Mojito / Privacy

Mojito and your privacy

Mojito reads your keystrokes, so you should know exactly what it does with them. This page lists every permission it asks for, every request it makes to the internet, and everything it keeps on your Mac, checked line by line against its source code.

Is Mojito safe to give keystroke access?

Here’s everything in one paragraph. Mojito watches what you type for shortcodes like :tada:, on your Mac. What you type isn’t saved or sent anywhere, with one exception: when you search for a GIF with :::, the search words go to KLIPY, the GIF service. Beyond that, Mojito goes online only to check for updates and, unless you switch it off, to send a once-a-day anonymous count of which features and emoji get used. It never opens in password fields. And it’s open source, so none of this has to be taken on trust.

What leaves your MacWhenWhat’s in it
Update checkPeriodically, in the backgroundA request for mojito.wells.ee/appcast.xml. Updates download from GitHub.
GIF searchOnly after you type ::: and a wordYour search words and your country, sent to KLIPY. No account, no device ID.
Usage statsAt most once a day, unless switched offAnonymous counts of features and emoji. Never text, apps, sites, or an ID. All published at /stats.
Anything elseNeverNo analytics or crash-reporting libraries, no ads, no account. (Links you click open in your browser, and one hidden easter egg opens homestarrunner.com.)

Why does Mojito need Accessibility and Input Monitoring?

Every app that autocompletes as you type, in any app, needs this same pair. Here’s what Mojito does with each.

Input Monitoring: seeing the shortcode

Mojito has to see keystrokes to notice :, ::, :::, or :) as you type them. It ignores key combinations that use ⌘, ⌃, or ⌥ (except ⌘ Z, so undo works). It holds only the shortcode you’re in the middle of typing, plus the current word so it can turn :) into 🙂, and only in memory. The shortcode is dropped the moment you insert or cancel; the word is dropped at a space or after a second of not typing.

The keyboard hook can swallow keys, because Return and the arrow keys need to drive the picker instead of your document while it’s open. It never swallows anything in an app you’ve excluded, and it’s removed entirely while Mojito is paused.

Accessibility: finding your cursor and inserting the emoji

Accessibility does four jobs:

  1. Find your text cursor, so the picker opens right next to it. To tell whether you’re at the start of a line, it looks at the one character before the cursor. It doesn’t read the rest of your document.
  2. Check what kind of field you’re in, so it stays out of password fields.
  3. Read the current website’s address in your browser, so per-site exclusions work. Only the host name is matched.
  4. Put the emoji in, by typing it the way a keyboard would, or by pasting a GIF.

In Electron and Chromium apps such as Slack, Mojito switches on the app’s accessibility support so it can find the cursor there.

Automation: Arc only

Arc doesn’t show its address bar to Accessibility, so to apply per-site exclusions there, Mojito asks Arc for the current tab’s address using AppleScript. macOS asks you first, with this reason: “Mojito reads the current tab’s URL in Arc to apply your per-site exclusions.” Every other browser uses Accessibility instead.

What Mojito doesn’t ask for

Screen Recording, Full Disk Access, your camera, microphone, location, or contacts. To check what it has, open System SettingsPrivacy & Security; you can switch any of them off there.

Password fields and Secure Input

Mojito won’t open its picker, search GIFs, or paste into a password field. It checks the field’s type before it starts listening for a shortcode, and again before it pastes. If it can’t tell what kind of field you’re in, it treats it as off-limits.

Separately, when an app switches on macOS’s Secure Input (Terminal’s Secure Keyboard Entry, some password managers and VPN clients do), macOS cuts off every keystroke tool, Mojito included, until that app lets go. If Mojito suddenly does nothing anywhere, that’s usually why; here’s how to find the app responsible.

What Mojito keeps on your Mac

None of it records the text you type. The closest it gets is which emoji you use, your alias words, and, briefly, a GIF search word.

Anonymous usage stats: exactly what’s sent

Stats are on by default, but nothing is sent until Mojito has shown a one-time notice explaining them. You can choose “Not now” there, or switch stats off any time in SettingsGeneral. Development builds never send them.

