Data processing agreement
Last updated:
This agreement covers the data your app's users send through the Words Are Flowing SDK. It forms part of the terms of service. Your own account data is covered by the privacy policy.
Parties and roles
You, the customer, decide what your app sends and why: you are the controller (the person or business responsible for the information). Studio Mubold, operated by Etienne Bolduc as a sole proprietorship registered in Québec (NEQ 2282295247), processes it only on your behalf: we are the processor. Our person responsible for the protection of personal information (Québec, Law 25) is Etienne Bolduc, privacy@mubold.com.
What we process
Notes. When one of your users sends a private note, we receive:
- the message (up to 2,000 characters) and, if given, a rating from 1 to 5;
- the trigger that led to the ask, the user's language, the platform, your app's version and the SDK's version;
- the attributes you choose to attach (up to 20, each value up to 200 characters) — you define them, we store them as sent;
- optionally, a
userId: an opaque identifier of your choosing (up to 128 characters) that lets you find and delete one user's notes later; - the time we received it.
Counters. Daily totals per product and trigger: how many times the rules were fetched, a store prompt was shown, and an ask was shown, dismissed or answered. These counts are not linked to any person or device.
Request logs. Our API's request logs record each request's method and address
path, its result and duration, the browser or operating system its user agent reports, and an
approximate location (city, region, country); they are kept 90 days, then deleted. A deletion
request through DELETE /v1/users/{userId}, or from the portal, carries the
userId in its address, so that userId stays in these logs for those
90 days.
What we do not receive
- No device identifier and no advertising identifier. The SDK sends none.
- No per-user history. The counters that decide when to ask a user — how often a trigger happened, when the last ask or store prompt was — stay on the user's device.
- No stored IP address. We do not store the device's IP address with notes or counters. In the request logs, the IP address is masked before it is stored: Azure Monitor uses it only to estimate the approximate location above, then records it as 0.0.0.0.
Your obligations
- You decide which attributes and which
userIdto send, and you are responsible for having a lawful basis and for informing your users, for example in your app's privacy policy. - Do not send special categories of information (health, religious or political beliefs, sexual orientation, biometric or government identifiers, or similar sensitive information).
- We discourage sending email addresses or names as attributes or as the
userId; an opaque identifier works just as well. - A note is free text written by your user. We cannot detect personal information inside it and do not claim to. If a user tells you a note contains something it should not, delete it from the portal.
Our obligations
- Purpose. We process this data only to provide the service to you: to store it, show it to you in the portal, count it against your plan and delete it. We do not sell it, use it for advertising, or combine it with other customers' data.
- Confidentiality. Access to the systems is limited to the operator, who is bound by this agreement. The database credential is shared by Studio Mubold's own services (its other apps), all run by that same person.
- Security measures. Connections are encrypted in transit (HTTPS, TLS 1.2 or later). API keys are stored only as one-way hashes. Customers share one database, and every query on notes is limited to the products of the account that owns them. We do not hold any security certification.
- Sub-processors. We use the providers listed below. We will tell you by email before adding or replacing one, so that you can object or close your account.
- Helping with requests. To answer a user's request, you can delete every note
carrying a given
userIdthrough the API (DELETE /v1/users/{userId}) or from the portal, delete a single note from the portal, and export notes as CSV from the portal. If you need more, write to us. - Retention. Notes are kept for your plan's retention period — 90 days on Free, 2 years on paid plans — then deleted automatically.
- Deletion at the end. When you delete your account, every product and every note and counter it received are erased from our database immediately. Deleted data may persist for a limited period in our database provider's backups, and is then gone for good. Request logs are kept 90 days, as described above.
- Incidents. If a confidentiality incident affects your end users' data, we will tell you without undue delay, with what we know, so that you can meet your own obligations.
- Transfers. Some sub-processors may store or process data outside Québec, including elsewhere in Canada and in other countries. We choose providers that offer protection comparable to what is required here, and we assess such transfers as the law requires.
Sub-processors
- Microsoft Azure — hosting of the API and its request and error logs, in Azure's Canada Central region.
- MongoDB Atlas — the managed database that stores notes and counters, hosted on Microsoft Azure in Toronto (Canada Central region).
These providers serve your account, not your end users' notes: Paddle (payments, merchant of record), RevenueCat (subscription status), Resend (transactional email), and Google and Apple (sign-in). They never receive your end users' notes.
Changes and contact
If we change this agreement, we will update the date at the top of this page and, for significant changes, tell account holders by email at least 30 days before they take effect. Questions: privacy@mubold.com.