Privacy ยท Updated July 6, 2026
Privacy Policy
How Mogging handles account details, photos, analysis data, rankings, payments, device information, and support requests.
Overview
Privacy Overview
This Privacy Policy explains how Mogging collects, uses, stores, and shares information when you use the app, website, analysis tools, leaderboards, and related services.
Because Mogging works with face photos and appearance-analysis features, you should upload only content you have the right to use and only content you are comfortable submitting to the service.
Information We Collect
Information We Collect
We may collect information you provide directly, information generated by your use of the service, and technical information from your device or browser.
- Account details such as name, email, social links, profile attributes, and authentication identifiers.
- Face photos you capture or select, local face landmark points generated from those photos, analysis inputs, generated reports, cosmetic scores, overlays, rankings, votes, comparison results, and share links.
- Payment status and checkout metadata from payment processors.
- Device, log, IP, cookie, rate-limit, diagnostic, and security information.
Face Data
Face Data We Collect and How We Collect It
Mogging does not collect Face ID data, TrueDepth sensor data, biometric faceprints, or persistent biometric templates. Mogging does collect face-related data when you choose to capture or upload a face image for a report.
- Face photos: the front-facing image you capture or select from your photo library.
- Local landmark data: approximate points such as eyes, nose, mouth, jaw, face outline, and related geometry generated on device to align overlays and improve report consistency.
- Report data: cosmetic analysis outputs such as PSL score, feature scores, visible age cues, visible UV-context cues, report text, generated overlays, and share-card images.
- Technical context: request IDs, account or anonymous session identifiers, timestamps, and basic device/network logs needed to process the request, prevent abuse, and troubleshoot errors.
Face data is collected only after you take an action to upload, capture, analyze, save, or share a report. The app asks for camera, photo library, location, and third-party report-processing permission where those permissions are needed for the feature you choose.
How We Use Data
How We Use Information
We use information to operate Mogging, deliver analysis and ranking features, personalize app behavior, prevent abuse, improve reliability, process payments, and communicate with you.
We may also use aggregated or de-identified information to understand feature performance and improve the product.
Payments
Subscriptions, Payments, and Web-to-App Access
Mogging offers paid evaluations, optional extras, and auto-renewable subscriptions. Purchases may be processed through Apple in-app purchase, RevenueCat, Stripe, or other payment infrastructure depending on where you start checkout.
- For Apple in-app purchases, Apple processes your payment and may provide transaction identifiers, product identifiers, subscription status, renewal status, expiration dates, refund status, and related receipt information to Mogging or RevenueCat so we can unlock paid access and restore purchases.
- For web checkout, Stripe processes payment details and may provide customer identifiers, checkout session IDs, subscription IDs, invoice status, refund status, chargeback status, email, billing country, and related checkout metadata. Mogging does not store full card numbers.
- RevenueCat helps us sync subscription status, restore purchases, manage entitlements, and connect web purchases or in-app purchases to the app account or install that should receive access.
- When you move from mogging.com to the app, we may use account identifiers, anonymous install identifiers, checkout session identifiers, referral parameters, campaign parameters, and device or browser context to attribute the purchase, prevent fraud, and grant the correct subscription or evaluation credits.
We use payment and entitlement data to complete checkout, unlock paid features, provide subscription access, restore purchases, support refunds or disputes, prevent abuse, measure campaign performance, and comply with tax, accounting, security, and legal obligations.
Face Data Use
How We Use Face Data
We use face photos and landmark data to prepare the image, confirm that a face is present, generate a cosmetic appearance report, place visual overlays, calculate report scores, save report history, create share-card images when you request sharing, and maintain abuse-prevention and support records.
Mogging reports are cosmetic and entertainment-oriented appearance estimates. They are not medical, dermatology, health, employment, identity, or biometric identification advice, and they should not be used for high-stakes decisions.
Some controls may let you decide whether a photo participates in battle, leaderboard, profile, or share-link features. Public or shared pages can be viewed by anyone with access to the link.
Third-Party Processing
Third-Party Report Processing
When you consent to generate a face report, Mogging sends the selected face photo, any local face landmark points, the analysis prompt, and account or anonymous session identifiers to Mogging servers. Mogging then sends the face photo and prompt data to Moonshot/Kimi, our third-party analysis provider, which applies advanced learning and mathematical algorithms to generate the report response.
