Privacy Policy
What personal data Mochi handles, where it lives, how long it is kept, and the rights you have over it.
Not yet reviewed by a lawyer
Placeholder, pending legal review
The binding privacy policy has not been drafted or reviewed yet. Nothing on this page is a legal representation, and the sections below describe what the reviewed policy will have to cover rather than stating the policy itself.
The plain-language description of how the product actually behaves is on the privacy page, and it is accurate today.
What the reviewed policy must cover
Controller and contact
Who the data controller is, how to reach them, and whether an EU representative has been appointed. An EU representative must be in place before selling into the EU.
Categories of data
- Account data: identity, email address and sign-in method.
- Subscription data: plan, status, renewal date and licence activations.
- A photograph, if you choose the photo path, processed once to generate your pet and deleted immediately afterwards.
- Generation allowance counters, so the per-account limit on pet generation can be enforced.
- Consent records: timestamped acknowledgements for photo rights, for biometric-adjacent processing and for recording, kept locally and referenced server-side without their content.
- Waitlist data, for as long as the waitlist is open: the email address you gave, the date you gave it, and a keyed hash of your IP address used to rate limit the form and for nothing else. The lawful basis is consent, the address is used to send one confirmation and one message when the app is released, and the whole list is deleted after that. Write to hi@brandnuits.com to be removed sooner.
What never reaches a Mochi server
Audio, transcripts, notes, voice profiles, screen captures and your model provider keys. Speech recognition and speaker separation run on your Mac. This is a statement about how the product is built, and the reviewed policy should say it plainly rather than hedging it.
Legal bases, retention and rights
The lawful basis for each category, how long each is kept, and how to exercise access, rectification, erasure, portability and objection. Account deletion must remove the identity record, the subscription record and any generation history.
Transfers and subprocessors
Where data is processed, which transfer mechanism applies, and a link to thesubprocessor list. Each subprocessor needs a data processing agreement and standard contractual clauses in place before the EU launch.
Faces
The biometric position is set out separately in thebiometric and facial data statement, and the reviewed policy must be consistent with it rather than restating it loosely.
Age
Mochi is for people aged 16 and over. Sign-up carries an age gate, and the reviewed policy must state what happens if an account is found to belong to someone younger.
How to ask about your data
Write to hi@brandnuits.com. Requests are answered by a person, not a form.
Who you are dealing with
Mochi is published by Nuits, a Finnish toiminimi (sole trader).
The registered business address and business ID are withheld for privacy and are available on request. Write tohi@brandnuits.com and you will get them.
All legal and support enquiries go to the same address:hi@brandnuits.com.