Privacy Policy
Effective date: July 17, 2026
Last updated: July 17, 2026
This Privacy Policy explains how Mohammad Hassani ("we," "us," or "Moro") collects, uses, discloses, and retains information when you use the Moro iPhone app, App Clip, invitation pages, website, and related services (collectively, the "Service").
Moro is built for private planning among people who already know one another. A person who posts an idea is visibly interested. Everyone else's Down, Maybe, Pass, or nonresponse is private before a match. If the stated threshold is reached, only the members who were Down are revealed to one another. Maybe and Pass are never revealed to friends.
1. Who we are
The Service is provided by Mohammad Hassani, an individual developer based in California, United States. For privacy questions or requests, email contact@thragna.com.
Where applicable law uses the term "controller" or "business," Mohammad Hassani is responsible for the processing described in this Policy.
2. Information we collect
We collect information needed to authenticate you, provide private group matching and planning, protect the Service, and respond to you.
2.1 Account and profile information
- Sign in with Apple information: the stable account identifier Apple provides to Moro, authentication tokens, and, if Apple supplies them, your relay or account email and name. Apple may provide name and email only the first time you authorize Moro.
- Profile information: your display name, optional profile photo, locale, time zone, account status, and service preferences.
- Eligibility and acceptance records: confirmation that you are at least 18, the version of the Terms and Community Guidelines you accepted, and acceptance timestamps. Moro does not ask for or store your full date of birth.
2.2 Circles, invitations, and relationships
- Circles you create or join, their names and emoji, membership and role records, muted or archived settings, and circle lifecycle information.
- Invitation records, including who created an invitation, the circle or idea it concerns, expiration, redemption, revocation, and a one-way keyed representation of the invitation credential. We do not store the raw invitation token after it is issued.
- People you block and the operational records needed to enforce a block.
2.3 Ideas, private choices, matches, and plans
- Ideas, notes, links, categories, approximate place hints, cost level, audience, threshold, expiry, and lifecycle state.
- Owner-only saved items that remain private until you choose to turn one into a circle idea.
- Your private response and the minimum operational information needed to apply it safely. Raw responses are held in a server-only area and are not exposed through the consumer database API or Realtime.
- Match membership after a threshold is reached. Moro records the members who were Down when the match formed so those members can plan together.
- Proposed dates and venues, votes, finalized plan details, coordinator notes, completion responses, and one optional shared memory with a caption or photo.
2.4 Safety, support, and account requests
- Reports, report reason and optional details, the item or person reported, review status, moderation action code, and tightly restricted audit records.
- Support and privacy communications, including your email address and anything you include in a message.
- Data-export and account-deletion activity, including a short-lived deletion workflow record used to complete media removal, Apple token revocation, and account removal safely.
2.5 Device and technical information
- Push-notification device tokens, notification preferences, app version, platform, locale, time zone, and token invalidation status.
- Security, reliability, and request information such as timestamps, IP address, user-agent or app version, response status, and redacted diagnostic details. Hosting and network providers may generate this information when they deliver the Service.
2.6 Information we do not collect
Moro version 1 does not collect or read your contacts, full date of birth, calendar contents, advertising identifier, continuous or live location, private messages, or cross-app tracking identifiers. Moro has no advertising SDK and no third-party behavioral analytics SDK. We do not use your information for targeted advertising.
3. How private responses work
Moro's response privacy is a service rule as well as a screen design:
- The idea creator's interest is visible because creating an idea means they are Down.
- Before a match, each invited person sees only their own response. Moro does not expose response totals, who responded, or response timing to other members.
- If enough eligible members are Down, Moro creates one match and reveals only those Down members to one another.
- Maybe, Pass, nonresponse, and a late response after a hidden match are never disclosed to friends.
- A friend may still make guesses from real-world context, especially in a small group. Moro therefore describes responses as private, not anonymous.
We use raw response information only to operate this matching rule, prevent inconsistent outcomes, secure the feature, and meet legal obligations.
