MogU Creator Portal
HomeTermsSupport
Legal

Privacy Policy

This policy explains what information the MogU: Glow Up app, former Android waitlist, public website, and Creator Portal collect, why we use it, and the choices available to app users, visitors, and creators.

Effective and last updated: September 9, 2026

1. Scope and operator

This Privacy Policy applies to the MogU: Glow Up mobile app (the “App”), the former Android launch waitlist, the public MogU website, the MogU Creator Portal, and the related MogU creator program (together, the “Services”). The Services are operated by Azim Qudrat. In this policy, “MogU,” “we,” “us,” and “our” refer to Azim Qudrat.

The App is the consumer product available through Apple’s App Store and Google Play. The Portal is intended for approved or prospective creators. Sections below identify practices that apply specifically to the App or the Creator Portal.

2. MogU app information

Account information

If you sign in with Apple or Google, we may receive an account identifier, email address, name or profile information that you authorize the provider to share, authentication tokens, and session information. Supabase provides App authentication. We do not receive your Apple or Google password.

Photos, face data, and AI results

When you choose to run an AI scan or request a Studio photo, the App processes a front selfie, side selfie, selected Studio source photo, and, when available, an optional previous front-selfie thumbnail. It may derive appearance scores, face-shape category, visual observations, comparison summaries, and generated styling photos. We refer to those images and visible facial attributes together as “face data.”

Face data is used only to provide the scan, comparison, progress, Vibe-ranking, and Studio features you request. MogU does not use it to identify or authenticate you, create a face-recognition profile or biometric identifier, infer ethnicity, or sell face data.

On Android, before the separate remote AI request, the App may use Google’s MediaPipe Face Landmarker on your device solely to draw the live camera guide and animated scan trace over your captured selfie. CameraX discards analyzed frames as they are processed. MogU does not retain or upload the live camera frames or landmark coordinates through this local feature, use them to identify or authenticate you, or create or retain a face-recognition profile or biometric template.

Google states that MediaPipe does not send the input image to Google for this on-device processing. MediaPipe Solution APIs may periodically contact Google for bug fixes, updated models, hardware compatibility, and performance or utilization metrics. Those metrics may include SDK usage, session and inference counts, hardware performance, the App identifier, general input characteristics, and host-system information, but not the input selfie itself.

Preferences and feature data

The App may process selected gender label, notification preference, image-processing consent, age, height, weight, routine and plan preferences, share-unlock progress, subscription status, scan-limit context, server-recorded Studio allowance dates, purchase-spend records, weekly-to-yearly upgrade-credit claims, and a local install identifier used to limit repeat referral redemptions.

The iOS onboarding quiz also collects a first name if entered, age, discovery source, self-selected area to improve, motivation, routine commitment, goal tier, and accountability response. Answers are saved locally on the device, and relevant preferences may be sent to Supabase and Google Gemini when you request a personalized plan.

Fuel body, meal, and nutrition data

If you use Fuel, the App may process or store your age, height, current weight, optional goal weight, selected goal, activity level, calculated calorie and macro targets, weigh-in dates and weights, meal descriptions, optional meal photos, meal times and categories, serving counts, food names, estimated or database-provided nutrition values, corrections submitted to an AI meal estimate, product barcodes, and typed food-search queries.

Your Fuel plan, weigh-ins, meal log, and downscaled meal photos are stored locally on your device. Meal photos are excluded from device backup. Meal entries older than the App’s local retention window are removed automatically, and deleting an individual meal removes its locally stored photo.

For an AI meal estimate or correction, the App authenticates your Supabase account and verifies the required access before sending the meal description, correction, prior estimate, or downscaled meal photo to Google Gemini. We do not intentionally store the submitted description, correction, prior estimate, or meal photo in our application database. To make retries idempotent and avoid using another request, the returned derived meal estimate may be cached in Supabase for up to 23 hours. It is unavailable after expiry and is removed by scheduled and request-triggered cleanup. Google may retain API prompts and responses for a limited safety and abuse-monitoring period under its applicable paid-service terms even when application-level request logging is disabled.

