Privacy Policy

Mooshie Moments · Last updated: 1 May 2026 · Effective: 1 May 2026

This Privacy Policy explains how Mooshie Moments (“Mooshie”, “we”, “us”, or “our”) collects, uses, and protects information when you use our mobile application (the “App”) and our website (the “Site”). It applies to anyone who downloads, installs, or interacts with our products.

Mooshie is a parent-facing app for parents and caregivers to share play activities with their toddler. The parent or caregiver is the user. The child does not interact with the App directly and does not have an account. We have written this policy in plain English; legal definitions are at the end if you need them.

Contents

  1. Who we are
  2. What information we collect
  3. Why we collect it
  4. Who we share information with
  5. Children’s information
  6. Cookies, tracking, and analytics
  7. How long we keep information
  8. How we protect information
  9. International transfers
  10. Your rights
  11. California residents (CCPA)
  12. Changes to this policy
  13. Contact us
  14. Definitions

1. Who we are

Mooshie Moments is operated by Samitpatelvs LTD, a company registered in United Kingdom. For privacy questions, contact us at contact@mooshiemoments.com

For the purposes of UK and EU data protection law (UK GDPR and EU GDPR), we are the “data controller” of the personal information described in this policy.

Plain-English summary. We collect very little. We don’t sell your data, ever. Photos you take inside the App stay on your device — we never see them. We use Apple, RevenueCat, and Firebase as service providers to run the App; we don’t share your data with advertisers.

2. What information we collect

We’ve split this into what we collect about you and what stays only on your device.

2.1 Information collected about you

CategoryWhat it includesSource
Subscription and purchase dataWhether you have an active Mooshie Pro subscription, the type (monthly, annual, lifetime), purchase date, renewal status, and the country / currency of purchase. We do not see your credit card details — those go to Apple directly.Apple App Store and our payment processor (RevenueCat)
App-usage analyticsAggregate counts of which screens are opened, which activities are completed, button taps, time-of-day patterns. This is anonymous (a random per-install ID, no name or email) and is not linked to your identity.Firebase Analytics (Google)
Crash and error dataIf the App crashes, we receive a stack trace, your iOS version, device model, and the screen you were on. No personal content is included. This helps us fix bugs.Firebase Crashlytics (Google)
Device identifiers (optional)If you grant App Tracking Transparency permission on iOS, your Identifier for Advertisers (IDFA) is included with analytics events. If you decline, we don’t receive it. The App functions identically either way.Your iOS device, with your explicit permission
Email or contact detailsOnly if you email us directly — we keep the message and your email address so we can reply.You

2.2 Information that stays on your device

The following information is stored only on your device’s local storage and is never sent to our servers or to any third party:

  • Your child’s name, age band, and any developmental notes you enter during onboarding (used to personalise activity recommendations).
  • Photos you take inside the App to attach to an activity memory. These are stored in the App’s local storage or, if you choose, your device’s Photos library. We never upload photos.
  • Activity completions, favourites, reactions, and notes — for your own history view inside the App.
  • Your sensory preferences and additional-needs settings — used by the App on-device to adapt activities.

Because this information stays on your device, you can delete it at any time by deleting the App or by clearing the App’s data in iOS Settings.

3. Why we collect it

We use the information described above for the following purposes:

  • To run the App. Subscription data is needed to give you access to Mooshie Pro and to remember your purchase across reinstalls or new devices.
  • To improve the App. Analytics tell us which features parents actually use, where they get stuck, and which activities work. We use this to prioritise improvements.
  • To diagnose problems. Crash data shows us what’s breaking so we can fix it.
  • To respond to you. If you contact us, we use your email to reply.

