Legal

Privacy Policy

Your AI studio. Your keys. Your data stays that way — this page explains exactly what leaves your device and what never does.

Draft. Placeholder content, not legal advice. This policy will be reviewed and replaced before public launch.

Last updated: 2026 (draft)

The short version

1. Our architecture, and why it matters

MovoCompose is client-side-first. Instead of routing your prompts and media through our servers, the app runs on your device and talks to the AI provider you selected using a key you supplied. The consequence is structural, not a policy promise: for most of what you do, there is no copy of your work on our infrastructure to leak, subpoena or lose.

This is not absolutist. A small backend exists for the things that genuinely require one — identity, subscription validation and the settings that make the app feel like yours across reinstalls. The rest stays with you.

2. Bring your own key (BYOK)

Provider keys are written to the platform's secure storage — the iOS Keychain and the Android Keystore-backed encrypted storage — through flutter_secure_storage. They are readable only by MovoCompose on that device.

Optional encrypted backup. If you switch on "Back up keys" in the app, each key is encrypted on your device with a device-generated key before upload. Our servers store only the resulting ciphertext and cannot decrypt it. Backup is off by default and can be turned off at any time.

When you generate something, the request travels from your device directly to your chosen provider. That provider's processing is governed by their privacy terms, not ours — please review them. We never see your prompts or outputs on that path.

3. What our backend actually holds

The complete list. Anything not here is not collected.
CategoryWhat it isWhy
Account basics Name, email address, optional phone number, sign-in provider, user id Identity and sign-in
Subscription state Plan tier, status, current period end, trial state, store receipt references Entitlement validation
Library metadata Titles, type, timestamps, like/rename flags for items you save So your library survives a reinstall
Settings Theme, language, notification preferences, per-module default providers Preferences follow your account
Push tokens Device push token and platform Delivery of notifications you enabled
Cortex memory The assistant's memory of your conversation and stated preferences Continuity of the AI assistant

Generated media is not in that table. Videos, images, audio files and transcripts you create are stored on your device. Library rows reference them by metadata only.

4. Analytics and crash reporting

We use Firebase Analytics and Firebase Crashlytics to understand which features are used and to fix crashes. Crashlytics collects crash traces, device state and coarse diagnostics. Analytics collects aggregated usage events.

Where the platform allows it, these are configured with the most restrictive data-collection settings available. They are never given your provider keys, your prompts, or your generated media. If Firebase fails to initialize, the app continues to work — analytics is not a precondition for using MovoCompose.

5. Your rights

Export

Settings → Export my data produces a copy of the account data we hold, in a portable format, on your device.

Erasure

Settings → Delete account removes your account and the data listed in section 3. Cortex memory can be wiped separately and immediately via Account → Reset Cortex memory. On-device media is yours and is not touched by either action — delete those files with your device's normal file controls if you want them gone.

Depending on where you live

If you are in the EEA, UK, Switzerland, Brazil or California, you may also have rights of access, rectification, restriction, objection and portability, and the right to lodge a complaint with your supervisory authority. Email support@movofo.com and we will action the request or tell you how to do it yourself in-app.

6. What we never do

7. Service providers

A short list of processors act on our behalf: our backend hosting and database provider, Firebase (analytics and crash reporting), the app stores for purchase handling, and the AI providers you choose — who act on your behalf, under your key and their terms, not ours.

8. International transfers

MovoCompose launches globally. Our backend and its processors may store data outside your country of residence, including in the United States and the European Union. Where a transfer requires a safeguard, we rely on the applicable standard contractual clauses or an equivalent mechanism. Your own AI provider's location is determined by the provider you pick.

9. Data retention

Account data is kept while your account is active and deleted when you delete it. Crash reports are retained for a limited window and then aged out. Backed-up key ciphertext is removed with the account.

10. Security

All traffic to our backend is over TLS. Keys use platform secure storage. Backups are encrypted client-side before they leave the device. Optional biometric sign-in (Face ID / Touch ID / Android biometrics) gates the app on your device; the biometric check never leaves it and we never see your fingerprint or face data.

No system is perfectly secure. If you believe your keys were exposed, rotate them at your provider immediately and remove them in Account → AI provider keys.

11. Children

MovoCompose is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect their data. If you believe a child has provided us with personal information, contact us and we will remove it.

12. Changes to this policy

If this policy changes materially we will update the date at the top of this page and, where the change affects you, notify you in the app before it takes effect.

13. Contact

Movofo Software

Email: support@movofo.com
Web: movofo.com

Questions about this policy, a privacy request, or how a specific feature handles your data — write to us. A human replies.