Privacy Policy
This Policy explains the information involved when you use MUVO, why it is processed, and the controls currently available. It covers the app, website, and support communications.
1. Who is responsible
SAVCO YATIRIM HOLDİNG ANONİM ŞİRKETİ, based in Türkiye, operates MUVO and is the controller responsible for the processing described here. Our full address and contact details appear below. Apple and services you independently choose when sharing content may also process information under their own privacy notices.
2. Information we process
- Account and security information: sign-in and MUVO account identifiers, authentication/session information, device-verification records, and information needed to protect account access. Sign in with Apple provides identity information when you choose to link or sign in with Apple; MUVO does not receive your Apple password. Guest accounts also use account and device credentials to maintain access.
- Creative inputs and results: descriptions, selected styles and settings, titles, lyrics, uploaded recordings, self-portraits, drafts, generated audio, stems, reference images, storyboards, videos, editing settings, and the history and status of your creation requests.
- Purchases: purchase and subscription identifiers, product and transaction details, renewal and cancellation events, refunds, restoration, membership status, credit balances and movements, and any credit debt. Apple handles App Store payments; MUVO does not receive your full payment-card details from those purchases.
- Device and usage information: network IP addresses, device/session identifiers, app and operating-system versions, device model, feature interactions, and technical errors. Analytics, attribution, notification and diagnostic processing are explained separately below.
- Support and privacy requests: your email address, message, relevant account or problem identifier, and information needed to verify and respond to the request. Please send only what is necessary.
Information comes from you, your device and app activity, Apple sign-in and purchase services, and services that process your requests. Media you upload may contain other people's personal information. Upload only material you are entitled to use and disclose.
Self-portrait features process your appearance and visible face and mouth to create reference images and synthetic performances. Audio features can process voices contained in uploaded recordings. These are not a request to enroll a face or voice as an account-authentication method. Complete the rights and consent checks before submitting media.
3. Purposes and legal bases
We process information to authenticate you, operate your library, carry out requested creation and editing, provide playback and downloads, verify purchases, maintain credits and subscriptions, deliver alerts, diagnose failures, measure product use and acquisition, respond to requests, and protect the service against misuse.
Account and creative information is needed for the associated account or creation feature; transaction information is needed to deliver and reconcile purchases. If you do not provide information needed for a particular action, that action may be unavailable. Optional notification and Apple tracking choices do not determine whether you can create music.
- Requested services: account access, library storage, generation and editing, purchase verification and credit administration involve processing necessary to perform the service agreement with you.
- Legal obligations: information necessary to meet applicable accounting, tax and legal-response requirements is processed to comply with those obligations.
- Claims and security: information necessary to establish, exercise or defend legal claims, prevent unauthorized access and investigate misuse is processed on the applicable legal-claims ground or legitimate-interest ground, subject to the safeguards and balancing required by local law.
- Support and privacy requests: we use your message and relevant account information to provide the help you request under our service agreement, and to comply with legal duties when you exercise a statutory privacy right.
- Consent: where the law requires consent, it must cover the relevant processing and be capable of withdrawal. Agreement to the Terms or acknowledgment of this Policy does not by itself supply that consent.
Product analytics and attribution operate as described below. Notification service setup can begin before permission to display alerts, and uploaded media can contain sensitive information. The current app controls do not provide separate consent for every processing purpose. We have not established a legal basis for all of these activities in every region where MUVO may be used.
4. Services that receive data
MUVO uses the following categories of services. Their access depends on the feature and data involved:
- Cloud hosting, authentication, database and storage services process account records, creative content, transactions, and network requests to run the app and website and store your library.
- AI text and music services receive the creative text, settings, lyrics, and any source audio needed for drafting, song generation, and instrument additions.
- Audio-analysis and separation services receive selected recordings or generated audio, and lyrics where needed, to create stems or synchronize lyrics.
- AI image and video services receive relevant creative instructions, portraits and reference images; lip-sync processing also receives the selected audio. Different stages can use different services.
- Purchase and subscription services receive an opaque account identifier and transaction information to verify purchases, manage membership, and reconcile credits. Apple processes App Store purchases and the related payment information.
- Analytics, attribution, notification and diagnostic services receive the information described in the following sections.
- Email and support services process your communications. Authorized staff can access information needed to handle support, privacy, security and operational tasks. Information may also be disclosed where required by law or necessary to address legal claims, subject to applicable law.
