Minfis
Попробовать

Политика конфиденциальности

Юридические документы доступны только на английском языке.

Minfis — minfis.com Revision 2026-09-13 · Last updated 9 September 2026

This policy explains what personal data the Minfis service collects, why we hold it, who else receives it, where it is stored, how long it stays and what you can ask us to do with it.

It covers the public website at https://minfis.com, the signed-in application, and the files a project produces — exterior options, the 3D model, the realistic views and the PDF booklet.

Every statement below describes the service as it runs today. Where the running service does not do something, this policy says so instead of promising it.

1. Who is responsible

ControllerANOMONUS - FZCO
Company typeFree Zone Company with limited liability, Dubai Silicon Oasis
AddressDSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates
Data protection contact[email protected]

We are established in the United Arab Emirates and process personal data under its Personal Data Protection Law. If you are in the European Union or the United Kingdom, we apply the rights set out in section 10 to you as well.

2. What we collect

2.1 Your account

DataWhere it comes fromWhy we hold it
E-mail address and a hash of your passwordYou, when you registerSigning you in, service e-mail
Google or Apple account identifier, e-mail address, name, picture addressYour provider, if you sign in that waySigning you in. We never see your provider password
Phone numberYou, if you signed in by phone while that entry was offered. It is not offered now, so no new number can reach usSending you a sign-in code
Name, profile picture address, chosen languageYouShowing your account, keeping the interface language
The revision of the Terms and this policy you accepted, and whenRecorded when you acceptProving what you agreed to
Our customer identifier at the payment providerCreated when you first payLinking your payments to your account

We do not verify your e-mail address when you register with a password. An address can therefore be registered by someone who does not control it. A code sent to the address is required to change it later and to reset a password.

2.2 Your projects

DataWhy we hold it
The brief you typed or dictated, and your answer to the clarifying questionIt is the input the concept is made from
The project name, the written analysis and the booklet text produced for youThey are the result you paid for
Exterior options, scene frames, realistic views, sketches, the 3D model files and the PDF bookletSame
A record of how the project was built: which pipeline, which model, how long, what it costSo a failed or disputed project can be explained
A site line — an area, a city, a country — and a boundary outline, if a project ever carries oneThe service accepts these fields, although the interface has no way to fill them in today

2.3 Money and teams

DataWhy we hold it
The balance ledger: every project credited, spent, refunded or written offAccounting, and so a charge can be traced
Payment records: the payment provider's identifiers, the amount, the plan, the invoiceAccounting and support
Team records: the team name, roles, and the e-mail address of anyone invited — including people who have no account with usRunning a shared team account
Booklet branding: your company name, website, contact line and logo imagePrinting your own brand on the booklet

2.4 Technical and security data

DataWhy we hold it
For each sign-in session: the time, the IP address, a description of the browser and device, and the reason the session endedSo you can see and end sessions you do not recognise
Failed sign-in counters keyed to an e-mail address, and request counters keyed to an IP addressSlowing down and blocking password guessing, and capping how many projects one address may start without an account
A random identifier for a browser used without an account, kept in that browser's cookie and recorded on the projects it startsSo anonymous work belongs to the browser that made it, and not to everyone sharing a network address — see section 3
An error log: the error text, the page path, and your account identifier if you were signed inFinding and fixing faults
Browser security reports, which land in the same error log; the page address in them can contain a project identifierDetecting content injected into our pages
A log of e-mail we sent you: the address and the full text of the message, which for a reset or sign-in message includes the code itselfProving what was sent when delivery is disputed
Application log files on the serverOperating the service

2.5 Advertising measurement, only if you agree to it

Nothing in this subsection exists unless you pressed Accept on the cookie notice. If you pressed Decline, or have not answered, no advertising script is loaded, no advertising cookie is written, nothing below is collected, and none of it is sent anywhere.

