Privacy Policy
Last updated: July 15, 2026
1. Introduction
Mocki ("we," "our," or "us") is a device mockup app for iPhone, built by one developer. This Privacy Policy explains what data Mocki collects, what it doesn't, and how it flows. Mocki works fully without an account: everything stays on your phone. Signing in is entirely optional and adds one thing, backing up your projects so they sync across your devices and survive a reinstall. This policy covers both cases.
2. How Your Data Flows
The cleanest way to understand Mocki's privacy model is to follow the data:
- Device only (signed out, the default): the screenshot you import, the projects you build (device, background, position, canvas size, text), and your app settings are stored locally on your phone via on-device storage. None of it is transmitted anywhere. If you never sign in, nothing about your projects ever leaves your phone.
- Device ↔ Photos (import & export):Mocki asks for photo library access to let you pick a screenshot to place inside a device frame, and to save your finished mockup back to Photos when you export. Both directions happen entirely through iOS's own Photos framework, on your device.
- Device ↔ Firebase (optional sign-in & cloud sync): if you choose to sign in (with email, Apple, or Google), Mocki stores a copy of your projects in your own private, account-scoped space in Google Firebase so they sync across your devices. What syncs is described in Section 3. This only happens after you sign in, and you can sign out or delete your account at any time.
- Device ↔ RevenueCat ↔ Apple (Mocki Pro purchase): if you subscribe to or buy Mocki Pro, the purchase itself is processed by Apple. RevenueCat sits between the app and Apple to confirm your Pro entitlement is active. RevenueCat never receives your screenshots or your mockup projects.
Mocki contains no analytics SDK — no PostHog, no Firebase Analytics, no Mixpanel, no Amplitude, or any equivalent. No behavioral events are sent anywhere. No AI is involved in building or exporting a mockup; every render happens on your device.
3. Information We Collect
Photos you choose to import
When you pick a screenshot to place inside a device frame, Mocki reads that image locally to render your mockup. The full-resolution screenshot is never uploaded to our cloud, even when you are signed in; it stays on your device.
Account information (only if you sign in)
If you sign in, Firebase Authentication stores the identifier for your chosen method: your email address (email sign-in), or the account identifier and any name/email you agree to share from Apple or Google. If you use Sign in with Apple and choose Apple's private relay, we only ever see the relay address. This is used solely to identify your account so your projects sync to the right place.
Project data synced to the cloud (only if you sign in)
When you are signed in, the following is stored in your private space in Firebase so it can sync across your devices:
- Your project documents: the mockup layout (chosen device, colour, background, positions, rotation, canvas size, and any text you add) and the project name and timestamps. Stored in Cloud Firestore.
- A small thumbnail preview image of each project (a downscaled render of the first page, which may include the screenshot you placed). Stored in Firebase Storage.
Every piece of this is scoped to your account: our security rules allow only you, signed in, to read or write your own data. It is never public and is never shared with other users.
Purchase and entitlement data (Mocki Pro only)
If you purchase Mocki Pro, RevenueCat receives your purchase receipt from the App Store, along with your device model, OS version, app version, and country/region, for purchase validation.
What we do NOT collect
- No analytics or behavioral event tracking of any kind
- Your full-resolution imported screenshots (they are never uploaded)
- No account or project data at all if you never sign in
- No advertising identifier (no IDFA-based tracking)
- No location, contacts, microphone, or camera data
- No health or biometric data
4. Tracking & Advertising
Mocki does nottrack you across other companies' apps or websites. We do not participate in ad networks, retargeting, or audience-building of any kind, and we do not use Apple's IDFA (Identifier for Advertisers). Accordingly, Mocki does not present an App Tracking Transparency (ATT) prompt because no cross-app or cross-site tracking occurs.
5. Third-Party Services
Mocki relies on the following third-party services:
- Google Firebase (Authentication, Cloud Firestore, Cloud Storage, and Cloud Functions): powers optional sign-in and the cloud backup/sync of your projects. Firebase is only contacted after you sign in. Google processes this data in the United States.
- Sign in with Apple and Google Sign-In: optional authentication providers, used only if you pick them to sign in.
- RevenueCat: subscription and in-app purchase management for Mocki Pro. Receives purchase receipts and device metadata for purchase validation only. RevenueCat processes data in the United States.
- Apple App Store: app distribution and payment processing for all purchases.
We do not sell, trade, or rent your information to anyone, and we do not share your projects or account data with any third party beyond the infrastructure providers above that make sync and purchases work.
6. Data Storage & Deletion
Your projects, settings, and any imported screenshot always live in your device's local storage; deleting Mocki from your phone removes that local copy.
If you signed in, a copy of your projects also lives in Firebase. You can remove it in two ways: signing out stops syncing and leaves the cloud copy in place, while Delete account (in Settings) permanently erases your account and all of its cloud data. Account deletion runs a Cloud Function that removes your Cloud Firestore data, your Firebase Storage thumbnails, and your Firebase Authentication record. Your local projects on the device are kept unless you also delete the app.
7. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process the limited data described above on the following legal bases:
- Consent (Art. 6(1)(a) GDPR): optional sign-in and cloud sync happen only if you choose to create an account. You can withdraw consent at any time by deleting your account.
- Contractual necessity (Art. 6(1)(b) GDPR): purchase and entitlement management via RevenueCat is necessary to fulfill your Mocki Pro purchase and grant access to paid features.
8. International Data Transfers
Firebase (Google) and RevenueCat process data in the United States. If you sign in from outside the United States, your account and project data is transferred there. Your full-resolution screenshots never leave your device. For data that is transferred, appropriate safeguards (such as Standard Contractual Clauses) are in place in accordance with applicable data protection laws.
9. Your Rights
You have the right to:
- Use Mocki fully without an account, keeping all project data on-device
- Delete your account and all cloud data at any time from Settings → Delete account
- Delete all local app data by deleting Mocki from your device
- Request a copy of the purchase data RevenueCat holds by emailing us
Additional rights for EEA/UK residents (GDPR): you also have the right to access and data portability, the right to restrict or object to processing, the right to withdraw consent, and the right to lodge a complaint with your local data protection authority.
Additional rights for California residents (CCPA/CPRA): you have the right to know what personal information we collect, the right to delete it, and the right to opt out of the sale or sharing of personal information. We do not sell or share your personal information as defined under the CCPA.
10. Children's Privacy
Mocki is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that a child has created an account or made a purchase, contact us and we will delete the account and assist with a refund through Apple.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will note material changes on this page. Your continued use of Mocki after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, contact us at support@moetalaat.com.
13. Summary
In short: Mocki works fully without an account, and if you never sign in, nothing about your projects leaves your phone. Signing in is optional and backs up your projects (layout data and small preview thumbnails, never your full-resolution screenshots) to your private space in Firebase so they sync across devices. You can delete your account and all cloud data from Settings at any time. There is no analytics SDK, no advertising, and no tracking. The only other data that leaves your device is a purchase receipt to RevenueCat and Apple if you buy Mocki Pro.
