1. Who We Are and What This Policy Covers
Nakhoyi Studio ("we", "our", or "us") is responsible for personal information handled through the nakhoyi.com website, MoaGam, and MoaByul. This single policy applies to all three services. Where a practice applies only to a particular service, we name that service so the policy remains accurate.
The Korean version is the governing text; English and Japanese versions are provided for convenience.
2. Information We Handle and Why
The Nakhoyi Studio website may handle the following information to deliver and protect the site.
- Website access data: IP address, approximate IP-based location, browser and device details, requested URL, access time, and security logs — to deliver the website, troubleshoot errors, prevent abuse, and maintain security
The website has no account system or contact form. Nakhoyi Studio does not add analytics, advertising trackers, or marketing cookies, and does not sell personal information.
MoaGam uses email one-time passcodes (OTP), Google, or Apple to sign users in and supports craft-studio records and workspace collaboration. It currently has no advertising, paid subscriptions, or in-app purchases.
- Account and authentication: an email address when provided, email OTP verification results, Google or Apple sign-in provider and provider user ID, internal user and session IDs, and authentication data needed to verify sign-in — to sign you in, identify and protect your account, and reauthenticate you
- Social sign-in data: authentication metadata supplied by the provider, such as a name or profile image — for authentication. This is separate from the nickname and avatar you set in MoaGam; a social name or photo is not automatically set as your team profile. Apple Hide My Email may supply a private relay address; when a provider response contains no email address, the provider user ID identifies the account
- Profile and workspace: the nickname and avatar or profile photo you set, workspace name, photo and base currency, ownership, membership, and invitation details — to display profiles, set the currency basis, share with the team, and manage workspace access
- Materials and products: photos, names, item numbers, notes, tags, suppliers, units, material prices and currencies, quantities, a product’s component materials and usage quantities, and calculated costs — to manage materials and products and calculate costs
- Shopping and purchase records: shopping items, quantities, purchase dates, purchase history, contributor information, and quantities added by each team member — for purchase planning, recordkeeping, and teamwork
- Social-disconnection data: authentication information needed to disconnect Google or Apple during account deletion — for disconnection according to the provider and authentication state. Where needed, it is processed encrypted on the server; this does not mean provider passwords are stored
- Authentication email: recipient address, authentication message content, and sending and delivery status — to send sign-in emails through Supabase Auth and Resend SMTP
MoaGam does not offer a separate password sign-in and does not receive your Google or Apple password. If the authentication provider supplies no email address, we use its user ID. We do not ask you to send passwords, OTPs, or authentication tokens in a support inquiry.
MoaGam uses the camera or photo picker to let you add profile, workspace, material, and product photos. Photos you select are uploaded for the relevant feature. Profile and workspace photos, and photos attached to shared items, may be visible to members of the same workspace according to their access and the feature used. Selecting a photo does not upload your entire photo library.
MoaGam’s try-it-out mode uses in-memory sample data separate from real accounts. Changes disappear when you leave the demo and are not saved as records in a real workspace. Viewing legal documents may still use a network connection.
MoaByul handles the following information so guardians and children can manage family missions and rewards together.
- Records of consent and verification for children’s information — to verify a legal guardian’s consent, manage consent history, and handle privacy-rights requests
- Guardian account: email address, email one-time password (OTP) verification result, Google or Apple sign-in provider and provider user ID, and internal user and session IDs — to sign guardians in, protect accounts, and verify deletion requests
- Family details: family name, selected icon, and guardian-to-family membership — to create a family space and manage access
- Child profile: nickname entered by a guardian, selected avatar, and optional elementary grade level — to identify a child within the family, tailor the display, and manage family activity
- Child-device connection: anonymous authentication ID, device model, operating system and version, connection and revocation times and status, and hashes and attempt records for one-time pairing codes — to connect a child device securely and show its status to guardians
- Missions: title, category, schedule, target child, completion requests, review results and messages, and bonus stars — to plan missions, confirm completion, and share family feedback
- Rewards and progress: reward name and star cost, redemption requests, review results and messages, star transactions, streaks, and activity history — to manage rewards and show progress
- Social sign-in data: authentication metadata such as name and profile image made available through the email and basic-profile permissions requested for Google sign-in, and tokens needed to verify sign-in — to identify and authenticate an account. Apple sign-in requests email permission; choosing Hide My Email may provide a relay address
- Social connection revocation data: credentials needed to revoke the connection, such as provider access or refresh tokens — stored encrypted on the server for revoking Google or Apple connections when deleting an account
- Push registration: app installation ID, FCM registration token, authenticated user and family or child-device association, operating system, app environment, and language — to select the receiving device and language and verify access
- Authentication emails: recipient email address, authentication or account-protection message content, and sending and delivery status — to send sign-in and account-protection emails through Supabase authentication and Resend SMTP
Nakhoyi Studio services may also handle the following information to operate securely. Service-specific items are labeled with the applicable service.
