Privacy Policy
Last updated: July 2026
1. Who we are
Mozhi is a heritage language learning platform for diaspora families, operated from Australia. References to "Mozhi", "we", "us", or "our" mean the operator of mozhiapp.com (ABN 72 269 836 976). Our Privacy Officer and Data Protection Officer (for GDPR and Singapore PDPA purposes) can be reached at privacy@mozhiapp.com.
We comply with the Australian Privacy Act 1988 and Australian Privacy Principles (APPs), the UK GDPR and EU GDPR, the United States COPPA and applicable state privacy laws including the California Consumer Privacy Act (CCPA/CPRA), Canada's PIPEDA (and Quebec's Law 25 for Quebec residents), Singapore's PDPA, Malaysia's PDPA, India's Digital Personal Data Protection Act (DPDPA), and New Zealand's Privacy Act 2020.
2. Information we collect
We collect only what we need to provide the service:
- Account information — your name and email address when you sign up.
- Child profiles— first name and age range for each child you add. We never collect a child's email address or contact details.
- Learning progress— lessons completed, phrases mastered, practice history. Used to personalise the experience and show you your child's progress.
- Voice recordings (pronunciation practice)— when your child uses the “Say it” feature, the app records a short clip of their voice for the sole purpose of converting it to text to score pronunciation. We do not store the recording.It is held only momentarily in the device's memory, sent over an encrypted connection to our transcription provider (OpenAI), converted to text, and then discarded — the recording is never written to our servers, databases, or logs. On the device, the clip is deleted as soon as it has been transcribed; any clip left by an unexpected app close is deleted automatically the next time the app starts. OpenAI processes the audio under its API terms (retained briefly for abuse monitoring, then deleted) and does not use it to train its models.
- Payment information — handled entirely by Stripe. We never see or store your full card number. Stripe is PCI DSS Level 1 certified.
- Usage data — which lessons are opened, session length, device type. Used to improve the product. Not sold or shared.
- Waitlist and contact submissions — your email and any message you send via our forms.
- Indirect collection — if you are referred to Mozhi by another user, we may receive your name and email from the referring party. We will only use this to send you one introductory email. You can opt out at any time.
3. How we use your information
- To provide, maintain, and improve the Mozhi service.
- To send transactional emails — account confirmation, receipts, password resets.
- To notify you of new languages or features you expressed interest in (waitlist emails). You can unsubscribe at any time.
- To respond to support requests you send us.
- To comply with legal obligations (e.g. tax records for subscriptions).
We do not sell your data, share it with advertisers, use it to train AI models, or use it for automated decision-making that produces legal or similarly significant effects on you.
4. Children's privacy (COPPA)
Mozhi is designed for children to use under parental supervision. We comply with the United States Children's Online Privacy Protection Act (COPPA) as updated in 2024.
- Accounts are created by parents or guardians (18+), not children. We do not knowingly collect personal information directly from children under 13.
- Child profiles contain only a first name and age range — no email, no phone number, no photo.
- Parents can request access to, correction of, or deletion of their child's profile data at any time by emailing privacy@mozhiapp.com.
- If you believe a child has provided us with personal information without parental consent, contact us and we will delete it within 5 business days.
5. Data storage, transfers, and security
Your data is stored on cloud infrastructure hosted in Singapore. We use HTTPS/TLS encryption in transit and AES-256 encryption at rest. Access to production data is restricted by role-based access controls and is logged.
International transfers: Data processed by Stripe may be transferred to the United States. Data Audio generation for lesson content does not involve personal data. For transfers from the UK or EU, we rely on Standard Contractual Clauses (SCCs) where applicable, and our infrastructure meets the EU/UK adequacy transfer requirements.
We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where required by law (e.g. billing records retained for 7 years per Australian tax law).
6. Cookies and tracking
We use minimal cookies: a session cookie to keep you signed in. We do not currently use analytics cookies, advertising cookies, or cross-site trackers. If we add analytics in future, we will update this policy and obtain consent where required.
7. Third-party services
We use the following third-party services, each with their own privacy policies:
- Stripe — payment processing (PCI DSS Level 1 certified).
- Cloud infrastructure provider — hosting, database, and email delivery. Data is stored in Singapore.
- Audio generation provider — text-to-speech for lesson content. No personal data is sent for this purpose.
- OpenAI — speech-to-text transcription for pronunciation practice. A short voice clip is sent for transcription only; it is not stored by us and is not used by OpenAI to train its models. See section 2 for details.
8. Your rights
Regardless of where you are located, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data.
- Withdraw consent for optional communications (unsubscribe links in every marketing email).
UK and EU users (UK GDPR / EU GDPR):
- Our lawful basis for processing is performance of contract (providing the service) and consent for optional communications.
- You have additional rights to data portability and to object to processing.
- You may lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your EU supervisory authority.
California users (CCPA / CPRA):
- We do not sell or share your personal information with third parties for cross-context behavioural advertising.
- You have the right to know what personal information we collect, to delete it, to correct it, and to opt out of any future sale or sharing (none currently exists).
- We do not discriminate against users who exercise their privacy rights.
- To submit a CCPA request, email privacy@mozhiapp.com. We will respond within 45 days.
Canadian users (PIPEDA):
- Our Privacy Officer handles all privacy enquiries and complaints for Canadian residents. Contact: privacy@mozhiapp.com.
- If your complaint is not resolved to your satisfaction, you may escalate to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
- Quebec residents:Quebec's Law 25 applies in addition to PIPEDA. You may also escalate a complaint to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
Singapore users (PDPA):
- Our Data Protection Officer (DPO) can be contacted at privacy@mozhiapp.com.
- You may lodge a complaint with the Personal Data Protection Commission at pdpc.gov.sg.
Malaysian users (PDPA):
- Our Data Protection Officer can be contacted at privacy@mozhiapp.com for any enquiry or complaint under Malaysia's Personal Data Protection Act 2010.
Indian users (DPDPA):
- Under India's Digital Personal Data Protection Act, 2023, a "child" is anyone under 18 — Mozhi requires parental consent before creating any child profile, consistent with this higher age threshold.
- We do not track, behaviourally monitor, or target advertising at children, in any jurisdiction — consistent with the DPDPA's requirements for children's data.
- Grievances can be raised with our Grievance Officer at privacy@mozhiapp.com.
Australian users (Privacy Act 1988):
- You may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.
To exercise any of these rights, email privacy@mozhiapp.com. We will respond within 30 days (45 days for California requests).
9. New Zealand users
We comply with the New Zealand Privacy Act 2020 and Information Privacy Principles, including Information Privacy Principle 3A (in effect since May 2026): if we collect your information from someone other than you — for example when a family member refers you to Mozhi, or when a parent creates a child profile — we will take reasonable steps to let you know what we collected, why, who else might receive it, and how to access or correct it. You may request access to or correction of your data, or lodge a complaint with the Office of the Privacy Commissioner at privacy.org.nz.
10. Changes to this policy
We may update this policy as the product grows. We'll notify account holders of material changes by email at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
Privacy questions?
Contact our Privacy Officer / DPO at privacy@mozhiapp.com. We aim to respond within 5 business days.
Or use our contact form →