We do not use your information to:

  • Show you targeted advertising
  • Sell your data to third parties
  • Build profiles for marketing
  • Train AI models on your inputs

3.1 Legal bases (UK and EU users)

If you are in the UK or EU, we rely on the following legal bases under the UK GDPR / EU GDPR:

  • Contract. Subscription and purchase data is processed because we need it to deliver the service you’ve paid for.
  • Legitimate interests. Analytics and crash data are processed because we have a legitimate interest in understanding how the App is used and in diagnosing failures. This processing is balanced against your privacy by being anonymous (analytics) and free of personal content (crash reports).
  • Consent. The optional iOS Identifier for Advertisers (IDFA), enabled via App Tracking Transparency, is processed only with your consent. You can withdraw consent at any time in iOS Settings → Privacy & Security → Tracking.
  • Legal obligation. In some cases (e.g. responding to valid legal requests), we may process information because the law requires it.

4. Who we share information with

We share the minimum amount of information necessary with the following categories of service providers (“processors”) who handle data on our behalf:

ProviderWhat they receiveWhy
Apple Inc.App download events; subscription receipts; payment.Distribution and payment processing for the App Store. Apple is the merchant of record for all purchases.
RevenueCat, Inc.Anonymous subscriber ID, subscription status, purchase events. No name, email, or payment card.Subscription management, restore purchases across devices, receipt validation. RevenueCat acts as our processor.
Google LLC (Firebase)Anonymous app-usage events (Firebase Analytics) and anonymous crash reports (Firebase Crashlytics). No personal content from inside the App.Aggregate analytics and crash diagnosis.
Cloud hostingIf we host static content (this Privacy Policy, Terms of Service) on services like GitHub Pages, Vercel, or Cloudflare, those providers receive standard server logs (IP address, user agent) when you visit our website.Serving web pages.

We do not share information with advertisers, data brokers, or any third party for marketing purposes.

We may disclose information if required by law (e.g. valid court order or legal process), to protect our legal rights, to investigate fraud, or in connection with a corporate transaction such as a sale or merger. If a corporate transaction transfers user data, you’ll be notified beforehand and given the option to delete your data.

5. Children’s information

Mooshie Moments is designed for parents and caregivers, not for children. The parent or caregiver is the user; they create the account, accept the Terms, and operate the App. Children do not log in, do not create profiles, and do not interact with the App independently.

We do, however, recognise that the App is about children. The parent enters the child’s first name and age band so the App can choose age-appropriate activities. This information stays on the device and is never transmitted to our servers or to third parties. We never see the child’s name.

We do not knowingly collect personal information from children under 13 (or under 16 in the UK and EEA). If you believe a child has provided information to us directly, contact us at the address below and we will delete it.

This App does not display advertising and does not include third-party social-media login. The optional photo feature stores photos only on the device — they are not uploaded.

6. Cookies, tracking, and analytics

6.1 In the App

The App does not use cookies. It does use the following analytics tools, as described above:

  • Firebase Analytics — anonymous usage events. Linked only to a randomly-generated per-install ID, not to your identity.
  • Firebase Crashlytics — anonymous crash reports.
  • App Tracking Transparency (ATT) — on iOS, you’ll be asked once whether to allow the App to collect your Identifier for Advertisers (IDFA). Mooshie functions identically whether you say yes or no. We use the IDFA, if granted, to measure aggregate marketing effectiveness — never to show targeted ads inside the App.

6.2 On the website

Our website uses minimal cookies for the purpose of remembering your cookie preferences and basic anonymous traffic measurement. We do not use third-party advertising cookies. If we add additional cookies in the future, we’ll update this policy and, where required, ask for your consent via a banner.

7. How long we keep information

InformationHow long
Subscription and purchase recordsFor the duration of your subscription plus seven (7) years for tax, accounting, and warranty compliance.
Anonymous analyticsUp to 14 months (Firebase Analytics default), then automatically deleted.
Crash reportsUp to 90 days (Firebase Crashlytics default).
Email correspondenceUp to 3 years from the last reply, then deleted unless legally required to keep longer.
On-device data (child name, photos, completions)Until you delete the App or clear the App’s data in iOS Settings.

