Privacy Policy and Personal Data Protection

Last updated: March 26, 2026

1. Data Controller

Molevi S.A.S. (hereinafter, "Molevi"), with domicile in Bogotá, Colombia, is the Data Controller for your personal data. This Privacy Policy (hereinafter, "the Policy") describes how we collect, use, store, and protect the personal information of our platform users.

This Policy complies with: Statutory Law 1581 of 2012 and its Regulatory Decree 1377 of 2013 (Colombia); Brazil's General Data Protection Law — LGPD (Law 13,709/2018); Mexico's Federal Law on Protection of Personal Data Held by Private Parties — LFPDPPP; Peru's Personal Data Protection Law 29733; and the guidelines of the Ibero-American Data Protection Network (RIPD).

2. Personal Data We Collect

Buyer data: email address (for authentication and notifications), name (optional, for personalization), payment transaction information (processed directly by Wompi; Molevi only receives payment status confirmation, does NOT store card data).

Narrator data: name (provided by the Buyer for question personalization), text responses to interview questions, audio and video recordings (when the Narrator chooses to respond in these formats), phone number (optional, only if provided by the Buyer for invitation delivery).

Technical data collected automatically: IP address, browser and device type, pages visited and time spent (through analytics tools), technical cookies necessary for Platform operation.

Sensitive data: The Narrator's responses may contain sensitive data (religious beliefs, health information, political opinions, etc.) when sharing their life story. This data is treated with the highest security and confidentiality guarantees, and its collection is based on the Narrator's prior, express, and informed authorization upon accepting these terms, pursuant to Article 6 of Law 1581 of 2012.

3. Purposes of Processing

Your personal data is processed for the following purposes: (a) Service delivery: processing the Narrator's responses through artificial intelligence to generate follow-up questions and create the Digital Book. (b) Authentication and security: verifying user identity and protecting accounts. (c) Transactional communications: sending invitations to the Narrator, progress reminders, book-ready notifications. (d) Payment processing: managing the commercial transaction through Wompi. (e) Service improvement: aggregate and anonymous analytics to improve user experience.

We do NOT use your data for: commercial profiling, sale to third parties, third-party targeted advertising, or artificial intelligence model training.

4. Legal Basis for Processing

Colombia (Law 1581 of 2012): prior, express, and informed authorization of the data subject. Use of the Platform constitutes your consent for the processing described in this Policy. For sensitive data, enhanced authorization is granted by expressly accepting this Policy before answering questions.

Brazil (LGPD): data subject consent (Art. 7, I) and contract execution (Art. 7, V). For sensitive data: specific and prominent consent (Art. 11, I). Mexico (LFPDPPP): tacit consent for ordinary data through the privacy notice, and express consent for sensitive data. Peru (Law 29733): free, prior, express, informed, and unequivocal consent of the data subject.

5. Data Retention

Buyer data is retained while the account is active and during legal tax and commercial retention periods (minimum 5 years under the Colombian Commercial Code).

User Content (responses, audio, video) is retained while the service is active. The Buyer may request content deletion at any time, which will be executed within thirty (30) business days of the request, unless there is a legal obligation to retain it.

Technical and analytics data is retained in aggregate and anonymous form for a maximum period of two (2) years.

6. Data Sharing with Third Parties

Molevi shares personal data only with the following third parties, acting as Data Processors, and exclusively for service delivery:

Supabase (database and authentication): secure storage of account data and content. Amazon Web Services — AWS (storage): audio and video files stored encrypted using presigned URLs in S3. OpenAI (AI processing): text responses are sent to the OpenAI API for follow-up question generation and Book creation; OpenAI does not retain this data per their API policy. Wompi (payments): transaction processing; Molevi does not access users' financial data. Resend (email): transactional notification delivery. PostHog (analytics): anonymized technical data.

All data processors are contractually obligated to protect data according to standards equivalent to this Policy. We do NOT sell, rent, or share personal data with third parties for advertising or commercial purposes.

7. International Data Transfers

Since we use infrastructure providers with servers outside Colombia (AWS, Supabase, OpenAI primarily operate from the United States), your data may be transferred and processed outside your country of residence.

