Privacy Policy
Last updated 15 August 2026
MOVO is a super-app for chat, calls, communities, wallet, marketplace, and the investor portal. This policy explains, in plain English, what we collect across those surfaces, why we collect it, and the control you keep over it.
Overview
MOVO is a super-app that combines real-time chat with cross-language translation, voice and video calls, communities, a wallet built around MCoin with card, bank and crypto top-ups, a marketplace, and an investor portal. This policy explains what we collect when you use any of those surfaces, why we collect it, and the control you keep over it.
It is written in plain English on purpose. Whenever we refer to “MOVO,” “we,” “us,” or “our,” we mean the operator of the MOVO mobile app, the movochat.com website, and the connected backend services. “You” means the person using them.
What we collect
We only collect what we need to run the product you signed up for. The categories below cover every surface of MOVO — messaging, translation, calls, wallet, marketplace, communities, and the investor programme.
- Identity data — your name, username, date of birth, phone number, email address, profile photo, and the country you registered from. If you sign up as an investor or a business, we also collect the legal entity name and role.
- Chat metadata — who is in a conversation, timestamps, delivery and read receipts, message size, media type, translation language pairs you chose, and the community or room a message belongs to. Regular chats are stored on our servers so they sync across your devices; chats opted into Secure Mode are end-to-end encrypted and we cannot read their content.
- KYC documents — government ID, selfie, proof of address, and, for higher tiers or investor onboarding, source-of-funds statements. These are handled by our verified-identity workflow and only used for compliance checks.
- Payment metadata — wallet balance, MCoin ledger entries, top-up and withdrawal history, payout destinations, escrow states, marketplace orders, and the tokenised references our payment processors return. We do not store your full card number or CVV — those live with the processor.
- Device and technical data — device model, operating system version, app version, language, time zone, IP address, push notification token, and crash and diagnostic logs.
- Optional data you choose to share — contacts (only when you grant permission, and only to find friends already on MOVO), location (only when you attach it to a message or search nearby listings), and any content you publish in communities, marketplace listings, or audio rooms.
How we use it
Every use of your data ties back to one of a small number of purposes. If we ever need to use your data for something outside this list, we will ask you first or update this policy and tell you.
- Deliver the service — route messages and calls, sync your chats across devices, host your communities and audio rooms, process wallet transactions, publish and browse marketplace listings, and run the investor portal.
- Translation on your behalf — when you translate a message, the text is sent to our self-hosted Argos translation infrastructure so we can return a translated version to you. The original text is not shared with any third-party AI vendor and is not used to train external models.
- Fraud, abuse and safety — detect account takeover attempts, unusual payment activity, marketplace scams, spam, and violations of our Terms. We use device signals, transaction patterns, and reports from other users to do this.
- Legal and regulatory compliance — verify identity for KYC and AML purposes, keep transaction records for the periods required by financial regulators, respond to lawful requests from authorities, and enforce sanctions screening.
- Product improvement — measure which features are used, diagnose crashes, and prioritise fixes. Where we can use aggregated or de-identified data for this, we do.
- Communicate with you — send transactional messages (security alerts, payment confirmations, KYC status, investor updates you subscribed to). Marketing messages are opt-in and you can unsubscribe at any time.
Third parties we work with
We do not sell your personal data. We do share limited information with the vendors and partners that make MOVO work. Each of them is bound by a written agreement and only receives what is strictly needed for their piece of the service.
- Payment processors — Stripe and equivalent regional processors handle card top-ups, bank withdrawals, and payout rails. They receive the payment details needed to complete the transaction; we receive the processor’s tokenised reference and status back.
- Translation infrastructure — our self-hosted Argos translation servers, run on infrastructure controlled by MOVO. Message text sent for translation is processed there and is not shared with a third-party AI vendor.
- Crypto custody and on/off-ramps — regulated custodians and liquidity partners that hold or move digital assets on behalf of users who choose crypto top-ups and withdrawals.
- Communications infrastructure — email delivery (Mailgun), SMS one-time codes (Prelude), and push notifications (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS).
- Hosting and storage — DigitalOcean for compute and DigitalOcean Spaces for media and file storage.
- Analytics — privacy-respecting product analytics used to understand feature usage in aggregate. See the Cookies and analytics section below.
- Legal and safety — courts, regulators, and law-enforcement agencies where we are required by law to disclose information, and professional advisors under a duty of confidence.
Retention
We keep your data only as long as we need it. Different categories have different clocks, driven either by product need or by law.
- Account data is kept while your account is open. When you delete your account, we begin a 7-day grace window — during that window you can cancel the deletion — after which we delete or de-identify the account.
- Chat content is stored while your account is active. Secure Mode messages sit only on your devices; if you lose all devices, they are gone.
- Payment and wallet records are retained for the period required by financial regulators (typically five to seven years after the last transaction), even after account deletion.
- KYC documents are retained for the period required by AML law in the region that verified you.
- Backups are rotated on a fixed schedule and are eventually overwritten. Deletion requests propagate to backups on the next rotation cycle.
- Crash and diagnostic logs are retained for 30 to 90 days.
Your rights
Depending on where you live, data-protection law (UK GDPR, EU GDPR, CCPA, and equivalents) gives you rights over the data we hold about you. MOVO honours these rights globally as a matter of policy, not only where the law compels us to.
- Access — request a copy of the personal data we hold about you.
- Erasure — delete your account and its associated personal data, subject to the retention rules above where financial or KYC law requires us to keep certain records.
- Portability — receive a machine-readable export of the data you have given us, including your profile, contacts you added, and marketplace listings you published.
- Rectification — correct anything that is inaccurate or out of date from inside the app.
- Object or restrict — tell us to stop or limit a specific use, such as marketing or non-essential analytics.
- Withdraw consent — turn off any permission (contacts, location, notifications) at any time in the app or in your device settings.
- Complain — lodge a complaint with your local data-protection authority. In the UK that is the Information Commissioner’s Office (ICO).
International transfers
MOVO operates globally, which means your data may be processed in a country other than the one you live in — for example, so a European user can call a friend in Asia and reach them in near real time.
When we transfer personal data out of the UK or the European Economic Area, we rely on the safeguards recognised under UK and EU law: adequacy decisions where they exist, and Standard Contractual Clauses (with the UK Addendum where relevant) with every vendor and internal entity that receives the data. Custodians and payment partners are chosen from regulated jurisdictions.
Changes to this policy
We update this Privacy Policy when the product changes or when the law changes. When we make material updates — for example, adding a new category of data or a new processor — we revise the “Last updated” date at the top and, where the change materially affects you, notify you in the app or by email before it takes effect.
Older versions are available on request so you can see what changed.
Contact
If you have a question about this policy, want to exercise one of your rights, or want to raise a privacy concern, get in touch and we will respond.
- Email: privacy@movochat.com
- Website: https://movochat.com
- Postal: MOVO Legal, London, United Kingdom