Privacy Policy
What stays on your phone, what goes to the server, and how long it is kept.
Effective: October 1, 2026
This is an English translation. If it differs from the Traditional Chinese version, the Traditional Chinese version applies.
Summary
- Typing, word suggestions, handwriting, the clipboard, your People profiles and the speaking habits MoqiKey learns are processed and kept on your phone.
- Of your screenshots, only the one you ask MOQI to read is sent. “Offer to read screenshots” is off by default; when on, the keyboard only looks on the phone for the screenshot you just took (see section 3).
- Content goes to MoqiKey’s AI server only when you use a MOQI assistant feature, speak with MOQI AI voice typing, copy a foreign-language message while “Auto-translate copied messages” is on, or when “My style” periodically summarizes messages you sent recently. Auto-translate and style learning are on by default and MOQI AI voice typing is off by default; each can be switched in Settings (see section 4).
- The AI is Google Cloud Vertex AI (Gemini). Our server only passes requests on; it does not store your messages, screenshots, recordings or the AI’s answers. Google may briefly cache them, or keep requests its systems flag for abuse review, under its own rules (see section 5).
- The server keeps usage (counts, features, cost, region), your email and account when you sign in with Google, the support messages you send us, the Google Play version’s integrity check result (3 days), your plan and purchase records when you subscribe to MoqiKey Plus or redeem a code, and anonymous statistics that are not linked to a device code or account.
- You can delete your account in the app at any time, or request deletion on the web.
- MoqiKey is for people 18 and older only.
1. Who we are
MoqiKey (the app, the keyboard and its AI server) is developed and run by Taco Hsiung.
- Contact: support@moqikey.com
- “We” in this policy means Taco Hsiung; “you” means a person using MoqiKey.
2. Scope
- Covered: the Android app “MoqiKey” (the settings app and the keyboard), MoqiKey’s AI server, the website moqikey.com, and the account deletion page (https://moqikey.com/account/delete).
- Not covered: the other apps you type into with MoqiKey (such as chat apps), your Google Account, and your phone’s speech recognition service. They have their own privacy policies.
- The website moqikey.com uses no cookies and no analytics or tracking scripts (see section 9).
3. Data processed only on your phone
The following stays on your phone and is not uploaded to our server (except when an AI feature in section 4 uses it, and then only for that request):
- What you type. A keyboard has to see what you type to work. Typing itself is never uploaded; messages you send teach your speaking habits on the phone and are sent only when an AI feature in section 4 uses them.
- Learned words: Zhuyin, pinyin and English words and word pairs MoqiKey learns.
- Clipboard history: cleared automatically after an hour, except pinned items. Verification codes are never kept in it. What you just copied shows its beginning in the keyboard’s toolbar for 3 minutes, so you can paste it; anything that looks like a password is masked.
- People (profiles of the people you chat with): name, photo, role and relationship stage, gender, age, birthday, language, country, personality, MBTI, notes, closeness, what MOQI has noticed, and names in chat apps.
- My style: your language, gender, age, catchphrases, emoji habits, and the speaking habits and recent sentences learned from messages you sent.
- Handwriting recognition: done on the phone. The recognition model is downloaded from Google the first time (see section 9).
- Language packs: the dictionaries for Cangjie, Quick, Stroke, Cantonese Pinyin and the Japanese, Korean, Thai and Vietnamese keyboards are “language packs”. They are downloaded from MoqiKey’s download server (packs.moqikey.com, hosted on Cloudflare) only when you turn on one of these input methods, and typing then happens on your phone. The app checks at most once a day for newer packs and swaps them in in the background. Only the files are fetched; no content, account or device code is sent. Like any website, the download server sees your IP address (see section 9).
- “Learn from a chat”: a chat log you paste is analyzed on the phone and only what you said is kept. Those sentences are then used like messages you sent, in the style summaries and suggestions of section 4.
- Move your data (export/import): you choose where the backup file is saved. It is encrypted with a password you set (PBKDF2-SHA256 with 600,000 iterations, AES-256-GCM); without the password nobody can open it, including us.
