Privacy Policy
Last updated: September 13, 2026
This Privacy Policy explains how Chibitek ("Chibitek," "we," "us") collects, uses, and protects information in connection with Mochii, our project-management application available at getmochii.com ("the Service"). By using the Service you agree to this Policy.
1. Information we collect
- Account & profile data: your name, email address, and organization, provided through single sign-on (Stiki / Google) when you or your administrator create your account.
- Content you create: projects, tasks, comments, attachments, time entries, and other data you enter into the Service.
- Usage & device data: log data such as IP address, browser type, and actions taken, used to operate and secure the Service.
- Google account data: only if you choose to connect Google (see Section 3).
2. How we use information
- To provide, maintain, and improve the Service.
- To authenticate you and secure your account.
- To send notifications and reminders you have enabled.
- To provide customer support and respond to your requests.
- To comply with legal obligations.
3. Google account connection (optional)
The Service offers an optional Google connection that syncs the tasks assigned to you to your own Google account, mirrors your Out of Office status to Gmail, and turns Google Meet transcripts into meeting notes. You enable it explicitly in Settings and may disconnect it at any time. When connected, we request these Google OAuth scopes:
https://www.googleapis.com/auth/calendar: to create a dedicated "Mochii" calendar in your Google account and write calendar events (with reminders) that mirror the Mochii tasks assigned to you that have a due date.https://www.googleapis.com/auth/tasks: to create a dedicated "Mochii" task list and create/update Google Tasks that mirror those same assigned tasks, including marking them complete.https://www.googleapis.com/auth/gmail.settings.basic: to read and update only your Gmail vacation (Out of Office) responder, so an Out of Office window you set in Mochii is mirrored to Gmail and an active Gmail responder is reflected in your Mochii presence. We call only the vacation-settings endpoint. We do not read, send, or modify your email messages, labels, filters, or any other Gmail setting.https://www.googleapis.com/auth/meetings.space.createdandhttps://www.googleapis.com/auth/meetings.space.readonly: to list the conference records, transcripts, and recording metadata of Google Meet calls that you hosted and that were scheduled from Mochii, so that finished calls receive AI-generated meeting notes attached to the originating task or project. Access is limited to meeting spaces you created; we do not download, store, or stream audio or video recording files.
The same Google app also powers two features of Stiki, the Chibitek sign-in and administration service at auth.chibitek.com, which you connect separately and may disconnect at any time:
https://www.googleapis.com/auth/gmail.readonly: Meeting Intelligence reads meeting invitation emails and their calendar attachments so that meetings can be matched to the client contacts and organizations you work with. Reads are limited by search query to meeting-related messages. We do not send email, modify your mailbox, or display unrelated messages.https://www.googleapis.com/auth/webmasters.readonly: to display Google Search Console performance reports for the websites you own. Read-only.
The calendar and task synchronization is one-way (from Mochii into your Google account) and is limited to the calendar events and task items that Mochii itself creates. We do not read, modify, or delete your other calendars, events, or tasks. We store only the minimum data needed to operate these features: OAuth tokens (encrypted, accessible only to our backend), the identifiers of the "Mochii" calendar/list we created for you, a mapping between your Mochii tasks and the corresponding Google items, the Out of Office window you chose to mirror, and the transcript text and AI-generated notes for meetings you hosted, stored with the task or project they belong to. You can delete those notes from the task at any time. Disconnecting in Settings revokes our access, removes the calendar and task items we created, and stops all further reads.
Limited Use disclosure
Mochii's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not sell it or transfer it to third parties except as necessary to provide or improve the feature, comply with applicable law, or as part of a merger or acquisition. We do not allow humans to read this data unless we have your affirmative consent for specific items, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymized. Google API Services User Data Policy.
4. Zoom (optional connection)
The Service offers an optional feature that lets you schedule Zoom meetings from the work they belong to in Mochii. You enable it explicitly in Settings and may disconnect it at any time. When connected, we request these Zoom OAuth scopes:
user:read:user: to identify which Zoom account is linked to your Mochii user, so meetings are created under the correct host and so we can delete the correct credentials when you disconnect.meeting:write:meeting: to create the Zoom meetings you explicitly request from a task, a project, or an EOS L10 meeting.meeting:read:meetingandmeeting:read:list_meetings: to read back the meetings Mochii created, so the current join link, start time, and status can be shown on the task.meeting:read:summaryandmeeting:read:list_summaries: to retrieve Zoom's AI Companion summary and action items for a meeting Mochii scheduled, so meeting notes live with the work.cloud_recording:read:recordingandcloud_recording:read:list_recording_files: to locate and download the transcript file of a meeting Mochii scheduled, so it can be attached to the task.
Access is limited to meetings Mochii itself created. We do not read your Zoom chats, other users' meetings or data, or meetings scheduled outside Mochii, and we never download, store, or stream the audio or video recording files. We store only what the feature needs: your Zoom user ID and email; the meeting ID, topic, start time, and join URL of meetings we created; and, when available, the transcript text and AI Companion summary attached to the originating task. You can delete those notes from the task at any time.
Zoom OAuth access and refresh tokens are stored server-side only, in a database table that our browser application cannot read, and they never reach your browser. All transport is encrypted with TLS. Disconnecting in Mochii Settings, or removing Mochii from your Zoom account, deletes the stored tokens immediately; Zoom notifies us of the removal and we purge them on receipt.
5. How we share information
We do not sell your personal information. We share information only with: (a) service providers who process data on our behalf (e.g., cloud hosting and database providers) under confidentiality obligations; (b) members of your own organization, to the extent the Service is collaborative; (c) authorities when required by law; and (d) a successor entity in connection with a merger, acquisition, or sale of assets.
6. Data storage & security
Data is stored with our cloud infrastructure providers and protected with industry-standard measures including encryption in transit and access controls. OAuth tokens are stored encrypted and are accessible only to our backend services, never exposed to other users or the client application. No method of transmission or storage is 100% secure, but we work to protect your information.
7. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. You may request deletion of your data, and disconnecting Google removes the Google-derived data we hold for the sync feature.
8. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information. To exercise these rights, contact us at the address below.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect their data.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by additional notice.
11. Contact us
Questions about this Policy or your data? Contact us at erick.grau@chibitek.com.