Privacy Policy
1. Data Controller
The Data Controller for your personal data is SpectroSec di Alan Ferraioli (VAT No. 04269550366), with registered office at Via Martiri della Libertà, 41033 Concordia sulla Secchia (MO), Italy. Contact email: [email protected]. "Mimmo Engine" is a product/brand of the Data Controller. This policy is provided pursuant to Articles 13 and 14 of EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003.
2. Legal Basis for Processing
We process your personal data based on the following legal grounds (Art. 6 GDPR):
- Performance of a contract (Art. 6.1.b): Account registration, profile management, service provision, payment processing
- Consent (Art. 6.1.a): Analytics cookies (Google Analytics, Microsoft Clarity), Google OAuth sign-in, AI features usage
- Legitimate interest (Art. 6.1.f): Service security, fraud prevention, service improvement, anonymized analytics
- Legal obligation (Art. 6.1.c): Tax and regulatory compliance, accounting record retention
3. Data We Collect
We collect the following types of personal data:
- Registration data: Name, email address, password (securely hashed)
- Payment data: Processed entirely by Stripe Inc.; we do not store credit card data on our servers
- Usage data: Pages visited, features used, interactions with the service
- Anonymous desktop app data: random installation and session identifiers, version, operating system and language, used to understand how many people use the editor and for how long. They cannot be linked to an account or a person, and your project content never leaves your computer. The country travels with it, already resolved by the hosting infrastructure: the IP address is not stored.
- Technical data: IP address, browser type, operating system, access timestamps
- AI data: Text content sent to AI services AI service for assisted dialogue generation (only upon your explicit action)
- Google OAuth data: Name, email, and avatar provided by Google when you sign in via your Google account (Art. 14 GDPR, data collected from third parties)
- Download data: product and version downloaded, platform, referring page, country and browser string. The country comes from our hosting infrastructure; the IP address is not retained. The downloaded file's name contains a random identifier, used only to tell whether that download became an installation: it does not identify the person and is not linked to any account. Basis: legitimate interest (Art. 6.1.f), to understand which operating systems are actually needed
- Email address for the download link: if you are on a phone and ask us to email you the download page, that address is used to send that single message. It is not stored and it is not added to any list. Basis: legitimate interest (Art. 6.1.f), so that someone who finds the site on a phone can install it later on a computer.
- Data from reports sent from the editor: app version, operating system, language, screen resolution, a numeric summary of the project (how many scenes, characters and variables) and, if you write it, your email address so we can reply. Project content is not sent. Basis: legitimate interest (Art. 6.1.f), to fix the defects reported. The country travels with it, already resolved by the hosting infrastructure: the IP address is not stored.
- Automatic crash reports from the editor: when the app crashes, the error message and technical trace are sent, with version, system, language and the random installation identifier. System paths and email addresses are stripped before sending, no project content is sent, and the reports can be turned off in the editor settings. Basis: legitimate interest (Art. 6.1.f), to notice crashes nobody reports. The country travels with it, already resolved by the hosting infrastructure: the IP address is not stored.
- First-session milestones: when you create a project, add a character, create a scene, write a line of dialogue, start the preview or attempt an export, we receive only the name of the step reached and when it happened, together with the random installation identifier. Nothing you wrote is sent: no titles, no character names, no dialogue. Each step is recorded once. It tells us where people who try the editor and never come back are stopping. Basis: legitimate interest (Art. 6.1.f), to improve the first minutes of use.
