Mojito / Privacy
Mojito and your privacy
Mojito reads your keystrokes, so you should know exactly what it does with them. This page lists every permission it asks for, every request it makes to the internet, and everything it keeps on your Mac, checked line by line against its source code.
Is Mojito safe to give keystroke access?
Here’s everything in one paragraph. Mojito watches what you type for shortcodes like :tada:, on your Mac. What you type isn’t saved or sent anywhere, with one exception: when you search for a GIF with :::, the search words go to KLIPY, the GIF service. Beyond that, Mojito goes online only to check for updates and, unless you switch it off, to send a once-a-day anonymous count of which features and emoji get used. It never opens in password fields. And it’s open source, so none of this has to be taken on trust.
| What leaves your Mac | When | What’s in it |
|---|---|---|
| Update check | Periodically, in the background | A request for mojito.wells.ee/appcast.xml. Updates download from GitHub. |
| GIF search | Only after you type ::: and a word | Your search words and your country, sent to KLIPY. No account, no device ID. |
| Usage stats | At most once a day, unless switched off | Anonymous counts of features and emoji. Never text, apps, sites, or an ID. All published at /stats. |
| Anything else | Never | No analytics or crash-reporting libraries, no ads, no account. (Links you click open in your browser, and one hidden easter egg opens homestarrunner.com.) |
Why does Mojito need Accessibility and Input Monitoring?
Every app that autocompletes as you type, in any app, needs this same pair. Here’s what Mojito does with each.
Input Monitoring: seeing the shortcode
Mojito has to see keystrokes to notice :, ::, :::, or :) as you type them. It ignores key combinations that use ⌘, ⌃, or ⌥ (except ⌘ Z, so undo works). It holds only the shortcode you’re in the middle of typing, plus the current word so it can turn :) into 🙂, and only in memory. The shortcode is dropped the moment you insert or cancel; the word is dropped at a space or after a second of not typing.
The keyboard hook can swallow keys, because Return and the arrow keys need to drive the picker instead of your document while it’s open. It never swallows anything in an app you’ve excluded, and it’s removed entirely while Mojito is paused.
Accessibility: finding your cursor and inserting the emoji
Accessibility does four jobs:
- Find your text cursor, so the picker opens right next to it. To tell whether you’re at the start of a line, it looks at the one character before the cursor. It doesn’t read the rest of your document.
- Check what kind of field you’re in, so it stays out of password fields.
- Read the current website’s address in your browser, so per-site exclusions work. Only the host name is matched.
- Put the emoji in, by typing it the way a keyboard would, or by pasting a GIF.
In Electron and Chromium apps such as Slack, Mojito switches on the app’s accessibility support so it can find the cursor there.
Automation: Arc only
Arc doesn’t show its address bar to Accessibility, so to apply per-site exclusions there, Mojito asks Arc for the current tab’s address using AppleScript. macOS asks you first, with this reason: “Mojito reads the current tab’s URL in Arc to apply your per-site exclusions.” Every other browser uses Accessibility instead.
What Mojito doesn’t ask for
Screen Recording, Full Disk Access, your camera, microphone, location, or contacts. To check what it has, open System SettingsPrivacy & Security; you can switch any of them off there.
Password fields and Secure Input
Mojito won’t open its picker, search GIFs, or paste into a password field. It checks the field’s type before it starts listening for a shortcode, and again before it pastes. If it can’t tell what kind of field you’re in, it treats it as off-limits.
Separately, when an app switches on macOS’s Secure Input (Terminal’s Secure Keyboard Entry, some password managers and VPN clients do), macOS cuts off every keystroke tool, Mojito included, until that app lets go. If Mojito suddenly does nothing anywhere, that’s usually why; here’s how to find the app responsible.
What Mojito keeps on your Mac
- Your settings: triggers, which features are on, your excluded apps and sites, and whether Mojito is paused.
- How often you use each emoji, as a single count per emoji with no dates, so the ones you use rise to the top. Plus lifetime totals (emoji, symbols, GIFs), and the date you first opened it.
- Your favorites and custom aliases.
- GIFs: a cache of up to 50 MB of results, and each GIF you paste, kept in a temporary folder for a few minutes. That file’s name includes your search word, because chat apps show it when you upload.
None of it records the text you type. The closest it gets is which emoji you use, your alias words, and, briefly, a GIF search word.
Anonymous usage stats: exactly what’s sent
Stats are on by default, but nothing is sent until Mojito has shown a one-time notice explaining them. You can choose “Not now” there, or switch stats off any time in SettingsGeneral. Development builds never send them.
