Moka Solutions / legal support@mokasolutions.dev

Legal / Privacy

Privacy Policy

What personal data we process across the apps, websites and services of the Moka Solutions brand — why, on what legal basis, for how long, who else sees it, and how to exercise your rights.

Version 1.0 · Effective 29 September 2026

In short. Our apps work on your device and have no telemetry, analytics or tracking. Your files, searches and usage never reach us. Our servers only see what is needed to deliver updates, run trials, sell and activate licences, send the newsletter you asked for, and answer your emails. We never sell data and never use it for advertising.

This policy is the information notice required by articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR") and by the Italian Personal Data Protection Code (Legislative Decree no. 196/2003). It applies to all apps, websites and online services we publish under the Moka Solutions brand. Each app also has a short page listing exactly what it keeps on your device and what it sends (for Espresso: Privacy details).

1. Who is responsible for your data

Moka Solutions is only a brand, not a company or legal entity, so it cannot be a data controller. The controllers are the two self-employed individuals who publish under it. Because we decide together why and how personal data is processed, we are joint controllers under art. 26 GDPR:

VAT holder 1

Full name[Person 1: full name]
StatusSelf-employed individual with an Italian VAT number
Registered address[Person 1: registered address]
VAT number (Partita IVA)[Person 1: VAT number]
Tax code (Codice fiscale)[Person 1: tax code]
REA number[Person 1: REA number or 'Not applicable']
Certified email (PEC)[Person 1: PEC address]
Tax regimeFlat-rate scheme (regime forfettario, Law no. 190/2014, art. 1, paragraphs 54–89)

VAT holder 2

Full name[Person 2: full name]
StatusSelf-employed individual with an Italian VAT number
Registered address[Person 2: registered address]
VAT number (Partita IVA)[Person 2: VAT number]
Tax code (Codice fiscale)[Person 2: tax code]
REA number[Person 2: REA number or 'Not applicable']
Certified email (PEC)[Person 2: PEC address]
Tax regimeFlat-rate scheme (regime forfettario, Law no. 190/2014, art. 1, paragraphs 54–89)

Single contact point: support@mokasolutions.dev (for formal requests you can also use the PEC address of either of us).

The essence of our joint-controller arrangement

We have agreed in writing that:

  • we share the same purposes and use the same systems and providers, described in this policy;
  • either of us may receive and handle your requests on behalf of both, through the contact point above, and we coordinate so that you get one answer;
  • each of us is responsible for the security of the devices and accounts they use for our work, and both of us for choosing and instructing our service providers;
  • you may exercise your rights against each of us, whatever our internal arrangement says (art. 26(3) GDPR).

We have not appointed a Data Protection Officer, as the GDPR does not require one for our activities.

2. Principles we follow

  • On-device first. Our apps process your content on your device. We build them so that it never needs to leave it.
  • No tracking. No analytics, advertising identifiers, fingerprinting, tracking pixels or third-party SDKs that report on you, in our apps or on our websites. For emails, see 3.5.
  • Minimum data. We collect only what each purpose below needs, and delete it when it is no longer needed.
  • No selling, no profiling. We never sell or rent personal data, and never use it to build profiles or for automated decisions about you.

3.1 Visiting our websites

Our websites (mokasolutions.dev, the websites of our products and their documentation) are static pages. They use no cookies, no analytics and no third-party fonts or embeds.

  • Data: the technical data every web request contains — IP address, date and time, requested page, browser and operating system (user agent), referrer.
  • Why: to deliver the pages and protect them from attacks and abuse.
  • Who: our hosting provider Cloudflare processes it on our behalf; we do not keep access logs of our own. The documentation mirror on GitHub Pages is hosted by GitHub.
  • Legal basis: our legitimate interest in running secure websites (art. 6(1)(f) GDPR).

