Privacy
What leaves your machine, and what does not
Last updated 2026-09-09. Mochi is local-first: your tables are files on your disk, and this page is mostly a list of the few things that are not.
Your workspaces never leave your machine
Tables, rows, cell values, column names, attachments and history live in SQLite files on your own disk. The app has no upload path for them: nothing in it sends a row anywhere, and no server here has anywhere to put one. If you delete the file, the data is gone — there is no copy here to ask us for.
This is a design constraint rather than a promise about intentions. The app opens four kinds of outbound connection and no others: your account, the plan-limit document, the version check, and feedback you type and send deliberately. Each is described below.
What we store, in full
This is the complete list. Nothing is stored that is not named here.
- Your email address, from signing in with Google. It identifies your account and is what a licence is attached to. We receive your email from Google and nothing else — not your name, not your profile picture, not your contacts.
- Your subscription status: an identifier from Polar Software Inc., whether it is active, how many seats, and when the current period ends. No card number, no billing address, no payment history.
- A weekly count of agent calls, so a plan limit can be enforced. A number per week — not what the calls did, not which tables they touched.
- Sign-in sessions: a hash of each session token, when it was created, when it was last used, and a short label taken from the browser or app that signed in. The token itself is never stored, only its hash.
- Feedback you send, if you send any: what you wrote, plus the app version and platform so a bug report can be placed. Sent only when you press the button that says so.
What we never receive
- The contents of your tables, or their names, or the names of your workspaces.
- Files you attach. They are copied into your workspace folder on your disk.
- Card numbers. Polar Software Inc. is the merchant of record and handles payment; we are told only that a subscription exists.
- Analytics of how you use the app. There is no telemetry in it.
The version check
The app asks this site whether a newer build exists. That request carries no account and nothing about your machine — the answer is the same for everybody, so there is nothing to say. As with any HTTP request, the server sees the IP address it came from.
How long it is kept
Account and subscription records last as long as the account. Sign-in sessions end when you sign out, when you end them from your profile, or when a new machine signs in past the limit. Weekly usage counts are kept for the current and previous periods so a limit can be shown and reset. Feedback is kept until it has been acted on.
Getting rid of it
Write to kurodenjiro@gmail.com and ask. We will delete the account, its email address, its sessions and its usage counts. Records Polar Software Inc. must keep for tax purposes are theirs rather than ours, and their policy governs those.
You can also ask for a copy of everything above, or for a correction. If you are in the EU or UK, those are rights you have rather than favours we grant.
Who to write to
Kuro
USA
kurodenjiro@gmail.com