Active MogU Pro includes 20 successful AI meal requests per server day, resetting at midnight UTC. Photo estimates, typed descriptions, retries, and AI corrections use this allowance; manual nutrition edits, repeated saved meals, barcode lookups, and USDA food searches do not. The server records hashed account, access, and request buckets, the UTC usage date, counts, and short-lived idempotency state. It also applies separate account and network attempt ceilings for security and abuse prevention. A known failed or abandoned estimate reservation is returned automatically; an identical retry can reuse a completed cached result without another request.

Barcode lookup sends the scanned barcode directly to Open Food Facts and may retrieve a public product image. Typed food search sends the query and your authentication token to our Supabase function; Supabase authenticates the request, verifies the required access, and sends the query, but not your account details or token, to USDA FoodData Central. Search results are not stored by our backend. Open Food Facts, USDA, Supabase, and their infrastructure providers may process request metadata and logs under their own terms.

Purchase and subscription information

If you buy or restore a subscription through Apple’s App Store or Google Play, buy a store-billed consumable Early Scan Pass or Studio Photo Pass, or buy an Apple-billed 50 AI Meal Requests pack, the applicable platform store handles payment processing and RevenueCat verifies the purchase and entitlement.

An unused Early Scan Pass is recorded locally on the installation that receives it until the early scan completes or local App data is deleted. Consumables are not restored in the same way as subscriptions through StoreKit or Google Play. Studio Photo Pass availability and Studio generation allowances are enforced server-side for signed-in accounts. The backend compares verified RevenueCat purchase history with hashed, transaction-derived purchase and consumption keys and generation reservations stored in Supabase. This prevents the same pass from being used twice and lets MogU return a reservation after a known failed generation without storing raw platform-store transaction identifiers or Google Play purchase tokens in those ledgers. A hashed Studio Photo Pass consumption key may be retained after account deletion to prevent an already spent consumable from being replayed.

The 50 AI Meal Requests pack is available only while MogU Pro is active. It adds 50 non-expiring requests after the included daily allowance is exhausted and does not itself grant MogU Pro. The spendable balance remains recorded if Pro lapses and can be used after Pro is active again. The backend reconciles RevenueCat’s verified consumable history with hashed purchase, owner, request, refund, and spend records; the App cannot grant itself a balance. Known failed estimates return their reserved request, and identical retries do not spend twice. If Apple reports a refund, any unspent requests from that transaction become unavailable; a verified refund reversal restores the remaining balance. We do not store raw App Store transaction identifiers in the meal-request ledger. Hashed purchase, refund, and spend records may be retained after account deletion to preserve the balance history, process later refund events, and prevent replay.

When the App offers a bonus for a verified weekly-to-yearly subscription upgrade through Apple or Google Play, the backend uses RevenueCat transaction information to grant one server-metered Studio photo bonus to the signed-in account and one scan bonus to the installation that claimed the upgrade. Supabase stores the account identifier, hashes derived from the verified transaction and installation identifier, and related grant, reservation, and consumption records. The raw platform-store transaction identifier, Google Play purchase token, and raw local installation identifier are not stored in these upgrade-credit records. These bonuses are separate from, and do not postpone, the normal seven-day scan and Studio allowance schedules.

Where web checkout is available and you choose it, our authenticated Supabase endpoint creates a Stripe-hosted Checkout Session and RevenueCat synchronizes the resulting subscription entitlement. To associate and restore the purchase, the endpoint sends Stripe a RevenueCat App User ID (your provider email when available, otherwise your Supabase user identifier), your Supabase user identifier, and the selected plan as Checkout Session and Subscription metadata.

We and our subscription providers may also receive your billing email, subscription status, product and price identifiers, entitlement status, receipt or invoice validation data, transaction identifiers and dates, renewal or cancellation state, limited payment-method details such as brand and last four digits, and similar purchase information. Your full payment card details are entered in Stripe Checkout outside the App, and MogU does not receive or store them.