- Offer to read screenshots (off by default): it works only after you turn it on in Keyboard › Screenshots and allow access to all photos when Android asks. If you tap “Read the screenshot just taken” and allow access to all photos, or, when you open “Understand them” or “Reply to them” with nothing copied, tap “Yes, turn on” on the card that explains this and allow access to all photos, this turns on too (the app tells you); turning it on from the card reads no screenshot. Once on, when a new image is saved the keyboard looks, on the phone only, at the file names and folders of images added in the last 2 minutes to find the screenshot you just took, and shows a small thumbnail of it with “Read screenshot” in the keyboard for about 2 minutes; where a field accepts pictures, “Paste screenshot” appears too, and tapping it hands that one picture only to the app you are typing in (like pasting a GIF), never to the AI. It opens no other photos and hands over no picture unless you tap; only when you tap “Read screenshot” is that one read, and opening “Understand them” or “Reply to them” never reads a screenshot by itself (see section 4). You can turn it off in Keyboard › Screenshots at any time, and remove photo access in your phone’s settings. For now, only versions not installed from Google Play have this feature; the version from Google Play has no photo access and gets only the screenshot you choose, through the system photo picker or sharing.
- Screenshots you ask MOQI to read: downscaled and kept in the app’s cache, one at a time, usable for 10 minutes; deleted when you use MOQI’s suggestion, pick another one, or the app restarts.
- Autofill (Android 11 and later): your password manager’s account suggestions (for example Samsung Pass or Google Password Manager) are drawn on the keyboard by the password manager itself and filled in by it when you tap; the keyboard cannot see the account or the password and sends nothing.
- Password fields: the keyboard uses no AI, neither shows nor keeps clipboard history, and learns no words or speaking habits.
- Incognito fields (fields an app asks keyboards not to learn from): no clipboard history, no learned words or speaking habits. The MOQI assistant can still be used there.
Also:
- The app turns off Android’s system backup. In a phone-to-phone transfer, the device code, the statistics code and its random draws, the sign-in, the Google Play integrity check’s record, support access codes, the error log and AI counts are left behind.
- Uninstalling the app deletes this data from the phone.
4. When content is sent to the AI server
The keyboard uses AI only after you agree to the privacy notice in the app. These are all the cases in which content is sent:
(Screenshots also work without photo access: MOQI’s “Read screenshot” and “Choose from photos” open the system photo picker, which gives MoqiKey only the one you choose; or share a screenshot from your gallery to “Read chat with MOQI”.)
| When | What is sent | Default | How to turn it off |
|---|---|---|---|
| You tap a MOQI assistant feature (Understand them, Help me write, Conversation starters, Change tone, translate, Spelling & grammar, Show pronunciation, Read screenshot, and so on), or Summarize on a person’s profile | The text or the screenshot you chose; Summarize sends what MOQI noted earlier from that person’s messages | Only when you tap | Do not tap |
| You tap “Read screenshot” in the keyboard or “Read the screenshot just taken” (needs “Offer to read screenshots” or photo access, see section 3; for now only in versions not installed from Google Play) | That one screenshot (“Read the screenshot just taken” reads the newest one from the last 10 minutes) | Only when you tap; “Offer to read screenshots” is off by default | Do not tap; turn it off in Keyboard › Screenshots |
| “Auto-translate copied messages” | A message you copied in a language other than yours in My style, sent when you open the keyboard (for example Japanese, Korean, English, Thai or Vietnamese when your language is Chinese; several copied in a row go together) | On | Settings › AI & key, or the keyboard’s quick settings |
| MOQI AI voice typing (hold the space bar and speak) | Fast mode: the text your phone’s speech recognizer wrote; accurate mode: the recording of that sentence | Off (fast mode once turned on) | Settings › AI & key |
| “My style” summarizing what it noticed | About the 40 latest things you said that it learned: messages you sent, sentences pasted from a chat log, and what you typed in the practice. Once per 30 newly learned (at most once a day), and also when you tap Summarize in My style or finish the learning step of the welcome screens | On | Turn learning off in My style |
| The practice chat in the welcome screens | What you type in the practice | Only if you choose it | Skip the practice |
To make suggestions fit, MOQI assistant features and auto-translate also include:
- A summary of the person’s profile: name, role, relationship stage, gender, age, birthday, language, country, how long you have known each other, what you call them, who is older, personality, MBTI, how they like to chat, topics to avoid, your notes, the formality setting, and what MOQI has noticed from earlier messages. Photos are never sent.
