Legal
Privacy Policy
Last updated September 30, 2026Also in Português · Español
This translation is here to help. The Portuguese version is the one that binds.
In short
- What you share is read by an AI (Google Gemini) to become a card. Only you can see your collection.
- We don’t sell data and we don’t run ads. We measure how the app is used with events that don’t carry what you save.
- Media files are kept in private storage and only open through temporary links.
- You can delete your account, and everything it stored, from inside the app.
On this page · 17
1Who we are
Munvi is a product developed and operated by GHM CONSULTORIA EM TECNOLOGIA DA INFORMAÇÃO LTDA (CNPJ 46.248.650/0001-51), based in Uberaba, Minas Gerais, Brazil (“Munvi”, “we”, “us”). “You” means anyone who uses the app or the website. We are the controller of the personal data described here, under Brazil’s General Data Protection Law (Lei 13.709/2018, “LGPD”).
Get in touch at oi@munvi.app. This is also the channel for our data protection officer (encarregado).
2What Munvi does
You share a link with Munvi (an Instagram, TikTok or YouTube post, a web page or a place on Google Maps) or an image from your device. Munvi reads the public content of that link, uses an artificial intelligence model to write a card (title, summary, ingredients, preparation steps, place, duration, tags) and saves the card in one of your folders. Then you can search, ask the assistant, mark what you’ve tried and share cards by link.
3Information we collect
Account. Email, name and photo from your Google profile, received when you sign in with Google. We don’t store a password.
Saved content. The links and images you send; the video, images, caption or page text obtained from them (YouTube videos are not downloaded: Google watches them on YouTube itself); the thumbnail; the generated card, with the transcript of what is said and the places on the map; your edits, notes and their photos; your folders, tags, favorites, “tried it” marks and shopping list; the items in the trash.
Assistant. The questions you ask the assistant and the answers it generates.
Sharing. The share links you create: for which card, when and, if applicable, when they stopped working.
Notifications. Your device’s notification token and your time zone, so we can send alerts and reminders at the right time.
Technical data. App version, error logs and the IP address in server logs, for a limited time.
App usage. Events about what happens in the app, not about what you save: opening the save screen, saving an item, opening an item, searching, starting and finishing cook mode, talking to the assistant, creating a folder, completing the introduction, signing in, opening a notification and, on our side, sending a reminder or email and unsubscribing from email. Each event carries counts, durations and the source platform, never titles, links, the text of your searches or the identity of a specific item. They are tied to your account’s identifier, not to your name or your email.
We don’t use ad networks, screen recording or automatic capture of screens and taps.
4How we use the information
- Running the service: downloading, processing, storing, searching and showing what you saved.
- Letting you know: when a card is ready, when an item failed.
- Reminding you of what got left behind: at most one message a week, with an item you saved and haven’t opened, a summary of the week or a note when you have been away for a while. Reminders that go unanswered space out and stop. You can turn them off in the app’s Settings or in your device’s notification settings.
- Emailing your account’s address: a welcome, a reminder if your collection stays empty and the app cannot send you notifications, a reminder if you are away for a month, and a confirmation when the account is deleted. Both reminders carry a link to stop receiving them, and you can turn all of them off in Settings.
- Suggesting a folder when several loose items seem to be about the same subject.
- Keeping the service secure and fixing errors.
We don’t sell your data. We don’t use what you save to train AI models.
5App permissions
Notifications. To let you know when an item is ready or didn’t work out, and for reminders. If you decline, the app works the same, without the alerts.
Camera and photos. Only when you choose to take or pick a photo, to save an image or add it to an item’s note. Gallery photos are picked in the system picker, and the app only sees the ones you chose. The photo’s location and other metadata are removed before it is stored.
Exact alarms (Android). So the cook mode timer rings on time with the app closed. We ask the first time you use a timer, and it is optional.
Clipboard. When you open the save screen or the introduction, the app checks for a copied link to offer to paste it. The text only leaves your device if you save the link.
