Privacy policy
Version 2026-10-04
This page says what the mokkan service stores about you, why, who else receives it, how long it is kept, and how to delete it.
Who
mokkan is a personal project run by Victor Benetatos, Greece, who is responsible for the data described here (the data controller).
Contact: info@mokkan.dev.
What we store and why
The mokkan server stores the following, so that your list syncs between sessions and due reminders reach you.
- Account. Your email address, a hash of your password, when the account was created, and which version of this policy you accepted and when.
- Reminders and todos. Their text, their due times and their history: when each was added, shown, acknowledged, done and emailed. Also which client added it.
- Sessions. Login tokens, each with a device label taken from the client’s User-Agent. Refresh tokens last 90 days and are deleted a day after they expire.
- Heartbeats. When a session last checked in, and from which client. They decide whether a due reminder is emailed to you.
- Billing. Your credit balance, the ledger of credits added and spent, your edit count, your Stripe customer id, and your purchases (Stripe ids, amount, currency). Card details never reach mokkan.
- Feedback. What you send with
mokkan feedbackis stored, and emailed to the developer with your email address. - IP addresses. In rate-limit records, which are deleted about a day later, and in logs (see How long). They are used to prevent abuse and to operate the service.
Legal basis
- Performing the service you signed up for: your account, your reminders, billing.
- Legitimate interest: security, abuse prevention, logs.
- Legal obligation: keeping payment records.
This policy tells you what happens to your data. It is not a request for your consent.
Who else receives data
- Hosting. The server and its database run in Germany (EU).
- Stripe. Stripe receives your email address and account id when you first buy credits, and your account id with each purchase. Stripe keeps its own records under its own privacy policy, independently of mokkan, and may process data outside the EU under standard contractual clauses.
- Zoho Mail. Zoho Mail sends the one-time codes, due reminders (with their text), low-credit notices and feedback. Sent mail may be kept in the mokkan mailbox [FILL IN: whether “save sent copies” is off for the sending account].
Nothing is sold. There are no ads, analytics or trackers.
On your machine
~/.config/mokkan/ holds credentials.json (your login tokens) and hook.log. The Claude Code pane keeps a copy of your last list in Claude Code’s plugin storage.
mokkan logout, or deleting the directory, removes the login.
How long
- Account data: until you delete the account.
- Login tokens and one-time codes: deleted a day after they expire.
- Server and proxy logs, which contain IP addresses: up to 14 days.
- Database backups: the last 10 daily backups are kept, so deleted data leaves them within about 10 days.
- Payment records: kept after you delete your account, without any link to you, for accounting and tax.
- Feedback emails in the developer’s mailbox, and Stripe’s own records, are not removed when you delete your account. To have the feedback emails deleted, ask by email.
Your rights
- Access to the data held about you.
- Correction of data that is wrong.
- Deletion: run
mokkan delete-accountin a terminal, or email info@mokkan.dev. - Portability:
mokkan list --jsonexports your list, or ask. - Objection to how your data is processed.
- Complaint to a data protection authority, such as the Hellenic Data Protection Authority.
For any of these, email info@mokkan.dev.
Deleting your account
Run mokkan delete-account in a terminal (or npx @vicmpen/mokkan-cli delete-account if mokkan isn’t installed). It shows what will be deleted, then asks for your password and for the word delete typed out. It does not run in the Claude Code pane or through /mokkan.
- It removes your account, login tokens, reminders and todos, feedback and credit ledger, and the one-time codes, queued emails and rate-limit records for your email address. On your machine it removes
credentials.jsonandhook.log. - Payment records are kept, without any link to you.
- Unspent credits are lost.
- A reminder email that is already being sent may still arrive.
Changes
A new version of this policy gets a new date. The clients announce it and ask you to accept it before they continue. Until you do, reminders you already have are still delivered.
Contact
Victor Benetatos, info@mokkan.dev.