Analytics, attribution, usage, and diagnostics

The App may send explicit events for app opens, onboarding screens, paywall views, purchase attempts and outcomes, scans, results, shares, and other core interactions to AppsFlyer and PostHog. Purchase events may include a product or package identifier, attempt number, completed, cancelled, or failed outcome, elapsed duration, entitlement status, and generic error domain and numeric code. Analytics events do not include payment-card information, selfies, meal photos, typed meal, search, or correction text, height, weight, other Fuel body or nutrition values, scan scores, barcodes, food details, authentication tokens, raw error messages, purchase transaction identifiers, localized prices, or meal-request balances.

On iOS, onboarding completion events may include the entered age and selected discovery source, area to improve, motivation, commitment, goal tier, accountability response, and notification-permission result. AppsFlyer and PostHog receive these answers for first-party onboarding and audience analytics. These events do not include the first name or selected gender label; they record only whether those steps were answered or skipped. Analytics providers retain the responses under their configured terms and policies.

Analytics may also include app and device information, approximate location derived from IP address, an AppsFlyer identifier, a PostHog anonymous identifier before sign-in, and the Supabase account identifier after sign-in. These identifiers and events are used for first-party analytics, attribution, subscription performance, and technical diagnostics.

The current iOS App uses AppsFlyer’s Strict SDK package, does not access Apple’s advertising identifier, does not request App Tracking Transparency permission, and is not configured to track users across third-party apps or websites. On Android, MediaPipe may process the SDK engagement, utilization, performance, application, input-type, and system-environment metrics described above. PostHog automatic screen capture, element autocapture, lifecycle capture, session replay, surveys, and automatic crash or error capture are disabled.

Support and security information

If you use the App’s support or feature-request form, we may receive the request type, message, optional reply email, App version and build number, platform, and your Supabase user identifier when signed in. Our servers may also process IP address, hashed account or network quota buckets, request timestamps, generic failure categories, RPC names, HTTP status codes, and similar information for access control, abuse prevention, reliability, and security. To enforce scan, Studio, and AI meal-request limits, the server may also process hashed meal-request, consumable-purchase, purchase-owner, refund-event, and spend keys; UTC meal-usage dates and counts; and a completed derived meal response for up to 23 hours. These quota tables and the meal-credit ledger use hashed keys rather than raw IP addresses, purchase transaction identifiers, or submitted meal content.

3. MogU app AI processing and storage

The App sends resized selected selfies to MogU endpoints hosted through Supabase, which send them to Google Gemini for the requested AI analysis or styling. When you request a meal estimate, the endpoint sends only the meal content needed for that estimate, such as your description, correction context, or downscaled meal photo; it does not send your MogU account details to Gemini. Scan-analysis, Studio-render, plan-generation, and meal-estimation requests use Gemini’s store: false option. Service providers may still process request data and logs under their own terms and retention practices.

Full-size uploaded selfies and submitted meal content are not intentionally stored in MogU’s application database. To make retries safe and avoid duplicate paid AI processing or request use, a completed derived scan response, a completed generated Studio photo response, and a completed derived meal-estimate response may each be temporarily cached in Supabase for up to 23 hours. The caches do not contain uploaded selfies or submitted meal photos, descriptions, or corrections. Each cache is tied to the signed-in account and exact request, is not used for training or identification, is blocked after expiration, and is removed through scheduled and request-triggered cleanup or earlier account deletion.

The App stores scan history, a downscaled scan thumbnail, a downscaled selected Studio source photo, generated Studio photos, Fuel plans, weigh-ins, meal entries and downscaled meal photos, preferences, and consent choices locally on the device. This local content remains until you replace it, delete it, it ages out under the App’s local retention rules, you delete App data or the App, or you complete the in-app account deletion flow, subject to device and backup behavior. Meal photos are excluded from device backup. The Android App excludes its app-private files and preferences from Android cloud backup and device-to-device transfer.

4. How MogU uses App information

  • Provide AI scan analysis, Vibe rankings, Studio photos, progress comparisons, plans, and personalized App features.
  • Calculate Fuel targets, provide meal estimates and database nutrition results, and maintain the local meal and weight history you request.
  • Authenticate accounts, restore sessions, and synchronize subscription access.
  • Verify purchases and entitlements, measure subscription performance, and diagnose purchase failures.
  • Enforce scan, Studio, referral, and AI meal-request limits, prevent abuse, and secure the Services.
  • Measure onboarding and product funnels and improve reliability, performance, and user experience.
  • Respond to support and privacy requests and comply with legal obligations.