DataWhy we hold it
That you accepted or declined advertising measurement, kept in your browser and not on our serverSo the answer is obeyed on every page, and so it can be shown that nothing runs without it
Where you came from: the campaign tags in the advertising link you clicked, the address — host only, never the page — of the site you came from, and the path of the first page you opened. Kept in a cookie of ours for thirty days from the first such visit, and never overwritten by a later oneSo we can tell which advertisement produced a customer instead of guessing. The company we bought the advertisement from already knows it clicked; this is how we know what it led to
The same three things copied onto your account, once, at the moment the account is created, and never changed afterwardsSo a registration can be attributed to the advertisement that caused it. Accounts created before this was built, and accounts created without any of it, carry nothing — which means "we do not know", not "came directly"
Nothing from the Meta pixel itself. It reports to Meta from your browser and never passes through our serversThere is no copy of it here to hold

The three items above are ours and are sent to nobody. What Meta receives, what it does not, and how to switch it off is section 5 of the Cookie Policy; Meta as a recipient is in section 5 below.

None of the three is a name, an address or a message. The campaign tags are words we wrote into our own advertising links. The referring site is kept as a host, deliberately without the page or its query, because a full referring address can carry personal data and a host cannot. The landing page is a path with the query removed, for the same reason.

2.6 What we never receive

  • Card details. They are entered on the payment page of Polar, our payment provider (section 5). They never reach our servers.
  • Your voice. The microphone button uses the speech recognition built into your browser. Only the recognised text reaches us, and you can edit it before you send it. In some browsers — Chrome in particular — the browser itself sends the audio to its vendor. That is your browser's behaviour, not ours, and we neither receive nor store audio.
  • Your provider password, for Google or Apple sign-in.

3. Using Minfis without an account

You can describe a site, get the analysis and see the exterior options without registering. An anonymous project is owned by a random identifier your browser is given the first time you use the service without an account. It is kept in a cookie, it is meaningless on its own, and it says nothing about who or where you are. Your IP address is not used to decide who owns a project.

What that means in practice:

  • The projects you start without an account are visible to your browser, and not to other people who share your network.
  • If you sign in, the projects that browser started while signed out become yours and stay in your list.
  • Clearing your cookies, using another browser or a private window means the work started earlier can no longer be shown to you. There is nothing else to identify it by, so it cannot be recovered.
  • We still cannot prove an anonymous project is yours, so we cannot honour a request about it. Register before you put anything into a brief that you would not want handled that way.
  • Anyone with the browser is the owner. On a shared or public computer, the next person using that browser sees the anonymous projects it started.

Projects started without an account before this revision were attached to a network address, as earlier revisions of this policy described. Those keep working for whoever uses that address, and they are the only projects to which this still applies; nothing new is attached to an address.

4. Why we are allowed to process it

BasisWhat it covers
Performance of our contract with youYour account, your projects and their files, the balance, payments, teams
Our legitimate interest in a service that works and is not abusedSign-in and session records, rate counters, the error log, backups, the record of how a project was built
A legal obligationFinancial records: the ledger and payment records
Your consentAdvertising measurement — the Meta pixel, section 2.5. Nothing else on this page rests on consent, and withdrawing it changes nothing but that

We do not sell personal data.

One statement here has changed. Earlier revisions said we run no advertising or analytics scripts at all. Since 9 September 2026 the service carries one — the Meta pixel, described in section 5 of the Cookie Policy. It loads under two conditions together: you have agreed to it, and our advertising account is connected to the site. If either is missing, nothing is sent to Meta at all — so while no advertising account is connected, the answer you give the banner changes nothing about Meta, and the pixel is simply not there. We still do not sell your data, we still build no profile of you ourselves, and every other purpose on this page is unchanged.

Withdrawing consent is one button, on the Cookie Policy page, at any time. It takes effect immediately and costs you nothing: the service behaves exactly the same for someone who has refused. Withdrawal is not retroactive — it stops the measurement, it does not reach into what Meta already holds, and Meta's own policy is where a request about that is made.

5. Who else receives your data

Read this first: the words you type leave our server. Your brief is sent to Anthropic exactly as you wrote it. A phrase the model writes from your brief, and every image of your project, are sent to Higgsfield. Higgsfield passes one image of your building on to Tripo, which returns the 3D model. If your brief contains something confidential — a client's name, a price, a plot nobody knows you are looking at — it goes to those companies.

