Privacy Policy — Jogg
Effective Date: April 12, 2026 Last Reviewed: June 24, 2026
Jogg is developed and operated by MokingBird Oy, a company registered in Finland. In this Privacy Policy, "Mokingbird", "Jogg", "we", "our", and "us" refer to MokingBird Oy.
This policy is written for:
- website publication and in-app legal display,
- app store review and user support,
- GDPR-facing transparency.
Please read this policy carefully. By using Jogg, you agree to the practices described herein.
1. Scope
This policy applies to:
- the Jogg mobile application (iOS and Android),
- official Jogg web pages and subpages,
- account, support, and product-related interactions directly operated by MokingBird Oy.
It does not apply to third-party services you may link to from within the app. Those services have their own privacy policies.
2. What Jogg Is
Jogg is a professional AI/ML learning application that combines:
- three AI learning frameworks with nine layers each,
- quiz and practice flows across multiple learning modes,
- daily spaced repetition review (Daily Jogg),
- research paper-based learning and quiz generation,
- custom quiz creation and sharing,
- progress tracking, XP, streaks, and certificates,
- optional leaderboard features,
- optional reminders and account security controls.
3. Data Controller
MokingBird Oy Operating Jogg as its product and brand. Privacy contact: [email protected]
For general support: [email protected] (when active)
MokingBird Oy is the data controller for all personal data processed through the Jogg application.
4. Personal Data We Process
We follow a strict data minimisation principle. We only process data that is necessary for the operation and improvement of the app. Depending on how you use Jogg, we may process the following categories of data.
4.1 Account and Identity Data
If you create an account, we process:
- email address,
- username and display name,
- password (stored as a cryptographic hash — never in plain text),
- authentication provider identifiers (for OAuth sign-in),
- account verification status,
- account creation and last-update timestamps.
Authentication is handled through Supabase-backed account infrastructure. Supported sign-in methods include:
- email and password,
- magic link (passwordless email),
- email OTP (6-digit one-time code),
- OAuth providers: Google, Apple, Facebook, and X/Twitter where configured.
4.2 Profile Data
Depending on what you choose to provide or enable in your profile, we may process:
- avatar or profile image,
- bio or short description,
- learning goal, aim category, and learning-interest tags,
- any optional profile fields you choose to complete.
We do not require your date of birth, phone number, or postal address. If date of birth is collected in a future version for age verification, it will be clearly disclosed.
4.3 Learning and Progress Data
To operate the core app functions, we process:
- quiz sessions and question attempts,
- correct and incorrect answers,
- mode-specific activity (Learning Path practice, Practice Quiz / Rush, Papers, Daily Jogg, Arcade, and custom quizzes),
- streak count and daily activity history,
- XP totals, level, and tier state,
- lane mastery percentages and unlock progress,
- certificate status and completion history,
- question and paper quiz history,
- session timing and time-taken where required for quiz operation, Practice XP modifiers, Arcade timers, and quality analysis,
- Daily Jogg session history.
This data is stored in your user account. Limited cross-user information is exposed only where required for features you use, such as opt-in leaderboard display and organizer access to participants/results in a shared quiz.
4.4 Settings and Preference Data
We may process app settings such as:
- theme selection,
- language preferences,
- sound and haptic settings,
- PIN and biometric security preferences,
- auto-lock timer settings,
- notification preferences and types,
- leaderboard sharing preferences,
- privacy-related toggles where available.
4.5 Leaderboard Data (Opt-In Only)
Leaderboard participation is entirely opt-in and requires your explicit consent.
If you choose to join leaderboard features, we may process and display limited information publicly, such as:
- username,
- ranking position,
- selected performance indicators (XP, level, tier, streak) according to your sharing settings.
The current app provides a global leaderboard with granular sharing controls. Additional leaderboard views may be introduced later.
We do not display your email address or any authentication details on the leaderboard.
You may withdraw from leaderboard participation at any time in your profile settings. Your entry is removed immediately.
4.6 Notification Data
If you enable reminders or notifications, we may process:
- device notification permissions,
- push-notification preferences,
- local reminder schedules,
- notification records associated with your account.
Examples of notification types include:
- Daily Jogg reminders,
- daily practice reminders,
- streak reminders and warnings,
- achievement and level-up notifications,
- quiz invitation notifications.
You can control all notification settings inside the app.
4.7 Anonymous Question Performance Data
To improve question quality and the learning experience, we may collect anonymous, aggregated data about how questions are answered. This collection is designed so it cannot identify you personally.
What we collect anonymously:
- question ID,
- whether the answer was correct or incorrect,
- time taken to answer (seconds),
- approximate user level at the time (not your identity).
Anonymisation method: Your user ID is transformed using a one-way cryptographic hash (SHA-256 with a salt) before any analytics data is stored. This result cannot be reversed to identify you.