- My style: your language, gender, age, catchphrases, emoji habits, sentence length, notes and learned speaking habits, with a few short messages you sent as examples.
- The current time, and the other person’s local time when they are in another time zone.
MOQI AI voice typing includes your speaking habits; the welcome screens’ practice includes that person’s name, gender and role.
Every request also carries (no content):
- A device code: made at random when the app is installed, used to count each device’s daily limit. It is not a hardware serial number.
- The app version and the kind of feature.
- Region signals: the country of the SIM card and of the mobile network, and the phone’s language and time zone. The server turns them into a single country or region code, used to decide which AI model may be used there (for example, OpenAI’s models are not used in Hong Kong) and to refuse places that cannot be served.
- Your sign-in token, when you are signed in with Google.
When you are not signed in and open the MOQI assistant or voice typing, or tap “Test connection” in settings, the app asks the server whether a sign-in is needed and how many uses are left today; that request carries only the items above, with no content.
5. Who processes the AI requests
- The server passes each request to Google Cloud Vertex AI (Gemini models) and streams the answer back to the phone. The server does not store the request or the answer, and neither appears in our logs.
- Google processes this data for us as a service provider under the Google Cloud terms and does not use it to train its models. According to Google’s documentation (checked October 1, 2026):
- By default Gemini caches requests and answers in memory for up to 24 hours, for our project only, to answer faster.
- Requests that Google’s automated safety systems flag as possibly breaking its usage policies may be kept for up to 90 days, only to check for a violation.
- To answer faster and at lower cost, the server has Vertex AI keep MOQI’s own fixed instructions (the wording we wrote, the same for every request) as a cache, which each request names instead of sending them again. This cache holds only our instructions, never anything of yours, and expires when no request has used it for a while.
- We use Vertex AI’s global endpoint, so Google may process requests outside Taiwan (see section 13).
- The server’s settings also include routes to Azure OpenAI and OpenRouter, which are not in use. We will update this policy before using them. In Hong Kong and other places OpenAI does not serve, the server never uses OpenAI’s models.
- When we cannot read the language of a support message you sent us, we translate it into Chinese with the same Vertex AI (Gemini); the translation is not stored.
- AI answers can be wrong or inappropriate. Check them before you send them. You can tap “Report this reply” in the keyboard’s AI panel to tell us.
6. What the server keeps, and for how long
The server runs in Google Cloud’s Taiwan region (asia-east1) and keeps data in Firestore. Only the server reads and writes it; the app never connects to the database directly.
6.1 For everyone
| Data | Contents | Kept for |
|---|---|---|
| AI usage records (one per request) | Time, device code, region, app version, feature, model, token counts, cost, response time (including when the first words reached the phone), how many times the server sent it to Google, and a success, error or cancellation code; the account code when signed in | Deleted after 30 days |
| Usage per device | By device code, daily and total counts, tokens, cost, region, app version, last use | No deletion period is set at present |
| Rate-limit counters | Keyed hashes of device codes and IP addresses (never the address or code itself), and counts | Deleted after the time window ends |
| System logs (Google Cloud Logging) | The IP address, URL, time, status and User-Agent Cloud Run records for each request (the app’s User-Agent is only its networking library’s name and version; anonymous statistics requests are excluded); our own log lines hold only numbers and codes, such as the device code, region, feature, tokens, cost and response time of an AI request, never content, your email or account codes | 30 days |
6.2 When you sign in with Google
| Data | Contents | Kept for |
|---|---|---|
| Account | Your Google Account email, a SHA-256 hash of your Google Account identifier (not the identifier itself), a random account code, a second random account code given to Google Play (see 6.7), when it was created and last used, its status, and consent records (the account notice version and time, and the time you confirmed you are 18 or older) | Until you delete the account |
| Sign-ins | A SHA-256 hash of the sign-in token, the device code, when it was created and last used | Ends after 180 days without use and is then deleted; deleted at once when you sign out or delete the account |
| Devices you signed in on | Device code, app version, first and last use | Until you remove the device or delete the account |
| Daily usage of the account | Counts, counts per feature, tokens, cost, region, app version | Until you delete the account |
| One-time sign-in codes | A hash | Expire after 10 minutes and are then deleted |
- Google’s sign-in data also includes your name and profile picture URL; the server takes only the email and the account identifier and does not keep your name or picture.