8. How we protect information

We use industry-standard security measures including:

  • HTTPS / TLS 1.2+ for all data transmitted between the App and our service providers.
  • Encryption at rest where supported by our service providers (Apple, RevenueCat, Firebase).
  • Restricted access to subscription data — only authorised members of our team can access it, and only when necessary to provide support.
  • No payment card data ever passes through our servers; all payments are handled by Apple via the App Store.

No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you and, where required, the relevant supervisory authority within the timeframes set out in applicable law.

9. International transfers

Mooshie is operated from United Kingdom. Some of our service providers are based in the United States (Google, Apple, RevenueCat). When we share information with these providers, your information may be transferred to, stored in, and processed in countries outside the UK and the European Economic Area.

We protect these transfers using:

  • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office and the European Commission, where applicable.
  • The provider’s certification under approved transfer mechanisms (e.g. the UK-US and EU-US Data Privacy Framework).

10. Your rights

Depending on where you live, you have the following rights regarding your personal information:

  • Access. Request a copy of the personal information we hold about you.
  • Correction. Ask us to correct information that’s inaccurate or out of date.
  • Deletion. Ask us to delete your personal information. Note: we may need to keep some records to comply with legal obligations (e.g. tax records of past subscriptions).
  • Restriction. Ask us to limit how we use your information.
  • Portability. Receive a copy of your information in a structured, machine-readable format.
  • Objection. Object to processing based on legitimate interests.
  • Withdraw consent. Where processing is based on consent (e.g. iOS App Tracking Transparency), withdraw it at any time. For ATT, do this in iOS Settings → Privacy & Security → Tracking.
  • Complain. Lodge a complaint with your local data protection authority. In the UK, that’s the Information Commissioner’s Office (ico.org.uk).

To exercise any of these rights, email us at the address in section 13. We respond within 30 days.

11. California residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know. What categories of personal information we have collected, the sources, the purposes, and the categories of third parties we share with. (See sections 2 and 4 above for our full disclosure.)
  • Right to delete. Request deletion of your personal information.
  • Right to correct. Request correction of inaccurate information.
  • Right to opt out of sale or sharing. We do not sell your personal information and do not share it for cross-context behavioural advertising. There is nothing to opt out of in this respect.
  • Right to limit use of sensitive personal information. We do not collect sensitive personal information as defined by CPRA.
  • Right to non-discrimination. We will not discriminate against you for exercising any of these rights.

To exercise these rights, email us. We do not require an account or impose unreasonable verification requirements; we may ask you to confirm details associated with the request to verify your identity.

We do not have a financial incentive program. We do not sell personal information of any consumer, including consumers under 16.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we’ll update the “Last updated” date at the top of the page. For material changes, we’ll provide a more prominent notice — for example, an in-App banner or an email if you’ve contacted us before.

Continued use of the App after changes means you accept the updated policy. If you don’t accept the changes, you can delete the App and, if you wish, request deletion of any personal information we hold (see section 10).

13. Contact us

For privacy questions, requests, or complaints:

14. Definitions

Personal information / personal data — any information that identifies, relates to, describes, or could reasonably be linked with a specific person.

Processing — any operation performed on personal information, including collection, storage, use, sharing, and deletion.

Controller — the entity that decides how and why personal information is processed. For the purposes of this policy, Mooshie is the controller.

Processor — a third party that processes personal information on behalf of a controller. RevenueCat, Apple, and Google are our processors.

Sale / sharing (under CCPA) — disclosing personal information to a third party in exchange for value, or for cross-context behavioural advertising. We do neither.

Aggregate / anonymous — information that has been stripped of identifiers and combined with other users’ information so that no individual can be identified.

© 2026 Mooshie Moments. All rights reserved. The “Mooshie” name and logo are trademarks.

Reading this policy on the web? Get in touch if anything is unclear — we’re a small team and we read every email.