inputs used for in-app planning features (such as age, height, weight, goal weight, and activity level);
- app settings and preferences (including notification preferences);
- premium or unlock status stored by the App;
- timestamps and progress history needed to operate features (for example, streaks, recaps, and reminders);
- Explore finds, Quiet Trail progress, rest days, Streak Shields, and related gameplay state.
4.4 Friends and social features
If you use Friends, we process information needed to connect you with people you add, including:
- your invite / friend code;
- pending and accepted friend connections;
- a public buddy card that friends can see (such as display name, pet name, species, stage, portrait, today’s step count, and whether Premium is active);
- stamps, weekly or monthly challenge standing, and sharing preferences you set in Settings → Friends & sharing.
Friends you accept can see the card and challenge details you share. People who are not your friends cannot browse your card.
4.5 Photos and files
If you choose to attach a meal photo to a nutrition entry, the App may access your camera or photo library through your device’s permission system. Meal photos are stored in the App’s private on-device storage by default. We do not intentionally upload meal photo files to our cloud backup in the current version of the App.
4.6 Device and technical information
We may process limited technical information necessary to operate the App, such as device type, operating system version, app version and build number (for example, when you report an issue), language or locale settings, and permission status relevant to App features.
We do not currently deploy dedicated crash analytics or product analytics SDKs that collect device identifiers for advertising or cross-app tracking.
Some third-party libraries used by the App (such as font delivery through Google Fonts) may cause your device to connect to third-party servers to retrieve resources. See Section 8.
4.7 Communications with us
If you contact us (including through Report issue or email), we collect the information you provide, such as your email address, message content, attachments you choose to send, and metadata needed to respond.
4.8 Information we do not collect
We do not intentionally collect:
- contacts from your address book;
- microphone or audio recordings;
- precise location or GPS data;
- advertising identifiers for cross-app tracking;
- information from social media except what you choose to share through your device’s share sheet.
5. How we use information
We use information to:
- provide the App and operate virtual pet gameplay tied to steps and in-app care actions;
- authenticate users and secure accounts;
- back up and restore progress when you use an account;
- personalize in-app features you configure (goals, profile inputs, pet and name display);
- operate Friends features you choose (invite codes, buddy cards, stamps, and weekly or monthly challenges);
- confirm Premium purchases and restore entitlements through the App Store or Google Play and RevenueCat;
- send local reminders you enable (for example, pet care nudges, step reminders, and weekly recap notifications);
- operate optional device features such as home-screen widgets showing pet and status summaries;
- respond to support requests and fix bugs or reliability issues you report;
- comply with law and enforce our terms;
- protect users and the Services against fraud, abuse, or security incidents.
We do not use your information for third-party targeted advertising.
6. Legal bases for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal data under the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the App and account features | Performance of a contract; legitimate interests |
| Health or step access you authorize | Your consent; performance of a contract where applicable |
| Local notifications you enable | Your consent |
| Cloud backup when you create an account | Performance of a contract |
| Friends and shared buddy cards you enable | Performance of a contract; legitimate interests |
| Premium purchase status via the store / RevenueCat | Performance of a contract |
| Support communications | Legitimate interests; performance of a contract |
| Security, fraud prevention, legal compliance | Legitimate interests; legal obligation |
You may withdraw consent for optional permissions (such as notifications or health access) through your device settings. Withdrawing consent may limit functionality.
7. Permissions
The App may request device permissions including:
- Health / steps — to read daily step counts;
- Activity recognition / motion sensors — fallback step counting where applicable;
- Notifications — to deliver local reminders you enable;
- Camera / photos — only if you choose to add meal photos;
- Internet access — for account sign-in, cloud backup, friends, purchases, and third-party service connectivity.
You can revoke permissions in your device settings. Some App features will not work without certain permissions.
8. Third-party service providers
We use service providers that process information on our behalf to operate the App. These may include:
8.1 Google / Firebase (Google LLC)
We use Firebase services, which may include:
- Firebase Authentication (account sign-in);
- Cloud Firestore (cloud backup of App progress tied to your account).
Firebase may process authentication tokens, account identifiers, and backup data in Google’s infrastructure. Google’s privacy policy: policies.google.com/privacy
8.2 Google Sign-In
If you choose Google Sign-In, Google processes information according to Google’s policies.
8.3 RevenueCat
We use RevenueCat to check Premium entitlement after you buy or restore through the App Store or Google Play. RevenueCat may process a store purchase identifier, product / entitlement status, and technical data needed to confirm the subscription. Payment card details stay with Apple or Google.
RevenueCat’s privacy policy: revenuecat.com/privacy
8.4 Apple (iOS users)
If you use the App on iOS, Apple processes App distribution, device permissions, and (if applicable in future) HealthKit data according to Apple’s policies.