- Accounts are never merged just because the email is the same.
- Usage before you sign in is not counted in the account’s usage. But once a device has signed in to an account, the admin dashboard shows the account’s email next to that device and its requests, so we can tell who it is (see 6.8).
- On the phone, the sign-in is encrypted with Android Keystore and is never put in a “Move your data” backup.
6.3 When you write to us (Help & feedback)
| Data | Contents | Kept for |
|---|---|---|
| Support tickets | Category, app language, device code, app version, times, what you wrote and the replies; the account code when signed in; with “Include diagnostics” on, also the app version, Android version, phone model, app language and the time, feature, status and code of the last 10 errors (no content) | 180 days after the last message (or after it is closed) |
| What “Report this reply” attaches | The original text (up to 500 characters), MOQI’s reply (up to 2,000 characters) and the kind of feature | 90 days after it is sent |
- No sign-in is needed. Only the phone holding the ticket’s access code can read it; the code stays on that phone and the server keeps only its hash.
- “Report this reply” first shows what will be sent and sends it only when you tap Send; choosing “Keep on phone” uploads nothing.
- Emails you send straight to support@moqikey.com stay in our mailbox so we can answer you.
6.4 When you request account deletion on the web
- The email and message you enter and your browser’s first language are kept as a deletion request.
- It is deleted 30 days after the request is handled (closed).
6.5 Anonymous usage statistics
See section 8. Data under each statistics code is deleted 400 days after its last report; totals that carry no code are kept indefinitely.
6.6 Google Play integrity checks (only the version installed from Google Play)
- Only after you agree to the privacy notice and while MoqiKey’s server is the AI service in use; nothing is sent before.
- Once when you agree to the privacy notice, then at most once a day (by the UTC date; in the background when the keyboard or the app opens) and once at each sign-in, the app asks Google Play for an integrity token and sends it to our server, which has Google decode it.
- For this check Google Play receives the app’s package name, version and signing certificate, your Google Play licence status and the phone’s attestation data, handled under Google’s terms (see section 9).
- The server keeps, by device code, Google Play’s three verdicts (whether the app is the genuine Google Play version, whether it was installed by a licensed user, and whether the phone passes integrity checks) and the time, and, when Google could not check a token for a while, the time of that try. They are deleted 3 days after the last check (or try). The token itself, the account and any content are never kept.
- The request carries the device code (and the sign-in token when signed in, which is only checked and never kept with the verdict), but no region and no content.
- It stops modified apps from using up the AI allowance.
- Versions not installed from Google Play do not do this check.
6.7 MoqiKey Plus, redeem codes and plans
MoqiKey Plus is a paid plan. It can be bought only in the version installed from Google Play, as a Google Play subscription, once subscriptions are open. Redeem codes work in every version.
- Payment is handled by Google Play; we never see your card or payment details. Google Play gets only a randomly generated account code, never your email or account code.
- After you subscribe, and each time you come back to the app (for purchases Google Play is still waiting to have confirmed), the app sends the purchase token Google Play gave it to our server. When you tap “Restore purchase” on the Plan page, every MoqiKey Plus purchase the Google Account on this phone has at Google Play is sent (for example one bought on another account, or on an account since deleted). A payment still pending is not sent and gives no Plus.
- Once Google Play confirms a purchase, the server keeps: a SHA-256 hash of the purchase token (never the token itself), the product, monthly or yearly, the state Google Play reports, start and expiry times, whether it renews, whether it is a test purchase, when it was acknowledged and updated, when it was refunded, and the account code it belongs to. The account also gets a “Plus grant” (its kind, start and end times, and the state and monthly or yearly plan Google Play reports). No order number, price, region or email is kept.
- Purchase records are deleted 3 years after the subscription expires. When Google Play later tells us the subscription changed (renewed, cancelled, refunded), the server checks with Google Play again and updates it.
- When another account sends the same subscription, the server does not move it on its own: it records a transfer request (both account codes, the purchase hash, its state and expiry) for us to review by hand, deleted 180 days after it was last sent.
- When Google Play tells us a subscription changed but it cannot be matched to any account yet, we keep nothing.
- The app keeps no purchase token on the phone.