- Automatically generated app data: IP address, app version, device and operating system details, access time, authentication session, and security logs — to maintain sessions in both apps, troubleshoot errors, protect the service, and prevent abuse
- Email inquiries: email address, display name, subject, message, and files you attach — for support, general inquiries, and rights requests relating to the website and both apps. Inquiry drafts created by MoaGam include the app version and OS information; we receive these details when you send the email to contact@nakhoyi.com
- MoaGam app settings: language and preferences you choose — to retain your selected features and app preferences
MoaByul does not receive your Google or Apple account password. Basic Google profile information may be supplied during authentication; it is not automatically published as a family or child profile.
MoaByul — Push notifications use Firebase Cloud Messaging (FCM), with Apple Push Notification service (APNs) on iOS. Their payloads do not include family names, child names, mission titles, or the text of messages written by guardians. Firebase may process Firebase installation IDs and technical information such as IP addresses needed for delivery.
MoaByul’s demo uses sample family data in memory, separate from real accounts. Changes are lost when you reset it or restart the app. It does not send real authentication emails or push notifications, perform social sign-in, or delete server accounts, but may access the network to load legal documents and similar resources.
3. How We Collect Information
We collect personal information in the following ways.
- You or a guardian enter information when creating an account, verifying an email OTP, setting up a profile or workspace, adding photos or content, or sending an email inquiry
- In MoaByul, a guardian creates a child profile, generates a one-time code, and uses that code to connect the child’s device
- Vercel automatically handles limited access data needed to deliver and protect the website when you visit it
- Both apps and the Supabase SDK automatically generate or transmit authentication identifiers, technical data, and user data needed while you use the service
- Users of the website or either app send inquiry details and chosen attachments by email to contact@nakhoyi.com
- When a MoaGam user or MoaByul guardian chooses Google or Apple sign-in, the provider and Supabase exchange provider IDs, authentication data, and any email or profile details provided
- The MoaByul app, Firebase, and APNs handle installation or device identifiers and technical data for notification delivery, and the app sends push registration details to its server
- When MoaGam or MoaByul sends authentication email, Supabase passes the recipient address and message content to Resend SMTP and processes delivery status
4. Legal Bases
Depending on applicable law, we rely on the following legal bases.
- Information needed for app accounts and core features: entering into or performing a contract with you, or taking steps you request
- Email and feedback inquiries: requests connected with entering into or performing a contract are handled to take necessary contractual steps; other general inquiries and service-improvement feedback are handled only where our legitimate interest in responding and improving the service clearly outweighs your rights and the handling remains reasonably limited
- Optional information: your consent where required by applicable law
- Information that must be retained by law: compliance with legal obligations
- Limited security logs and fraud-prevention data: our legitimate interest in operating a safe service, where that interest clearly outweighs the impact on your rights
5. Retention and Deletion
We retain personal information for the periods below and delete it without undue delay when the period ends.