When stats are on, Mojito sends at most one report a day to stats.mojito.wells.ee. This is the complete list of what’s in it:
| Sent | Example |
|---|---|
| Mojito version, macOS major version, chip type | 1.10.0, macOS 27, Apple silicon |
| Your language and default skin tone | en, medium |
| Which features are switched on (16 on/off flags) | GIF search on, arrows off |
| Counts of emoji, symbols, GIFs, and emoticons inserted | 42 emoji, 3 GIFs |
| Which emoji you used, and how often (up to 300 emoji, each capped at 100) | 🎉 × 7, ❤️ × 12 |
| Which emoji you’ve pinned as favorites, and how many | 4 favorites |
| How many easter eggs you’ve found | 2 |
Never sent: anything you type, which apps or websites you use, your GIF searches, your aliases, timestamps, or any ID that could link one day’s report to the next. The stats service reads only the report itself, never your IP address or device details, and stores daily totals, not individual reports. Everything it has is published at mojito.wells.ee/stats.
Coming in the next release: three yes/no answers worked out on your Mac (is this a new install, used this week, used this month) so active users can be counted without giving anyone an ID.
GIF search and KLIPY
Type ::: and a word, and Mojito asks KLIPY for matching GIFs. Each request carries:
- Your search words. Requests go out after a short pause in typing, so a half-typed word can be sent too.
- The results page, the number of results (24), a content rating (KLIPY’s “medium”), and “GIFs only.”
- Your country, so results suit where you are.
- Mojito’s app key, which is the same for everyone. No customer ID, device ID, or account.
The GIF images themselves then load from KLIPY’s servers. KLIPY’s own privacy policy covers what it keeps on its side. Mojito doesn’t keep a list of your searches, though recent results sit in its GIF cache for a while. Mojito used GIPHY until version 1.10.0, and no GIPHY code is left in the app.
By default, GIF search works even in apps and sites Mojito otherwise steps aside for, like Slack and Discord. Turn off Always let GIF search work in SettingsExclusions to change that, or switch GIF search off entirely in SettingsGeneral.
How to check all this yourself
- Read the code. Mojito is AGPL-3.0 open source. The keyboard hook, the field checks, and the network code are all there, and you can build it yourself.
- Watch its connections. With a firewall like LuLu or Little Snitch, you’ll see
mojito.wells.eeandgithub.com(updates),api.klipy.comand KLIPY’s image servers (only during GIF search), andstats.mojito.wells.ee(at most daily). Or, in Terminal:lsof -nP -i -a -c Mojito. - Check the signature. Mojito is signed with an Apple Developer ID and notarized by Apple, and every update is signed with a key the app checks before installing. The Homebrew cask is pinned to the checksum of the GitHub release.
Your controls
| To… | Go to |
|---|---|
| Stop sending usage stats | Settings › General |
| Turn off GIF search (no KLIPY requests at all) | Settings › General |
| Keep GIF search out of excluded apps too | Settings › Exclusions › Always let GIF search work |
| Keep Mojito out of an app or website | Settings › Exclusions, or flip it to an allowlist |
| Pause it for an hour, or until tomorrow | The menu-bar icon |
| Take its permissions away | System Settings › Privacy & Security |
Privacy changelog
| Version | What changed |
|---|---|
| 1.10.0 · Oct 1, 2026 | GIF search moved from GIPHY to KLIPY. No customer or device ID is sent. |
| 1.9.1 · Sep 22, 2026 | Turns on accessibility support in Electron apps such as Slack, to find the cursor there. |
| 1.8.1 · Jul 22, 2026 | Fields Mojito can’t identify are treated as off-limits, like password fields. |
| 1.8.0 · Jul 16, 2026 | Per-site exclusions in Arc, using AppleScript (asks for Automation permission, Arc only). |
| 1.6.0 · Jun 25, 2026 | Pinned favorites added to the anonymous stats. |
| 1.2.3 · Jun 5, 2026 | Development builds stop sending stats. |
| 1.2.2 · Jun 3, 2026 | Anonymous usage stats introduced, with a one-time notice before anything is sent. |
| 1.1.0 · May 29, 2026 | Allowlist mode: run Mojito only in the apps you name. |
| 1.0.4 · May 27, 2026 | GIF search added, using GIPHY. |
| 1.0.0 · May 24, 2026 | First release. Password fields excluded from the start. |
This website
mojito.wells.ee sets no cookies and loads no analytics or tracking scripts. The stats page loads its numbers from stats.mojito.wells.ee. Download buttons go through mojito.wells.ee/download, which sends you on to GitHub and may note which page the click came from, the referring site, and your country, with no cookies and no IP address.
Privacy questions
Does Mojito work offline?
Yes. Emoji, symbols, emoticons, and arrows all work with no connection. Only GIF search and update checks need the internet.
Can Mojito see my passwords?
It won’t open in password fields, and when an app turns on macOS Secure Input, macOS blocks Mojito from seeing keystrokes at all.
Does Mojito sell or share data?
No. There’s no account, no advertising, and nothing to sell: the only usage data is the anonymous daily counts above, and they’re public. Apart from the services that host downloads and stats (GitHub and Cloudflare), KLIPY is the only outside company involved, and it only sees GIF searches.
Who do I ask about this?
Me: Wells Riley, at [email protected]. Bug reports about privacy are especially welcome on GitHub.