- Plus days we give you as support compensation are kept on the account’s grants, with the number of days and the reason we wrote.
Redeem codes are only ever given away free (for example at events or as support compensation). They cannot be bought, and there is nowhere in the app to buy one:
- The server keeps only a keyed hash (HMAC) of each code, with no user data, deleted 180 days after the code’s redeem-by date.
- When you redeem one, the server records which account, when, and which code (its hash) and batch, kept until you delete the account; the Plus days given are kept on the account’s grant.
- To stop code guessing, wrong tries per account are counted under a hashed code for an hour and a day, then deleted. The app checks the format on the phone first and does not send a mistyped code.
Plans and daily limits:
- How many MOQI AI requests the free plan and MoqiKey Plus get each day is set by us and may change; when it is set, the app’s Plan page shows the current numbers. Each device also has its own daily limit.
- The server works out your plan from the account’s Plus grants; no other data is needed.
6.8 Who can see it
- Only Taco Hsiung: on an admin dashboard that requires his Google Account through Identity-Aware Proxy, and in the Google Cloud console (for example to look at the database and system logs).
- Google stores and processes this data for us as a service provider (section 9).
- The dashboard shows accounts by their email, and shows the account’s email next to the devices, requests and support tickets that signed in to it, so we can tell who it is. The anonymous usage statistics (section 8) are never linked to an email.
- Every dashboard action on an account (search, ban, sign out on all devices, delete, giving or revoking Plus) is recorded with the time, the admin account, the action and the account code, never the email. After an account is deleted, its code in these records is replaced with one that leads back to no one. No deletion period is set for these admin records at present.
7. What we do not keep
- What you type in any app.
- The messages, screenshots and recordings sent to the AI, and its answers (except what you choose to send us with “Report this reply”, see 6.3; for Google’s caching see section 5).
- People profiles, photos, your style and learned speaking habits.
- Your Google Account name and picture.
- IP addresses in our database (rate limits keep only keyed hashes). IP addresses appear only in the system logs in 6.1.
8. Anonymous usage statistics
These help us understand how MoqiKey is used, for example how many profiles people set up and which features few use.
- On by default (the option is ticked in advance in the welcome screens). You can turn them off at any time in the privacy notice. Nothing is sent before you agree to the privacy notice and have been shown the statistics notice.
- At most once a day, with only options and counts:
- app and Android versions, the app’s language and yours, your country or region, and the countries of the SIM card and the mobile network (countries outside a fixed list are sent as “Other”);
- your own gender and age band; which “My style” fields are filled in and how much was learned;
- which keyboards, appearance options and features are on; how often each AI feature was used today and in the last 7 days;
- how many people you have, and for each: identity, relationship stage, language, age band, country, days since created, which fields are filled in, whether there is a photo, how many chat names, the closeness band and how many things were learned.
- Never sent: names, any text you wrote, birthdays, photos, messages, what you type. The other person’s gender is never in your record.
- The other person’s gender is sent separately, with no code at all, in two requests at different random times:
- one only adds to overall shares (how many women, men, other);
- the other is counted with your SIM country, your gender and the person’s country (or language), but for each person there is a one-in-two chance it is replaced with a randomly drawn gender (drawn once and kept on your phone). A single report cannot be trusted; we only estimate shares across many people, and the dashboard hides groups of fewer than 30 people.
- Statistics use a separate anonymous code, with no device code and no sign-in, and the server does not read IP addresses; the system logs are set not to record statistics requests. We do not link statistics to your device code, account or IP address.
- “Delete my stats” deletes everything under the code on the server and switches to a new code. Totals with no code cannot be told apart, so they cannot be deleted and are kept.