- Website access data: Nakhoyi Studio does not retain a separate analytics database or copy of website access logs. Vercel handles this data for the period required by its service settings and privacy practices
- MoaByul — Account, profile, and user content: until you delete the account or the relevant app service ends. Content you delete earlier is removed from the active service at that time
- MoaGam account and personal profile: retained until account deletion or service closure. Successful account deletion removes the personal profile and account access. Account deletion has several stages; a failed stage may require a retry or follow-up processing
- MoaGam materials, products, and workspaces: successful deletion removes the relevant service data from the operational database, without a separate 30-day deletion grace period. Photos are deleted from separate storage; failed file deletion may require follow-up cleanup, so record data and all photos are not necessarily deleted at the same time
- MoaGam retained shared records: workspaces whose ownership was transferred, or where you only participated as a member, and their shared records remain for other team members. Deleting a source material may leave the information previously recorded in shopping and purchase history. Internal IDs or historical information may remain in collaborative records after account deletion; this is not complete anonymization
- MoaGam social-disconnection credentials: used to disconnect Google or Apple according to the provider and authentication state, and processed encrypted on the server where needed. Provider conditions and credential states differ, so we do not guarantee a single disposal deadline for all credentials
- MoaGam internal processing records: some records of deletion status, duplicate-execution prevention, and deletion or recovery verification may remain separately from deleted service data. This does not mean a uniform automatic deletion period applies to them
- MoaGam logs and backups: deletion of operational app data is distinct from logs and backups separately managed by providers such as Supabase and Resend. Retention periods stated for other services are not blanket periods for all MoaGam logs and backups
- MoaByul child-device data: used for access while the connection is active. A guardian disconnecting a device only blocks that device’s access; it does not delete the child’s profile or activity or immediately delete the anonymous authentication account. Completing the leave-device process on the child device deletes that device’s authentication and connection data and anonymous authentication account
- MoaByul child profiles and related activity: retained until a guardian deletes that child’s data in the app, deletion following a separate deletion or consent-withdrawal request is completed, or the last guardian account is deleted. If the service closes, this data is handled under the service-closure process
- MoaByul legal-guardian consent and verification records: kept as needed to manage consent and handle privacy-rights requests, then deleted without undue delay when that purpose ends. Only a legal retention duty permits further retention, limited to the required purpose and period with restricted access
- Support inquiries: up to one year after our final response, or longer only where needed for a dispute or legal obligation
- Security and access logs: only for the minimum period needed to protect and troubleshoot the service, or for the period required by law or the relevant provider’s settings
- MoaByul guardian social-connection revocation credentials: stored encrypted on the server for as long as the account is maintained. When a guardian-account deletion job is accepted, credentials needed to revoke the connection are moved into that job and removed from their original store. The guardian-account deletion-job credential retention and destruction rules below then apply
- MoaByul guardian-account deletion-job records: limited records used to confirm completion and recover from errors become eligible for cleanup 30 days after completion. Encrypted credentials held for that job become eligible for destruction seven days after the initial guardian-account deletion request. Both periods apply only to guardian-account deletion jobs, not individual child-data deletion, ordinary account data, or credentials stored during normal sign-in
- Anonymous authentication accounts associated with MoaByul child-data deletion: deleting a child’s data immediately blocks access from that child’s devices. Related anonymous authentication accounts are deleted through a separate cleanup process, with retries on failure and without the 30-day grace period for ordinary unused accounts. Pending-cleanup records contain only the authentication account ID and request and retry times, and are removed when cleanup completes or is cancelled. If the account is actively connected to another child or converted to a permanent account before cleanup, it is retained and that cleanup is cancelled
- Ordinary disconnected or unused MoaByul anonymous authentication accounts: separate from child-data deletion cleanup, an account that was never connected becomes eligible for scheduled cleanup 30 days after creation; an account that was simply disconnected becomes eligible 30 days after disconnection. Accounts with an active connection are excluded. This cleanup does not delete child profiles or activity
- MoaByul push registrations and external-service records: signing out or disconnecting a device removes it from notification targeting and triggers token cleanup attempts. A failed network request may be retried on the next app launch or resume. Authentication and email-delivery records, Firebase installation IDs, and providers’ technical logs are handled separately under the relevant settings, purposes, and deletion procedures
For the website and MoaByul, electronic files under the studio’s control are permanently deleted using the relevant service’s deletion function when their purpose has ended. Data remaining in limited backups is removed on the scheduled rotation and is used only for recovery. MoaGam’s operational database, photos, internal records, and external-service logs and backups are handled as distinguished above and below.