What the app does not intentionally attach to question-performance analytics: your name, email, or advertising identifier. Infrastructure providers may process ordinary network metadata such as IP address for security, routing, and service operation under their own processor obligations.
This anonymous data is used exclusively to improve question difficulty calibration, identify poorly worded or ambiguous questions, and improve future question generation. It is not used for advertising or profiling.
4.8 Support, Legal, and Operational Data
We may process:
- support correspondence (emails, in-app feedback),
- app error context submitted via crash reports (opt-in),
- account deletion requests,
- data export actions,
- abuse-prevention and security-related signals.
4.9 Data We Do NOT Collect
We do not collect:
- your location or GPS data,
- your contacts or phone book,
- your browsing history outside the app,
- microphone recordings; camera access is requested only for user-initiated features such as QR scanning or profile-image capture where available,
- your messages or content from other apps,
- behavioural tracking data for advertising purposes.
4.10 Purchases and Entitlements
When production in-app billing is enabled, Jogg will process store product identifiers, purchase tokens or transaction identifiers, entitlement status, platform, renewal/expiry status, and purchase-restoration results. Google Play or Apple processes payment-card details; Jogg does not receive full card details. The current development billing scaffold must not be treated as production payment processing.
4.11 Shared Quiz Membership
For custom quizzes, Jogg stores quiz ownership, participant membership, waiting-room state, joined-quiz history, attempts, and notification-routing metadata. This cloud membership allows joined quizzes to remain available after reinstalling the app or clearing local app data. Quiz organizers can see participant usernames or display labels and quiz-result information required to operate the shared quiz.
5. Why We Process Data (Purposes)
We process data in order to:
- create and manage user accounts,
- authenticate users and manage sessions,
- save and synchronise learning progress,
- deliver quizzes, question sets, and learning content,
- personalise question selection based on your interests and goals,
- support three framework learning paths and per-layer progress,
- support daily review and streak mechanics,
- support research paper-based learning and paper-request flows,
- enable shared and custom quiz features,
- operate leaderboard features when you opt in,
- send reminders and notifications you have enabled,
- support account data export and deletion,
- protect the service and its users,
- debug, maintain, and improve reliability,
- improve question quality through anonymous performance data.
6. Lawful Bases Under GDPR
For users in the European Union or European Economic Area, we rely on one or more of the following lawful bases under the General Data Protection Regulation (GDPR).
6.1 Performance of a Contract (Art. 6(1)(b))
We process data necessary to provide the app and its core functions, including:
- account access and session management,
- quiz delivery and progress saving,
- certificate and history access,
- settings persistence.
6.2 Legitimate Interests (Art. 6(1)(f))
We may process data where necessary for our legitimate interests, including:
- service security and abuse prevention,
- product reliability and internal troubleshooting,
- anonymous quality improvement and content analysis.
We have assessed that these interests are not overridden by your rights and interests.
6.3 Consent (Art. 6(1)(a))
For certain optional features, we rely on your consent:
- leaderboard participation,
- optional crash reporting and analytics,
- push notifications,
- optional future integrations where consent is appropriate.
You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
6.4 Legal Obligation (Art. 6(1)(c))
We may process data when required to comply with applicable law, regulation, lawful requests, or enforcement obligations.
7. Guest Mode
Jogg supports guest mode for users who wish to try the app without creating an account.
In guest mode:
- some activity may be stored locally on-device only,
- account-bound features (progress sync, certificates, leaderboard) are not available,
- continuity across devices is not available,
- no personal data is linked to a server-side account.
Guest-mode data handling differs from full account mode because guest activity is not tied to a Supabase-authenticated identity.
8. Where Data Is Stored
Jogg uses:
- Supabase — for account authentication and application data storage (database and storage infrastructure),
- local on-device storage — for cached app data and offline use,
- encrypted local storage — for sensitive local state and cryptographic keys.
Supabase operates on cloud infrastructure. Depending on Supabase's hosting configuration, your data may be processed in servers within or outside your country of residence. Where required by GDPR for cross-border transfers, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms as available through Supabase's data processing agreements.
9. Security Measures
Jogg uses multiple layers of technical and organisational security measures, including:
- Local data encryption: AES-256-GCM encryption for local database storage (Hive),
- Secure key storage: Device-backed secure storage (iOS Keychain / Android Keystore) for encryption keys and refresh tokens,
- Access tokens: Short-lived session tokens are handled by the authentication stack; storage behavior depends on platform SDK internals and current rollout configuration,
- Transport security: Communication with our backend is encrypted in transit using TLS,
- Authentication: OAuth 2.0 with PKCE for social logins; passwords stored as cryptographic hashes,
- Row Level Security: Supabase database-level policies preventing cross-user data access,
- Optional biometric protection: Touch ID / Face ID / fingerprint for app access,
- Optional PIN protection: User-set PIN with auto-lock timer,
- Account deletion: Real authenticated account deletion via backend RPC (not cosmetic UI-only),
- Data export: Users can export their data at any time.