MUVO's library media is held in private object storage and accessed through short-lived links. This does not mean that AI processing takes place only on your device or that every processing service has the same retention or media-delivery controls. Exporting or sharing sends a copy to the destination you choose, where its own rules apply.
AI services process content outside your device. We have not verified every downstream processing location, the retention of every service copy, or every model-specific exception to restrictions on training. We do not promise that all services exclude model training or immediately delete content after processing.
Our music-generation service's API terms prohibit using submitted inputs and generated results to develop or improve that service. The audio-alignment workspace's model-improvement permission is switched off. These restrictions do not mean that processing leaves no records, and an opt-out does not undo uses that occurred before it took effect. Technical usage records and creative content can be subject to different rules.
5. Product analytics and advertising attribution
When you use MUVO, we collect product analytics to understand how features are used, identify problems, and improve the app. Collection starts after you tap Continue on the first-launch screen linking to the Terms and this Policy. The app stores the acknowledgment version and time on your installation. There is currently no in-app analytics toggle. Acknowledging this Policy does not by itself provide any separate consent required by law.
Product analytics measures feature interactions and newly displayed problems using app, operating-system and device-model information and service-generated device, delivery and session identifiers. After sign-in, it also uses a MUVO account identifier. The analytics service receives your network IP address and derives approximate country, city, region and advertising-market area.
Data, including approximate location, can be linked to the MUVO account identifier after sign-in. MUVO does not request GPS or precise location for this purpose. This analytics integration processes data in the United States.
The app's product-analytics events exclude creative text, lyrics, media, URLs, file paths, raw errors, and purchase or generation identifiers. This exclusion is specific to events sent by the app; creative services necessarily process the inputs required for creation.
RevenueCat also sends purchase and subscription events to Amplitude for product and revenue analytics. These server events include purchase amounts, currency, products, transaction and customer identifiers, subscription changes, and customer attributes held by RevenueCat. We associate them with the MUVO account identifier used for app analytics. Subscription events can be sent while the app is closed.
An attribution service measures installs, sessions, first successful Apple sign-in, first draft creation, first successful newly initiated song generation, and accepted song, clip, and directed-video full-render generations. The app sends event identifiers and random deduplication values for those conversion events. The purchase service receives an attribution identifier and forwards configured purchase information, including gross storefront value and currency, to measure purchases and acquisition.
Attribution matching: our backend receives Adjust installation and attribution callbacks. Starting with v1.0.1, MUVO can associate Adjust device identifiers with your account. When attribution syncing is enabled, we use this association to add initial and current network, campaign, ad group, creative and attribution time to that account in Amplitude. When provided by Meta through Adjust, these properties also include campaign, ad-set and ad names and IDs, and a creative ID. A device identifier associated with different accounts remains unresolved. This helps compare acquisition with later app activity; it does not duplicate purchase events or assign aggregate-only attribution to individuals.
After release, we plan to share app activity, including purchase events and purchase amounts, through our attribution service with an advertising platform to measure advertising performance, build advertising audiences, and show ads again to people who have interacted with MUVO. This advertising-platform connection is not currently enabled.
The app requests Apple's tracking permission directly. If you deny permission or it is restricted, the app receives no usable Apple advertising identifier. The app keeps attribution partner sharing enabled independently of that choice. Delivery to advertising partners depends on the configured integrations and their handling of tracking permission. That choice does not disable every install, session or attribution measurement, and it does not erase existing records. Changing Apple's tracking choice does not change the core app features available to you.
6. Notifications and diagnostics
For generation alerts, the first accepted free draft or paid creation triggers setup with a push-notification service and Apple's notification permission request. Service setup can begin before you decide whether to allow alerts. The service processes an opaque notification identity and device, permission, app and push-subscription information. Permission to display alerts is separate from that service processing.
Alerts can contain your song title and appear on your lock screen according to your device settings. Notification routing uses opaque content identifiers to open the relevant item. You can disable alerts or change preview visibility in iOS Settings. Disabling visible alerts does not by itself promise erasure of notification-service records.
The app also sends technical crash, hang and selected failure diagnostics to a reliability service in the European Union. These include stack and binary information, app/OS versions, device model, bounded failure categories and, for certain server failures, a request identifier. The app filters out creative content, user and request objects, arbitrary error text, screenshots, recordings, and URLs from this diagnostic stream. Network connections still expose an IP address to the receiving infrastructure.
