1. Who we are
Mochi is made by Hestvera, currently operating as a California sole proprietorship owned by Zhicong Zhong. [Counsel to confirm whether Hestvera is a registered fictitious business name, or whether this policy should identify Zhicong Zhong directly as the service provider.]
- Business address: 1100 Steely, Irvine, CA 92614
- Privacy contact: zcongera@gmail.com
- Product: Mochi, an iOS mobile application
- Website: hestvera.ai
- Initial launch market: United States
This policy explains how Hestvera handles information in connection with Mochi. [Counsel to confirm whether this policy also governs hestvera.ai and any waitlist collected there, or whether the website will have a separate, shorter notice.]
2. What Mochi is — and isn’t
Mochi helps family members create or join a family circle, invite relatives, share lightweight daily check-ins, send messages and nudges, and optionally share other information through permissions they explicitly grant.
Mochi is not:
- A medical device or healthcare service
- An emergency-response service
- A fall-detection or safety-monitoring service
- A substitute for contacting emergency services or a person directly
- A guarantee of any person’s safety, health, or wellbeing
- A professional caregiving or clinical service
A missed check-in, a delayed notification, unavailable connectivity, a device problem, or simply not using the app does not necessarily mean anything is wrong. In an emergency, contact emergency services or the person directly — do not rely on Mochi.
3. Our privacy commitments
Mochi necessarily handles information like phone numbers, names, family relationships, messages, and check-in data in order to work. Rather than claim we don’t collect personal information, here is what we actually promise:
- We collect only the information reasonably necessary to provide Mochi.
- We do not sell personal information.
- We do not use personal information for targeted advertising.
- We share information only as described in this policy and according to each user’s family-circle settings.
- Permissions are requested explicitly, feature by feature, and can be denied or revoked.
- We do not routinely access or review the content families share through Mochi.
4. Information we collect
Account and family-circle data
- Phone number, used for account verification
- One-time verification and authentication records
- Display name and optional profile photo/avatar
- Family-circle name
- Relationship labels, such as parent, child, grandparent, or caregiver
- Name and phone number of anyone you invite to a circle
- Circle membership and invitation status
- Account, device, and session identifiers
- Push-notification device tokens
- Timezone and check-in preferences
Content you and your family create
Available today:
- Text messages and nudges sent within a family circle
- Daily mood/check-in selections and optional check-in notes
- Check-in dates and timestamps
- Missed-check-in notification records
Planned for later releases:
- Photos
- Voice notes (stored, but not transcribed or analyzed)
[Counsel to determine whether mood/check-in information should be treated and disclosed as sensitive information, even though Hestvera does not use it for medical diagnosis, treatment, or health profiling.]
5. How we use information
We use the information above to:
- Create and secure accounts, and verify phone numbers
- Operate family circles, invitations, and relationship labels
- Deliver messages, nudges, check-ins, and related notifications
- Send required account, security, and service messages
- Provide customer support and respond to requests
- Maintain the security, integrity, and reliability of Mochi
- Detect, investigate, and prevent fraud, abuse, and misuse
- Comply with legal obligations
We do not use messages, photos, voice notes, mood data, or location data to build advertising profiles.
6. Permissions
Mochi may ask for permission to access:
- Photos
- Microphone, for voice notes
- Location
- Activity or motion-related data [to be defined precisely by product/counsel]
- Notifications
- Other permissions required by future features
- Permissions are requested explicitly, at the point a feature needs them.
- You can deny a permission and continue using features that don’t require it.
- You can revoke a permission at any time in your device settings.
- We collect only the minimum data needed for the enabled feature.
- We do not collect precise location or activity data unless a specific feature clearly requires it and you’ve granted permission.
- Permission-based data is not sold, used for advertising, or used for unrelated profiling.
[Counsel/product to confirm and disclose whether location, when used, will be precise, approximate, city-level, continuous, or manually shared — this affects the required disclosure language.]
8. Notifications and SMS
We use SMS and push notifications for:
- Login verification codes
- Family invitations
- Daily reminders
- Missed-check-in notifications
- New-message notifications
- Product or marketing communications, where separately permitted
Verification codes and other transactional messages are required to operate your account and cannot be turned off while your account is active. You can opt out of product and marketing communications at any time without disabling required account and security messages.