The app doesn’t ask for access to your location, your contacts or the microphone.
6How processing works (AI and third parties)
To write the card, we send Google Gemini (Google LLC) the content of what you saved: the post’s video or images and caption, the YouTube video’s address, the page text or the image you sent. For the assistant to answer, we send your question and a catalog of your items (titles, summaries, ingredients). We use the paid Gemini API, and under its terms Google doesn’t use this data to train or improve its products.
To measure app usage we use PostHog (PostHog, Inc.), whose data is hosted in the United States. We send it only the events described in “App usage”, identified by your account’s identifier. This transfer is based on the data processing agreement (DPA) signed with PostHog.
To put a card’s places on the map, we send each place’s name and city to Google Maps Platform (Google LLC), which returns its location. Searches you make when looking up a place in the app also go through it.
To send email we use Resend, which receives your email address, your name and the message, which may include titles and covers of items you saved.
We also use providers for hosting, file storage, notification delivery and error monitoring, which process data only on our behalf and under contract.
The sources (Instagram, TikTok, YouTube, the websites you save, Google Maps) are not our partners. We only fetch the public content of the link you shared; we have no access to your account on those platforms.
7Media files and visibility
Videos, images and thumbnails are kept in private storage. The app opens them through signed links that expire within a day, generated only for whoever has access to the item.
When two people save the same post, the file is stored only once and shared between the two accounts. That’s why deleting your item doesn’t delete the file while another account still references it (see “Account deletion”).
8Sharing a card
When you share a card, Munvi creates a public link. Anyone with the link sees a preview: the title, the post’s author, your display name (never your email), the cover and part of the card. Whoever opens the link with Munvi sees the whole card and can save a copy to their own collection; that copy becomes theirs, and deleting your item doesn’t delete it.
Your personal note and its photos never go along, nor do images Munvi identifies as sensitive (nudity, for example): in that case, only the card goes. The link stops working when you delete the item; to turn off a link without deleting the item, write to oi@munvi.app.
9Retention
- Your account and your collection are kept for as long as the account exists.
- Deleted items go to the trash and are permanently deleted after 30 days, or sooner if you empty the trash.
- Encrypted database backups are kept for 30 days.
- Processing and error logs are deleted within 90 days.
10Account deletion
You can delete your account inside the app, under Profile. Deletion removes your folders, items, cards, share links, notification tokens and the account, all at once. Media files are deleted when no other account references them; if someone else saved the same post, the file continues to exist for them. Backups expire on their own within 30 days.
11Your rights (LGPD)
You can request confirmation that your data is processed, access to it, its correction, anonymization or deletion, portability, information about who we share it with and the withdrawal of your consent. Write to oi@munvi.app; we reply within 15 days. To take your data with you, use “Export my data” in Profile, which creates a file with your whole collection.
Legal bases we rely on: performance of a contract (running the service you asked for), legitimate interest (security, fixing errors, reminders and emails) and consent (notifications, given through your device’s system).
12Children and teenagers
Munvi is for people aged 18 or older. We don’t knowingly collect data from people under that age; if you know of such an account, let us know at oi@munvi.app and we’ll remove it.
13International transfers
Our servers, the database and the files are in the United States, as are Google (Gemini and Maps) and PostHog. These transfers follow article 33 of the LGPD, based on the providers’ contractual clauses.
14Security
Sign-in through your Google account, with no password stored by us, traffic over HTTPS only, files in private storage, your session kept in your device’s secure storage, encrypted backups (AES-256) and restricted access to the infrastructure. No system is infallible; if we discover an incident that affects you, we’ll let you know.
15Cookies and website
The app doesn’t use cookies. It uses the PostHog SDK to send the events described in “App usage”, and nothing else. The munvi.app website uses no analytics tools and no advertising cookies: it only keeps a cookie with the language you chose and, in your browser, the light or dark theme.
16Changes
When we change this policy, we update the date at the top and let you know in the app when the change is significant.
17Contact
oi@munvi.app