7. International processing
MUVO is operated from Türkiye. Its primary database project is in the United States, and the API and processing services are configured for the United States. The documented product-analytics location is also the United States; the diagnostic-service location is the European Union. Other processing and support locations depend on the services involved. Your information may therefore be processed outside your country, including outside the EEA or UK when you are located there.
Our business email, diagnostic, and audio-alignment services are covered by data-processing agreements governing their handling of information on our behalf, including security, deletion, and assistance with privacy requests.
You can request information about the recipients of your data and copies or details of applicable transfer safeguards using our privacy contact below.
We have not confirmed transfer safeguards for every international data flow. The agreements described above do not establish that all transfers are covered by an adequacy decision, standard contract or other required transfer mechanism.
8. Retention and deletion
- Library and creative content: retained for your use until deletion is requested. Deletion removes access and schedules cleanup; active work and related media dependencies can delay physical removal.
- Account and local data: account deletion clears the current app profile's downloaded media and relevant caches and schedules account-identity removal. Exported copies and copies shared elsewhere are outside that cleanup.
- Account-linked purchase and credit records: we currently keep these records for as long as MUVO continues operating, including after account deletion, for transaction reconciliation and handling purchase or credit disputes. Account deletion does not automatically erase this history. Applicable rights to request erasure or restriction remain available.
- Notification delivery and late-result matching records: the documented cleanup rules purge terminal notification delivery records and expire limited deleted-content callback identifiers after 30 days. This is not a 30-day deadline for deleting every category of data.
- Analytics and attribution at providers: existing provider records are not automatically erased by ordinary MUVO account deletion and currently have no configured automatic age-based deletion period. Separate verified erasure requests require support handling.
- Planned backend attribution matching: callback payloads will be kept for 30 days after receipt. Active account mappings and attribution snapshots will remain until account deletion, which will also remove pending delivery data. Minimal hashed device identifiers will remain without an automatic expiry to prevent late callbacks from recreating deleted associations.
- Support and privacy emails: we currently keep these messages without a fixed deletion schedule. Deleting your MUVO account does not automatically delete this correspondence. You may contact us to request erasure, subject to applicable legal conditions and exceptions.
- Diagnostic error events: retained for 30 days under the current diagnostic-service plan. This period does not apply to every category of operational or audit record.
- Hosting application logs: the current hosting plan provides a seven-day log window. This is separate from records held in the database and from the hosting service's own security and administrative records.
- Database backups: daily backups preserve earlier database records within a rolling recovery window of approximately one week. Deletion from the live database does not immediately remove those earlier copies. These database backups contain storage metadata, but do not include the uploaded or generated media files themselves.
- Music-generation service copies: that service's published API policy limits output retention to one month. This is separate from your saved MUVO library. Other records are retained under its service, legal, tax, and financial needs; the output limit is not a deadline for erasing all submitted inputs or related records.
Signing out or deleting the app is not a request to erase server-held information. Account deletion also does not cancel an Apple subscription. See the full deletion instructions for retained information and the separate privacy-request route.
We do not currently have a verified retention period for every audit, authentication, privacy-request verification or external AI-service record. Account deletion and external-service cleanup do not have a single confirmed completion period. The periods and practices above describe current handling; they do not limit applicable rights to request deletion or restriction.
9. Your existing controls
- Review creative inputs, media permissions and each paid quote before confirming.
- Use in-app content deletion or Account → Account details → Delete Account.
- Change notification permissions and previews in iOS Settings for MUVO.
- Change Apple's tracking permission in iOS Settings → Privacy & Security → Tracking.
- Contact us for access, correction, objection or erasure requests.
Where processing is based on consent, you may withdraw that consent without affecting the lawfulness of earlier processing. Contact us about a withdrawal request that the existing app controls do not support. The current app has no analytics withdrawal toggle; sending an email does not automatically stop SDK collection. Apple tracking permission is not a general control for product analytics or diagnostics.
10. Privacy rights and requests
Depending on the law that applies, you may have rights to learn whether we process your information, access it, understand its purposes and recipients, correct it, obtain a portable copy, request deletion or restriction, object to processing, and withdraw consent. Rights have legal conditions and exceptions; a request may not require deletion of a record that must lawfully be retained.