9. Other services that handle data
We do not sell your data, show no ads, and include no advertising or analytics SDKs (Google ML Kit, used for handwriting, sends usage information to Google; see the table). These services handle some data under their own terms:
| Service | What | Why |
|---|---|---|
| Google Cloud (Cloud Run, Firestore, Vertex AI, Cloud Logging, Secret Manager, Identity-Aware Proxy) | The data in sections 4 and 6 | Running the server, storing data, AI |
| Sign in with Google (Android Credential Manager, Google Play services) | The Google Account you pick | Signing in |
| Google ML Kit (handwriting recognition) | Downloading the handwriting model. According to Google, ML Kit sends Google the phone’s maker, model and Android version, the app’s package name and version, a per-installation identifier (not meant to identify you or the phone), performance figures such as latency, feature settings, events and error codes, and the handwriting languages set, for diagnostics and usage analytics. What you write is recognized on the phone and not sent | Handwriting keyboard |
| Your phone’s speech recognition service (usually Google) | What you say (regular voice typing, and MOQI AI voice typing in fast mode) | Speech to text, under your phone’s settings and that service’s policy |
| Google Play integrity checks (Play Integrity, Google Play version) | The app’s package name, version and signing certificate, your Google Play licence status and the phone’s attestation data (see 6.6) | Checking that the app and phone are not modified, to prevent misuse |
| Google Play Billing (Google Play version) | Payments and payment details are handled by Google Play; we give it only a random account code and check purchases with it (see 6.7) | MoqiKey Plus subscriptions |
| Cloudflare (language packs, packs.moqikey.com) | Connection data when a language pack is downloaded or the daily check for newer ones runs, such as your IP address; the request asks only for the file and carries no content, account or device code | Downloading and updating the input methods’ dictionaries (language packs) |
| Cloudflare (the website moqikey.com) | Connection data when you visit the website, such as your IP address and what your browser sends; deletion requests sent on the web page pass through Cloudflare to our server on Google Cloud | Serving the website |
| Google Fonts (the website moqikey.com) | Your browser connects to Google to load the website’s fonts, so Google receives your IP address and browser information | The website’s fonts |
Otherwise we disclose data only when the law requires it (for example a court order or a lawful request by an authority).
10. The other person’s data, and your responsibility
- MoqiKey processes what you and others say in your chats, and what you write about them in their profile. They have not agreed to it.
- Use the AI features only when you need them, and do not put unnecessary private details (such as ID numbers, health information or private photos) into profiles or send them to the AI.
- You are responsible for the data you provide about others and for following the law where you live.
- The other person can write to us. But profiles stay only on your phone and are not on our server, so we cannot look them up or delete them for that person; please ask the user to delete them.
- The other person may be under 18 (for example a family member). Take extra care and write only what is needed.
11. Children
- MoqiKey is for people 18 and older only and is not designed for children.
- When you sign in with Google, you confirm that you are 18 or older.
- If we learn that someone under 18 has an account, we delete it. Please tell us if you find such a case.
12. Why we use the data
- To provide the AI features: passing the content you choose to the AI and returning the result.
- To count each device’s and account’s daily limit (by your plan), control costs, and prevent abuse and misuse.
- To pick the AI models allowed in each region, following the AI services’ regional restrictions and export controls.
- To sign you in, manage your account and devices, and delete your account.
- To answer your support messages.
- To improve the app with anonymous statistics.
- To confirm the app is the genuine version from Google Play (Google Play version).
- To provide MoqiKey Plus: checking Google Play subscriptions and redeem codes, working out your plan, and preventing refund abuse and one subscription being used by several accounts.
We do not use your data for advertising or personal marketing profiles.
13. International transfers
- The server and database are in Taiwan (Google Cloud asia-east1). If you use MoqiKey outside Taiwan, your data is transferred to Taiwan.
- AI processing uses Vertex AI’s global endpoint and may take place in Google data centers outside Taiwan; the caching and abuse-monitoring records in section 5 may also be outside Taiwan.
- System logs (Cloud Logging) may also be stored outside Taiwan.
- Sign in with Google, Google Play, ML Kit and Google Fonts are handled by Google under its policies, and the website and language packs are served by Cloudflare; any of these may be in other countries.
14. Your rights
| What you want | How |
|---|---|
| See what the server holds about you | The app’s Account page shows your email, the devices you signed in on and today’s count; the Plan page shows your plan, until when, and your Google Play subscription’s state. For a full copy, write to support@moqikey.com |
| Export the data on your phone | Settings › Move your data (export/import) |
| Correct it | Your email follows your Google Account and updates at your next sign-in; data on the phone is edited in the app |
| Delete your account | In the app, Account › Delete account, then confirm with the same Google Account; it is deleted right away. If you cannot use the app, fill in the email you sign in with on the account deletion page. We handle it within 7 days: we first email that address to confirm it is you, then delete the account |
| Delete statistics | Privacy notice › Delete my stats |
| Remove a device, sign out on all devices | The app’s Account page |
| Withdraw consent | Privacy notice › Withdraw consent (the keyboard stops using AI); you can also turn off anonymous statistics, style learning, MOQI AI voice typing and Auto-translate copied messages one by one |
| Anything else (for example to stop processing) | Write to support@moqikey.com |
When you delete your account:
- Deleted: the account, its link to your Google Account, your email, consent records, the account code given to Google Play, all sign-ins, the devices you signed in on, the account’s daily usage, Plus grants and redemption records.