4. Device features you choose to use
Photos
Moro uses Apple's system photo picker, which lets you select specific images without granting broad library access. Before upload, Moro downsizes the selected image and re-encodes it as JPEG to remove location and camera metadata. The resulting profile or memory image is stored in a private Supabase Storage bucket and is made available only in an authorized Moro context.
Maps and venues
When you search for a place, the search text is sent through Apple MapKit under Apple's terms. Moro does not request continuous or live location. If you select a result or enter a venue manually, Moro stores the venue name, address, provider reference or source link where available, and coordinates with the match plan so authorized match members can use it.
Calendar
When you tap Add to Calendar, Moro opens Apple's event editor prefilled with the finalized plan. The event is written only if you explicitly save it. Moro does not read or upload your calendar contents.
Notifications
If you allow notifications, Moro registers a device token and uses Apple Push Notification service (APNs) to deliver content-minimized service updates. Notification permission is optional, and planning remains usable without it.
5. How we use information
We use information to:
- authenticate you and maintain your account;
- create and operate circles, invitations, private responses, matching, planning, completion, and memories;
- synchronize authorized changes and deliver notifications you permit;
- enforce blocks, investigate reports, prevent abuse, and protect users and the Service;
- provide support, exports, account deletion, and privacy-rights responses;
- diagnose faults, secure infrastructure, enforce rate limits, and maintain service continuity;
- comply with law, resolve disputes, and enforce our Terms and Community Guidelines.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use private response choices, idea content, or friend relationships for advertising.
6. Legal bases for EEA, UK, and similar jurisdictions
Where a legal basis is required, we generally rely on:
- Contract: to provide the Service you request and enforce its core private-matching rules.
- Legitimate interests: to secure, maintain, and improve the Service; prevent abuse; support users; and understand failures, balanced against your rights.
- Consent: for optional device permissions and where the law otherwise requires it. You can withdraw device permission in iOS Settings, although this does not make prior processing unlawful.
- Legal obligation and legal claims: to comply with law, respond to valid process, preserve evidence, and establish, exercise, or defend claims.
7. When information is disclosed
Other Moro users
We disclose information only as the feature requires: your display name and optional avatar to authorized circle or match members; an idea to its snapshotted audience; match identities only to members of that match; planning and memory content only to authorized match members; and limited report status to the reporter. Private Maybe and Pass choices are not disclosed to friends.
Service providers
We use providers that process information to operate the Service:
| Provider | Purpose | Relevant information |
|---|---|---|
| Apple | Sign in with Apple, App Store and App Clip distribution, APNs, MapKit place search, system photo picker, and calendar event editor | Account identifier and optional relay email/name; push token and content-minimized notification payload; venue searches; information Apple processes under device and Apple-account settings |
| Supabase | Authentication, PostgreSQL database, Realtime sync hints, private media storage, scheduled jobs, and server functions | Account/profile data, circles, ideas, responses, matches, plans, media, device tokens, safety records, and operational metadata |
| Cloudflare | Hosts and delivers the Thragna/Moro website and invitation fallback | Standard web request and security metadata such as IP address, user agent, path, timestamp, and response status |
These providers process information under their own terms and privacy commitments. Learn more at Apple Privacy, Supabase Privacy, and Cloudflare Privacy.
Legal, safety, and business circumstances
We may disclose information when reasonably necessary to comply with valid law or legal process; protect a person's safety or rights; investigate fraud, abuse, or a security incident; or establish, exercise, or defend legal claims. If the Service is reorganized or transferred, information may be part of that transaction subject to this Policy, appropriate confidentiality, and applicable law. We do not provide private response data to friends through support or moderation tools.
8. Retention
We retain information only as long as reasonably needed for the purposes above, then delete, anonymize, or restrict it. Current operational periods are:
- Account and profile: while your account is active, then handled through the deletion process below.
- Open ideas and responses: while the idea remains open. A scheduled job runs hourly and removes matched members' raw Down responses after membership is safely represented in the match. It also removes unmatched responses after an idea expires, is cancelled, or is restricted. A nonparticipant's private choice after a hidden match remains only until the fixed idea expiry so the app can preserve a non-revealing state, then the hourly job removes it.
