Privacy
Last updated:
This policy covers you as a customer: the person or business with a Words Are Flowing portal account. The notes your own app's users send through the SDK are covered by the data processing agreement, because for that data you decide and we process on your behalf.
Who we are
Words Are Flowing is made by Studio Mubold, operated by Etienne Bolduc as a sole proprietorship registered in Québec (NEQ 2282295247).
The person responsible for the protection of personal information (Québec, Law 25) is Etienne Bolduc, privacy@mubold.com. Write to that address about anything on this page. For everything else: support@mubold.com.
What we collect about you
- Account information. Your email address and a display name. If you sign in with Google or Apple, we also receive the provider's account identifier and, when the provider supplies one, a profile picture address. If you register with an email and password, we store a one-way hash of the password, never the password itself.
- Consent record. The date and version of the terms and this policy you accepted.
- Plan and billing status. Your plan, its status and its end date, and the identifiers that link your account to your subscription. Paddle processes the payment itself; we never receive your card number.
- Security log. A record of security events on your account (registration, sign-in, password change or reset, email verification, data export), with the time. It does not include your IP address.
- Your product configuration. The products you create, their store identifiers, their rules, and the attribute names seen on their notes. API keys are stored only as a one-way hash; the full key is shown to you once.
- Usage counts. How many notes each of your products received and how many were refused each month, so the plan limits can apply.
- Help notes. Notes you send from the portal's Help page are stored as feedback in our own Words Are Flowing product and are subject to the same retention.
- Error reports. When the portal hits an error, it may send us the error message, the technical trace, the app version, your browser's language and a random identifier created in your browser. These are not linked to your account.
- Request logs. Our API records each request it receives: the method and address path, the result and how long it took, the browser or operating system the request reports, and an approximate location (city, region, country) derived from the network address. The IP address itself is masked before it is stored. Some log messages can include your email address or account identifier, for example when an email could not be sent or a subscription event is processed.
Why we collect it
To create your account and sign you in; to run the service you signed up for; to apply your plan and bill for it; to send you the emails the service needs (email verification, password reset); to keep the service secure; and to answer you when you write to us. We do not sell or rent your personal information, and we do not use it for advertising.
Who processes it for us
A small set of service providers run parts of the service on our behalf, only as needed:
- Microsoft Azure — hosting. Our API and its request and error logs run in Azure's Canada Central region; the portal and this site are static files served from Azure's global network.
- MongoDB Atlas — the managed database that stores accounts, products and notes, hosted on Microsoft Azure in Toronto (Canada Central region).
- Resend — sending transactional email.
- Paddle — payments. Paddle is our reseller and merchant of record, and processes your payment details under its own privacy policy.
- RevenueCat — records your subscription status, so your plan follows your payment.
- Google and Apple — sign-in, if you choose them.
Some of these providers may store or process information on servers located outside Québec, including elsewhere in Canada and in other countries. We choose providers that offer protection comparable to what is required here, and we assess such transfers as the law requires. We may also disclose information if the law requires it.
How long we keep it
- Your account is kept until you delete it. Deleting your account from the portal erases it completely: your profile, your security log, your usage counts, every product, and every note and counter those products received, as well as the log of subscription events we received from RevenueCat for your account. When you delete your account we cancel its Words Are Flowing subscription immediately, so nothing further is charged; refunds follow Paddle's refund policy. If we cannot (for example, you paid with a different email address), cancel it from the link in your Paddle receipt or write to support@mubold.com. Paddle and RevenueCat keep their own records of past transactions, as their own obligations require.
- Notes your products receive are kept 90 days on the Free plan and 2 years on paid plans, then deleted automatically.
- Request logs and error reports are kept 90 days, then deleted, including after you delete your account.
- Backups. Data you delete may persist for a limited period in our database provider's backups, and is then gone for good.
Your rights
Under Québec law you may, at any time:
- access the personal information we hold about you;
- have it corrected if it is inaccurate or incomplete — your name and preferences can be edited in the portal;
- receive a copy of it in a structured, commonly used format — the portal's Export my data button downloads it as JSON;
- delete your account and its data — from the portal's profile page;
- withdraw your consent, which means closing your account.
For anything the portal does not do for you, write to privacy@mubold.com. We will answer within the time the law allows. If you are not satisfied, you may complain to the Commission d’accès à l’information du Québec (cai.gouv.qc.ca).
Security
Connections to the service are encrypted (HTTPS). Passwords and API keys are stored only as one-way hashes. Access to the systems is limited to the operator. The database credential is shared by Studio Mubold's own services (its other apps), all run by that same person. No system is perfectly secure; if a confidentiality incident ever presents a risk of serious injury, we will notify the people affected and the Commission d’accès à l’information, as the law requires.
Cookies and browser storage
This public site sets no cookies and stores nothing in your browser.
The portal sets no cookies of its own. It keeps these in your browser's local storage: your sign-in token, your theme and language choices, the fact that you accepted the storage notice, and, for error reports, a random identifier and any report not yet sent. Signing out removes the sign-in token; clearing your browser's site data removes the rest. To take payments, the portal loads Paddle's checkout script from Paddle, and Paddle sets cookies during checkout under its own policy.
Children
Portal accounts are for businesses and for people 16 or older. We do not knowingly collect personal information from children.
Changes to this policy
If we change this policy, we will update the date at the top of this page. For significant changes, we will tell account holders by email or in the portal at least 30 days before they take effect.