MocaMoco MOON (the "App") is a period tracking application provided by Mocamoco Co., Ltd. (the "Company", "we", "us", or "our"). We recognize the protection of our users' ("you" or "users") personal information as an important responsibility, and we have established and comply with this Privacy Policy (this "Policy").
The App is distributed in Japan and in other countries and regions designated by the Company. For additional information for users living outside Japan, please see Section 16, "For Users Outside Japan".
1. Business Operator
- Company name: Mocamoco Co., Ltd.
- Address: Resona Kudan Building 5F KS Floor, 1-5-6 Kudanminami, Chiyoda-ku, Tokyo, Japan
- Contact: moon@mocamoco.com
2. Information We Collect
The App collects the following information.
2.1 Information you enter directly
- Email address (when you register an account)
- Nickname, date of birth, and gender (when you register an account)
- Information about your periods
- Weight and body fat percentage
- Body temperature
- Other information you enter voluntarily (physical condition, notes, etc.)
2.2 Information collected automatically
We may automatically collect the following information for purposes such as service improvement, troubleshooting, and usage analysis.
- Device information (OS type, OS version, device model, language and region settings, etc.)
- Information about your use of the App (operation history, usage, screen transitions, etc.)
- Crash information and error logs
- The device token required to deliver push notifications (only if you allow notifications)
In addition, to display ads on the free plan, Google's advertising SDK may use your device's advertising identifier (IDFA or AAID). On iOS, this occurs only if you grant permission through App Tracking Transparency (ATT). For details, see Section 5.2, "Google AdMob".
2.3 Information obtained from your device's OS health data (only if you enable syncing)
- Weight, body fat percentage, body temperature, and period records (including menstrual flow)
For details, see Section 6, "OS Health Data Syncing".
2.4 Subscription (paid plan) information
If you purchase a paid plan, we collect and retain the plan type, the dates and times of purchase, renewal, and expiration, and the transaction identifiers issued by the App Store or Google Play, in order to manage your purchase status. Payment information such as credit card numbers is processed by Apple or Google, and we do not collect it.
2.5 Records of consent
When you give consent to the Terms of Use, this Policy, or the processing of your health data, we record the following as evidence of that consent: the type of consent, the version of the document you consented to, the date and time of consent, your IP address, browser/device identification information (User-Agent), and your device's region setting.
2.6 Information related to auto-sending to a partner (LINE linking; only when enabled)
The "Auto-send via LINE" feature automatically sends how you are doing and what you would like to a person you register (your "partner") on LINE at key moments of your cycle, such as before your period or on the day it starts. Only when you enable this feature, we obtain and keep the following information.
- The name shown to your partner (entered by you)
- Your "what I'd like" for each situation (a preset or text you write yourself), which moments to send at, whether to mention your cycle in the message, the message language, and your device's time zone
- Your partner's LINE user identifier (an identifier LINE issues to our LINE official account; we do not obtain your partner's name, phone number, friend list, etc.)
- A hashed value of the link code (the code itself is not stored), the linking status, and a record of sending (the type of moment and the date and time; the message text is not stored)
Your partner does not need to be a member of the App. Your partner's LINE display name is fetched from LINE each time to show on your settings screen and is not stored on our servers. Your partner can stop receiving messages at any time by sending "stop" on LINE or by blocking our LINE official account.
3. Handling of Sensitive Personal Information
Information collected through the App, such as period dates, weight, and body temperature, may constitute "special care-required personal information" under the Act on the Protection of Personal Information of Japan and sensitive or consumer health data under other applicable laws.
We collect and use such information only with your explicit consent and handle it under a strict management framework.
4. Purposes of Use
We use the collected information for the following purposes.
- Providing the App's features (period tracking, graphs, calendar, health data syncing, etc.)
- Account authentication and management
- Providing paid plans and managing purchase status
- Displaying ads on the free plan
- Analyzing usage of the App and improving its features
- Preventing unauthorized use
- Responding to inquiries
- Delivering important announcements (including push notifications)
- Recording and managing consent (as evidence of legal compliance)
- Creating statistical data processed so that individuals cannot be identified
- Complying with laws and regulations
- Automatically sending messages via LINE to a partner you designate (when the feature in Section 2.6 is enabled)
5. Third-Party Services
The App uses the following third-party services. For details on how each service handles data, please review each provider's privacy policy.
5.1 Google Firebase (analytics and push notification delivery)
- Provider: Google LLC
- Services used: Google Analytics for Firebase (usage analytics) and Firebase Cloud Messaging (push notification delivery)
- Information collected: usage information, device information, analytics identifiers, device tokens, attribute information (age group and gender), etc.
