MokoRoll

Privacy Policy

Last updated: August 17, 2026

MokoRoll lets event hosts create a shared "Film" and hand every guest a film camera: guests capture photos during the event, and the photos develop together at the reveal. This policy explains exactly what we collect, why, where it lives, and how to get rid of it. It applies to the MokoRoll app (web and iOS) and to mokoroll.com.

MokoRoll is operated by MokoRoll, and we are the data controller for the information described here. You can reach us any time at trymokoroll@gmail.com.

What we collect

We do not collect your precise location or your contacts. The camera captures only what you point it at. If you pick a cover image from your photo library, we receive only the single image you chose, never the rest of your library.

What we don't do

Why we're allowed to hold it

If you are in the UK, EU, or another region with similar law, these are our legal bases under the GDPR:

WhatWhyLegal basis
Account details, photos, event metadataTo provide the Service you asked forPerformance of a contract
Purchase recordsTo grant what you paid for, and for tax and accountingContract, and legal obligation
Guest join records shown to a hostSo a host can run their own guest listLegitimate interests of the host, plus your consent choices at join
Reports and blocksTo keep the Service safeLegitimate interests, and legal obligation

How photos are protected

Photos live in a private storage bucket on our backend (Supabase, running on AWS infrastructure). They are only reachable through short-lived signed URLs (valid for one hour) issued to members of that Film.

Before the reveal

Reveal timing is enforced on our servers, not in the app. Until a Film's reveal moment, our database rules withhold other guests' photo records from your device entirely, so the app has nothing to show you but your own shots. It is not a matter of the app choosing to hide them.

Cover images and profile pictures are public

Film cover images and profile avatars are served from public buckets. That means anyone who has the file's web address can open it, whether or not they were invited to your event, and whether or not they have a MokoRoll account. The addresses are long and not listed anywhere, but they are not secret. Choose covers and avatars on that basis. Photos inside a Film are not affected: those stay in the private bucket described above.

Who can see what

Service providers

These companies process data on our behalf, under contract, and cannot use it for their own purposes:

ProviderWhat forWhat they get
Supabase (on AWS)Database, file storage, authenticationEverything listed above
VercelWebsite and app hostingRequest logs, including IP address
StripeSubscription payments on the webYour email and payment details, which they hold, not us
AppleIn-app purchases in the iOS appThe purchase itself. Apple is the merchant of record and tells us only that a transaction is valid
Google, Apple, LinkedInSign-in, only if you choose oneThe fact that you signed in, plus the basic profile they return to us

Where your data is held

Our providers store and process data in the United States. If you are outside the US, that means your information is transferred there. For transfers out of the UK and EU we rely on the European Commission's Standard Contractual Clauses with each provider.

How long we keep things

Deleting your data

Open Settings, then Delete Account in the app. This immediately and permanently deletes your profile, every Film you own, all of your photos (including the stored files), your memberships, your guest records, and your sign-in identity. There is no undo, and we cannot recover anything afterwards.

If you'd rather we did it, email trymokoroll@gmail.com from your account address and we'll complete the deletion within 30 days.

Reporting and blocking

Every photo can be reported from inside the app, and any guest can be blocked. Blocking hides their photos and profile from you immediately. Hosts can remove any photo from their own Film at once. We review reports within 24 hours and remove content that breaks our Terms of Use.

Children

MokoRoll is not for children under 13, or under the minimum age of digital consent where you live if that age is higher (16 in some EU countries). We do not knowingly collect data from them, and our Terms require you to confirm your age when you create an account. If you believe a child has created an account, email trymokoroll@gmail.com and we will delete it and its contents promptly, usually within a few days.

Security

Data is encrypted in transit (HTTPS) and at rest by our hosting providers. Access to the production database is limited to people who need it. Photos sit behind row-level database rules that check your membership of a Film on every request. No system is perfect: if a breach ever affects your data, we will tell you and the relevant regulator as the law requires.

Your rights

Depending on where you live, you may have rights to access, correct, export, restrict, object to, or erase your personal data, and to withdraw consent you previously gave. Under the GDPR you may also complain to your local supervisory authority. Under California law (CCPA and CPRA) you have rights to know, delete, and correct, plus the right to opt out of sale or sharing, which is moot here because we do neither.

Email trymokoroll@gmail.com and we'll answer within 30 days. We honor these requests for everyone, wherever you live, not only where the law compels us to. We will never charge you or degrade your service for exercising them.

Changes

If this policy changes in a way that matters, we'll note it in the app and update the date at the top of this page before the change takes effect.

Contact

MokoRoll · trymokoroll@gmail.com · mokoroll.com