Privacy Policy

Revision 18 · en-US

Your words and your choices

Dear Mori is operated by Kiwi Tree in California, United States. Contact support@ohmymori.com.

Your private journal words stay on your device in the current app. The whole app is not data-free: connected accounts and purchases use Google/Firebase services, paid operations include some intention and progress metadata, and optional diagnostics use Firebase. This policy distinguishes those practices.

Information for children and parents

Age choice and local access

Dear Mori no longer asks for an age group during onboarding. New installations open the standard profile without recording an age declaration. Age bands saved by earlier versions remain only in local secure storage and are not transmitted. Existing under-18, unspecified-age and unrecognized saved values continue to open the local-only profile so its journal remains accessible.

An existing local-only profile has a separate device database and does not construct Firebase, Google Sign-In, Play Billing or optional diagnostics services. Historical account recovery and diagnostics consent are not restored into it. Standard-profile databases are retained separately. Local profiles can use earned progress, suitable Mori activities and local device features without a Google account or the standard onboarding agreement. Journal import/export, image save/share and externally opened support links remain disabled in these existing local profiles.

The app does not verify age or parental consent. No parental-verification service or in-app upgrade from an existing restricted profile is provided. Your platform and device providers handle processing outside the app’s control under their own policies.

Journal and local processing

Wishes, inscriptions, optional personal details, custom actions, reflections and outcomes are stored in the local journal. The commerce API excludes that private text. Ordinary free practice, earned Petals and much of your guided progress are local. Paid-operation metadata described below is an exception to the broader progress boundary.

Your local database uses the device’s storage protections; Dear Mori does not claim that this SQLite database is independently encrypted. Password-encrypted exports are a separate feature. Device loss, clearing app storage or uninstalling can remove local records. We cannot retrieve journal words that were never sent to our services.

Accounts and commerce

When you choose connected commerce or restoration, Google sign-in and Firebase process your account identifier, email and provider-supplied profile information. The connected email is shown to help you recognize the account. Authentication attempts, including cancelled or incomplete checkout, can involve security processing before a purchase finishes.

The commerce service processes product and purchase-token/order information, purchased balances, ownership, transaction records, use grants, funding contributions and refunds. It verifies purchases with Google Play, prevents duplicate grants and restores purchased data to the same account. These records are needed for the connected feature you request; free local use does not require them.

Paid operations also send Mori and activation identifiers, dates, and some ritual/carry totals, checkpoints and connection requirements. Mori identifiers can reveal interests such as health, recovery, fertility or childbirth. We treat these as potentially sensitive metadata and do not describe the commerce service as containing no intention-related information. It does not receive the underlying private words.

Switching accounts changes the purchased data shown while keeping the separate local journal and earned progress. Journal text is not cloud-synced.

Terms acceptance records

A device acceptance receipt contains the legal release/version, contract hash, client acceptance time and locale. It is kept in dedicated local secure storage, not journal exports or diagnostics. It does not create a cloud account.

When you sign in for connected commerce, Dear Mori records your existing onboarding acceptance against the selected account. The authenticated record contains the legal release, Terms version, contract hash, onboarding as its source and the time the server recorded it. The server time is the association time, not a claim about when you read or accepted the agreement on your device. The account association comes from authentication, not a client-supplied account identifier. These records do not enable optional diagnostics.

Optional usage and crash diagnostics

Usage analytics and crash diagnostics are unavailable in local child/unknown-age profiles and off by default in standard profiles. If you turn on Share usage and crash diagnostics, Google Analytics for Firebase and Firebase Crashlytics process limited app interactions, coarse progress counts, purchase outcomes, crash stack traces and app/device technical information, including SDK installation/device identifiers. Analytics can derive approximate location from masked IP addresses even without location permission. This does not require Google account sign-in.

App event fields exclude private journal text, selected Mori, account identifiers and purchase receipts/tokens. This exclusion does not mean that the SDKs process no technical identifiers. Advertising integrations and advertising consent are not enabled by the app.

You can turn sharing off in Settings. The app stops reporting, resets local Analytics data and deletes unsent crash reports. Already transmitted data is subject to the actual provider configuration and applicable rights processes; switching off does not erase every report already held by Google.

Security and service information

Firebase Authentication, App Check/Play Integrity and service operation process technical information such as IP addresses, app/SDK and device information, and attestation signals for authentication, security and abuse prevention. These services can process information even when optional analytics is off.

Data sent to Firebase services uses encrypted HTTPS connections. We use access controls and server-side purchase validation. No service is guaranteed free of every security risk, and we do not claim an independent security certification or HIPAA compliance.

Device features, exports and sharing

Reminders are optional local Android notifications. Widgets and live wallpaper render selected app content locally. Supported wallpaper motion uses local device-motion signals. Image export saves a selected image to device storage or sends it to the app you choose through Android sharing.

Journal export creates a password-encrypted file you control. We cannot recover its password. The file contains journal history, not purchased balances, ownership or Terms receipts, and is not a full export of all account data. Files you save or share can be handled by your chosen storage or receiving provider. Delete those copies separately if no longer needed.

