← Back to Jogg
Legal

Privacy Policy

Effective Date: April 12, 2026 · Last Updated: April 12, 2026

Jogg is developed and operated by MokingBird Oy, a company registered in Finland. In this Privacy Policy, "Mokingbird", "Jogg", "we", "our", and "us" refer to MokingBird Oy.

This policy is written for website publication and in-app legal display, app store review and user support, and GDPR-facing transparency.

Please read this policy carefully. By using Jogg, you agree to the practices described herein.


1. Scope

This policy applies to:

It does not apply to third-party services you may link to from within the app. Those services have their own privacy policies.


2. What Jogg Is

Jogg is a professional AI/ML learning application that combines:


3. Data Controller

MokingBird Oy
Operating Jogg as its product and brand.
Privacy contact: [email protected]

For general support: [email protected] (when active)

MokingBird Oy is the data controller for all personal data processed through the Jogg application.


4. Personal Data We Process

We follow a strict data minimisation principle. We only process data that is necessary for the operation and improvement of the app.

4.1 Account and Identity Data

If you create an account, we process:

Authentication is handled through Supabase-backed account infrastructure. Supported sign-in methods include email and password, magic link (passwordless email), email OTP (6-digit one-time code), and OAuth providers: Google, Apple, Facebook, and X/Twitter where configured.

4.2 Profile Data

Depending on what you choose to provide or enable in your profile, we may process:

We do not require your date of birth, phone number, or postal address.

4.3 Learning and Progress Data

To operate the core app functions, we process:

This data is stored in your user account and is only accessible by you, unless you explicitly opt into leaderboard features.

4.4 Settings and Preference Data

We may process app settings such as theme selection, language preferences, sound and haptic settings, PIN and biometric security preferences, auto-lock timer settings, notification preferences, leaderboard sharing preferences, and privacy-related toggles where available.

4.5 Leaderboard Data (Opt-In Only)

Leaderboard participation is entirely opt-in and requires your explicit consent. If you choose to join leaderboard features, we may display limited information publicly, such as username, ranking position, and selected performance indicators (XP, level, tier, streak) according to your sharing settings.

We do not display your email address or any authentication details on the leaderboard. You may withdraw from leaderboard participation at any time in your profile settings.

4.6 Notification Data

If you enable reminders or notifications, we may process device notification permissions, push-notification preferences, local reminder schedules, and notification records associated with your account.

4.7 Anonymous Question Performance Data

To improve question quality, we may collect anonymous, aggregated data about how questions are answered. We collect: question ID, whether the answer was correct or incorrect, time taken to answer (seconds), and approximate user level at the time.

Anonymisation method: Your user ID is transformed using a one-way cryptographic hash (SHA-256 with a salt) before any analytics data is stored. This result cannot be reversed to identify you.

We do not collect your name, email, IP address, or device identifiers in analytics. This data is used exclusively to improve question quality and is not used for advertising or profiling.

4.8 Support, Legal, and Operational Data

We may process support correspondence (emails, in-app feedback), app error context submitted via crash reports (opt-in), account deletion requests, data export actions, and abuse-prevention and security-related signals.

4.9 Data We Do NOT Collect

We do not collect:


5. Why We Process Data (Purposes)

We process data in order to create and manage user accounts, authenticate users and manage sessions, save and synchronise learning progress, deliver quizzes and learning content, personalise question selection, support the 9-lane learning path, support daily review and streak mechanics, operate leaderboard features when you opt in, send reminders and notifications you have enabled, support account data export and deletion, protect the service and its users, and improve question quality through anonymous performance data.


6. Lawful Bases Under GDPR

For users in the European Union or European Economic Area, we rely on one or more of the following lawful bases under GDPR.

6.1 Performance of a Contract (Art. 6(1)(b))

We process data necessary to provide the app and its core functions, including account access, quiz delivery, progress saving, and settings persistence.

6.2 Legitimate Interests (Art. 6(1)(f))

We may process data where necessary for our legitimate interests, including service security and abuse prevention, product reliability and internal troubleshooting, and anonymous quality improvement. We have assessed that these interests are not overridden by your rights.

6.3 Consent (Art. 6(1)(a))

For certain optional features, we rely on your consent: leaderboard participation, optional crash reporting and analytics, push notifications, and optional future integrations. You may withdraw consent at any time without affecting the lawfulness of prior processing.