Deleting the last MoaByul guardian account also deletes the family, child profiles, missions, stars, rewards, and activity data. If another guardian remains, the family data remains.
Completion of app-account deletion does not mean that every provider’s logs, backups, and installation identifiers have been erased at the same moment. Google or Apple connection revocation is also a separate process; a failure may require a retry or action in the provider’s account settings. Access to retained information is restricted to the purpose that requires retention.
MoaGam’s deletion targets and processing stages are distinct from MoaByul’s 30-day guardian deletion-job record and 7-day encrypted-credential rules. Supabase database backups do not include the contents of photo files stored in Storage; database backups and original photos are not the same deletion or recovery targets. The absence of an in-app undo feature also does not mean all external logs and backups have been erased immediately. Information subject to a legal retention duty is kept with restricted access only for the required purpose and period.
6. Sharing with Third Parties
We do not sell personal information or disclose it to third parties without prior consent unless required by applicable law. The external services below may process information on our instructions or collect it directly as independent providers of social sign-in.
In MoaGam, members of the same workspace can see nicknames, avatars, shared photos, materials, products, shopping items, purchase history, and quantities added, according to their access and the relevant feature. Sharing records with your team is explained separately from processing by external service providers or authentication providers. Records may remain available to other members after you transfer ownership or leave a workspace. Avoid adding unnecessary personal or sensitive information to shared records.
7. Processors and External Services
We use the following services only where needed to operate Nakhoyi Studio services. Each item states the service to which it applies.
- Vercel Inc. (privacy@vercel.com) — Nakhoyi Studio website: website hosting and security. Processes IP address, approximate IP-based location, browser and device details, requested URL, access time, and security logs
- Supabase Pte. Ltd. (privacy@supabase.io) — MoaGam and MoaByul: provides databases, authentication, real-time synchronization, and account deletion. Processes account, email OTP, social authentication, and security-log data for both apps; profile, workspace, shared-record, and photo-storage data for MoaGam; and family, child, and device-link data for MoaByul
- Cloudflare, Inc. (dpo@cloudflare.com) — email inquiries for the website and both apps: routes messages sent to contact@nakhoyi.com and screens for spam. Processes sender and recipient addresses, email headers, message, attachments, and delivery records
- Google LLC’s Gmail (privacy contact: Google Privacy Help Center below) — email inquiries for the website and both apps: provides the final inquiry mailbox. Processes email address, display name, headers, message, attachments, and delivery records
- Google LLC’s Google sign-in and Apple’s Sign in with Apple (privacy contacts: the providers’ privacy resources below) — MoaGam and MoaByul: social authentication for users or guardians and the applicable disconnection process. Processes provider IDs, authentication data, and any email or profile details supplied. Apple may provide a private relay email, or no email may be provided. Each provider’s own account operations follow its policy
- Google’s Firebase Cloud Messaging (privacy contact: Firebase privacy information below) — MoaByul: handles installation IDs, registration tokens, technical information, and notification payloads for delivery. This does not mean that Firebase Analytics or advertising tracking is used
- Apple’s APNs (privacy contact: Apple Privacy Policy below) — MoaByul on iOS: handles device push tokens, delivery-related technical information, and notification payloads
- Resend, operated by Plus Five Five, Inc. (support@resend.com) — MoaGam and MoaByul: sends Supabase authentication emails, processing recipient addresses, message content, and delivery status. This is separate from the Cloudflare and Gmail route used for inquiries to contact@nakhoyi.com
We review contracts and service settings so processors handle information only as needed for the stated purposes, and we update this policy when the service configuration changes.
Supabase also handles MoaByul social-authentication metadata, encrypted revocation credentials, push registrations, and deletion-job records. Processing on our behalf to deliver emails and notifications differs from Google’s and Apple’s operation of their own accounts and services; these roles are not all treated as the same kind of third-party disclosure.