Under Turkish data-protection law, applicable rights include asking whether processing serves its stated purpose, learning about domestic or overseas recipients, requesting correction or lawful deletion and notification of those actions to recipients, objecting to an adverse result arising solely from automated analysis, and seeking compensation for unlawful processing. EEA and UK users may also complain to their competent data-protection authority; Turkish users may use the statutory complaint route to the Personal Data Protection Board.
Where applicable US state privacy laws cover the processing, additional rights may include opting out of sale, sharing or targeted advertising, limiting certain sensitive-information uses, appealing a request decision, and exercising rights without unlawful discrimination. An authorized agent may submit a request where permitted, subject to appropriate verification.
Email sacitemre@evalabs.studio or write to the company address below. Describe the right you want to exercise and the information involved. If available, include the User ID from Account → Account details; you can still contact us if you cannot access the app. We may need proportionate verification before disclosing or erasing account data. Do not send passwords, sign-in tokens, payment-card numbers, or identity documents in an initial email. Applicable statutory response periods and complaint rights remain available.
Where Turkish Law No. 6698 applies, requests must be concluded as soon as possible and within 30 days. Under the EEA GDPR, the usual response period is one month; a permitted extension of up to two further months requires notice within the first month. UK requests are subject to the corresponding statutory timetable and any legally permitted adjustment. These are privacy-rights response rules, not general support service guarantees or universal physical-erasure deadlines.
Our team handles privacy requests through the email and postal routes above. The app does not currently provide a dedicated sale, sharing or targeted advertising opt-out control. We have not appointed an EEA or UK representative. This Policy is currently available in English.
11. Website and support communications
These website pages use Google Analytics after you allow analytics through the cookie controls. Google receives page views, interactions such as scrolling, outbound and App Store clicks, campaign labels, cookie identifiers, browser and device information, and network information needed to receive those events. The website does not send MUVO account identifiers or creative content to Google Analytics. Analytics is not loaded before you make a choice or when you decline. Your choice is saved in this browser's local storage.
Choosing Accept all additionally allows Google advertising cookies and identifiers, ad measurement, personalized advertising and remarketing. Google signals can associate activity with information from signed-in Google users who allow Ads Personalization. Choosing Analytics only keeps advertising consent denied. You can change or withdraw your choice through Cookie settings in the footer; this stops future collection according to your new choice and removes the website's first-party Google cookies. It does not erase data already received by Google. See how Google uses information from sites that use its services and Google's ad controls. Signed-in Google users can access and delete activity associated with their Google account through Google My Activity.
The website does not provide account sign-in, purchase processing, or a deletion-request form. A small script carries supported campaign labels between product pages and into download links; visiting a page does not itself send an event to Adjust. The hosting infrastructure receives the network information needed to deliver pages. The static hosting service does not provide us with website access logs. Its own network and security processing is separate from the application-log window described above.
Download buttons may take you through Adjust before opening the App Store. When you follow one of these links, Adjust receives the request, including network and browser information and the campaign, source, and button-placement labels in the link, for download attribution. Static QR codes identify the website/QR placement rather than retaining your original campaign. A direct App Store link is also available on the download page.
Email links open your email service. Messages and attachments you choose to send are processed to handle your request. Links to Apple and other destinations take you to services with their own privacy practices.
12. Age and policy updates
MUVO is intended for people aged 18 or older who have reached the age of legal majority where they live. Do not use MUVO or submit self-portraits if you do not meet that requirement. Contact us if you believe a child has provided personal information so the situation can be assessed. This eligibility rule does not mean that the app verifies every user's age.
This Policy shows its version and effective date above. Changes to purposes or processing will require the information and any consent required by applicable law. An earlier app interaction does not establish consent to new processing.
Company and contact
MUVO is operated by SAVCO YATIRIM HOLDİNG ANONİM ŞİRKETİ (referred to as “MUVO,” “we,” or “us” in these documents).
Rüzgarlıbahçe Mah. Kavak Sok. No:12/2Beykoz, İstanbul, 34805, Türkiye
sacitemre@evalabs.studio
Tax office: Beykoz Vergi Dairesi
Tax number: 7531273218
Trade register number: 1002751
Use this contact for support, privacy requests, and legal notices. See our Terms of Use, Privacy Policy, Account Deletion instructions, and Support page.