These transfers are made with the following safeguards: (a) Colombia: pursuant to Article 26 of Law 1581 of 2012 and SIC External Circular 005 of 2017, we verify that the destination country offers adequate levels of protection or, alternatively, establish contractual clauses guaranteeing data protection. (b) Brazil: pursuant to Article 33 of the LGPD, transfers are based on specific contractual clauses and compliance guarantees. (c) Mexico: pursuant to Article 36 of the LFPDPPP, receiving third parties assume the same protection obligations. (d) Peru: pursuant to Article 15 of Law 29733, an adequate level of protection is guaranteed.

8. Security Measures

We implement appropriate technical and organizational measures to protect your personal data: encryption in transit (TLS/HTTPS on all communications), encryption at rest for multimedia files (AWS S3 with server-side encryption), magic link authentication (no stored passwords), Row Level Security (RLS) policies on the database ensuring each user only accesses their own data, role-based access with minimum necessary privileges (principle of least privilege), time-expiring presigned URLs for multimedia file access.

In the event of a security breach affecting personal data, Molevi will notify the Superintendency of Industry and Commerce (Colombia) and affected data subjects within legally established timeframes, as well as competent authorities in other countries pursuant to applicable legislation (ANPD in Brazil, INAI in Mexico, ANPD in Peru).

9. Data Subject Rights

Under applicable legislation, you have the right to: (a) Know/Access: request information about the personal data we hold about you. (b) Update/Rectify: correct inaccurate or incomplete data. (c) Delete/Erase: request deletion of your data when it is no longer necessary for the purpose for which it was collected, or when you withdraw consent. (d) Revoke authorization: withdraw your consent for processing at any time. (e) Object: object to the processing of your data for specific purposes. (f) Portability (Brazil — LGPD): request the transfer of your data to another provider.

To exercise these rights, send an email to hola@molevi.co indicating: your full name, registered email address, the right you wish to exercise, and a clear description of your request. We will respond within legal timeframes: Colombia (15 business days, extendable by 8 more — Art. 15, Law 1581), Brazil (15 days — Art. 18, LGPD), Mexico (20 days — Art. 32, LFPDPPP), Peru (10 business days — Art. 24, Law 29733).

If you are not satisfied with our response, you may file a complaint with the data protection authority in your country: Superintendency of Industry and Commerce — SIC (Colombia), National Data Protection Authority — ANPD (Brazil), National Institute of Transparency, Access to Information and Personal Data Protection — INAI (Mexico), National Authority for Personal Data Protection — ANPDP (Peru).

10. Cookies and Similar Technologies

The Platform uses strictly necessary technical cookies for its operation (authentication, language preferences, session security). We also use PostHog for web analytics, which may use performance cookies to collect anonymous information about Platform usage.

We do not use advertising or third-party tracking cookies. You can configure your browser to reject cookies, although this may affect Platform functionality.

11. Minors

The Platform is not directed at individuals under 18 years of age. We do not intentionally collect personal data from minors. The Buyer must be of legal age to purchase the service. If a Narrator is a minor, the Buyer declares having the authorization of the minor's legal representative, pursuant to Article 7 of Law 1581 of 2012 (Colombia), Article 14 of the LGPD (Brazil), and applicable legislation in each jurisdiction.

In accordance with Law 1098 of 2006 (Colombian Children and Adolescents Code) and equivalent legislation in other countries, the best interest of the minor is guaranteed in all data processing.

12. Modifications to this Policy

Molevi reserves the right to update this Policy to reflect changes in our practices or applicable legislation. Modifications will take effect upon publication on the Platform.

We will notify registered users about material changes via email at least fifteen (15) days in advance. Continued use of the Platform after notification constitutes acceptance of the modified Policy.

13. Contact and Support

For inquiries, rights exercise requests, or claims related to the processing of your personal data, you may contact us at: email: hola@molevi.co. Data Protection Officer: Molevi S.A.S., Bogotá, Colombia. We will address your request within the legal timeframes established by the legislation of your country of residence.

Privacy Policy — Molevi