Supabase also processes MoaGam’s authentication and workspace-permission data and information needed for account deletion and Google or Apple disconnection. Firebase and APNs push notifications, child-device linking, and family features apply only to MoaByul, not to MoaGam.
8. Processing Outside Korea
The Supabase project databases for MoaGam and MoaByul are hosted in the Seoul region of South Korea. Domestic database storage is separate from overseas access or processing for support, security, and similar operations; the Seoul region does not mean that all information is processed only in Korea. The following overseas providers may receive information over a network or access and process it abroad while providing the website, app features, and support; applicable services and data are distinguished below.
Supabase’s Data Processing Addendum distinguishes storage and primary processing in the selected region from exceptions needed for additional customer instructions, legal compliance, or services requested by the customer. The MoaGam database location and operational-data deletion described below do not give a complete account of the countries or retention periods for overseas support access, external logs, or backups.
- Vercel Inc. (privacy@vercel.com) — Countries: United States and countries where Vercel operates data-processing facilities. Data: website IP address, approximate IP-based location, browser and device details, requested URL, access time, and security logs. Timing and method: automatically handled over an encrypted network when you visit the website. Purpose: website hosting, security, and operational improvement. Retention: under Vercel’s service settings and Privacy Notice
- Supabase Pte. Ltd. (privacy@supabase.io) — MoaByul: Countries: United States and countries in which its published subprocessors operate. Data: the MoaByul Supabase data described in Section 7. Timing and method: encrypted network transfer during authentication, storage, synchronization, support, or security operations. Purpose: cloud application infrastructure and security. Retention: until account deletion, contract termination, or completion of the purpose, followed by Supabase’s deletion process
- Supabase Pte. Ltd. (privacy@supabase.io) — MoaGam: Database storage country: South Korea (Seoul). Data: account, email OTP, and social-authentication data; profile and workspace permissions; materials, products, shopping and purchase history, and photos; account-deletion and disconnection data; and technical and security logs. Timing and method: encrypted app-server communications during authentication, storage, synchronization, and deletion requests. Purpose: account authentication, storing shared records and photos, access control, deletion processing, and service security. Operational-data retention and deletion: accounts and personal profiles are kept until account deletion or service closure and removed from the operational database once deletion is successfully processed. Shared records and purchase history needed by other team members may remain separately from account deletion, and photos may be removed through follow-up storage cleanup. Internal processing records and external logs and backups are distinct categories; the deletion scope and procedures in Section 5 apply
- Cloudflare, Inc. (dpo@cloudflare.com) — Countries: United States, European Economic Area, and countries where Cloudflare operates data-processing facilities. Data: sender and recipient addresses, headers, message content, attachments, and delivery records. Timing and method: network transfer through Cloudflare Email Routing when you send an email. Purpose: routing to the Gmail mailbox and spam prevention. Retention: Email Routing does not store or access email content; delivery and security records are retained under Cloudflare’s policy
- Google LLC (privacy contact: Google Privacy Help Center below) — Countries: United States and countries where Google operates servers. Data: inquiry email address, display name, headers, message content, attachments, and delivery records. Timing and method: network transfer when Cloudflare forwards the email to the Gmail mailbox. Purpose: mail storage, responding to inquiries, maintaining and securing Gmail, and detecting spam and abuse. Retention: the studio deletes the message from Gmail no later than one year after the final response; Google’s Privacy Policy governs subsequent system deletion and limited retention
- Google sign-in and FCM — Countries: United States and countries where Google operates data-processing facilities. Data: provider IDs, authentication data, and any email and profile details supplied for MoaGam and MoaByul sign-in; push installation IDs, registration tokens, technical data, and notification content for MoaByul only. Timing and method: encrypted communications for social sign-in or disconnection, and for MoaByul SDK initialization, registration, and notification delivery. Purpose: authentication for both apps and notification delivery for MoaByul. Retention: Google’s authentication and Firebase retention and deletion processes; deleting a MoaByul FCM token does not immediately delete the Firebase installation ID
