Privacy Policy
Version: 12.04.2026
This Privacy Notice explains how Mojo Innovation AG ("Mojo", "we", "us") processes personal data when you use evooia (the "Service"), including our website, web app, and mobile app.
Your Privacy, Our Priority
We are committed to protecting your personal data and respecting your privacy, whether you use evooia as an Individual (for example, as a client or patient) or as a Professional (for example, a clinic, practitioner, or other specialist) (collectively, "User"). This Privacy Policy outlines how we collect, use, disclose, and protect your information when you use the evooia mobile app and its related services (together, the "Service"). Please review this policy carefully to understand how we handle your personal data.
Data Controller & Processor
- Professionals (Data Controller): If you use the Service in connection with a Professional (e.g., a clinic/practitioner), that Professional is the Data Controller for any client/patient data (including health-related data) that is generated, uploaded, or shared through the Service. The Professional determines the purposes and means of processing in accordance with applicable laws.
- Individuals (standalone use): If you use the Service on your own (for example, by downloading the app and creating an account directly), Mojo Innovation AG acts as Data Controller for the personal data processed to provide and operate the Service for you (as described in this Privacy Policy).
- Individuals (used with a Professional): If you use the Service in connection with a Professional (for example, you are invited, linked, or otherwise associated with a Professional's account/workspace), the Professional is typically the Data Controller for personal data processed in that context, and Mojo Innovation AG acts as Data Processor on the Professional's behalf.
- Company (Processor / Provider): evooia (a product by Mojo Innovation AG, incorporated in Zurich, Switzerland) acts as Data Processor where it processes personal data on behalf of Professionals, and ensures appropriate technical and organizational safeguards.
1. Scope of This Privacy Policy
This Privacy Policy applies to information that we collect from Users (Individuals and Professionals) when they use the evooia mobile app and the related services required to operate it.
2. Data Collection and Use
What Data Do We Collect?
Registration Information: We collect User name and email address to set up and manage User account, authenticate a User, and provide customer support.
Legal basis: performance of contract and our legitimate interest in account security.
Images and Associated Metadata: Individuals may capture "before/after" images and related metadata in the app. By default, these images are securely stored both on the Individual's device and in our encrypted cloud storage. This allows Individuals to access their images across devices and ensures secure backup.
Because before-and-after documentation and communication are core features of evooia, images you capture are shared by default with the Professional connected to your account, where such a relationship exists. You can switch off sharing of new images and content for the future in the app at any time.
Uses of your images that go beyond your own documentation always require your separate explicit consent, which can be withdrawn at any time:
- Individuals may authorize a Professional to use selected images for educational purposes (e.g., explaining treatments to other Individuals).
- Individuals using the Service on a standalone basis (without a linked Professional) may authorize the Company to use selected images to demonstrate the Service.
Technical data extracted from images: The app also reads technical data from images (such as coordinates of points on the face) so that follow-up photos can be framed and displayed next to earlier photos. This data is stored alongside your images and follows the same rules for sharing and consent. These reference points are detected on your device. They are never used for facial recognition or to identify you, and no face template, faceprint or other biometric identifier is created. The coordinates are kept only for as long as the corresponding image is kept, and are deleted together with it. If you enable Face ID to unlock the app, Apple handles the authentication entirely; evooia never receives or stores your Face ID data.
How your images may be used: Your images are stored so that you and your Professional have a visual record of your appointments. With your separate explicit consent, collected at the time of your appointment, images may also be used for:
- Educational purposes (shown to other patients, with or without de-identification)
- External purposes (marketing, publications, research, outside the clinic)
Each of these is optional, requires your explicit consent, and can be withdrawn at any time by contacting your clinic or info@evooia.com.
Technical measurements derived from your photos, such as landmark coordinates and how accurately two photos line up, may also be used to improve our alignment technology. The photos themselves are not used for this, and these measurements do not identify you. You may object at any time by contacting info@evooia.com and your data will be excluded from future use.
De-identification through masking: the mobile app may allow Individuals and practitioners to apply masking to selected facial regions directly on the device in order to create a de-identified version of an image for preview or export. This masking is performed locally on the device.
Ratings and Feedback: We may ask the Individual to rate the app or care experience. If the Individual opts in, we may publish the Individual's feedback (e.g. testimonials); otherwise it remains private between the Individual and respective Professional (if applicable).
Legal basis: consent and legitimate interest.
Messaging Data: When Individuals use our secure in-app chat, we collect the content of messages (text, images, attachments), timestamps, and sender/recipient identifiers. Where chat is used in connection with a Professional, this is processed on behalf of that Professional to facilitate communication and record-keeping.
Legal basis: performance of contract and compliance with applicable data protection requirements.
Product Analytics (PostHog): We collect usage and event data (e.g., feature usage, screen events, device/app technical signals) to improve the Service, understand usage, fix issues, and improve stability.
This data cannot be traced back to you — not even by us. It is sent under a random identifier created on your device, and we keep no record linking it to your name, email address or account. Age and gender, where known, are sent only as broad ranges; your photos and contact details are never sent at all.
