Mogoru
Privacy Policy
What Mogoru collects, why, who else touches it, and how to get it back or get rid of it.
Last updated 5 August 2026
The short version
- We collect what is needed to run a reading app you sign into — and, deliberately, not much else.
- Your library, decks and tutor conversations are private to your account.
- When you use an AI feature, the text it needs is sent to a third-party AI provider. Nothing leaves until you ask for it.
- There are no advertising networks, no data brokers, no analytics companies and no error-reporting services. Everything we measure, we measure ourselves.
- This landing page sets no cookies at all and loads no third-party scripts.
Who is responsible
Pedro Guedes Guimarães, an individual based in Brazil, is the controller of your personal data — the one who decides why and how it is processed. Mogoru is run by one person rather than a company, so “we” throughout this policy means him.
Write to [email protected] about anything on this page, including any of the rights set out below. There is no separate data protection officer; that address reaches the controller directly.
What we collect
Almost all of it is something you created on purpose. In full:
- Account — your email address and display name. Credentials are held by our authentication provider; we never store your password.
- Sessions — each active session records the IP address and browser user-agent it was created from, so you can tell your devices apart and so we can rate-limit abuse.
- Your library — the documents you import and their full text, cover images, the original file where we retain it (a source PDF, for example), and your reading position.
- Study data — decks, notes, cards, note types, card templates, your review history, and the knowledge status of every word you have met.
- Activity — reading and progression events, daily activity counts and streaks.
- Tutor — your conversations, their titles, and the full message history including the actions the tutor took.
- Preferences — timezone, day-rollover hour, interface language, study language, daily goal and onboarding state.
- Files — media you upload, held in a private bucket, along with its filename, type, checksum, size and storage key.
- AI usage records — for each AI operation: the feature, provider, model, token counts, estimated cost, status, error code, latency and timestamps. No prompt text, no AI response, no document titles.
- Administrative records — a privacy-safe audit entry when an administrator views or acts on an account, recording the action and outcome rather than any of your content.
Why we process it
- To provide the service — importing, reading, scheduling, syncing across your devices, and answering your questions in the tutor.
- To keep it secure and available — session integrity, rate limiting, abuse prevention and diagnosing failures.
- To understand usage in aggregate and keep AI spending under control.
- To meet legal obligations where they apply.
Under Brazil's Lei Geral de Proteção de Dados (Lei 13.709/2018), the bases are performing our contract with you (art. 7, V), our legitimate interests in security and in operating the service (art. 7, IX), and legal obligation where one applies (art. 7, II). If GDPR applies to you, the equivalent bases are contract, legitimate interests and legal obligation.
What leaves for AI processing
This is the part worth reading twice. Each AI feature sends only what it needs, and only when you use it:
| Feature | What is sent |
|---|---|
| Sentence translation and grammar breakdown | The sentence you selected (up to 500 characters), the document title, and a short run of preceding text for context |
| Dictionary examples | A headword, its readings and its dictionary glosses. No text from your documents |
| Manga bubble translation | The text recognised in the bubbles, and the document title |
| Manga OCR refinement | Cropped images of the text regions, plus the draft recognised text |
| Damaged PDF repair | The damaged characters and the text surrounding them |
| Tutor chat | Your recent messages in that conversation (up to the last 40) and a summary of your progress: known-word count, level estimate, mastery, words learned this week, streak, and cards due |
Finding and reading the text in a comic — the OCR itself — runs on Mogoru's own private service. Only the optional refinement step sends crops onward.
We never send your library wholesale to anyone, and we do not use your content to train models of our own.
Who else touches your data
- Railway — hosts the application, the PostgreSQL database and the private bucket your files live in.
- Clerk — handles sign-up, sign-in and your credentials, and holds the email address and display name attached to your login.
- Third-party AI providers — process the text described above when you use an AI feature. Providers can change; this page is updated when they do.
That is the complete list. We do not sell your data, share it for advertising, or hand it to anyone else except where the law requires it.
What we measure
All measurement is first-party and stays in our own database. There is no Google Analytics, no PostHog, no Mixpanel, no Sentry and no advertising pixel anywhere in the product.
Our internal dashboard shows aggregate counts — sign-ups, reviews, reading activity — plus token and cost totals for AI. It is built so that prompts, AI responses, chat messages, document titles, resource names and note fields are never collected into it. Per-account figures require a fresh password check and return metrics only, never content.
How your data is kept apart
- Your account is the boundary. Every read and write is scoped to your user at the data layer, and database triggers reject cross-account links as a second line of defence.
- Files are stored under keys namespaced to your account and are served only after an ownership check. A storage path is never treated as permission.
- The application is not reachable from the public internet. Every request arrives through the gateway that serves this page.
- Sessions use HttpOnly, SameSite cookies over HTTPS, and every change requires a signed CSRF token bound to your session.
- Authenticated responses are marked private and no-store, so your content is not left in shared caches.
How long we keep it
Long enough to run the service, and no longer. Because the detail matters more than a sentence can carry, it has its own page: Data & Retention lists every category, where it lives, how long it stays, and how to remove it.
Your rights
Under the LGPD you can ask us to confirm what we hold and give you access to it; correct anything incomplete or wrong; anonymise, block or delete data that is unnecessary or excessive; provide your data in a portable form; tell you who we have shared it with; and delete data processed on the basis of consent.
Email [email protected] from the address on the account. We confirm it is you before acting, and complete requests within 30 days. If GDPR or UK GDPR applies to you, the equivalent rights apply and the same address works.
If we get it wrong, you can complain to Brazil's Autoridade Nacional de Proteção de Dados (ANPD), or to your local supervisory authority.
Where your data lives
Our infrastructure runs in cloud regions outside Brazil — file storage is currently in the United States — and our AI providers process data in their own regions. Using Mogoru means your data is transferred internationally so the service can run.
Children and teenagers
Mogoru is not for anyone under 13. Between 13 and 18, an account needs a parent or guardian's permission, and by allowing it they accept the Terms on the account holder's behalf.
Brazil's LGPD (art. 14) requires a minor's data to be handled in their best interest, and treats anyone under 12 as a child whose data may only be processed with specific, prominent consent from a parent or legal guardian. The floor of 13 keeps us out of that category altogether: we do not knowingly hold data on anyone younger, and there is nothing in Mogoru that would need it.
Where GDPR applies, the age at which someone can agree to an online service without a parent is set by their own country — 16 in much of the European Union, lower in some member states, never below 13. That age governs instead of ours.
We have no way to verify anyone's age, and would rather say so than imply a check we do not perform. If you believe someone below these ages has an account, email [email protected] and we will remove it.
Changes to this policy
We update this page when what we do changes — including when we add or replace a processor — and revise the date at the top.