5. App service providers and disclosures

MogU uses service providers that may process App information under their own terms and privacy policies:

  • Apple, for App Store purchases, Sign in with Apple, device permissions, and platform services.
  • Google Play, for Android app distribution, purchases, subscription management, refunds, and platform services.
  • Supabase, for authentication, backend functions, quotas, share-unlock progress, and server infrastructure.
  • Google Sign-In, for optional Google account authentication.
  • Google Gemini, for requested AI image analysis, styling, plans, and meal estimates.
  • Google MediaPipe, for Android on-device facial-landmark processing and the SDK performance and utilization metrics described above.
  • Open Food Facts, for public barcode and packaged-food nutrition data.
  • USDA FoodData Central, for typed food search and public nutrition data.
  • RevenueCat, for subscription entitlement management, receipt validation, and synchronizing web purchases.
  • Stripe and Link, for hosted web checkout, payment processing, tax handling when Managed Payments applies, fraud prevention, receipts, transaction support, and web subscription management.
  • AppsFlyer, for attribution and reviewed product analytics.
  • PostHog, for first-party product analytics.

We may also disclose information when required by law, reasonably necessary to protect rights and safety or investigate abuse, or as part of a merger, financing, acquisition, reorganization, or sale of service assets subject to appropriate protections.

6. App retention, choices, and account deletion

Subscription and transaction records may be retained by Apple, Google Play, RevenueCat, Stripe, and MogU as reasonably needed for billing, accounting, fraud prevention, customer support, and legal compliance. In-app support requests may be retained as needed to handle the request, prevent abuse, and maintain appropriate records. Analytics providers retain data under their configured terms and policies.

Current scan history, Studio photos, plan answers, generated plans, Fuel plans, weigh-ins, meal logs, and meal photos are primarily stored locally on your device. A completed derived scan response, a completed generated Studio photo response, and a completed derived meal-estimate response may each be cached in Supabase for up to 23 hours solely to make retries idempotent and prevent duplicate paid AI processing or request use. Expired entries are blocked from use and removed by scheduled and request-triggered cleanup.

You can stop using scans or Fuel, change permissions or notification settings in iOS or Android, manage an Apple subscription in your Apple account, manage a Google Play subscription in Google Play, manage a web subscription through the applicable web billing link, and delete your MogU account from Settings → Account → Delete account. Account deletion removes the Supabase authentication account and clears local App data on that device, including Fuel data and locally held unused consumable passes. It does not cancel an Apple-, Google Play-, or web-managed subscription. Hashed server-side consumable purchase, refund, and spend records may remain so a store-billed purchase cannot be replayed and a remaining server-metered balance can be reconciled if the same verified purchase history is later associated with an active account.

If you cannot access the App, follow the request instructions on the Delete a MogU account page. That page also explains which information is deleted and which limited records may be retained.

Depending on where you live, you may also have rights to request access, correction, deletion, portability, restriction, or objection. Contact support@getmogu.app for help.

7. Creator Portal and website information

Information from Discord

When you sign in with Discord, we receive the Discord user ID, username, display name, and avatar that you authorize Discord to share. We do not request access to your private Discord messages.

Connected social-account information

When you connect or submit a TikTok or Instagram account, we may collect the platform, username, platform-specific account ID, profile image, public profile details, connection status, and verification information. Verification information may include a physical video you choose to record with a second device showing your username, on-screen audience analytics, and your hand navigating the relevant platform. Do not include private messages, passwords, access codes, or unrelated personal information in a verification recording. If you authorize an official platform connection, we also receive the permissions you granted and access credentials used to maintain that connection.

Content and performance information

We may collect identifiers and metadata for submitted posts, including captions, links, publication dates, thumbnails, and public or authorized performance metrics such as views, likes, comments, shares, reach, and watch-time information. Instagram audience insights are available only for eligible Professional accounts. TikTok and Instagram audience-demographic eligibility may be reviewed manually using information you choose to provide.

