1. Information we handle
We handle the information needed to create and secure your account, including your email address, authentication details, and sign-in provider. Our authentication provider processes this information on our behalf.
If you choose Google sign-in, Moventify receives the basic account information needed to authenticate you, such as your email address and provider account identifier. Moventify does not request access to your Gmail messages, Google Drive files, contacts, or calendar. Essential session cookies keep you signed in securely.
Your business profile may include the business name, category, city or region, website, social handle, sales channels, and the goal you select during onboarding.
During controlled onboarding, you may choose to schedule an introductory appointment through Google Calendar. Google processes the appointment details you submit under its own terms and privacy policy, and Moventify receives the scheduling information needed to arrange the meeting. A founder-issued invitation is associated with the intended email address. The one-time code is stored only as a protected hash, and short-lived hashed request signals are used to prevent repeated code guessing. We use this information to arrange a walkthrough, secure onboarding, and manage cohort capacity.
We may use your account email to send security, service, and material product-update notices. Product-update campaigns are limited to recently active accounts, track a per-release delivery receipt to prevent duplicates, and include a way to request that optional product updates stop.
Confirmed operational records may include products, variants, prices, optional unit costs, quantities, inventory movements, market transactions, discounts, payment-method labels, estimated gross-profit calculations, market expenses, checklist progress, reconciliation decisions, and market reports. If you choose to add them to a sale, records may also include a customer name, email address, phone number, and whether the customer agreed to receive business updates. Do not enter payment account identifiers or credentials into Moventify.
2. Inventory files and voice capture
Inventory file bytes are parsed inside Moventify’s authenticated server boundary. The raw file is not retained or sent to an AI provider. Only the normalized rows you review and confirm become part of your inventory record.
After public-storefront discovery, you may optionally ask Terra to clean product naming. That request sends only the proposed family, product, and variant names, together with temporary row numbers, to our AI provider with provider response storage disabled. It excludes SKU, price, quantity, inventory levels, source URLs, customer data, and uploaded files. Your original proposal remains available if cleanup does not complete.
Speak Mode sends audio through an authenticated server gateway for transcription and structured draft creation. Moventify does not save the audio or transcript. Only the transaction summary you review and confirm becomes a business record.
3. How Cogitate uses business context
Cogitate receives a purpose-limited context bundle built from your onboarding information and aggregated, confirmed inventory and market records. The bundle excludes account and business database identifiers, email, customer identity, payment identity, raw files, raw transactions, location identifiers, and internal database metadata. When optional unit costs are present, the bundle may include bounded aggregate discount and estimated gross-profit figures calculated from confirmed records and aggregate market-expense figures; it does not send the underlying sale ledger or optional customer contact fields.
The Moventify application does not retain your Cogitate question, generated answer, retrieved page content, or source bundle in the current pilot. AI requests are made through a server-side gateway with provider response storage disabled.
Moventify Pro lets you deliberately upload private documents, spreadsheets, and images as Business Memory sources. The source is sent to our AI provider once to prepare a concise summary and factual proposal, with provider response storage disabled. The original is stored in private, business-scoped storage. Only the summary and facts you confirm may enter future Cogitate context; the original file is not resent for routine questions. You can delete a source and its derived memory from Cogitate. Do not upload customer personal data, payment information, credentials, or secrets.
4. Public website comparisons
Moventify retrieves public website content only when you place eligible public URLs in your current question. Retrieval is limited to those domains, and the resulting answer identifies its sources and evidence boundaries. A website or social handle saved during onboarding is context metadata and is not automatically searched during ordinary guidance.
5. How we use information
We use information to provide authentication, maintain your confirmed business records, connect Inventory, Market Mode, and Cogitate, enforce allowances and security controls, and respond to requests you make. We do not sell your personal information or expose one business’s private records to another business.
6. Service providers and limited access
Moventify currently uses Google and Supabase for authentication, Supabase for database and private file storage, Vercel for application hosting, and OpenAI for AI processing that you request. These providers may process information only as needed to deliver their services under their applicable agreements and policies.
Authorized Moventify administrators and service-provider personnel may be technically capable of accessing production information, but access is limited to legitimate support, security, incident-response, recovery, or legal needs. We may also disclose information when required by law, to protect the service and its users, or as part of a business transaction with appropriate safeguards.
7. How we protect business information
Moventify uses HTTPS/TLS for network connections. Authentication sessions are handled through secure cookies, and protected pages and server actions verify the signed-in owner close to the requested operation. Business-owned database tables use tenant-scoped grants and row-level security so an authenticated owner can access only records belonging to their business.
Privileged credentials remain server-only and are not placed in browser code. Pro Business Memory originals use private, business-scoped storage, and routine Cogitate requests receive confirmed summaries rather than the original files. Our hosting and database providers maintain their own security and compliance controls, including protections for hosted data and backups.
Optional customer contact details are kept in a separate, tenant-scoped record. They are not supplied to Cogitate, Speak Mode, transcription, or image-generation requests. Report downloads omit them by default; an owner must deliberately choose to include them in a CSV export and is responsible for protecting the downloaded file.
We review access boundaries and test tenant isolation as the product evolves. No method of storage or transmission is completely secure. If a security incident requires notice under applicable law, we will provide that notice as required.
8. Retention and deletion
We retain account information and confirmed business records while your account is active and as reasonably necessary to provide the service, preserve required audit history, resolve disputes, or meet legal obligations. You may request access, correction, or deletion of your information. Some records may remain temporarily in protected backups or where retention is legally required.
9. Cookies, local storage, and tracking
Moventify uses essential authentication cookies to maintain a secure session. The workspace uses local browser storage to remember whether you have viewed a “What’s new” notice on that device.
Moventify uses Vercel Web Analytics to understand aggregated website traffic, such as page views, referring sites, general location, browser, operating system, and device type. This privacy-focused service does not use analytics cookies and does not associate analytics activity with your Moventify account or business records. Moventify does not use third-party advertising cookies or sell personal information for targeted advertising.
10. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, or to appeal a decision about a privacy request. Moventify is not directed to children under 18.
11. Changes and contact
We may update this policy as Moventify develops. We will revise the effective date and provide additional notice when a change materially affects how information is handled.
For a privacy question or request, email us at hello@moventify.ai. We will verify requests before acting on account information.