Privacy Policy
DraftLast updated: Aug 20, 2026 (draft)
This policy describes how we handle information obtained in providing MojiCare (the "Service").
1Information we collect
- 1
We collect account information (such as the email address and user identifier obtained from the authentication provider).
- 2
In connection with use of the Service, we collect request metadata (IP address, timestamp, response status, latency, and so on).
2Handling of submitted text
- 1
We do not store the body of text submitted for moderation. It is processed in memory for moderation and discarded after the response.
- 2
We never record the body of submitted text or plaintext API keys in logs, databases, or error messages.
3Metadata retention
- 1
Request metadata is retained for 90 days for abuse detection, billing verification, and incident response, and then deleted.
4Missed-word reports
- 1
Text that the user deliberately submits as a missed-word report is stored to improve moderation accuracy.
- 2
This is the only exception to our policy of not storing submitted text, and is limited to what the user intentionally sends through the report form.
5Provision to external services
- 1
To provide the Service, we share information with the following external services to the extent necessary.
- 2
Infrastructure: Google Cloud Platform; Payments: Stripe; Email: Resend. Each company handles data under its own privacy policy.
6Account closure and data deletion
- 1
We delete personal data 30 days after account closure. API keys are revoked at closure.
- 2
Billing and transaction records that we are legally required to keep are retained for the required period.
7Use of cookies
- 1
We use cookies and similar technologies to remember the display language and theme and to keep you logged in.
8Contact and requests for disclosure
- 1
For requests to disclose, correct, or delete retained personal data, please contact us. We will respond in accordance with the law after verifying identity.