Summary

1. Who we are and what this policy covers

Mori (月序) is a privacy-first, offline-first period tracking and cycle estimation app for iOS and Android, developed and operated by an individual developer, Jie Cao (the "developer"). Mori is currently published for users outside mainland China; this policy does not describe a mainland-China-specific offering.

Developer (legal) name: Jie Cao
Contact: privacy@moricycle.com.

This policy covers the Mori app on all platforms where it is published, and this website. It explains what information the app handles, where it is stored, why it is needed, how long it is kept, and how you can export or delete it. Purchase and refund terms are published separately in the Purchase & Refund Policy.

2. What information we handle

The table below is the complete inventory of personal data the app can handle. "Leaves device" means the data is transmitted off your device; everything else stays local by default.

DataPurposeWhere it livesLeaves device?Retention
Period dates, cycle clusters derived from them; symptoms, moods, notes, custom tags (all user-entered)Recording, cycle estimates, calendar, insightsApp's local database (device only)No (only inside an encrypted sync snapshot if you enable sync)Until you delete it or reset the app
Predictions, statistics, insights derived from your recordsOn-device computation for displayDevice onlyNo — never uploaded, not even with syncUntil you delete the underlying records
Reminder settings; language, theme, cycle preferencesApp functionalityDevice onlyOnly a small subset inside the sync snapshotUntil you change or delete them
Anonymous on-device identity (randomly generated)Separates local data namespaces; not a login, not an accountSystem secure storage (device only)No — never uploadedUntil you erase on-device data
Export files (JSON / CSV / readable summary)Export — generated only when you askWherever you choose to save or share themOnly if you share them; then outside our controlUnder your control
Email address (sync account, optional)Sign-in, verification, security notices, password resetSync server (Thailand)Yes — only if you create a sync accountUntil you delete the account
Encrypted sync snapshot (optional)Cross-device backup/restore of your recordsSync server (Thailand) as ciphertextYes — only if you enable syncUntil you delete the snapshot or the account
Payment fields: email, order number, license keyProcessing your one-time purchase (handled by the payment provider)Payment provider and sync serverYes — only if you purchaseSee §7 and the Purchase & Refund Policy
Update-check metadata (platform, app/runtime version)Checking for app updates over the networkUpdate service (Expo) — no health data involvedYes — automatic, minimal technical data onlyHandled by the update service

All estimates shown in the app are computed from your own history. They are estimates, not medical facts.

3. Permissions

PermissionWhen requestedUsed forIf refused
NotificationsOnly when you enable a period or ovulation reminder — never at first launchLocal reminders. Notification text never contains period or ovulation detailsReminders are unavailable; everything else works

Mori requests no location, contacts, photos, microphone, calendar or health-platform permissions.

4. Storage, processing and what leaves your device

Without sync: all health data lives in the app's local database; the anonymous identity lives in system secure storage. The only network traffic the app generates is checking for software updates (technical metadata only, never health data). Core features need no network.

System backups: on-device data may be included in your OS backup (e.g. iCloud or Google backup). We cannot control how long your OS retains backups, and deleting data in the app does not delete existing OS backups.

What we do not do: no advertising or ad SDKs; no analytics, tracking or telemetry SDKs; no health data in logs, crash reports or diagnostics; no sale, rent or sharing of your health data with third parties.

5. Optional cloud sync

Sync is off by default and requires that you actively create a verified-email sync account. By enabling sync you explicitly consent to the processing described in this section; turning sync off withdraws that consent for future uploads (previously uploaded snapshots stay until you delete them).

When enabled, only the following leaves your device, as a client-encrypted snapshot:

Predictions, statistics, insights, export files, notification schedules and your anonymous identity are never uploaded. The sync server stores only ciphertext and does not parse, search or display your health data. However, the account-recovery flow can unwrap the encryption key, so this service is not end-to-end encrypted and not "zero-knowledge". We never describe it otherwise.

Three deletions are independent: delete on-device data, delete the cloud snapshot, delete the account. None of them performs the others automatically.

6. Payments

If you purchase the one-time cloud-sync unlock, checkout is processed by a third-party payment provider (Creem). Only the minimal fields needed for the transaction — email, order number and license key — are handled; your health data is never part of the transaction. Refunds, license-key rules and chargeback handling are published in the Purchase & Refund Policy.

7. Third-party services

ServiceRoleData involvedWhere
Sync server (self-hosted)Stores sync accounts and encrypted snapshotsEmail, credentials (hashed), ciphertextThailand
CreemPayment checkoutEmail, order number, license keyOperated by Creem — see their privacy policy
ResendSends verification and password-reset emailsEmail address only; emails never contain health dataOperated by Resend
CloudflareDNS / CDN / TLS for our domainsStandard network metadata (e.g. IP) as processed by CloudflareGlobal network
Expo (EAS Update)App update deliveryUpdate-check metadata (platform, versions)Operated by Expo
Apple App Store / Google PlayApp distributionYour relationship with the store (account, downloads)Per the store's own terms

We do not embed advertising, analytics or tracking SDKs. Health data is shared with none of the services above.

8. International transfers

Mori is published for users outside mainland China. Depending on where you are, using sync, email verification or purchases transfers the limited data described above to Thailand (sync server) and to the third-party services in §7 in their operating regions. Those services process data under their own privacy policies.

9. Retention and deletion

DataRetentionHow to delete
On-device records, settings, derived dataUntil you delete themPer-record delete, or Settings → Data & Privacy → Erase All On-Device Data & Reset
Anonymous on-device identityUntil erased with on-device dataSame erase action as above (irreversible)
Email address and accountUntil account deletionSettings → delete account (removes account, sessions, wrapped key, snapshots, reset tokens)
Encrypted snapshotsUntil deletedSettings → delete cloud snapshot (keeps the account)
Verification / reset one-time codes10 minutes, single useExpire automatically
Server logsShort operational window; never contain health data or message contentRotate out automatically
Server backupsEncrypted backups rotate within ~30 days of online deletionAutomatic — we cannot promise instant disappearance from backups

10. How we protect your data

If a security incident affects your personal data, we will notify you and take reasonable remediation steps without undue delay.

11. Your rights and how to exercise them

Where data-protection law applies to you (for example the GDPR if you are in the EEA or UK), you have the right to access, correct, delete, restrict and port your personal data, to object to certain processing, and to withdraw consent. You also have the right to lodge a complaint with your supervisory authority.

Most rights can be exercised directly in the app: export (access & portability) and deletion of on-device data, cloud snapshots and account. For anything else, contact us at privacy@moricycle.com — we aim to respond within 30 days. We may need to verify your identity before acting on a request; if we refuse a request, we will explain why.

12. Children

Mori is not directed at children under 13 (or a higher minimum age where local law requires). If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to this policy

We publish the current version on this page with its version number, effective date and last-updated date. Material changes will be announced in the app or on the website before they take effect; the version available in the app always matches this page.

14. Contact

Questions about this policy or your data: privacy@moricycle.com. Purchase and refund matters: see the Purchase & Refund Policy.