PRIVACY, PLAINLY

Your station is personal. It needn’t become a dossier.

Mochi keeps enough to restore your dial, prepare the briefings you request and learn whether the product works. It does not build an advertising profile or collect your music library.

Last updated 24 August 2026

The short version

  • No Mochi account is required.
  • Your temporary station profile expires after 90 days.
  • A new browser may receive a visible, removable state-and-country suggestion inferred approximately from its network connection.
  • Local music files stay in your current browser session and are not uploaded to Mochi.
  • Product analytics contain fixed, aggregate events—not a listener ID, location, interests, music or source links.
  • You can delete the temporary server profile with Reset saved settings on the station page.

What Mochi stores for 90 days

Mochi creates a random browser credential in a secure, HttpOnly, same-site cookie. It connects this browser to a temporary profile stored in Cloudflare D1. The profile contains your music-provider choice, entered or accepted approximate place, selected interests, bulletin timing and length, presenter style and voice, intro preference, and whether music pauses for a bulletin.

The profile does not contain your name, email address, music files, Spotify credentials, YouTube or Spotify listening history, bulletin source links, pasted AI-profile text, or a persistent analytics identifier. Each profile expires 90 days after its latest update.

Approximate place suggestion

On a new browser, Cloudflare may infer a country and first-level region such as a state from the network request. Mochi uses only those two coarse fields to suggest a visible place. It does not request browser location permission, return network-derived city, postcode or coordinates, or use the suggestion as an exact weather location. The suggestion can be changed or removed before use.

What stays in this browser

Mochi also remembers some station settings in browser storage, including the last YouTube link and Spotify source. If you connect Spotify, the public Client ID for your own Spotify developer app and Spotify’s authorisation tokens remain in this browser. They are not added to the 90-day Mochi profile.

Reset saved settings removes those browser values, disconnects the players and deletes the temporary Mochi profile. Clearing a token from this browser does not revoke the underlying permission at Spotify; you can also remove your developer app from your Spotify account’s authorised-apps page.

What leaves your browser

News briefings
Your approximate entered place, selected interests, bulletin length and presenter style are sent through Mochi’s Worker to OpenAI to find current reporting and write the requested bulletin.
Weather
Your weather search and selected coordinates are sent to Open-Meteo for place search and forecast data.
Spotify
Sign-in, authorisation, catalogue search and playback use Spotify’s services. Mochi never needs your Spotify password or Client Secret.
YouTube
A pasted video or playlist plays through YouTube’s visible official player. YouTube may receive the usual player and browser information under its own policies.
Voice
The Kokoro model is downloaded through Mochi’s same-origin proxy, then speech is generated in a separate worker in your browser.

Aggregate product analytics

Mochi records a small fixed set of events such as page views, playback starts and stops, bulletin outcomes, voice readiness, coarse failure type and completed listening-session length. An event may include the chosen provider, manual or scheduled mode, or bulletin-length band.

Analytics do not include your location, topics, pasted profile, source URLs, Spotify data, credentials, music metadata or a persistent listener ID. The owner-only dashboard can separately show counts of the entered places in active temporary profiles by reading D1 directly; those places are not copied into Analytics Engine.

Delete and reset

On the station page, go to Set the dial and choose Reset saved settings. Mochi stops active playback, clears its saved station and provider values from this browser, deletes the linked server profile and expires its cookie. If the server deletion cannot be confirmed, Mochi says so and asks you to retry instead of claiming that it succeeded.

You can also clear all data for mochiradio.com in your browser. Mochi is currently an early MVP without accounts, profile export or a public privacy inbox. A public contact route will be added before any move beyond that limited release.