Mocavoca · Mocavoca
Privacy Policy
广州登月科技有限公司 (“we,” “us,” or “our”) develops and operates Mocavoca. This policy applies to versions of the Mocavoca app that link to it and to mocavoca.com.
Current app data summary
Local learning features can be used without signing in. After registration or sign-in, the email address, name or display name, account ID, sign-in sessions, synced learning records, social data, and the APNs device token used for friend notifications are sent to the account server. The app contains no advertising and does not track users across apps.
1. On-device and account data
The app stores wordbook selection, learning and answer records, review progress, coins, furniture and cat status, reminder time, pronunciation, and sound settings on the device. Today’s new-word and review counts and completion streak may also be stored in on-device storage shared by the app and Home Screen widget.
When a user chooses an email verification code, Apple, or Google sign-in, we process the email address, name or display name, account ID, sign-in provider identifier, and session information. Session information includes the session identifier and expiry and, when available to the server, the IP address and browser or device identifier. Authentication data is processed by our NestJS account service using Better Auth and PostgreSQL.
After sign-in, when the user or app performs a sync, the server stores learning events, including word identifier, learning stage, answer result, and time; daily progress; coin and furniture inventory; display name and friend handle; friend requests and friendships; and leaderboard records. Wordbook content and widget data are not uploaded to the account server.
Accepted friends can see each other's daily task completion, new-word count, review count, and shared streak. After a user explicitly enables Share learning details, friends can also see the specific words and coins earned that day. Turning it off hides those two details. After a friendship is removed, neither person can access the other's friend learning data.
After sign-in, the app obtains an app-and-device-specific token from Apple Push Notification service (APNs) and associates the token, development or production environment, and interface language with the account. The token is used to send friend-request and request-accepted notifications to that device, not for advertising or cross-app tracking.
2. Product analytics and system permissions
When product usage analytics is enabled, the app sends PostHog app launches, screen views, feature interactions, a device identifier that is not associated with the signed-in account, and app and system versions. Users can turn this feature off or on again on the Privacy & Data screen. We do not use this data for advertising targeting or cross-app tracking.
After sign-in, the app requests system notification permission to show friend-request and request-accepted notifications. When the user enables Daily Reminder, the same permission is also used for local study reminders. Notifications can be disabled in system settings, and Daily Reminder can also be disabled in the app.
Pronunciation and sound effects use device audio output. The current app does not request microphone, camera, contacts, or location permission.
3. Sign-in providers, website, and support email
Apple or Google sign-in sends an authentication request to the corresponding provider, and our server receives a token used to verify identity. For email sign-in, the email service provider processes the email address and one-time verification code.
When you visit the website, the server may automatically process IP address, request time, request path, browser identifier, and referrer to deliver pages, protect security, and diagnose faults. The website uses no advertising trackers or cookies for cross-site tracking.
When a user emails support@mocavoca.com, we process the sender address, message, and any device model, system version, app version, screenshots, or attachments the user chooses to provide so we can respond and handle the request.
4. Data sharing
We do not sell personal information or provide learning or account data to advertisers. Providers for the account service, Apple Push Notification service, PostHog analytics, website hosting, network transport, and business email process only the data needed to provide the corresponding function, subject to their terms and applicable law.
We may provide relevant information when required by law or a lawful judicial or administrative request, or when necessary to protect the lawful rights of users or the public.
5. Retention and deletion
- Account and synced data: retained until the user selects Delete Account on the account screen. Once deletion completes, the account, sessions, synced learning records, friendships, leaderboard profile, coins, furniture data, and associated APNs device tokens are deleted from the server.
- APNs device tokens: the client requests deletion of the current token when signing out on that device; account deletion removes every token associated with the account; and the server removes a token when APNs reports that it is invalid.
- On-device data: kept until the user chooses Clear Local Data in the app or uninstalls the app; copies in system backups follow the applicable backup rules.
- Product usage analytics: handled under the analytics project’s retention settings. Turning off product usage analytics stops the app from sending further events.
- Website access logs: retained while needed for security and troubleshooting and removed according to server log-rotation settings.
- Support email: kept while needed to handle inquiries, complaints, or disputes, then deleted when no longer needed and no legal retention duty applies.
Deleting the app account does not delete on-device data or automatically cancel an Apple subscription. Local data must be cleared separately, and subscriptions are managed in Apple Account subscription settings. See the Data & Deletion page for steps.
6. Information security
The app and website use HTTPS. We restrict access to servers and the support mailbox and use reasonable access control, log rotation, and software updates for the processing purpose. No network or storage method can guarantee absolute security.
7. Children and minors
Minors should use the app and contact support with guidance from a guardian. Guardians may contact us through the support email with questions about data processing.
8. Policy updates
We may update this policy and its effective date when app features, third-party services, or applicable rules change. Material changes will be communicated through an appropriate channel.
9. Contact us
For privacy questions, data requests, or complaints, email support@mocavoca.com.
Operator: 广州登月科技有限公司