When stats are on, Mojito sends at most one report a day to stats.mojito.wells.ee. This is the complete list of what’s in it:

SentExample
Mojito version, macOS major version, chip type1.10.0, macOS 27, Apple silicon
Your language and default skin toneen, medium
Which features are switched on (16 on/off flags)GIF search on, arrows off
Counts of emoji, symbols, GIFs, and emoticons inserted42 emoji, 3 GIFs
Which emoji you used, and how often (up to 300 emoji, each capped at 100)🎉 × 7, ❤️ × 12
Which emoji you’ve pinned as favorites, and how many4 favorites
How many easter eggs you’ve found2

Never sent: anything you type, which apps or websites you use, your GIF searches, your aliases, timestamps, or any ID that could link one day’s report to the next. The stats service reads only the report itself, never your IP address or device details, and stores daily totals, not individual reports. Everything it has is published at mojito.wells.ee/stats.

Coming in the next release: three yes/no answers worked out on your Mac (is this a new install, used this week, used this month) so active users can be counted without giving anyone an ID.

GIF search and KLIPY

Type ::: and a word, and Mojito asks KLIPY for matching GIFs. Each request carries:

The GIF images themselves then load from KLIPY’s servers. KLIPY’s own privacy policy covers what it keeps on its side. Mojito doesn’t keep a list of your searches, though recent results sit in its GIF cache for a while. Mojito used GIPHY until version 1.10.0, and no GIPHY code is left in the app.

By default, GIF search works even in apps and sites Mojito otherwise steps aside for, like Slack and Discord. Turn off Always let GIF search work in SettingsExclusions to change that, or switch GIF search off entirely in SettingsGeneral.

How to check all this yourself

Your controls

To…Go to
Stop sending usage statsSettings › General
Turn off GIF search (no KLIPY requests at all)Settings › General
Keep GIF search out of excluded apps tooSettings › Exclusions › Always let GIF search work
Keep Mojito out of an app or websiteSettings › Exclusions, or flip it to an allowlist
Pause it for an hour, or until tomorrowThe menu-bar icon
Take its permissions awaySystem Settings › Privacy & Security

Privacy changelog

VersionWhat changed
1.10.0 · Oct 1, 2026GIF search moved from GIPHY to KLIPY. No customer or device ID is sent.
1.9.1 · Sep 22, 2026Turns on accessibility support in Electron apps such as Slack, to find the cursor there.
1.8.1 · Jul 22, 2026Fields Mojito can’t identify are treated as off-limits, like password fields.
1.8.0 · Jul 16, 2026Per-site exclusions in Arc, using AppleScript (asks for Automation permission, Arc only).
1.6.0 · Jun 25, 2026Pinned favorites added to the anonymous stats.
1.2.3 · Jun 5, 2026Development builds stop sending stats.
1.2.2 · Jun 3, 2026Anonymous usage stats introduced, with a one-time notice before anything is sent.
1.1.0 · May 29, 2026Allowlist mode: run Mojito only in the apps you name.
1.0.4 · May 27, 2026GIF search added, using GIPHY.
1.0.0 · May 24, 2026First release. Password fields excluded from the start.

This website

mojito.wells.ee sets no cookies and loads no analytics or tracking scripts. The stats page loads its numbers from stats.mojito.wells.ee. Download buttons go through mojito.wells.ee/download, which sends you on to GitHub and may note which page the click came from, the referring site, and your country, with no cookies and no IP address.

Privacy questions

Does Mojito work offline?

Yes. Emoji, symbols, emoticons, and arrows all work with no connection. Only GIF search and update checks need the internet.

Can Mojito see my passwords?

It won’t open in password fields, and when an app turns on macOS Secure Input, macOS blocks Mojito from seeing keystrokes at all.

Does Mojito sell or share data?

No. There’s no account, no advertising, and nothing to sell: the only usage data is the anonymous daily counts above, and they’re public. Apart from the services that host downloads and stats (GitHub and Cloudflare), KLIPY is the only outside company involved, and it only sees GIF searches.

Who do I ask about this?

Me: Wells Riley, at [email protected]. Bug reports about privacy are especially welcome on GitHub.