Payment and program information

We collect the stablecoin asset, blockchain network, and wallet address, Revolut Revtag, or Cash App $Cashtag you provide for creator payouts. We also maintain BASIC eligibility, approval, campaign, payment-status, and fraud-review records.

Android waitlist information

The Android waitlist is closed now that MogU is available on Google Play. If you previously joined, we collected the email address you submitted. We use any retained waitlist email only for the Android availability and closely related launch updates you requested. Supabase stores the address in MogU’s private database. We do not send the address to PostHog or connect it to a creator profile.

Technical information

Our hosting and service providers may process IP address, browser and device information, request timestamps, security events, and similar logs. The Portal also uses a necessary session cookie and may store interface preferences in your browser.

If you visit an unadvertised MogU referral link, we may set a signed, HttpOnly first-party attribution cookie containing the private link identifier and a random visit identifier for up to 30 days. Supabase stores limited counts for referral landings and selected App Store, Creator Portal, and Discord link clicks. A referral link may then redirect to a MogU page or a disclosed third-party channel such as YouTube, which processes the destination visit under its own privacy terms. The attribution tables do not intentionally store an IP address or user-agent string. If you first create a Creator Portal profile during that period, we may associate the referral with your Discord identifier to measure that campaign’s conversion. Referral metrics are restricted to authorized MogU staff and are not displayed in the creator-facing Portal. We do not set the attribution cookie or record these events when a supported Do Not Track or Global Privacy Control signal is enabled.

The public MogU landing page uses PostHog product analytics to count page visits and selected interactions, including the App Store, Google Play, creator program, Discord, and Creator Portal calls to action. We send only those explicitly configured interaction events and related technical context; we do not connect them to a creator profile. The analytics identifier is stored only in browser memory for the current page load, not in a cookie or local storage. We disable automatic interaction capture, session replay, heatmaps, automatic error and performance capture, surveys, and feature-flag requests, and we honor supported browser Do Not Track signals.

8. How we use website and Creator Portal information

  • Complete the Android launch communications previously requested by waitlist members.
  • Measure visits and conversion from limited private referral campaigns.
  • Authenticate creators and secure the Portal.
  • Verify that a creator controls a submitted social account.
  • Import eligible posts and synchronize authorized performance metrics.
  • Review audience eligibility, assign BASIC program status, and administer campaigns.
  • Calculate, review, and deliver creator earnings and leaderboard awards.
  • Detect duplicate accounts, manipulated engagement, fraud, abuse, or violations of program rules.
  • Provide support, communicate operational notices, and improve the Portal.
  • Comply with legal, accounting, tax, security, and platform obligations.

Where applicable law requires a legal basis, we process information to perform our creator-program agreement, with your consent, to comply with law, and for legitimate interests such as security, payment administration, and program integrity.

9. How we share website and Creator Portal information

We do not sell waitlist or creator personal information. We may share or disclose information in the following circumstances:

  • Infrastructure providers. Cloudflare hosts the website and Portal, processes referral-link requests, stores new audience-verification originals in private R2 object storage, and prepares private playback copies through Cloudflare Stream. Supabase stores Android waitlist addresses and restricted referral-attribution records, provides the program database, and temporarily continues to store legacy verification originals submitted before the R2 transition.
  • Analytics provider. PostHog processes the limited landing-page event and technical information described above so we can measure visits and selected call-to-action conversion. PostHog does not receive Android waitlist email addresses.
  • Connected platforms and destinations. Discord, TikTok, Instagram, YouTube, and their affiliates process information when you use their login, API, or destination services under their own policies.
  • Program operations. Authorized MogU team members may review account, content, demographic, earnings, and payout information. Operational notices may be sent to restricted MogU Discord channels.
  • Payment providers. Information needed to complete a payout may be provided to the selected financial or payment service.
  • Legal and safety. We may disclose information when reasonably necessary to comply with law, enforce program rules, protect rights and safety, or investigate fraud or abuse.
  • Business changes. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of program assets, subject to appropriate protections.

