Privacy Policy
Your AI studio. Your keys. Your data stays that way — this page explains exactly what leaves your device and what never does.
Draft. Placeholder content, not legal advice. This policy will be reviewed and replaced before public launch.
Last updated: 2026 (draft)
The short version
- Your API keys are stored in your device's keychain / keystore. They are never uploaded in plain text.
- Your creations — videos, images, audio, transcripts — are generated and stored on your device.
- AI requests go directly from your device to the provider you chose. MovoCompose is not in the middle of that traffic.
- Our backend holds a deliberately short list: account basics, subscription state, library metadata, settings, push tokens and Cortex memory.
- We do not sell your personal data. Ever.
- You can export your data and delete your account from inside the app.
1. Our architecture, and why it matters
MovoCompose is client-side-first. Instead of routing your prompts and media through our servers, the app runs on your device and talks to the AI provider you selected using a key you supplied. The consequence is structural, not a policy promise: for most of what you do, there is no copy of your work on our infrastructure to leak, subpoena or lose.
This is not absolutist. A small backend exists for the things that genuinely require one — identity, subscription validation and the settings that make the app feel like yours across reinstalls. The rest stays with you.
2. Bring your own key (BYOK)
Provider keys are written to the platform's secure storage — the iOS Keychain and the Android Keystore-backed encrypted storage — through flutter_secure_storage. They are readable only by MovoCompose on that device.
Optional encrypted backup. If you switch on "Back up keys" in the app, each key is encrypted on your device with a device-generated key before upload. Our servers store only the resulting ciphertext and cannot decrypt it. Backup is off by default and can be turned off at any time.
When you generate something, the request travels from your device directly to your chosen provider. That provider's processing is governed by their privacy terms, not ours — please review them. We never see your prompts or outputs on that path.
3. What our backend actually holds
| Category | What it is | Why |
|---|---|---|
| Account basics | Name, email address, optional phone number, sign-in provider, user id | Identity and sign-in |
| Subscription state | Plan tier, status, current period end, trial state, store receipt references | Entitlement validation |
| Library metadata | Titles, type, timestamps, like/rename flags for items you save | So your library survives a reinstall |
| Settings | Theme, language, notification preferences, per-module default providers | Preferences follow your account |
| Push tokens | Device push token and platform | Delivery of notifications you enabled |
| Cortex memory | The assistant's memory of your conversation and stated preferences | Continuity of the AI assistant |
Generated media is not in that table. Videos, images, audio files and transcripts you create are stored on your device. Library rows reference them by metadata only.
4. Analytics and crash reporting
We use Firebase Analytics and Firebase Crashlytics to understand which features are used and to fix crashes. Crashlytics collects crash traces, device state and coarse diagnostics. Analytics collects aggregated usage events.
Where the platform allows it, these are configured with the most restrictive data-collection settings available. They are never given your provider keys, your prompts, or your generated media. If Firebase fails to initialize, the app continues to work — analytics is not a precondition for using MovoCompose.
5. Your rights
Export
Settings → Export my data produces a copy of the account data we hold, in a portable format, on your device.
Erasure
Settings → Delete account removes your account and the data listed in section 3. Cortex memory can be wiped separately and immediately via Account → Reset Cortex memory. On-device media is yours and is not touched by either action — delete those files with your device's normal file controls if you want them gone.
Depending on where you live
If you are in the EEA, UK, Switzerland, Brazil or California, you may also have rights of access, rectification, restriction, objection and portability, and the right to lodge a complaint with your supervisory authority. Email support@movofo.com and we will action the request or tell you how to do it yourself in-app.
6. What we never do
- We do not sell personal data.
- We do not share it with advertisers or data brokers.
- We do not train models on your prompts, keys or creations.
- We do not read the contents of your encrypted key backup — we cannot.
7. Service providers
A short list of processors act on our behalf: our backend hosting and database provider, Firebase (analytics and crash reporting), the app stores for purchase handling, and the AI providers you choose — who act on your behalf, under your key and their terms, not ours.
8. International transfers
MovoCompose launches globally. Our backend and its processors may store data outside your country of residence, including in the United States and the European Union. Where a transfer requires a safeguard, we rely on the applicable standard contractual clauses or an equivalent mechanism. Your own AI provider's location is determined by the provider you pick.
9. Data retention
Account data is kept while your account is active and deleted when you delete it. Crash reports are retained for a limited window and then aged out. Backed-up key ciphertext is removed with the account.
10. Security
All traffic to our backend is over TLS. Keys use platform secure storage. Backups are encrypted client-side before they leave the device. Optional biometric sign-in (Face ID / Touch ID / Android biometrics) gates the app on your device; the biometric check never leaves it and we never see your fingerprint or face data.
No system is perfectly secure. If you believe your keys were exposed, rotate them at your provider immediately and remove them in Account → AI provider keys.
11. Children
MovoCompose is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect their data. If you believe a child has provided us with personal information, contact us and we will remove it.
12. Changes to this policy
If this policy changes materially we will update the date at the top of this page and, where the change affects you, notify you in the app before it takes effect.
13. Contact
Movofo Software
Email: support@movofo.com
Web: movofo.com
Questions about this policy, a privacy request, or how a specific feature handles your data — write to us. A human replies.