Privacy Policy
Learn how we collect, use, and protect your personal data
Last Updated: December 22, 2025
Version: 1.0.1
Effective Date: December 22, 2025
App Version: 1.1.6
Privacy Policy
At Mochroom, we value your privacy and are committed to protecting your personal data.
This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use the Mochroom mobile app and related services operated by Zidyn Solutions (Mississauga, Ontario, Canada).
By using our app, you consent to the terms of this policy.
2. Information We Collect
2.1 Account & Authentication Data
- Email address, user ID (UID), and authentication credentials
- Multi-factor authentication (MFA) settings and trusted device fingerprints
- Profile information (name, handle, bio, avatar, gender, DOB)
2.2 Content & Activity Data
- User-generated content: watchlists, reviews, lists, polls, comments, and ratings
- Engagement data: notifications received, content interactions, search history, and session activity
- Group interactions: membership, posts, invites, and shared activities
2.3 Preferences & Settings
- App settings and local preferences (AsyncStorage / Firestore)
- Consent choices, privacy settings, and onboarding state
2.4 Device & Analytics Data
- App usage metrics, feature engagement, session IDs, interaction timestamps
- IP-based approximate location for feature customization.
- Device type, operating system, app version, and performance diagnostics
3. Cookies, Tracking & Analytics
3.1 Analytics Services
- Firebase Analytics: Tracks user engagement, app performance, and crash diagnostics
- Custom Analytics Service: Privacy-compliant tracking with no external advertising SDKs
- No third-party ad tracking SDKs (e.g., Google Ads, Facebook Pixel)
3.2 Local Storage
- AsyncStorage: Saves preferences, onboarding state, MFA data, session info, consent states
- Encrypted Storage: Stores sensitive MFA tokens and trusted device data securely
3.3 Third-Party APIs & Services
- TMDB API – Movie data, posters, and metadata
- OMDB API – Additional movie details (via Firebase Functions)
- Firebase Services – Authentication, Firestore database, Cloud Functions, Analytics, Storage
- Expo Services – Push notifications, device info, file system access
- React Native Libraries – UI, navigation, and image handling
- Node.js Dependencies: Crypto-js for encryption, Axios for HTTP requests
3.4 Automated Decision-Making
We do not use automated profiling or algorithmic decision-making that affects legal or significant rights of users.
3.5 User Control & Opt-Out
- Analytics Opt-Out: Full disable or category-based consent management
- Location Tracking: Withdraw anytime with immediate effect
- Marketing & Promotions: Unsubscribe or revoke consent anytime
- Device Data: Stop collection via app consent settings
4. How We Use Your Information
We process data to:
- Deliver and improve Mochroom services
- Personalize recommendations, content, watchlists and notifications
- Measure engagement and app performance.
- Facilitate social features (friends, followers, groups)
- Ensure security, detect fraud, and maintain app integrity
- Fulfill legal obligations and respond to lawful requests
Legal bases include consent, legitimate interest, and legal compliance.
5. Sharing Your Information
- Internal Sharing: For user visibility (friends, followers, groups)
- Third-Party Sharing: With TMDB, OMDB, and Firebase services for app functionality
- No Advertising Sharing: No personal data is sold or shared with advertisers. Movie promotions and advertisements shown in the app are selected internally based on user preferences (such as genres, language, or location). No personal information is shared with external advertisers or ad networks.
- Legal Disclosure: Only if required by law or lawful request
6. Data Security & Storage
- Encryption: AES-256 encryption for Firestore and Storage data at rest
- Transport Layer Security: All communications use HTTPS/TLS 1.2+
- Access Controls: Role-based and user-ownership Firestore rules
- Audit Trails: Immutable logs for consent and data exports
- Incident Response: 72-hour breach notification policy
7. Data Retention & Deletion
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| User Profile Data | 7 years | Legal compliance |
| Analytics Data | 1 year | Legitimate interest |
| Location Data | 3 months | Consent |
| Marketing Data | 3 years | Consent |
| Consent Records | 7 years | Legal requirement |
| Notification History | 90 days | Legitimate interest |
- Automatic Deletion: Inactive accounts (2+ years) purged
- User Deletion: 30-day grace period after deletion request
- Data Export: human readable format, downloadable anytime
You may request deletion of your personal data by contacting us at privacy@mochroom.com. We may take steps to verify your identity before processing such requests. We will respond within 30 days, as required by applicable data protection laws.
8. International Data Transfers
Mochroom operates in Canada but may use servers in other regions via Firebase (Google Cloud). All data transfers comply with GDPR and equivalent data protection laws through Google's Standard Contractual Clauses (SCCs).
9. Age Restrictions & Children's Privacy
- Users must be 18 years or older to register
- We do not knowingly collect data from minors
- DOB field cannot be set to <18 years
- If underage use is detected, accounts are terminated and data deleted
- Parents can contact privacy@mochroom.com for immediate action
10. Your Rights
You have the right to:
- Access your personal data
- Rectify inaccurate information
- Delete your account or content
- Export your data in machine-readable form
- Withdraw consent to analytics, marketing, or tracking
- Object to specific processing under applicable laws
10.1 Data Deletion Rights
If you wish to delete your personal data, you may request deletion by sending an email to privacy@mochroom.com. Please include your account information (email address or user ID) to help us identify your account.
We may take steps to verify your identity before processing such requests to ensure the security of your data. We will respond to your deletion request within 30 days, as required by applicable data protection laws.
Requests can also be made through the app via Account Settings > Privacy Preferences > Data Rights.
11. Legal Disclaimers
- Movie Data Accuracy: Information from TMDB/OMDB may not always be accurate or updated.
- External Links: We are not responsible for content or privacy policies of third-party websites.
- Service "As Is": Mochroom services are provided without warranties of any kind.
- User Content: Users are solely responsible for content they post or share.
12. Governing Law & Dispute Resolution
- Governing Law: Ontario, Canada
- Dispute Resolution:
- Parties agree to attempt informal resolution first (written notice to privacy@mochroom.com).
- If unresolved within 30 days, disputes are subject to binding arbitration under the Arbitration Act, 1991 (Ontario), held in Toronto, Canada.
- If arbitration is unenforceable, exclusive jurisdiction lies with the courts of Toronto, Ontario.
13. Data Breach Notification
- Affected users will be notified within 72 hours of breach discovery.
- Notices include details of what occurred, what data was affected, and mitigation steps.
- Regulatory authorities will be notified where required by law.
Preventive measures include:
- Regular penetration testing
- Staff security training
- Periodic backup and restore testing
13.1 User Actions
- Change passwords immediately if notified of a breach
- Monitor accounts for suspicious activity
- Report any suspicious activity to privacy@mochroom.com
14. Changes to This Policy
We may revise this policy periodically to reflect legal or service updates. Significant changes will be communicated via app notifications or email. Last updated: October 2025
15. Compliance Statement
This privacy policy is designed to be transparent about our data practices and compliant with GDPR, CCPA, and other applicable privacy laws.
We are committed to protecting your privacy and ensuring that your personal data is handled responsibly and in accordance with international privacy standards.
16. Contact Us
If you have any questions, feedback, or concerns about this Privacy Policy or our data practices, please contact us:
Contact Us
📧 Email:
- privacy@mochroom.com
- hello@mochroom.com
🌐 Support: https://mochroom.com/support
📍 Address: Mississauga, Ontario, Canada
Company: Mochroom – A Product of Zidyn Solutions