Minfis
Try it

Privacy policy

Last updated August 3, 2026

1. Data controller

ANOMONUS - FZCO (Free Zone Company with limited liability). Address: DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates. Contact: [email protected].

We process personal data in line with the UAE Personal Data Protection Law (PDPL), and also with regard to GDPR principles for visitors from the EU.

2. What we collect

  • Account: e-mail address and password hash. With Google or Apple sign-in, your provider account identifier (sub) and verified e-mail (for Apple this may be a private relay address @privaterelay.appleid.com); we never see your provider password. With phone sign-in, your phone number (the verification code is delivered via Telegram Gateway).
  • Name: if you provide it.
  • Project content: site boundaries (polygons), the criteria you set, and computed results.
  • Token ledger: the history of token credits, debits and related payments.
  • Assistant chat: your messages to the criteria assistant and its replies.
  • Technical data: IP address, request timestamps and browser type — in server logs and for brute-force protection.
  • Payment data: the make-up and status of a payment. Card details are handled by the payment provider and never reach our servers.
  • Rendered images and booklets: photoreal frames of your project and the assembled PDF booklets are stored so you can open them by link later. The render gallery link does not require signing in — knowing the address is the access — so do not publish it if the project is not meant for others.
  • Sign-in and session log: the time, IP address and a description of the device/browser for each active session — so you can see and end sessions you do not recognise in the Account section.
  • Voice input: the microphone button in the project assistant uses your browser’s built-in speech recognition. The audio is handled by the browser and, in some browsers (Chrome in particular), sent to that vendor’s servers — we neither receive nor store audio; only the recognised text reaches us, and you can edit it before sending.

3. Why, and on what basis

We process data to provide the service (performance of a contract): to compute results, keep your projects, credit and debit tokens; for security and abuse prevention (legitimate interest); and to meet record-keeping obligations. We do not sell data or share it for advertising.

4. Processors we use

Only to sub-processors the service depends on:

  • Mapbox maps and tiles, address search, the land-cover check and the static site image for the booklet. Plot coordinates and the search string are sent.
  • OpenAI the language model behind the AI assistant and the written concept description. The TEXT you type yourself — a question to the assistant, the wording of a project edit — is sent, together with the project’s parameters and figures. Account data — e-mail, phone, payment details — is not sent. Do not type into the assistant anything you would not want passed to a third-party service.
  • Stripe card payment processing. Card details are entered on Stripe’s side and never reach us; we store only the customer and subscription identifiers.
  • Resend e-mail delivery (verification codes, payment receipts, notices that a booklet or a render set is ready). Your e-mail address and the message content are passed on.
  • Telegram Gateway delivery of the verification code when signing in by phone number. Your phone number is passed on. Used only if you choose that sign-in method.
  • OpenStreetMap services Nominatim (address search and resolving the city for a plot), Overpass (surrounding buildings, land-cover check) and opentopodata (terrain). Plot coordinates and the search string you typed are sent; no account data is. These are public non-commercial services.
  • Render server a separate machine that computes the photoreal presentation renders. Your project’s scene geometry is sent to it (no account data). The machine is rented by us and is not a public service.
  • Backblaze B2encrypted database backups.
  • Cloudflareproxy, DDoS protection, caching.
  • Googlesign-in via Google account (OAuth), if you use it.
  • AppleSign in with Apple, if you use it.

5. Retention

By category:

  • Account and projects — until you delete them. A deleted project is purged after 30 days (a window in case you change your mind).
  • Token-ledger records — kept after account deletion, but anonymised and unlinked from you: they are immutable by design and required for financial accounting.
  • Ended sign-in sessions — 90 days.
  • Log of sent e-mails — 90 days.
  • Stored PDF booklets — 30 days (a cache: the booklet is rebuilt from the project on demand).
  • Server technical logs — up to 90 days.

6. Your rights

You may exercise your right of access, rectification, erasure, restriction of processing, objection to processing based on legitimate interest, and portability — receiving your data in a machine-readable form. Deletion is available to you directly in the Account section: your profile and projects are erased, while financial records are anonymised and kept unlinked to you, as accounting requires. For other requests write to [email protected].

We answer such requests within 30 days. If you are in the EU or the UK, you have the right to lodge a complaint with the supervisory authority where you live. We have not appointed an EU representative under GDPR Article 27: we do not specifically offer goods or services to EU residents and do not monitor their behaviour. Should that change, a representative will be appointed and named here.

7. International transfer

Our sub-processors may process data outside your country of residence. We choose providers that maintain an adequate level of data protection.

8. Cookies

We use strictly necessary cookies only. See the Cookie Policy.

9. Contact

Data protection enquiries: [email protected].