Vendors we use, or are evaluating, to support these features include:
- Apple Push Notification service, for push notifications
- Twilio or another SMS provider, for verification codes and text messages
- Supabase, AWS, Cloudflare, or other infrastructure providers, for hosting and data storage
- Cloudflare R2 or another object-storage provider, for future media such as photos and voice notes
[Before publishing, replace this list with the actual named production vendors and identify each as a service provider/subprocessor, as applicable. “Providers include but are not limited to” is not acceptable for the final policy.]
9. Analytics and advertising
- We currently use only Apple-provided analytics. [Counsel to confirm whether this means Apple’s App Store/App Analytics only, or also iOS diagnostic and crash data.]
- We do not use targeted advertising.
- We do not sell personal information.
- We do not use advertising pixels or retargeting.
- We do not use messages, photos, voice notes, mood data, or location data to build advertising profiles.
10. Children and minors
Mochi is designed primarily for adults age 21 and older. Family circles may include minors, but a minor’s participation must be controlled and consented to by a parent or legal guardian who manages the circle. Mochi is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13.
[This section reflects a conservative starting position and requires final legal/product sign-off, including: whether users under 18 may create their own accounts; whether users under 13 are prohibited outright; whether verified parental consent is required for a minor’s participation; how that consent is obtained; and who may authorize collection of a minor’s phone number, messages, check-ins, photos, or voice notes. Because Mochi may include minors and collects mobile phone numbers and other identifiable information, counsel should specifically analyze COPPA and applicable state child-privacy laws before this section is finalized.]
11. Data retention and deletion
We retain information for as long as needed to provide Mochi. Current starting points, pending final adoption by counsel, are:
- Account data: retained until account deletion
- Family-circle data: retained while the circle exists or until deleted
- Messages, check-ins, and mood history: retained until deleted by the user or under the product’s deletion rules
- One-time verification records: deleted or anonymized shortly after expiration and any abuse-review needs
- Push tokens: deleted when you sign out, remove the device, or the token becomes invalid
- Security logs: retained for a limited period, such as 90 days, unless a longer period is needed for security or legal reasons
- Deleted production data: removed within 30 days
- Encrypted backups: may retain deleted data for up to 90 days before routine expiration
[Counsel to confirm what specifically happens when: a user deletes their account; a user leaves a family circle; a circle owner deletes the circle; a message recipient deletes their account; or a user requests deletion of content they authored. These retention periods must be finalized, not left as vague “industry standard” language.]
12. Security
We use technical and organizational measures designed to protect your information, including:
- Encryption in transit
- Encryption at rest, where supported by our infrastructure providers
- One-time-password-based authentication
- Session expiration and token controls
- Access controls that separate data between family circles
- Rate limiting on authentication attempts
- Restricted, logged production access
- Reliance on vendors’ own security controls
- Incident-response procedures, including breach notification where required by law
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Mochi does not currently use end-to-end encryption.
13. Your choices and rights
You can review and update your profile, relationship labels, and check-in preferences in the app; leave a family circle at any time; manage notification and marketing preferences; control permissions through your device settings; and request access to, correction of, or deletion of your information by contacting us at zcongera@gmail.com.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act, including the right to know, delete, and correct personal information, and to be free from discrimination for exercising these rights. Hestvera does not sell personal information and does not use it for cross-context behavioral advertising.
[Counsel to confirm the specific state and federal privacy laws that apply at launch, whether Hestvera will operate only in the United States, and whether account-deletion and data-access requests will be handled by email or require a dedicated request mechanism.]
14. Changes to this policy
We may update this policy as Mochi evolves. If we make material changes, we will notify users through the app or by other reasonable means before the changes take effect.
15. Contact us
Questions about this policy or your information can be sent to zcongera@gmail.com, or by mail to Hestvera, 1100 Steely, Irvine, CA 92614.
Open items for legal and product sign-off
- Is Hestvera a registered fictitious business name, or should the policy identify Zhicong Zhong personally?
- Are users under 18 allowed to create accounts? Are users under 13 prohibited outright?
- Will minors require verified parental consent, and how will it be obtained?
- Will location be precise, approximate, city-level, continuous, or manually shared?
- What exactly counts as “activity” data?
- Which vendors will actually be used in production?
- Will the website waitlist collect and store email addresses, and under what notice?
- What exact retention periods will Hestvera adopt for each data category?
- Under what controls can employees access user-generated content for support?
- Will account deletion and data-access requests be handled by email, or a dedicated process?
- Will this policy cover both the website and the mobile app, or will they be separate?
- Will Hestvera operate only in the United States at launch?
- Will Hestvera use any analytics beyond Apple-provided analytics?