PRIVACY POLICY

Last Updated: 31 July 2026

1. Data Controller

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Organic Law 3/2018 (LOPDGDD), notice is given that the Data Controller for personal data collected through the Sindria application is:

  • Owner: Francisco Muñoz Cuevas (MOMUSA)
  • ID/DNI: 43321407Z
  • Postal Address: Torrent 23, Sant Jordi, Balearic Islands (Spain)
  • Data Protection Contact Email: support@momusa.tech

2. Data Collected, Purposes, and Legal Basis

Sindria collects strictly necessary data to deliver social media management and AI content generation services:

1. Profile and Identification Data

Name, email address, and platform-generated user IDs.

Purpose: Account creation, authentication, and contractual management.
Legal Basis: Performance of service contract (Art. 6.1.b GDPR).

2. AI Prompts and Generated Content

Text instructions, prompts, and user-uploaded images.

Purpose: Processing input information to generate copy and design proposals.
Legal Basis: Performance of service contract (Art. 6.1.b GDPR).

3. Transaction and Subscription Data

Purchase history, active plan tier, and Apple/Google token IDs.

Purpose: Subscription billing verification and compliance.
Legal Basis: Contract performance and legal tax obligations (Art. 6.1.b & 6.1.c GDPR).

4. Social Media Access Tokens

Encrypted connection keys for Instagram, Facebook, or LinkedIn.

Purpose: Execution of automated publishing scheduled by the user.
Legal Basis: Explicit user consent when linking accounts (Art. 6.1.a GDPR).

3. Artificial Intelligence Guarantees and Prompt Privacy

When utilizing Google Gemini artificial intelligence technology to process requests, MOMUSA guarantees:

  • Input data (prompts) and uploaded image files are never used to train public Google AI models without explicit consent.
  • All data transfers occur over encrypted channels to safeguard business confidentiality and brand privacy.

4. Protection of Minors

While there is no technical age restriction to access the Application, under Spanish law, processing personal data of minors under 14 is lawful only with express consent from parents or legal guardians. MOMUSA does not knowingly collect data from minors without authorization.

5. Data Retention Period

Personal data is retained while the commercial relationship remains active or the account is open. Upon account cancellation or contract termination, user data will be held blocked for a maximum of three (3) years to address potential legal or contractual liabilities. Thereafter, data is permanently erased or anonymized.

6. Security and Technical Measures

MOMUSA enforces appropriate technical and organizational measures to ensure confidentiality, integrity, and availability:

  • Data encryption in transit via TLS/SSL cryptographic protocols.
  • Data encryption at rest using AES-256 standard for sensitive credentials (e.g. social access tokens).
  • Least privilege access controls and strict authentication controls.

7. International Data Transfers

To deliver the service, infrastructure providers located outside the European Economic Area (EEA) are used:

  • Google Cloud / Google LLC: United States (AI processing & hosting).
  • RevenueCat Inc.: United States (In-App Purchases & subscription management).

Transfers are conducted under the EU-U.S. Data Privacy Framework or European Commission Standard Contractual Clauses (SCCs), ensuring equivalent protection to EU standards.

8. User Rights

Users may exercise Rights of Access, Rectification, Erasure, Limitation, Portability, and Objection:

  • Automatic In-App Mechanism: Settings menu includes a "Delete Account" button that immediately and irreversibly deletes profile data, post history, and database records from servers and RevenueCat.
  • Email Mechanism: Written request to support@momusa.tech. If rights are unsatisfied, users may lodge a complaint with the Spanish Data Protection Agency (AEPD at www.aepd.es).

9. B2B Annex: Data Processing Agreement (DPA)

Applies to professional users or agencies processing client personal data. User acts as Data Controller and MOMUSA as Data Processor:

  • Instructions: Data processed strictly to provide requested services.
  • Authorized Subprocessors: Subcontracting authorized for Google LLC, RevenueCat Inc., Meta Platforms Inc., and LinkedIn Corp.
  • Security Breach Notification: Breaches affecting user data will be notified within 24–48 hours of confirmation.

10. Changes to this Privacy Policy

MOMUSA reserves the right to modify this Privacy Policy to adapt to legal changes or new features. Material changes will be notified in advance via in-app notices.