HiyaMojo - Return to Home

Privacy Policy

Your privacy matters to HiyaMojo

Effective date: June 1, 2026

Last updated: June 1, 2026

Introduction

HiyaMojo ("we", "us", or "our") operates the HiyaMojo web application (the "Service"). This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, and the choices and rights you have.

HiyaMojo is operated by an individual sole trader based in Vilnius, Lithuania (European Union). For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we are the data controller for your personal data. Our contact details are in the "Contact Us" section at the end of this policy.

We serve users worldwide, so this policy is written to meet the GDPR and UK GDPR, the California Consumer Privacy Act as amended by the CPRA (together, "CCPA"), and general good-practice standards. Where a specific law gives you rights, the relevant section below tells you how to use them.

Information We Collect

Account information

When you create an account, we collect:

  • Required: email address, username (3-20 characters), and a password (for local accounts; stored only as a secure hash).
  • Optional profile details: date of birth, gender, country of residence, and timezone. Your date of birth is used to derive your age where needed; we do not store a separate age value.
  • If you sign up with Google or Facebook: we receive your email address, name, and a unique account identifier from that provider, and (for Google) your locale. We do not receive your social-media password.

Information you provide while using the Service

  • Task and productivity data: the tasks and tags you create, the effort levels you assign, your completion logs, bonus and reward settings, streaks, Mojo balance and history, rest periods, and your in-app display preferences.
  • Onboarding survey: if you answer the "what brought you here today?" prompt, we store your response (and a single inferred "purpose word") to personalise your experience.
  • Communications: messages you send us through the contact form (name, email, country, and your message) and any feedback you submit.

Information we collect automatically

  • Device and technical data: your IP address, browser user-agent string, and the device type we derive from it (desktop / mobile / tablet).
  • Activity logs: we log account and security events (such as logins, failed logins, password changes, email verification, task and tag operations, and profile changes) together with the IP address and user-agent for that event. These logs are used for security, fraud prevention, debugging, and abuse investigation.
  • Approximate location: at registration, social login, and contact form submission, we may derive your country from your IP address (via ip-api.com). We store only the resulting country code, not a precise location.
  • Marketing attribution: if you arrive through a campaign or referral link, we record the UTM parameters (source, medium, campaign, term, content) and the referring URL so we understand how people find us.

Visitor data (before you have an account)

When you browse our public pages without signing in, we record limited, anonymous events - such as page views, "learn more" clicks, and your cookie-consent choice - along with your IP address, user-agent, device type, referrer, and any UTM parameters. This helps us measure traffic and the effectiveness of our consent prompts. These records are not linked to a named individual.

How We Use Your Information

We use the information we collect to:

  • provide, maintain, and operate the Service and your account;
  • authenticate you and keep your account secure;
  • save and display your tasks, progress, and preferences;
  • send you service emails (such as verification and password reset) and, where enabled, reminder and summary emails;
  • respond to your enquiries and support requests;
  • detect, prevent, and address security issues, fraud, and abuse;
  • understand how the Service is used and improve it (with your consent for non-essential analytics); and
  • comply with our legal obligations.

Analytics and Tracking Technologies

We use the third-party tools below to understand usage and measure our marketing. With the exception of essential cookies, these tools load only after you choose "Agree" on our cookie prompt. If you choose "Disagree", they are not loaded (or are switched off). Our consent prompt is currently a single all-or-nothing choice that covers all of the technologies in this section; essential cookies needed to run the Service are always active.

  • PostHog (product analytics and session replay): hosted on PostHog's EU Cloud (eu.i.posthog.com). PostHog records product events (for example, creating or logging a task) and can record replays of your session - your clicks, navigation, and interactions - so we can see how features are used and fix problems. Form inputs are masked, so the content you type (such as passwords or task text) is not captured in replays. When you are signed in, we associate analytics with an identifier and may attach your user ID, email, signup date, marketing attribution, founder status, and account age.
  • Google Analytics 4 (usage analytics): provided by Google (United States). We use Google Consent Mode so that analytics and advertising storage are only enabled after you consent. GA4 collects page views, feature-usage events, and general device and approximate-location information.
  • Reddit Pixel and Conversions API (advertising measurement): provided by Reddit (United States). If you consent, we measure conversions from Reddit advertising. For better matching, we may send Reddit a cryptographically hashed (SHA-256) version of your email address and an account identifier; we do not send your email in plain text.
  • Google reCAPTCHA v3 (anti-abuse): provided by Google (United States) and used on our registration, contact, and password-reset forms to tell humans from bots. reCAPTCHA collects your IP address and interaction signals and is subject to Google's privacy policy and terms.

You can withdraw consent at any time by clearing this site's cookies and storage in your browser, which makes the consent prompt appear again so you can change your choice.

Cookies and Local Storage

We use the following cookies and browser-storage items:

  • Session cookie (hiyamojo_session): essential - keeps you logged in and secures your session. Set as Secure and HttpOnly.
  • "Remember me" cookie: optional - keeps you logged in for up to 30 days if you choose it.
  • Consent and app preferences (local/session storage): your cookie-consent choice (cookieConsent) and small flags that remember in-session state.
  • Analytics and advertising cookies: set by Google Analytics, PostHog, and Reddit only after you consent.

Essential cookies cannot be switched off because the Service cannot run without them. All other technologies are controlled by your consent choice. Loading some assets (for example, country-flag images via FlagCDN) may expose your IP address to that content provider, as is normal for any website.