- Saved items: until you delete them or delete your account.
- Matched plans and memories: until an authorized deletion, account deletion, or an applicable circle retention action. If an author deletes their account, their memory text and photo are removed and shared idea content is anonymized as needed to preserve other members' records.
- Invitation credentials: raw tokens are not stored after issue. Their keyed hashes remain through expiration or revocation and for a limited operational period needed for replay and abuse defense. Invitation links should still be treated as credentials and revoked if exposed.
- Push tokens: until logout, account deletion, token invalidation, or a short operational grace period.
- Reports: open reports remain through review. Once a report is closed, its current retention deadline is 180 days; a daily job then removes the report unless a longer period is required for safety, appeal, legal, or security reasons.
- Deletion workflow record: retained for 30 days after completion, then removed by an hourly reconciliation job.
- Support communications, restricted audit data, and redacted logs: retained for the shortest period appropriate to the request, security risk, or legal obligation. Routine raw application and infrastructure logs are intended to be kept for approximately 14–30 days; security records may be retained longer when reasonably necessary.
- Backups: deleted information may remain temporarily in encrypted, access-controlled backups and ages out under the applicable provider backup lifecycle. We do not restore deleted information to active use except where needed for disaster recovery, and restored data remains subject to deletion controls.
Data exports are assembled for the authenticated user rather than stored as a durable server download. The app may create a temporary local file so you can save or share it; iOS and the app remove that working copy after the flow completes. Anything you save elsewhere is under your control.
9. Account deletion and data export
In Moro, open You → Data and account to prepare an export or delete your account.
Deletion requires recent Sign in with Apple verification. Once the deletion workflow begins, account access ends immediately. Moro then removes or anonymizes profile and content as appropriate, safely transfers or closes shared group responsibilities, invalidates devices, deletes private media, revokes the Apple authorization token, removes the Supabase authentication account, and retains only narrowly justified safety, security, legal, or deletion-completion records. Shared records may be anonymized instead of removed when deletion would affect other users' plans or legal rights.
If you cannot access the app, email contact@thragna.com. We may ask for information reasonably necessary to verify that the request concerns your account.
10. Your choices and rights
You can edit your display name and photo, change notification preferences, leave or archive circles, revoke invitations you created, block or unblock people, delete saved items, and use the export and deletion controls described above.
Depending on where you live, you may have rights to request access, a portable copy, correction, deletion, restriction, or objection; to withdraw consent; and to appeal or complain to a data-protection authority. California residents may also have rights to know, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service when exercising privacy rights. Moro does not sell or share personal information for cross-context behavioral advertising, so there is no sale or advertising share to opt out of.
To make a request, use the in-app controls or email contact@thragna.com. We will verify the request as appropriate, respond within the period required by applicable law, explain any lawful exception, and not discriminate against you for exercising a right. Authorized agents may submit requests where the law permits, subject to verification of their authority and your identity.
11. Security
Moro uses transport encryption, private storage, server-side authorization, database row-level security, keyed invitation hashes, encrypted push tokens, redacted operational data, and least-privilege service paths. Access to especially sensitive response, report, and deletion records is restricted from consumer APIs. No service can guarantee absolute security. If you believe an invitation or account has been compromised, revoke the invitation when possible and contact contact@thragna.com.
12. International transfers
We and our providers operate from the United States and other countries. Your information may therefore be processed in places whose laws differ from those where you live. Where required, we use contractual or other approved safeguards and provide any rights available under local law.
13. Adults only
Moro is for people 18 and older and is not directed to children. We do not knowingly allow anyone under 18 to create an account. If you believe a person under 18 has provided personal information through Moro, contact us so we can investigate and take appropriate action.
14. Changes to this Policy
We may update this Policy as the Service, providers, or law changes. We will post the revised version at thragna.com/moro/privacy, change the "Last updated" date, and provide additional notice or seek consent when required. Material changes do not retroactively reduce your rights without a valid legal basis.
15. Contact
Questions, requests, complaints, or security reports may be sent to:
Mohammad Hassani
Email: contact@thragna.com
California, United States