- Apple sign-in and APNs — Countries: United States and processing countries listed in Apple’s privacy resources. Data: provider IDs, authentication data, and any email address supplied, including a private relay address, for MoaGam and MoaByul; device push tokens, technical data, and notification content for MoaByul only. Timing and method: encrypted communications for social sign-in or disconnection and for MoaByul iOS notification registration and delivery. Purpose: authentication for both apps and notification delivery for MoaByul. Retention: as needed for the feature and security, followed by Apple’s retention and deletion processes. MoaGam’s server-side disconnection credentials are separate from the provider’s own records; no single disposal period applies to both
- Resend, operated by Plus Five Five, Inc. (support@resend.com) — Countries: United States for storing and managing data such as message content and delivery records; Japan for sending emails through the Tokyo region. Data: MoaGam and MoaByul authentication-email recipient address, content, and delivery records. Timing and method: sent from Supabase over SMTP when an authentication or account-protection email is requested. Purpose: delivering authentication emails and managing delivery records. The sending region differs from the data-storage country. Retention: email and log data is kept for 30 days under the default settings of the standard plan we use. This is not the retention period for app-account data or our support inbox; Resend backups and similar records follow that service’s separate retention and deletion procedures
Overseas processing needed for the website and core app features relies on processing and storage necessary to provide the service or perform the contract; we obtain separate consent where required. You can choose not to use the relevant website, authentication, or email-inquiry feature, or request that processing stop, but this may limit services or features that depend on it.
- Vercel Privacy Notice
- Supabase Privacy Policy
- Supabase Data Processing Addendum
- Supabase Subprocessor List
- Google Privacy Policy
- Google Privacy Help Center
- Cloudflare Privacy Policy
Social sign-in and MoaByul notification permissions are optional. However, denying notification permission in MoaByul does not guarantee that Firebase SDK initialization communications or installation-ID processing never occur. This Firebase explanation does not apply to MoaGam. To request that necessary overseas processing stop or that information be deleted, contact contact@nakhoyi.com; features that require the processing may become unavailable.
10. Children’s Information
MoaByul helps guardians manage family activities and connect a child’s device. A guardian enters the child’s nickname, avatar, and optional grade level and provides the pairing code directly. We recommend a nickname rather than a real name. Children are not asked to enter an email address or password.
Before collecting a child’s information, Nakhoyi Studio explains to the guardian what is collected, why it is used, how long it is kept, and how to request deletion or exercise privacy rights. Where applicable law requires a legal guardian’s consent, including for children under 14 under Korean law, we obtain consent and verify it before processing the information, and keep and manage records of consent and verification. Accepting the terms, signing in to a guardian account, passing a guardian screen, or using a child’s pairing code does not itself replace the legal guardian’s consent or its verification.
Age thresholds and consent requirements may differ by country; we check and apply the requirements of applicable law. Child profiles and activity are used only as needed for family features, not for personalized advertising. “Anonymous authentication” is a technical sign-in method without email; it does not mean that a linked child’s profile or activity is anonymized.
Guardians can review a child’s information and activity and manage device connections. A child’s ability to edit their own nickname and avatar is distinct from the guardian’s viewing and device-management functions. Guardians cannot currently freely edit every field in a child profile.
Guardians can delete a child’s profile and related records in “More → Our family → select the child → Delete child’s data,” without deleting their own account. If you cannot use the app, you can request deletion at contact@nakhoyi.com. You can also use that address to withdraw consent or exercise other privacy rights. See “MoaByul Account and Data Deletion” below for the scope of individual child-data deletion and the effect of deleting the last guardian account.
A legal guardian can request withdrawal of consent to the processing of a child’s information at contact@nakhoyi.com. Nakhoyi Studio uses the minimum information needed to verify their authority, stops consent-based processing and the affected child’s use of the relevant features, and deletes the related information without undue delay. Information we must retain by law is kept only for the required purpose and period, with restricted access. Disconnecting a device alone does not delete information or withdraw consent.
11. Your Rights
You may review and, where available, correct or delete account, profile, and content data in the app. To request access, correction, deletion, restriction, withdrawal of consent, or account deletion, use the app’s account menu or email contact@nakhoyi.com.