6.4 Legal Obligation (Art. 6(1)(c))

We may process data when required to comply with applicable law, regulation, lawful requests, or enforcement obligations.


7. Guest Mode

Jogg supports guest mode for users who wish to try the app without creating an account. In guest mode, some activity may be stored locally on-device only, account-bound features are not available, and no personal data is linked to a server-side account.


8. Where Data Is Stored

Jogg uses Supabase for account authentication and application data storage, local on-device storage for cached app data and offline use, and encrypted local storage for sensitive local state and cryptographic keys.

Supabase operates on cloud infrastructure. Your data may be processed on servers within or outside your country of residence. Where required by GDPR for cross-border transfers, we rely on appropriate safeguards such as Standard Contractual Clauses as available through Supabase's data processing agreements.


9. Security Measures

Jogg uses multiple layers of technical and organisational security measures, including:


10. Data Sharing

We do not sell, rent, or trade your personal data to any third party for their own commercial use.

10.1 Service Providers

ProviderPurposeData Shared
SupabaseDatabase, authentication, storageAccount and progress data
Crash/error reporting (when enabled)App diagnosticsDiagnostic error data as configured in current rollout

10.2 Legal Requirements

We may disclose data if required by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect legal rights, your safety, or the safety of others.

10.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, user data may transfer as part of that transaction. You will be notified in advance and retain the right to delete your account before any transfer.


11. International Data Processing

Your data may be processed in countries outside your country of residence, including countries outside the European Economic Area. Where required by applicable law, we implement appropriate safeguards for such transfers, relying on Supabase's data processing agreements and applicable transfer mechanisms.


12. Data Retention

Data CategoryRetention
Account data (email, username, progress)Until account deletion
Learning progress and historyUntil account deletion
Raw anonymous analytics (question answers)90 days
Aggregated anonymous analyticsIndefinite (fully anonymised)
Crash reports (opt-in)90 days
Support correspondenceAs required by legal or operational need
Deleted account dataProcessed via backend account-deletion flow; some records may remain temporarily in backups/logs where legally required

13. Your Rights

Depending on your jurisdiction, and in particular under GDPR if you are in the EU/EEA, you have the following rights:

13.1 Right of Access (Art. 15)

You may request a copy of all personal data we hold about you in a structured, machine-readable format (JSON) within 30 days. How to exercise: "Download My Data" in app Settings, or email [email protected].

13.2 Right to Rectification (Art. 16)

You may correct inaccurate or incomplete personal data. Username and profile information can be updated directly in the app.

13.3 Right to Erasure (Art. 17) — "Right to Be Forgotten"

You may request deletion of all your personal data. How to exercise: "Delete Account" in app Settings. Limited records may be retained where required for security, fraud prevention, legal, or bookkeeping purposes as permitted by GDPR Art. 17(3).

13.4 Right to Data Portability (Art. 20)

You may export your personal data in JSON format at any time via app Settings.

13.5 Right to Restriction of Processing (Art. 18)

In certain circumstances, you may request that we restrict processing of your personal data.

13.6 Right to Object (Art. 21)

You may object to processing based on legitimate interests, including anonymous analytics. You can disable analytics in app Settings.

13.7 Right to Withdraw Consent

Where we rely on consent, you may withdraw it at any time via app Settings. Withdrawal does not affect the lawfulness of prior processing.

13.8 Right to Lodge a Complaint

You have the right to lodge a complaint with your national data protection authority. In Finland:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Website: tietosuoja.fi


14. Children

Jogg is designed as a professional and educational AI/ML learning product intended for users aged 16 and over. We do not knowingly collect personal data from children below the applicable age threshold. If you are a parent or guardian and believe your child has provided personal information without appropriate consent, please contact us at [email protected].


15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Reviewed" date at the top, notify you via in-app notification, and for significant changes affecting your rights, provide advance notice and, where required, seek renewed consent.


16. Contact

MokingBird Oy
Privacy contact: [email protected]
Subject line: "Privacy — Jogg"
Website: https://jogg.mokingbird.xyz

We aim to respond to all privacy-related enquiries within 30 days.


17. Plain-Language Summary