We share this face data with Moonshot/Kimi only to provide the report feature you requested, improve request reliability, classify provider errors, and return the resulting cosmetic analysis to you. We do not ask the provider to identify you, verify your identity, infer sensitive traits, create a biometric template, or make medical diagnoses.
Moonshot/Kimi may process and store submitted user content, including prompts, images, files, outputs, account information, device and usage information, and log data under the Kimi OpenPlatform Privacy Policy at https://platform.kimi.ai/docs/agreement/userprivacy.md. That policy states that information is stored as long as necessary to provide the services, fulfill the purposes in the policy, support legitimate business purposes such as service improvement, disputes, safety, or security, comply with legal obligations, and that account and input information may be retained while the API account is active. It also states that Kimi OpenPlatform stores collected information on secure servers in Singapore.
Mogging does not authorize Moonshot/Kimi to use submitted face data to identify users, build biometric face profiles for Mogging, verify identity, or make medical diagnoses. If you delete your Mogging profile or request deletion, Mogging deletes or de-identifies the copy held in Mogging systems as described below, but Moonshot/Kimi may continue to retain its own service logs or submitted user content according to its published policy and legal obligations.
Mogging also uses Vercel for hosting and serverless request processing, Cloudflare R2-compatible object storage for uploaded face photos and generated image assets, a Postgres database provider for report records, and authentication, payment, security, analytics, and support providers as needed. These providers may store face data only when their service is used to host, store, secure, process, or support the report feature you requested.
Analytics
Analytics, Attribution, and Cookies
We may use analytics, diagnostics, cookies, local storage, referral links, campaign parameters, and similar technologies to understand app and website performance, measure marketing attribution, remember sessions, prevent abuse, and troubleshoot checkout or entitlement issues.
If platform rules require permission for tracking or access to advertising identifiers, we request or respect that permission before using those identifiers for tracking. You can also adjust device, browser, and cookie settings to limit certain analytics or attribution signals.
Retention
Face Data Retention and Deletion
Explicit face-data retention statement: Mogging does not retain Face ID data, TrueDepth data, biometric faceprints, or persistent biometric templates because the app does not collect those categories of face data. Mogging does retain report-related face data when you create, save, or share a report: uploaded face photos, local landmark points, report outputs, overlay data, share-card images, and share links.
Reasons for storing report-related face data: Mogging stores this data so you can view prior reports, compare changes over time, regenerate overlays, create and serve share cards, receive support, delete your profile, troubleshoot errors, secure the service, prevent abuse, resolve disputes, and comply with legal obligations.
Length of retention in Mogging systems: uploaded face photos, landmark points, report outputs, overlay data, and share links are retained while your profile or report remains active, and in any event no longer than 12 months after your last account activity unless a longer period is required for security, legal compliance, dispute resolution, or fraud prevention. We use this finite period because reports and share links are account-history features, while stale inactive data is not needed indefinitely.
Temporary processing files and generated share-image caches are kept only as long as needed to complete the request, improve performance, or support a current share action. Server or CDN caches for generated share images are normally short-lived and may persist for up to 24 hours before automatic expiry or replacement.
Deletion: if you delete your profile in the app or request deletion at support@mogging.app, we delete or de-identify active account records, uploaded face photos, reports, landmarks, and share links tied to that profile. Active systems are targeted for deletion promptly after the request is processed, and backup copies are overwritten or removed on their normal cycle, generally within 90 days.
Third-party retention: Moonshot/Kimi may retain submitted user content and related logs according to the Kimi OpenPlatform Privacy Policy, including while the API account is active and as long as necessary for service, safety, security, dispute, legitimate business, or legal purposes. Hosting, storage, database, authentication, payment, security, analytics, and support providers may retain service records according to their own processor obligations and backup cycles, but they are not authorized by Mogging to identify users from face data or create biometric templates for Mogging.
Choices
Your Choices and Requests
You can request access, correction, deletion, or help with account data by emailing support@mogging.app. Include the account email, app install context, checkout email, or relevant share link when available so we can locate the right records.
- You can manage or cancel Apple subscriptions in your Apple ID subscription settings.
- You can request purchase support for web payments by contacting support@mogging.app with the checkout email and approximate purchase time.
- You can delete your profile in the app where available or request deletion by email.
- You can control camera, photo library, location, notification, tracking, and other device permissions in system settings.
Security
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. No online service can guarantee absolute security.
You should keep your account credentials private and notify us if you suspect unauthorized access.
Contact
Contact Us
For privacy questions or data requests, email support@mogging.app with the subject Privacy Request and include the account email or relevant share link when available.