Analytics is switched off when you first install the app. It is enabled only once you accept this Privacy Policy and the Terms of Service in the app. It cannot be switched off separately while you use the Service; if you do not want this processing, please do not use the app. Uninstalling the app ends this processing for the future.
Legal basis: consent.
Diagnostics: We collect pseudonymized and/or aggregated crash reports and performance metrics to identify and fix bugs, optimize app stability, and tailor feature development.
Legal basis: our legitimate interest in service quality.
3. Data Storage, Retention, and Security
On-Device Storage
- Images remain on the Individual's device until app deletion
- Local processing ensures data privacy
- Individuals have complete control over image sharing and deletion
Cloud Storage
- Swiss-based secure servers for stored data
- State-of-the-art encryption for all stored data
- Compliance with GDPR and Swiss data protection standards
Service Providers
We use established, industry-standard service providers to operate the Service (e.g., cloud hosting, email delivery, analytics, and push notification delivery). They process data only as necessary to provide their services to us and are bound by contractual data protection obligations.
These include:
- PostHog Cloud (EU, Germany): product analytics (usage/events)
Where We Process Data
We use cloud infrastructure hosted in Switzerland (Microsoft Azure Switzerland). Our analytics provider PostHog processes certain identifiers and metadata in Frankfurt, EU — outside Switzerland.
Where required, we rely on appropriate safeguards for international data transfers.
Professional Access (Where Applicable)
- Encrypted data transmission to Professionals (where applicable)
- Authentication required for access to Individual's records
- Data remains stored on Microsoft Azure cloud hosted in Switzerland
Data Retention
We retain collected data only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law. The retention periods vary depending on the type of data:
- Registration Data: Retained for the duration of your account's existence and deleted upon account termination, unless otherwise required by legal obligations.
- Images: Stored on your device until you delete them or uninstall the app, and by default in our encrypted cloud storage on servers in Switzerland.
- Images Authorized for Professional Access: Retained in accordance with applicable record-retention laws and professional guidelines (where applicable).
- Feedback and Ratings: Kept for as long as your account exists and for up to 24 months afterwards, unless you request their deletion earlier.
- Usage Data and Diagnostics: Retained in pseudonymized and/or aggregated form for analytics, performance monitoring, and troubleshooting, without identifying individual users.
Data Security
- Encryption: All data transmitted to and from the app is encrypted.
- Secure Storage: Data is stored on Microsoft Azure servers in Switzerland, complying with GDPR and Swiss data protection laws.
- Access Controls: Strict authentication is required to access personal records within the Service.
4. How We Use Your Data
- Account Management: We use registration details to manage your account, provide core app functionalities, and offer customer support.
- Professional Support & Communication: Images, messages, and attachments shared by Individuals are securely transmitted to the Individual's Professional and its authorized staff (where applicable) to support documentation and communication between you and your Professional.
- Service Improvement: We analyze pseudonymized and/or aggregated data (e.g., app usage frequency) to enhance functionality, fix issues, and improve your overall experience.
- Testimonials & Feedback: Individuals may be invited to rate the app or share feedback. We will request explicit consent before making any testimonial public. Without consent, feedback remains private and visible only to you and (where applicable) your Professional.
- Legal Compliance & Safety: We may process data to comply with legal requirements, enforce our terms, and prevent misuse or fraudulent activity.
We Do Not
- Sell Collected Data: We do not sell collected data to third parties for marketing or commercial purposes.
- Share Without Consent: We do not share collected data with third parties without explicit user consent, except as necessary to deliver our services or as required by law, as outlined in this Privacy Policy.
Control Over Collected Data
Users have certain rights regarding their collected data, subject to applicable laws and regulations:
- Access: Individuals may request access to the data collected about them, including registration information and images shared through the app.
- Rectification: Inaccurate or incomplete data can be corrected upon request.
- Erasure: Deletion of collected data, such as registration information or shared images, can be requested, subject to legal and contractual retention requirements.
- Withdrawal of Consent: Consent for data processing may be withdrawn at any time. This may affect access to certain app functionalities. Consent to product analytics is part of accepting this Privacy Policy and the Terms of Service and cannot be withdrawn separately while you continue to use the Service; to end it, stop using the app.
5. Analytics & Tracking
- App Analytics (PostHog): We may use pseudonymized and/or aggregated analytics and performance data to understand app usage, improve stability, and develop features.
- Web Cookies: If you use our website or web app, essential cookies are required for login, security, and core functionality. Optional cookies (e.g., analytics such as PostHog) are used only if you opt in.
You may manage or disable non-essential cookies in your browser or device settings; doing so may affect functionality.
6. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated to you via either:
- Email Notification
- In-App Notification
The continued use of the app after changes signifies acceptance of the updated policy.
Contact Us
Your privacy is our priority. We are committed to safeguarding your personal data and being transparent about our data practices. If you have any questions or concerns, please do not hesitate to contact us.
- Email: info@evooia.com
Acknowledgment
By using evooia, you acknowledge that you have been informed as set out in this notice.