- Kept, but no longer linked to the account: AI usage records from the last 30 days (deleted after 30 days), support messages you sent us (deleted on the schedule in 6.3), usage by device code (see 6.1), the Google Play integrity verdict (3 days) and system logs (30 days).
- Records of admin actions on the account stay, with the account code replaced by one that leads back to no one (6.8).
- Not affected: data on your phone (profiles, your style, learned words, settings). Uninstall the app to delete it.
- Anonymous statistics were never linked to the account; to delete them use “Delete my stats”.
- If you have a MoqiKey Plus subscription: deleting the account does not cancel your Google Play subscription or refund it; Google Play keeps renewing and charging it. Cancel it first under “Payments & subscriptions” in Google Play, then delete the account; the app reminds you before deleting, with a link to Google Play.
- On deletion, Plus ends (including days from redeem codes and support compensation). Purchase records stay without the account code, keeping only the purchase itself and that it once belonged to an account (not which one), to prevent refund abuse; they are deleted 3 years after the subscription expires (6.7). Transfer requests the account made that are waiting for our review are deleted.
We answer requests within the time the law requires. You also have the right to complain to the data protection authority where you live.
15. Security
- The app and the server always talk over HTTPS; the app allows no unencrypted connections.
- The server keeps only SHA-256 hashes of sign-in tokens, support access codes and one-time sign-in codes.
- The server verifies Google’s sign-in tokens itself (signature, audience, expiry and one-time code).
- On the phone, the sign-in is encrypted with Android Keystore.
- The app cannot reach the database; only the server reads and writes it. Its service account has only the permissions it needs, and secrets are kept in Secret Manager.
- The admin dashboard requires the owner’s Google Account through Identity-Aware Proxy, and every admin action is recorded.
- System logs never contain message content, your email, account codes or tokens.
- “Move your data” backups are encrypted with your password.
No system is perfectly secure. If a breach affects your data, we will notify you and the authorities as the law requires.
16. Changes to this policy
When we change how we handle data (for example a different AI service, or new kinds of data), we will update this policy first and tell you in the app; where new consent is needed, we will ask again. The effective date is at the top of this policy.
17. Contact us
- Email: support@moqikey.com
- In the app: Help & feedback › Write to us (no sign-in needed)
Appendix: notice under Article 8 of Taiwan’s Personal Data Protection Act
| Item | Details |
|---|---|
| Collector | Taco Hsiung |
| Purposes | 069 contracts, quasi-contracts and other legal relationships; 090 consumer and customer management and service; 135 information and communication services; 136 information, communication and database management; 157 surveys, statistics and research (anonymous statistics); once MoqiKey Plus subscriptions open, also 148 online shopping and other e-commerce services |
| Categories of personal data | C001 identifying a person (email, account code, device code); C011 personal description (gender, age band, country or region); and the content sent for AI processing in section 4, which we do not keep; once MoqiKey Plus subscriptions open, also C002 financial identification (purchase records) |
| Period of use | The retention periods in section 6 |
| Area of use | Taiwan; AI processing may happen outside Taiwan (section 13) |
| Recipients | Us, and the service providers in section 9 |
| Method of use | Automated electronic processing |
| Your rights | To ask about or review your data, get a copy, add to or correct it, have its collection, processing or use stopped, and have it deleted (section 14) |
| If you do not provide it | Without signing in or agreeing to the privacy notice you can still type and use the features on the phone, but not MOQI AI (when the server requires a sign-in) or related features |
| Special categories | A profile’s relationship and gender together with your own gender may be seen as relating to sex life. These are sent for AI processing and not kept by us; anonymous statistics include your own gender, and the other person’s gender appears only in totals with no code and in randomized combinations (section 8) |