10. Social-platform authorization

Official TikTok and Instagram connections require your express authorization. We request only the permissions shown during the platform authorization flow. Access and refresh credentials are intended to be stored server-side and used only for the connected creator-program features.

You can revoke a platform authorization through the relevant platform and can remove a connected account through the Portal. Revocation stops future authorized synchronization. We may retain previously collected campaign and payment records when needed for accounting, disputes, fraud prevention, or legal compliance.

11. Website and Creator Portal retention

We retain an Android waitlist email while the waitlist and requested launch communications are active. We delete or de-identify it when it is no longer reasonably needed for that purpose, or earlier if you ask us to remove it.

A referral-attribution cookie expires after 30 days. We retain the limited server-side referral counters and any new-creator attribution while reasonably needed to evaluate and administer the applicable campaign, resolve attribution disputes, and prevent duplicate conversion credit, after which we delete or de-identify them.

We retain profile and connection information while your Portal account or creator relationship remains active. Platform credentials are retained until you disconnect, revoke access, the credentials expire, or they are no longer needed. Submission, approval, metric, payment, fraud-prevention, and transaction records may be retained for the period reasonably necessary to administer campaigns, resolve disputes, and meet legal, tax, and accounting obligations.

Audience-verification recordings are kept in private storage while a review is pending. After a final BASIC or rejected decision, MogU schedules the submitted original and its playback copy for deletion after 30 days. A replaced recording or removed connected account may be scheduled for deletion sooner. MogU may retain an original longer when an authorized legal, dispute, or fraud hold is recorded before deletion begins. Provider processing may not be immediate, so MogU keeps private, provider-aware deletion records and retries removal until the relevant storage service confirms it.

New originals are stored in private Cloudflare R2 object storage. Originals submitted before the storage transition may remain in private Supabase Storage under the same review and retention rules until they are deleted. MogU asks Cloudflare Stream to create a private, playback-optimized copy for authorized review and gives Stream an encrypted, one-hour MogU source link rather than an object-store key or credential. Authorized administrators may also receive an encrypted five-minute link to the original. The Stream copy has its own upload-based expiration and may be deleted sooner without affecting the private original or the review; replacement or account removal may also trigger earlier deletion. MogU retains a limited Stream-attempt audit for up to seven days to prevent upload abuse and control processing costs.

A resumable recording-upload session remains active for up to 24 hours after its most recently accepted part. If a session is abandoned, MogU attempts to abort it, and Cloudflare R2’s default lifecycle rule separately aborts incomplete multipart uploads after seven days. Incomplete parts remain private and are not treated as a submitted verification recording.

Deletion from active systems may not immediately remove information from security backups. Backups are isolated and removed according to normal retention cycles.

12. Website and creator choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or information about our processing, and to withdraw consent where processing is based on consent.

You may remove individual social accounts and payout methods from Settings. You can ask us to remove a waitlist email by contacting support@getmogu.app from that address. To request deletion of the entire creator profile or exercise another privacy right, follow the instructions on our Support and data requests page. We may verify your request through the email or Discord identity associated with the relevant information.

13. Security and international processing

We use reasonable administrative and technical measures designed to protect creator information, including authenticated server-side access and restricted database permissions. No online service can guarantee absolute security.

Our providers and team members may process information in countries other than your own. Where required, we use appropriate protections for international transfers.

14. Children and younger creators

The App, website, waitlist, and Portal are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Creators must also meet the minimum-age requirements of every social platform they connect.

If you are under the age of legal majority where you live, you may participate only with the permission and supervision of a parent or legal guardian and with any consent required by applicable law. A parent or guardian may contact us to review or request deletion of a younger creator’s information.

15. Changes and contact

We may update this policy as the App, website, Portal, platform requirements, or applicable laws change. We will post the updated date and provide additional notice when a material change requires it.

Questions or privacy requests for the MogU Services can be emailed to support@getmogu.app. Creators may also use the official MogU creator-program Discord support channel. Additional instructions are available on the Support page.

© 2026 MogU
PrivacyTermsSupportDelete account