- Purpose: analyzing and improving the App, and delivering push notifications
- Privacy policy: https://policies.google.com/privacy
5.2 Google AdMob (ad serving)
- Provider: Google LLC
- Information collected: advertising identifiers (IDFA, AAID), device information, information about ad views and interactions, etc.
- Purpose: serving and measuring ads on the free plan
- Privacy policy: https://policies.google.com/technologies/ads
We handle advertising as follows.
- In regions where consent is required by law, we obtain consent for ad personalization through an in-app consent form (Google's consent management platform). You can change your consent choices at any time from "Ad Privacy Settings" on the My Page screen (shown to users in applicable regions).
- On iOS, advertising identifiers are used only if you grant permission through Apple's App Tracking Transparency (ATT) dialog.
- We do not provide health-related information, such as period dates or body temperature, to advertising providers for ad serving or targeting purposes.
- If you subscribe to a paid plan (the ad-free plan), no ads are displayed.
5.3 Sentry (error monitoring)
- Provider: Functional Software, Inc.
- Information collected: crash information, error logs, device information, etc.
- Purpose: detecting and investigating defects and improving quality
- Privacy policy: https://sentry.io/privacy/
5.4 LINE (message delivery to your partner)
- Provider: LY Corporation
- Service used: LINE Official Account (Messaging API)
- Information sent: your partner's LINE user identifier, the name you set, and the message for each moment of your cycle (how you are doing and what you would like; only if you choose so, wording about your cycle such as "period is coming up" or "period has started")
- Purpose: automatically delivering messages to your partner as instructed by you
- Privacy policy: https://line.me/en/terms/policy/
Messages are sent only when you enable "Auto-send via LINE" and invite a partner. You can preview the exact message on the settings screen beforehand. You can disconnect at any time; when you do, your partner's LINE user identifier and the settings in Section 2.6 are deleted from our servers.
6. OS Health Data Syncing (Apple Health / Android Health Connect)
Only if you enable syncing, the App reads and writes the following data to and from the health data management feature provided by your device's OS (Apple Health (HealthKit) on iOS, and Health Connect on Android).
- Weight
- Body fat percentage
- Body temperature (basal body temperature)
- Period (menstruation) records and menstrual flow
The purposes of use are as follows.
- Writing the data above recorded in the App out to your device's health data (App → OS)
- Importing the data above recorded in your device's health data into the App (OS → App)
Regarding health data syncing, we comply with the following.
- Syncing is optional. When you start syncing, we obtain your explicit permission through the OS permission screen.
- You can grant permission for each data type individually and revoke it at any time from your OS settings.
- We do not use data obtained from Apple Health or Health Connect for advertising purposes.
- We do not provide or sell data obtained from Apple Health or Health Connect to third parties.
- Imported data is managed under this Policy in the same way as data you enter directly into the App, and is deleted when you delete your account (see Section 11, "Account Deletion").
- Account deletion deletes the data on our servers. It does not delete data that has been written to Apple Health or Health Connect. If you no longer need that data, please delete it from your OS's Apple Health or Health Connect settings.
7. Provision of Information to Third Parties
We do not provide your personal information to third parties except in the following cases.
- When you have given consent
- When required by laws and regulations
- When necessary to protect a person's life, body, or property
- When particularly necessary to improve public health or promote the sound development of children
- When it is necessary to cooperate with national government agencies or similar bodies
- When provided as statistical data from which individuals cannot be identified
In particular, we do not sell health-related information, such as period dates or body temperature, to third parties, and we do not share it with third parties for advertising purposes.
Under item 1 above (with your consent), the "Auto-send via LINE" feature sends how you are doing and what you would like to the partner you designate through LINE (LY Corporation), based on your own explicit settings. See Sections 2.6 and 5.4 for details.
8. Data Retention Periods
| Type of information | Retention period |
| Account information (email address, password, etc.) | Until account deletion |
| Entered data such as period dates, weight, and body temperature | Until account deletion |
| Subscription purchase records | After account deletion, retained in a form separated from information that can identify you (pseudonymized), for purchase entitlement checks and refund handling (books and records that must be kept by law are retained for the statutory period) |
| Records of consent (Section 2.5) | 3 years after account deletion |
| Usage logs | 2 years from collection |
| Audit records of deletion requests (processed so that individuals cannot be identified) | 3 years after the deletion is completed |
| LINE linking settings and your partner's LINE user identifier (Section 2.6) | Until you disconnect, or until you request account deletion (deleted immediately, without waiting for the cancellation period) |
| Records of sending via LINE (type of moment and date/time) | Until account deletion |
| Identifiers of notifications received from LINE (to prevent duplicate processing; cannot identify individuals) | 7 days from receipt |
Account deletion is carried out after a 30-day cancellation period from your request, and the target data is physically deleted from our databases. Data stored in backups is erased through short-term rotation (automated backups are retained for 1 day), except for information that must be retained by law and the exceptions in the table above.