4. Purposes of Processing
We use your data for the following specific purposes:
- Provide, maintain, and improve the Mimmo Engine service
- Process payments and manage subscriptions through Stripe
- Send service-related communications (updates, technical support)
- Comply with legal, tax, and regulatory obligations
- Ensure service security and prevent fraud and abuse
5. Data Recipients and Sub-processors
We do not sell your personal data. Your data may be shared with the following third-party processors acting as data processors (Art. 28 GDPR):
- Supabase Inc. (USA), Database and authentication, Legal basis: contract (Art. 6.1.b), Safeguards: Standard Contractual Clauses (SCCs)
- Stripe Inc. (USA), Payment processing and financial data, Legal basis: contract and legal obligation, Safeguards: SCCs
- Google LLC (USA), OAuth authentication and Google Analytics, Legal basis: consent (Art. 6.1.a), Safeguards: EU-US Data Privacy Framework (DPF)
- AI service providers (USA/EU), AI services for assisted text generation, Legal basis: consent / legitimate interest, Safeguards: SCCs and DPA
- Resend Inc. (USA), Transactional email delivery, Legal basis: contract, Safeguards: SCCs and DPA
- Vercel Inc. (USA), Hosting, CDN, and performance analytics, Legal basis: legitimate interest, Safeguards: Vercel DPA
- Cloudflare Inc. (USA), DNS, DDoS protection, security and @mimmoengine.com email routing, Basis: legitimate interest, Safeguards: SCCs
- Microsoft Corp. (USA), Microsoft Clarity (heatmaps and session recording), Basis: consent (Art. 6.1.a), Safeguards: SCCs and DPA
- Competent authorities, When required by Italian or European law
6. International Data Transfers
Your data may be transferred to countries outside the European Union, particularly to the United States. For each transfer, we adopt adequate safeguards pursuant to Art. 46 GDPR, including: Standard Contractual Clauses (SCCs) approved by the European Commission, EU-US Data Privacy Framework (DPF) where applicable, and a signed Data Processing Agreement (DPA) with each sub-processor. You may request a copy of the safeguards by writing to [email protected].
7. Data Retention Periods
We retain your data only for the time strictly necessary for the processing purposes:
- Account data: For the duration of the contractual relationship, and up to 30 days after account deletion
- Accounting and payment data: 10 years from the transaction (Italian tax obligations)
- Technical and security logs: 90 days
- Analytics data: 26 months (Google Analytics 4 configuration)
- Data sent to AI: Not retained after response generation
8. Your Rights (Art. 15-22 GDPR)
As a data subject, you have the following rights:
- Right of access to your personal data (Art. 15)
- Right to rectification of inaccurate or incomplete data (Art. 16)
- Right to erasure, right to be forgotten (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability in a structured, readable format (Art. 20)
- Right to object to processing (Art. 21)
- Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7.3)
- Right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) pursuant to Art. 77 GDPR
To exercise your rights, send a request to [email protected]. We will respond within 30 days of receipt.
9. Artificial Intelligence and Automated Processing
The service uses artificial intelligence systems (AI services) to assist in generating dialogues and text within the editor. This processing: (a) occurs only upon your explicit action; (b) does not produce automated decisions with legal or significant effects (Art. 22 GDPR); (c) is not used for user profiling. Content sent to AI is used solely to generate the requested response. You have the right not to use AI features and to object to this processing by contacting us.
10. Cookie Policy
The site uses the following categories of cookies:
- Technical cookies (necessary): Session, authentication, language preferences, cookie consent, Always active, no consent required
- Analytics cookies (Google Analytics 4, Microsoft Clarity): Activated ONLY after your explicit consent via the cookie banner, You can revoke consent at any time
- Payment cookies (Stripe): Used exclusively on the payment page for secure transaction processing
- Cookie-free traffic measurement (Vercel Analytics): aggregate page view counts, with no cookies and nothing that identifies a person. Active for everyone: where there is neither a cookie nor an identifier, no consent is required.
11. Processing Security (Art. 32 GDPR)
We adopt appropriate technical and organizational measures to protect your personal data, including: encryption of data in transit (TLS 1.2/1.3 with HSTS preload), secure password hashing, Content Security Policy with nonce for XSS prevention, anti-bot protection, API endpoint rate limiting, and data access based on the principle of least privilege.
12. Minors
The service is intended for users at least 14 years of age (Art. 8 GDPR and Italian law). We do not knowingly collect personal data from children under 14. If you believe a minor has provided personal data, contact us for immediate removal.
13. Changes to this Policy
We may update this privacy policy. In case of substantial changes, we will notify you by email or a prominent notice on the site. The date of the last update is shown at the bottom of the page.
14. Data Controller Contact
To exercise your rights, for questions about the processing of your personal data, or for any request related to this policy, contact the Data Controller SpectroSec di Alan Ferraioli, Via Martiri della Libertà, 41033 Concordia sulla Secchia (MO), Italy, at:
Last updated: 30/07/2026