Support, requests and website

If you email support or prepare a privacy/deletion request, we use the account, order and contact information you provide to respond, verify authority and resolve the issue. Never send passwords, full payment-card details or private journal content. Preparing a mailto message does not send it; you must send it from your email app.

Support correspondence may include voluntary product suggestions or intellectual-property complaints. We use the reply details and information you choose to supply to understand the suggestion or investigate the identified concern, and share only what is necessary with people assisting that work or appropriate professional advisers. The product-suggestion permission in the Terms does not authorize reuse of personal information. The retention and rights provisions below apply to these records.

The static legal/support pages contain no app-authentication requirement or app-added advertising/analytics scripts. Hosting and browser/email providers may process request and technical logs. The absence of a site analytics script does not mean there is no server logging.

The app does not enable advertising integrations or sale of journal entries. The static pages do not implement cross-site behavioural tracking or a special response to browser Do Not Track. External links lead to providers with their own practices.

Providers and international processing

Connected features use Google/Firebase Authentication, Firestore, Cloud Functions, App Check/Play Integrity, Google Play Billing and, only when opted in, Analytics and Crashlytics. Support uses a Gmail inbox. Providers’ contractual roles differ by service and processing purpose.

Commerce functions are configured in us-central1. Other processing locations depend on the service and provider, and information may be processed outside your country. You can contact support@ohmymori.com for information about processing locations and the transfer safeguards relevant to your information.

A possible transfer of the business

If a sale, reorganization or other lawful transfer of the Dear Mori business is proposed, we may disclose the minimum information necessary to evaluate and carry out that transaction to legitimate prospective counterparties and their professional advisers, subject to appropriate confidentiality, access and security safeguards and an applicable legal basis. Any transfer concerns only records actually held, such as necessary account, transaction and support records. We cannot provide local journal text that has never reached our services.

A successor receiving personal information must assume the applicable privacy obligations. We will provide required notices and obtain any consent or offer any choice that applicable law requires before a transfer or a materially different use. This paragraph does not authorize a sale to data brokers, new advertising uses or unrestricted reuse of sensitive information. It describes a possible future event, not a transaction currently announced by Kiwi Tree.

Retention and deletion

Local journal records remain on your device until you erase them; exported copies remain where you save them. Connected account records are used while providing balances, ownership, restoration and support. Account deletion removes the account and its acceptance subcollection while preserving your separate local journal until you erase it.

Restricted purchase receipts have a 180-day deletion target after account deletion, pending purchases have a 30-day expiry, and deletion markers have a one-day expiry. Database expiry processing is asynchronous; these targets are not guaranteed maximum retention periods. Restricted receipts support refunds and prevention of repeat credits; they are not a journal backup.

Clearing app storage does not automatically erase active-account transaction records, service logs, transmitted diagnostics, support emails or privacy-request records. Contact us about retention or deletion of those records through the privacy-request route below.

Your choices and rights

You can use local free features without a connected commerce account, choose whether to enable diagnostics, control local notifications, export your journal, and request account deletion. Depending on applicable law, you may also have rights of access, correction, deletion, portability, objection, restriction, withdrawal of consent, complaint or appeal.

We will identify the rights and response requirements applicable to your request and verify identity or authority proportionately. A journal export is not a substitute for access to account or support information held by the operator. These request routes do not require accepting Terms or making a purchase.

Where EEA/UK law applies, processing requires an applicable legal basis, such as providing requested connected functionality, compliance with legal obligations, properly assessed security interests or consent for optional processing. Additional legal protections apply to sensitive intention metadata. Consent is not bundled into Terms acceptance.

Privacy requests

Delete an account

Changes and contact

Material changes will be communicated through appropriate app/service notices before new processing where required, and fresh consent obtained where necessary. Contact support@ohmymori.com with privacy questions.

Privacy rights and dispute resolution

This Privacy Policy explains processing and choices. It is not a blanket consent, release of claims or waiver of privacy rights. The Terms contain individual arbitration and class-proceeding restrictions for covered United States disputes, including some disputes about app-related processing, but only within their lawful scope and subject to the Terms’ 30-day arbitration opt-out. They do not waive non-waivable privacy rights, remedies or means of enforcement, prevent complaints to a privacy regulator, or require you to agree to Terms in order to make a privacy request.

Dispute notices, related correspondence and information reasonably necessary to assess or defend legal claims may be processed by the operator and relevant professional advisers, an arbitrator, a court or an authority for handling the claim and meeting legal obligations. Provide only information needed for the issue. Do not send passwords, private journal entries or full payment-card details. We determine how long to retain dispute records based on the claim, applicable legal duties, limitation periods and legal holds. Account Terms acceptance records are deleted with the account.

If you send an arbitration opt-out, we process your name, mailing address, account email if any, statement and available timing information to identify and honor your choice. An account is not required. Necessary correspondence may be handled through support and by professional advisers where needed. We retain the minimum opt-out evidence only as reasonably necessary to honor that choice and handle related legal obligations or claims, with a documented review and deletion criterion. This is separate from account Terms acceptance records, which are deleted with the account; we do not preserve a hidden copy of those records. Applicable privacy rights continue to apply.

Terms, arbitration and exceptions

Privacy requests