3.2 Contacting us

  • Data: your email address, name if you give it, the content of your message and anything you attach, plus any licence key or order number you share.
  • Why: to answer you, provide support, handle refunds and requests.
  • Legal basis: performing a contract or steps you asked for before one (art. 6(1)(b)); for general enquiries, our legitimate interest in answering (art. 6(1)(f)).
  • Retention: up to 24 months after the conversation ends, then deleted, unless it is needed to handle a dispute.

Please don't send us personal data of others, or sensitive data, unless needed. If you send a file for troubleshooting, we delete it once the issue is solved.

3.3 Checking for and downloading updates

Our apps check for updates by downloading a small file from our update server (for Espresso, once a day by default; you can turn it off in Settings).

  • Data: IP address, app name and version, operating system version (in the user agent of the request), time.
  • Why: to offer updates, including security fixes.
  • Legal basis: our legitimate interest, and our legal duty towards consumers, to keep the apps up to date and secure (art. 6(1)(f) and (c)).
  • Retention: we don't store these requests; the hosting provider processes them transiently.

3.4 Free trials

When you ask for a trial in an app:

  • Data: email address, trial code, an anonymous device identifier, the language of the app, start and end dates.
  • Why: to email you the code and a reminder before it ends, and to allow one trial per person and per device.
  • Legal basis: providing the trial you asked for (art. 6(1)(b)); preventing repeated trials is our legitimate interest (art. 6(1)(f)).
  • Retention: 24 months after the trial ends, then deleted.
  • Required? Yes: without an email address we can't send you the code.

The anonymous device identifier is a one-way cryptographic hash of your device's hardware identifier. It lets us recognise the same device again without learning or storing the hardware identifier itself.

3.5 Newsletter (optional)

  • Data: email address, language, date and time of consent.
  • Why: to send occasional news about our apps — only if you ticked the separate newsletter box.
  • Legal basis: your consent (art. 6(1)(a)), which you can withdraw at any time with the unsubscribe link in every email or by writing to us, without affecting the lawfulness of earlier sending.
  • Retention: until you unsubscribe. We then keep only a record of the unsubscription, so that we never write to you again by mistake.

About email statistics. Our email provider, Brevo, records whether each email (newsletter or service email, such as a trial code) was delivered and, as a standard feature it does not let us switch off, whether it was opened or a link was clicked. We use Brevo's anonymised tracking where available, look at these figures only in aggregate (for example, to check that trial emails arrive), and never use them to profile you. You can block them entirely by turning off remote images in your mail app — Apple Mail's Mail Privacy Protection does this automatically.

3.6 Buying a licence

Purchases are handled by our reseller Creem (Armitage Labs OÜ, Estonia), which acts as merchant of record and is an independent controller of the data you enter at checkout (name, email, billing address, country, VAT number, payment details). Its privacy policy is shown at checkout. Payment details never reach us.

From Creem we receive and store:

  • Data: email address, order and customer references, the product, the licence key, the purchase date and status (for example refunded).
  • Why: to deliver and manage your licence, let you open your customer page from the app, handle refunds and support, and meet our accounting duties.
  • Legal basis: performing the licence contract (art. 6(1)(b)); tax and accounting obligations (art. 6(1)(c)).
  • Retention: for as long as the licence exists, so that we can recover and verify it for you, and then for 10 years for accounting records (art. 2220 of the Italian Civil Code). You may ask us to delete your licence records earlier, except for data we must keep by law; the licence then stops working, as we can no longer verify it.

If you buy one of our apps on an app store, the store (for example Apple) is the controller of the purchase and we only receive anonymous sales reports.

3.7 Activating and checking licences

When you activate a licence or trial code, deactivate a device, open your customer page, or when an app renews its licence (for Espresso, about once a month):

  • Data: the licence key or trial code, the anonymous device identifier, the name of the device as you set it (for example "Anna's MacBook Pro", so you can recognise your devices in the list of activations), the date of activation, and the signed licence token.
  • Why: to activate the licence, apply the device limit, let you move it to another device, and stop refunded, disputed or published keys.
  • Legal basis: performing the licence contract (art. 6(1)(b)); preventing fraud (legitimate interest, art. 6(1)(f)).
  • Retention: each activation until you deactivate that device, or until the licence records are deleted (3.6). For trials, as in 3.4.