Before acting on a request, we may ask for the minimum information needed to confirm your identity or a representative’s authority. A legal guardian may exercise these rights for a child under 14.
Where the law applicable in your place of residence provides additional privacy rights, we will support the exercise of those rights in accordance with that law.
You may also raise a concern with Korea’s Personal Information Infringement Report Center (118) or Personal Information Dispute Mediation Committee (+82-1833-6972).
12. Security
We use administrative and technical safeguards designed to protect personal information.
- Email OTP, Google, and Apple authentication and reauthentication before account deletion in MoaGam; limited validity periods for email one-time codes and child-device connection codes in MoaByul
- Encryption in transit, least-privilege access based on MoaGam workspace roles and ownership or MoaByul family relationships, and database row-level access controls
- Account and device disconnection and deletion procedures, security-log review, and protection for external-service accounts
- Limited recovery backups for the website and MoaByul, and security features provided by each service provider
- Server-side encryption and restricted access for MoaByul social-revocation credentials, with separate destruction of credentials left in deletion jobs
13. Privacy Contact
Privacy contact: Nakho Lee, representative of Nakhoyi Studio · contact@nakhoyi.com. Please use this address for questions, complaints, or rights requests concerning personal information.
14. Changes and Effective Date
This revision is announced and takes effect on October 4, 2026. When information handling, providers, or features change, we update this single source and its web and app versions together. Changes that materially affect your rights are communicated before or when they take effect through an appropriate channel, such as the website, app, or email.
- September 12, 2026: the previous published version took effect. This revision does not retroactively change that version’s effective date or history.
- September 20, 2026 revision: clarifies MoaByul authentication, notifications and email, notices before collecting children’s information, consent and verification records, individual child-data deletion, withdrawal of consent, and retention rules.
- October 4, 2026 revision: updates the product name to MoaGam and corrects authentication, collected data, collaboration, and deletion descriptions to reflect current handling. Distinguishes operational data, photo storage, retained shared and internal records, and external logs and backups. It does not introduce new blanket retention periods or automatic deletion policies. Earlier published effective dates and history remain unchanged.
15. MoaByul Account and Data Deletion
Use the following options to delete an account or child data in MoaByul, operated by Nakhoyi Studio. Signing out or uninstalling the app does not delete an account.
- In the guardian view, open “More → Delete account” and review what will be deleted. Reauthenticate using a linked email, Google, or Apple sign-in method, then complete the final deletion confirmation.
- If you cannot use the app or do not want to reinstall it, email contact@nakhoyi.com with “MoaByul account deletion request.” Initially, provide only the account’s sign-in email and whether you want the entire account or a particular child’s data deleted. If you use Apple’s Hide My Email, you can provide that relay address.
- We request only the additional information needed to verify the account holder or authorized guardian and act without undue delay after verification. If further checks or recovery steps are needed, we reply with the reason and expected timetable and follow applicable legal deadlines.
- Do not email passwords, one-time verification codes, social sign-in tokens, or unnecessary sensitive information about a child.
- To delete only a particular child’s data, open “More → Our family → select the child → Delete child’s data.” You do not need to delete your guardian account. If you cannot use the app, you can send a request to contact@nakhoyi.com.
Deleting a child’s data removes that child’s profile, star history, mission-completion, praise, reward-request and activity records, and device connections. Missions and rewards assigned exclusively to that child are also deleted. For items shared by several children, only the selected child’s association is removed; other children’s records, guardian accounts, and family information remain. Deleted information cannot be restored in the app.
When a guardian account is deleted, family data remains if another guardian is still in the family. Deleting the last guardian account also deletes the family, child profiles, missions, stars, rewards, and activity.
Disconnecting a device only blocks that device’s access; it does not delete the child’s profile or activity. Its anonymous authentication account is not deleted immediately and instead follows the ordinary disconnected-account cleanup rule below. “Leave on this device” on the child device deletes that device’s authentication and connection data and anonymous authentication account, while retaining family data. These disconnection actions do not withdraw consent to the processing of the child’s information.
