⚠ Draft for legal review — not yet effective. This document is a draft baseline. It will be reviewed by qualified legal counsel and updated before launch. The published version supersedes this draft.
Privacy Policy
Last updated
Plain summary
We collect what we need to give you the Service: account info, payment info, AI generation history, support messages. We never sell your data. We never run advertising trackers. We share data with the providers we need to run the Service (Paddle, Anthropic, Helius, Hetzner, etc.) and nobody else. EU-hosted, GDPR-compliant. You have full GDPR rights: access, deletion, export, and more. Email [email protected] to exercise any of them.
1. Introduction and Controller Identity
This Privacy Policy explains how ("Mintovo", "we", "us") collects, uses, shares, and protects personal data when you use the Mintovo Service.
We are the Data Controller under the EU GDPR (Regulation (EU) 2016/679) and the Polish Personal Data Protection Act of 10 May 2018.
Contact: , Email: [email protected]. DPO: to be appointed if required by GDPR Art. 37 — pending legal counsel.
2. Data We Collect
Account data
- Email address, display name, password hash (Argon2id), 2FA secret (TOTP, encrypted at rest), preferences (locale, appearance).
Authentication data (OAuth)
- Google account ID and email if you sign in with Google. We do not access your Google contacts, calendar, drive, or other Google data.
Payment data
- Processed by Paddle.com Market Limited. We see customer ID, plan, payment status, invoices. We never see card numbers or CVV.
- For crypto: the Solana wallet address that paid us, the transaction signature, and the amount.
Wallet data
- Public Solana wallet addresses you connect. Mint transaction signatures and metadata. We never access wallet private keys or seed phrases.
Content data
- AI generation prompts and outputs, model+token+cost metadata, token configurations, reference images uploaded (stored on IPFS).
Support data
- Contact form submissions (name, email, topic, message, IP, user agent), email correspondence.
Technical data
- IP address, user agent, session identifiers (cookies), error logs (Sentry).
3. Legal Basis for Processing (GDPR Article 6)
| Data category | Legal basis |
|---|---|
| Account data | Performance of contract (Art. 6(1)(b)) |
| Payment data | Performance of contract + legal obligation (tax, accounting) |
| Wallet data | Performance of contract |
| Content (AI generations) | Performance of contract |
| Support data | Legitimate interest (Art. 6(1)(f)) |
| Technical / security data | Legitimate interest — security, fraud prevention, geo-restriction |
| Marketing emails (if any) | Consent (Art. 6(1)(a)) — opt-in only |
| KYC data (Agency tier, large transactions) | Legal obligation (AML) |
4. How We Use Your Data
We use your data to provide and operate the Service, process payments, generate AI Content, submit signed transactions to Solana, send transactional emails, provide support, detect fraud, enforce geo-restrictions and AML obligations, and comply with legal obligations.
We do not sell your data, run behavioural advertising, share with marketing third parties, or use AI prompts to train models (our AI providers are bound by DPAs not to train on customer data).
5. Data Sharing
| Recipient | Purpose | Location |
|---|---|---|
| Paddle.com Market Limited | Payment processing, MoR | Ireland (EU) |
| Anthropic, PBC | AI text generation | USA (DPA + SCCs) |
| Replicate / fal.ai | AI image generation | USA (DPA + SCCs) |
| Pinata Cloud, Inc. | IPFS asset storage | USA (DPA + SCCs) |
| Helius Labs, Inc. | Solana RPC | USA (public blockchain) |
| Hetzner Online GmbH | Hosting | Germany / Finland (EU) |
| Sentry | Error tracking | USA (DPA + SCCs) |
| SumSub or Veriff | Identity verification (when KYC required) | EU |
We may also disclose data to comply with legal obligations, enforce our Terms, or in connection with a corporate transaction.
6. International Data Transfers
Primary processing in the European Union (Hetzner, Falkenstein DE / Helsinki FI). Some providers (Anthropic, Replicate, Pinata, Sentry, Paddle US ops) are in the US — protected by SCCs (GDPR Art. 46(2)(c)), DPAs, and where applicable the EU-US Data Privacy Framework.
7. Retention Periods
| Data | Retention |
|---|---|
| Account data | Until account deletion |
| Financial records (invoices, payment logs) | 5 years from end of fiscal year (PL accounting law) |
| AI generation history | Indefinitely while account is active; deleted on account deletion |
| Wallet addresses | Until account deletion |
| Tokens minted | Until account deletion (on-chain data is permanent and outside our control) |
| Support tickets / contact messages | 2 years from last interaction |
| Application logs | 90 days |
| Error logs (Sentry) | 90 days |
| KYC data | 5 years post-relationship (AML) |
8. Your GDPR Rights
You have the following rights under GDPR Articles 15–22:
- Article 15 — Right of access
- Article 16 — Right to rectification
- Article 17 — Right to erasure ("right to be forgotten")
- Article 18 — Right to restriction of processing
- Article 20 — Right to data portability
- Article 21 — Right to object
- Article 22 — Right not to be subject to automated decision-making
You also have the right to withdraw consent and to lodge a complaint with the Polish supervisory authority (UODO, https://www.uodo.gov.pl).
9. How to Exercise Your Rights
Email [email protected] with your account email and the rights you wish to exercise. We respond within 30 days (extendable to 60 with notice). Free of charge for standard requests.
10. Children
The Service is not intended for users under 18. If you believe we have collected data from a child, contact [email protected] and we will delete it.
12. Security
Encryption at rest (LUKS), TLS 1.3 + HSTS in transit, Argon2id passwords, hashed API keys, TOTP 2FA, OAuth scope limitation, signed wallet nonces, append-only audit logs, annual penetration testing, bug bounty $500–$10,000. Report compromised accounts to [email protected].
13. Data Breach Notification
Within 72 hours to the supervisory authority (UODO), and without undue delay to affected users when the breach is likely to result in a high risk to rights and freedoms.
14. Changes to This Policy
Material changes notified via email at least 30 days in advance, dashboard banner, and an updated "Last updated" date.
15. Contact
Email: [email protected]