For Pro licences, the key and activation are also registered with Creem, which provides the licence key system.

3.8 Protection from abuse

Our licence servers limit how many requests can come from the same connection (for example, a few trial requests per hour).

  • Data: a one-way hash of your IP address, used as the key of a request counter, and the time the counting window started.
  • Why: to stop automated abuse and keep the service available for everyone.
  • Legal basis: legitimate interest in the security of our services (art. 6(1)(f)).
  • Retention: the counter is valid for one hour and is not linked to your email, licence or device. We don't store IP addresses in any other form.

We may process the data above when needed to comply with a legal obligation (for example, a lawful request from an authority) or to establish, exercise or defend legal claims (art. 6(1)(c) and (f)), and only for as long as that requires.

4. What stays on your device

Our apps store your content and their working data — for example Espresso's index of your disks — only on your device. We have no access to it, and it is not covered by the retention periods above: you control it, and uninstalling the app (and deleting its folder) removes it. Each app's privacy page explains where the data is and how to remove it.

5. Integrations you choose

Some apps let you connect other software, such as AI assistants (through the Model Context Protocol), launchers (Raycast, Alfred) or scripts. When you set one up, it receives what it requests (for example the names and paths of files matching a search) and handles that data under its own privacy policy; cloud-based assistants may send it to their provider. We receive none of it. Connections are always off until you enable them.

6. Who receives your data

We share personal data only with:

  • service providers that process it on our behalf under a data processing agreement (art. 28 GDPR), bound to confidentiality and security — hosting, database, email sending. The full list, with their locations, is on the Service providers page;
  • Creem, as independent controller for purchases (see 3.6);
  • our tax adviser (accountant), for accounting and tax obligations;
  • authorities, only when the law requires it.

Nobody else. We don't sell, rent or share personal data for advertising.

7. Transfers outside the European Economic Area

Most of our providers are in the EU. Cloudflare (hosting) and GitHub (documentation mirror, downloads) are based in the United States and may process data there or in other countries. These transfers are protected by the EU–US Data Privacy Framework (both companies are certified) and by the European Commission's Standard Contractual Clauses (art. 46 GDPR). You can ask us for a copy of the relevant safeguards.

8. Security

We use encrypted connections (HTTPS) for all our services, keep only minimal data, protect our accounts with strong authentication, sign licences cryptographically, and limit access to the two of us. If a personal data breach occurs that is likely to put your rights at risk, we will notify the Italian Data Protection Authority and, where required, you, as the GDPR prescribes.

9. Your rights

You have the right to:

  • access your data and receive a copy (art. 15);
  • rectify inaccurate data (art. 16);
  • erase your data (art. 17);
  • restrict processing (art. 18);
  • data portability, for data you gave us under a contract or consent (art. 20);
  • object at any time to processing based on our legitimate interest (art. 21);
  • withdraw consent at any time, without affecting earlier processing (art. 7(3)).

Write to support@mokasolutions.dev, ideally from the address the data refers to. It's free. We reply within one month (extendable by two further months for complex requests, in which case we tell you). We may ask you to confirm your identity — for example by writing from the email address linked to a licence — only when needed to protect your data.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. In Italy: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — garanteprivacy.it.

10. Automated decisions

We make no decisions based solely on automated processing that produce legal or similarly significant effects on you (art. 22 GDPR). Our licence servers automatically check simple rules — for example whether a key is valid or has reached its device limit — and you can always write to us to have a person look at your case.

11. Children

Our services are not directed at children under 14, the age of digital consent in Italy (art. 2-quinquies of the Italian Personal Data Protection Code). If you believe a child under 14 has given us personal data, write to us and we will delete it.

12. Changes to this policy

We will update this policy whenever our apps or services change the way they process data — before the change takes effect. The version and effective date are at the top of this page. If a change is significant, we will also tell you in the app or by email. We keep previous versions and send them on request.