A legal guardian can keep their own account and email contact@nakhoyi.com to withdraw consent for a particular child’s information. After verifying their authority with the minimum information needed, we stop consent-based processing and the affected child’s use of the relevant features, and delete the related information without undue delay. Information subject to a legal retention duty is kept with restricted purposes, periods, and access as described in Section 5.
Deleting the app account does not delete your Google or Apple account. Revoking a social connection is separate from app-account deletion; if revocation fails, it may need to be retried or completed in the provider’s account settings.
Limited guardian-account deletion-job records become eligible for cleanup 30 days after completion, and that job’s encrypted credentials seven days after the initial guardian-account deletion request. These rules do not apply to individual child-data deletion and are not blanket retention periods for family data.
Deleting a child’s data immediately blocks device access. Related anonymous authentication accounts are deleted through a separate cleanup process, with retries on failure and without the 30-day grace period for ordinary unused accounts. Accounts that are simply disconnected or unused become eligible for scheduled cleanup 30 days after disconnection or creation; active connections are excluded. Section 5 explains pending-cleanup information and exceptions for accounts reconnected to another child or converted to permanent accounts.
Information subject to legal retention, limited security logs and backups, and providers’ records are handled separately for the purposes and under the procedures in Sections 5 and 8. Inquiry emails are retained for up to one year after our final response, subject to the legal-obligation and dispute exceptions in Section 5.
16. MoaGam account and data deletion
Deleting a MoaGam account is distinct from deleting shared workspace records. Signing out or uninstalling the app does not delete the account or records held on the server.
- Select “Delete account” in the Account section of the More screen. In the deletion screen, review how to handle workspaces you own and the impact of deletion. Transfer ownership to another current team member or explicitly select spaces to delete with the account, including spaces where you are the only member. An ownership transfer takes effect when completed and is not automatically reversed if account deletion is later cancelled.
- Reauthenticate using an email OTP or a linked social sign-in method, then confirm the final deletion.
- If you cannot use the app, email contact@nakhoyi.com with “MoaGam account deletion request.” Tell us your sign-in method, an account email you can identify, including an Apple private relay address if applicable, and what you want deleted. For accounts with no email supplied, we will explain the minimum information needed to verify ownership.
- Do not email passwords, OTPs, authentication or disconnection tokens, or unnecessary identity documents or sensitive information. We verify identity and authority using only necessary information, then process the request. If further checks are needed, we explain why and give an expected timeline.
Successful account deletion removes your personal profile and workspace access. Workspaces you transferred to another owner or only joined as a member, and their shared records, remain for other team members. Some internal IDs or historical information may remain in collaborative records; this is not complete anonymization. Workspaces explicitly selected for deletion include materials, products, photos, shopping records, and purchase history created by other team members in the deletion scope.
When a deletion request is successfully processed, the relevant data is deleted from the operational service database. Files such as photos in separate storage may be deleted through follow-up cleanup, and a failed file deletion may need additional processing. Deleting a source material alone does not remove the information already recorded in shopping and purchase history. Account deletion has several stages, and failed stages may need retries or follow-up processing. Internal records for deletion status, duplicate-execution prevention, and recovery verification may remain separately.
Where shared records are retained, leaving the service does not delete all of those records. To request access, correction, or deletion of your personal information within them, email contact@nakhoyi.com. We consider the rights of other members and applicable law when handling the request.
Deleting a MoaGam account does not delete your Google or Apple account. Google and Apple disconnection is handled separately according to the provider and authentication state. Where needed, the required credentials are processed encrypted on the server. If disconnection fails or the necessary credentials are unavailable, you may need to disconnect the app yourself in that provider’s account settings. This does not involve storing provider passwords or guarantee the same disposal deadline for every credential.
MoaGam internal processing records and external-service logs and backups are distinct from operational data deletion. MoaByul’s 30-day deletion-job record and 7-day credential rules are not blanket rules for MoaGam. Having no in-app feature to restore deleted records is different from immediately and completely erasing all records, photos, and backups across every system. See sections 5 and 8 for service-specific processing scope.