Legal Basis for Processing (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract: to create your account and provide the Service you ask for.
  • Legitimate interests: to keep the Service secure, prevent fraud and abuse, and maintain basic operational logs - balanced against your rights.
  • Consent: for all non-essential analytics, session replay, and advertising technologies. You can withdraw consent at any time.
  • Legal obligation: where we must process data to comply with the law.

How We Share Your Data

We do not sell your personal data for money. We share data only with the service providers ("processors") that help us run HiyaMojo, each under a data-processing agreement:

  • Google Cloud Platform (United States) - hosting, database, and infrastructure.
  • SendGrid (Twilio) (United States) - sending our emails.
  • PostHog (EU Cloud) - product analytics and session replay (consent).
  • Reddit (United States) - advertising measurement (consent).
  • Google (United States) - Google Analytics, reCAPTCHA, and Google sign-in.
  • Meta / Facebook (United States) - Facebook sign-in, if you use it.
  • ip-api.com - country lookup from your IP address at registration, login, and contact.

We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety, and security of our users, the public, or HiyaMojo.

A note for California residents: we do not "sell" your data for money. However, using advertising and analytics tools such as the Reddit Pixel and Google Analytics may be treated as "sharing" or a "sale" under California law. You can opt out of this by choosing "Disagree" on our cookie prompt, and we honour Global Privacy Control (GPC) signals where applicable.

International Data Transfers

We are based in the EU, and several of our processors are located in the United States. This means your personal data may be transferred to, and processed in, the United States and other countries. Where we transfer data outside the EU/EEA or the UK, we rely on appropriate safeguards, such as the providers' certification under the EU-US Data Privacy Framework (and the UK extension) and/or the European Commission's Standard Contractual Clauses. We deliberately keep our PostHog analytics on EU servers.

Data Retention

  • Account and productivity data: kept for as long as your account is active.
  • Activity and visitor logs: retained while needed for security, abuse prevention, debugging, and legal compliance. We are working towards a defined maximum retention window for these logs.
  • Contact-form messages: kept as long as needed to handle your request and our records of it.

When you delete your account, we describe exactly what is removed and what is retained in the "Data Deletion" section below.

Your Privacy Rights

EU, EEA, and UK users (GDPR / UK GDPR)

You have the right to:

  • Access a copy of your personal data;
  • Rectify data that is inaccurate or incomplete;
  • Erase your data ("right to be forgotten");
  • Restrict or object to certain processing;
  • Data portability - receive your data in a portable format;
  • Withdraw consent at any time, without affecting prior processing.

You also have the right to lodge a complaint with your local supervisory authority. Our lead authority is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt).

California residents (CCPA / CPRA)

You have the right to:

  • Know what personal information we collect and how we use it;
  • Access and delete your personal information;
  • Correct inaccurate personal information;
  • Opt out of the "sale" or "sharing" of your personal information for cross-context behavioural advertising - choose "Disagree" on our cookie prompt, or send a Global Privacy Control (GPC) signal, which we honour where applicable;
  • Limit certain uses, and not be discriminated against for exercising your rights.

How to exercise your rights

You can update most details in the app, and delete your account from Settings → Profile Settings → Delete Account. For any other request - including access, correction, or a portable copy of your data - email us at support@hiyamojo.com from your registered address and we will respond within the time required by law. We may need to verify your identity first.

Children's Privacy

You must be at least 13 years old to use the Service, and we do not knowingly collect personal data from children under 13. In the EU, EEA, and UK, the minimum age for consent to online services ranges from 13 to 16 depending on the country; if you are under the digital-consent age in your country, you may use the Service only with the consent of a parent or guardian.

If you believe a child has provided us with personal data without the required consent, please contact us and we will delete it.

How We Protect Your Data

We use technical and organisational measures to protect your personal data, including:

  • passwords stored only as salted, one-way hashes;
  • encryption of all traffic in transit (HTTPS/TLS) and encryption at rest;
  • Secure, HttpOnly session cookies;
  • CSRF protection, rate limiting, and reCAPTCHA on sensitive endpoints;
  • HTTP security headers and database row-level locking;
  • least-privilege access controls for our infrastructure.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work hard to protect your data and to respond quickly to any issue.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page, and for material changes we will also make reasonable efforts to notify you by email or in the app. Your continued use of the Service after an update means you accept the revised policy.

Data Deletion

You can delete your HiyaMojo account at any time:

  • In the app: go to Settings → Profile Settings → Delete Account.
  • By email: send a request to support@hiyamojo.com from your registered email address.

What happens when you delete your account:

  • Your personal content - tasks, tags, daily logs, medals, Mojo history, and rest records - is deleted.
  • Your account is deactivated and your identifying details are removed or de-identified so the account can no longer be used or logged into.
  • If you signed in with Google or Facebook, that connection is removed.
  • We retain a limited record of the deletion, and certain activity/security logs, where necessary for security, fraud prevention, and legal compliance.
  • This action cannot be undone.

In-app deletions take effect immediately; email requests are handled within a few business days. Residual copies may remain in encrypted backups for up to 30 days before they are overwritten.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact the data controller:

  • HiyaMojo (operated by an individual sole trader)
  • Address: Šv. Ignoto g. 5-8, Vilnius 01144, Lithuania
  • Email: support@hiyamojo.com
  • Contact form: www.hiyamojo.com/contact

You also have the right to lodge a complaint with your local data protection authority (for Lithuania, the State Data Protection Inspectorate, vdai.lrv.lt).