For a full description of our security practices, see our Security Document.
10. Data Sharing
We do not sell, rent, or trade your personal data to any third party for their own commercial use.
We may share data only in the following limited circumstances:
10.1 Service Providers
We use third-party services to operate Jogg, who process data strictly on our behalf under data processing agreements:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, storage | Account and progress data |
| Crash/error reporting (when enabled) | App diagnostics | Diagnostic error data as configured in current rollout |
10.2 Legal Requirements
We may disclose data if required by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect our legal rights, your safety, or the safety of others.
10.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, user data may transfer as part of that transaction. You will be notified in advance and retain the right to delete your account before any transfer is completed.
We do not share personal data with unrelated third parties for unrelated commercial exploitation.
11. International Data Processing
Depending on the infrastructure used by Jogg and its service providers, your data may be processed in countries outside your country of residence, including countries outside the European Economic Area.
Where required by applicable law, we implement appropriate safeguards for such transfers, including relying on Supabase's data processing agreements and applicable transfer mechanisms.
12. Data Retention
We retain personal data only for as long as reasonably necessary:
| Data Category | Retention |
|---|---|
| Account data (email, username, progress) | Until account deletion |
| Learning progress and history | Until account deletion |
| Raw anonymous analytics (question answers) | 90 days |
| Aggregated anonymous analytics | Indefinite (fully anonymised) |
| Crash reports (opt-in) | 90 days |
| Support correspondence | As required by legal or operational need |
| Deleted account data | Processed via backend account-deletion flow; some records may remain temporarily in backups/logs where legally required |
Retention periods may differ depending on data type and any applicable legal obligations (e.g., fraud prevention, legal disputes).
13. Your Rights
Depending on your jurisdiction, and in particular under GDPR if you are in the EU/EEA, you have the following rights:
13.1 Right of Access (Art. 15)
You may request a copy of all personal data we hold about you. We provide this in a structured, machine-readable format (JSON) within 30 days. How to exercise: "Download My Data" in app Settings, or email [email protected].
13.2 Right to Rectification (Art. 16)
You may correct inaccurate or incomplete personal data. Username and profile information can be updated directly in the app.
13.3 Right to Erasure (Art. 17) — "Right to Be Forgotten"
You may request deletion of all your personal data. How to exercise: "Delete Account" in app Settings. Account deletion is processed through backend deletion flow. Limited records may be retained where required for security, fraud prevention, legal, or bookkeeping purposes. Note: Some records may be retained when required for security, fraud prevention, legal, or bookkeeping reasons, as permitted by GDPR Art. 17(3).
13.4 Right to Data Portability (Art. 20)
You may export your personal data in JSON format at any time via app Settings.
13.5 Right to Restriction of Processing (Art. 18)
In certain circumstances, you may request that we restrict processing of your personal data.
13.6 Right to Object (Art. 21)
You may object to processing based on legitimate interests, including anonymous analytics. You can disable analytics in app Settings.
13.7 Right to Withdraw Consent
Where we rely on consent, you may withdraw it at any time via app Settings. Withdrawal does not affect the lawfulness of prior processing.
13.8 Right to Lodge a Complaint
You have the right to lodge a complaint with your national data protection authority. In Finland:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) Website: tietosuoja.fi
14. Children
Jogg is designed as a professional and educational AI/ML learning product intended for users aged 16 and over.
If local law requires parental or guardian consent for a user under a different age threshold, that consent must be obtained before use.
We do not knowingly collect personal data from children below the applicable age threshold. If you are a parent or guardian and believe your child has provided personal information without appropriate consent, please contact us at [email protected] and we will promptly address the matter.
15. Changes to This Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will:
- update the "Last Reviewed" date at the top,
- notify you via in-app notification,
- for significant changes affecting your rights, provide advance notice and, where required, seek renewed consent.
Continued use of the app after updated Terms take effect constitutes acceptance, subject to applicable law.
16. Contact
For any privacy-related questions, requests, or concerns:
MokingBird Oy Privacy contact: [email protected] Subject line: "Privacy — Jogg" website https://jogg.mokingbird.xyz
We aim to respond to all privacy-related enquiries within 30 days.
17. Plain-Language Summary
In short:
- Jogg stores your account and learning data so the app can function,
- we do not sell your personal data,
- leaderboard participation is always opt-in,
- guest mode is available with limited scope and no server-side account,
- we use Supabase-backed authentication and storage infrastructure,
- privacy and security controls are available directly inside the app,
- we may use anonymised aggregated performance data to improve question quality,
- you can export or delete your data at any time.
This Privacy Policy is governed by the laws of Finland and EU GDPR. MokingBird Oy, April 2026.