9. Use of Anonymized Statistical Data
We may create and use statistical data processed so that individuals cannot be identified, for service improvement and research purposes.
- Processing: identifying information such as names, email addresses, and device identifiers is removed and converted into a form that cannot be re-identified
- Purpose: trend analysis and feature improvement
- Retention period: no limit
If you do not wish your data to be used in anonymized form, please contact us at the contact point below.
10. Your Rights
You have the following rights regarding the personal information we hold about you.
- The right to request disclosure
- The right to request correction, addition, or deletion
- The right to request suspension of use or erasure
- The right to request suspension of provision to third parties
- The right to withdraw consent
You can exercise these rights as follows.
- Suspension of use / erasure: use "Delete Account" on the My Page screen in the App (see Section 11, "Account Deletion")
- Disclosure, correction, suspension of third-party provision, withdrawal of consent, and other requests: contact us at the "Contact" address below
11. Account Deletion
You can request account deletion at any time from the My Page screen in the App. After you submit a request, the process is as follows.
- You can no longer sign in to the App, starting immediately after your request.
- We send an email with a cancellation link to your registered email address. Within 30 days of your request, you can cancel the deletion from this link and continue using the App.
- After the 30-day cancellation period, the following information is physically deleted from our databases. Deleted data cannot be restored.
- Account information (email address, password, nickname, date of birth, gender)
- Your records in the App: period dates, body temperature, weight, body fat, and physical condition
- Notification and push notification registrations, and health data syncing usage records
- Your authentication account
After the deletion is completed, you may register again with the same email address, but your past data cannot be restored.
As exceptions, the following information is retained after deletion (see Section 8, "Data Retention Periods").
- Records of consent (3 years after account deletion)
- Audit records of deletion requests (processed so that individuals cannot be identified; 3 years after the deletion is completed)
- Subscription purchase records (retained in a form separated from information that can identify you (pseudonymized))
Please note the following.
- Deleting your account does not cancel your paid plan subscription. Please cancel it from the subscription management screen of the App Store or Google Play.
- Data written to Apple Health or Health Connect is not deleted (see Section 6, "OS Health Data Syncing").
Because we do not sell or share your health information, such as period dates and body temperature, with third parties, no third-party deletion notifications arise from your account deletion. Data stored in the backups of our cloud provider (Amazon Web Services), to which we entrust data processing, is erased through short-term rotation (automated backups are retained for 1 day).
12. Use by Children Under 13
The App is intended for users aged 13 and over. If you are under 13, please do not use the App.
If we learn that we have mistakenly collected information from a child under 13, we will promptly delete that information.
13. Data Security
We take the following measures to prevent leakage, loss, or damage of personal information.
- Encryption of communications (SSL/TLS)
- Password hashing
- Restriction of access privileges
- Periodic security audits
- Employee training
14. Data Storage Location and International Transfers
The App's servers are located in Japan (the Tokyo region of Amazon Web Services). If you use the App from outside Japan, your information is transferred to and stored in Japan.
In addition, the servers of third-party services used by the App (Google, Sentry, etc.) may be located outside Japan, such as in the United States. When transferring data internationally, we confirm the legal framework of the destination country and take appropriate protective measures.
15. Cookies and Similar Technologies
The App uses analytics identifiers (such as Firebase instance IDs) to analyze usage.
16. For Users Outside Japan
If you use the App from outside Japan, the following applies in addition to this Policy.
- For users living in the United States, the "Consumer Health Data Privacy Policy" (in English), based on state laws such as the Washington My Health My Data Act, applies. It is available from the My Page screen in the App.
- The App is not currently distributed in the EU/EEA or the United Kingdom. If we begin distribution in these regions, we will revise this Policy to comply with the GDPR and other applicable laws and take the necessary measures.
- This Policy is provided in Japanese, English, and Traditional Chinese. If there is any discrepancy between the versions, the Japanese version prevails.
17. Changes to This Policy
We may change this Policy in response to amendments to laws, changes to the service, and other circumstances. The revised Policy takes effect when posted in the App or on our website. If there are material changes, we will notify you in advance through in-app notices or similar means, and we may ask for your renewed consent in the App where necessary.
18. Contact
For inquiries about this Policy, or to request disclosure, correction, or deletion of personal information, please contact us at the following.
- Company name: Mocamoco Co., Ltd.
- Email: moon@mocamoco.com
- Hours: email only (no fixed hours; we reply within 3 business days as a rule)
For how we respond to data requests from government agencies and law enforcement, see our Law Enforcement Request Policy.
Mocamoco Co., Ltd.
Last updated: October 3, 2026