8.5 Google Fonts
The App may download fonts from Google servers at runtime. This may involve your device’s IP address and basic technical data being processed by Google when fonts are fetched.
We do not allow these providers to use your personal information for their own marketing purposes except as permitted by their terms and applicable law.
9. Local storage vs. cloud backup
9.1 On your device
Most App data is stored locally on your device (including pet progress, logs, settings, and meal photos in App-private storage).
9.2 Cloud backup and live cloud features
When you are signed in, we store a backup snapshot of selected App data in Firestore under your user ID. This may include pet state, settings, nutrition entries, water logs, achievements, cosmetics, premium flag, and related gameplay data.
Separately, Friends features use live cloud data (invite codes, friend connections, public buddy cards, stamps, and challenge standing) so accepted friends can see what you share. That is not the same as restoring a full save onto another device.
Not all device-local data is backed up. For example, certain raw sensor step ledger data and local photo files may remain device-only. Cloud backup is intended for restore and backup, not real-time multi-device synchronization of your whole save.
10. How we share information
We do not sell your personal information.
We may share information only in these situations:
- Service providers — as described in Section 8, under contractual obligations to protect data;
- Legal requirements — if required by law, regulation, legal process, or governmental request;
- Protection — to protect the rights, safety, and security of Mochi, our users, or others;
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets;
- With your friends — when you add friends, we show them the buddy card and challenge details you share;
- With your direction — when you use share features (for example, sharing a stat card through your device’s share sheet).
11. International data transfers
If you use the App from outside the country where our service providers operate, your information may be transferred to and processed in countries that may have different data protection laws (including the United States, where Google and Firebase infrastructure may be located).
Where required by law, we implement appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses or equivalent mechanisms offered by our providers.
12. Data retention
We retain information only as long as necessary for the purposes described in this Policy:
- Account and cloud backup data: retained while your account is active; deleted when you delete your account, subject to provider deletion schedules;
- Local device data: retained until you delete the App, use Start fresh, or delete your account;
- Support emails: retained as long as needed to resolve your request and for reasonable recordkeeping;
- Legal or security records: retained longer where required by law or for dispute resolution.
13. Security
We implement reasonable administrative, technical, and organizational measures designed to protect personal information, including authenticated access controls for cloud backup, encrypted transport (HTTPS/TLS) for network communications with our providers, and on-device storage within the App sandbox.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
14. Your privacy rights
Depending on where you live, you may have rights including access, correction, deletion, restriction, objection, portability, withdrawal of consent, and the right to lodge a complaint with a data protection authority.
14.1 Account deletion in the App
Signed-in users can delete their account in Settings → Delete account. This generally:
- deletes your cloud backup document in Firestore;
- deletes your Firebase authentication account;
- removes friend connections and your public buddy card where we control that data;
- signs you out and wipes local App progress on the device.
Deletion may fail if recent re-authentication is required for security reasons. If that happens, sign in again and retry, or contact us. Start fresh clears local data but does not delete your cloud account.
Full step-by-step instructions (in-app and by email): Delete your account.
14.2 How to exercise rights
Contact us at steppet.support@gmail.com with the subject line “Privacy Request.” We may need to verify your identity and will respond within timelines required by applicable law.
14.3 California residents (CCPA/CPRA)
California residents have additional rights, including the right to know, delete, and correct personal information, and the right to opt out of sale or sharing for cross-context behavioral advertising.
We do not sell or share personal information for cross-context behavioral advertising as defined under California law. We do not discriminate against you for exercising privacy rights. Authorized agents may submit requests on your behalf with proof of authorization.
15. Children’s privacy
Mochi is not directed to children under 13 (or the minimum age required in your jurisdiction without verifiable parental consent).
We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact steppet.support@gmail.com and we will take steps to delete such information.
16. In-app purchases and payment information
Optional Premium is offered through the Apple App Store or Google Play. Payment processing is handled by the store provider, not directly by us. We do not receive your full payment card number.
We may receive purchase-related information from the store and from RevenueCat (such as product ID, purchase status, and subscription status) as needed to unlock Premium.
17. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, where required by law, provide additional notice (such as in-App notice or email).
Your continued use of the App after the effective date of an updated Policy constitutes acceptance of the updated Policy, except where further consent is required by law.
18. Contact us
If you have questions or concerns about this Policy or our privacy practices:
Email:
steppet.support@gmail.com
Data controllers: Naidžels Naglāzs (Nigel Naglazs)
and Mihails Fedurcja (Michael Fedurcja), operating as Mochi: Walk Buddy
Country of establishment: Latvia