RecipientWhat we sendWhyWhere they are
Anthropic (the Claude model)Your brief as you wrote it, the site line, your answer to the clarifying question, your language and, later, frames of your scene and the exterior options. No e-mail address, no phone number, no account identifierReads the brief, names the project, writes the programme that builds the scene, writes the bookletAnthropic PBC, San Francisco, United States; for people in the European Economic Area, the United Kingdom and Switzerland the company is Anthropic Ireland, Limited, Dublin. Anthropic states that personal data is transferred to its servers in the United States
Higgsfield (image service)A phrase the model wrote from your brief — not your own words — and image files from your project: the option you chose and the frames of your sceneDraws the exterior options, the realistic views and the booklet sketchesHiggsfield Inc., San Francisco, United States. Its policy adds an office in Kazakhstan and vendors around the world, and names no other processing country
Higgsfield (Blender cloud)The generated scene programme, the frames, the chosen option and the project nameBuilds and rebuilds the 3D sceneThe same company, Higgsfield Inc., United States
Tripo (Holymolly Ltd, reached through Higgsfield)One cleaned aerial image of your buildingTurns that image into the 3D model shown in the viewerHolymolly Ltd, Sai Ying Pun, Hong Kong; its terms run under Hong Kong law. It publishes no processing country — only that data may be transferred outside the country you live in under standard contractual clauses
Polar (payments)Your name and e-mail address, the billing address and country you enter, the plan and the amount. Your card details are entered on Polar's own page and never pass through usPolar is the merchant of record: it is the seller to you, takes the payment, issues the receipt and the invoice, handles refunds, and calculates and remits the sales tax or VAT you owePolar Software Inc., Dover, Delaware, United States. It states that data it collects may be stored in the United States, Canada or other destinations, and that card payments are processed through Stripe
Stripe (not the provider you buy from)Your e-mail address, your name if you gave one, our internal identifier for your account, the plan and the amount — sent while Stripe was our payment provider, not sent by us nowPayments before Polar; Stripe still holds the customer records made then. It also sits underneath Polar as the company that processes the cardStripe, LLC and Stripe Payments Company, United States; Stripe Payments Europe, Limited, Dublin, for Europe. Stripe states that which of its companies is responsible depends on where you are
GoogleOnly the sign-in exchange. In return we receive and store your Google account identifier, e-mail address, name and picture address"Sign in with Google", if you use itGoogle LLC, Mountain View, United States; Google Ireland Limited, Dublin, provides consumer services in the European Union. Google states that it keeps servers around the world and may process your data outside the country you live in
AppleThe same. Apple may give us a relay address instead of your own"Sign in with Apple", if you use itApple Inc., Cupertino, United States; for people in the European Economic Area, the United Kingdom and Switzerland the controller is Apple Distribution International Limited, Ireland. Apple states that data collected worldwide is generally stored by Apple Inc. in the United States
ResendYour e-mail address and the full text of the messageDelivering our e-mail: sign-in and reset codes, welcome, team invitationsPlus Five Five, Inc., trading as Resend, United States, under the law of California. It states that data is transferred to and processed in the United States, and every company on its published sub-processor list is American
World LabsA depth panorama we compute from an apartment plan, a text description of the finish and a seed number — no personal data, no address of the site, no nameGenerating the 3D worlds of an apartment tour (Terms 7.2.5)World Labs, Inc., United States. Output made for paid API accounts belongs to the account; World Labs keeps a licence to the input for improving its service, which is one reason no personal data is sent
Telegram GatewayYour phone number and a sign-in code — only if you used phone sign-in while that entry was offered. Nothing is sent nowDelivering that codeTelegram Messenger Inc., under the Gateway terms; the group's published companies are Telegram Group Inc., British Virgin Islands, and Telegram FZ-LLC, Dubai. No processing country is published for the Gateway
HOSTGW SRL, trading as eComputeNothing is sent to them as such. They own and run the machine, so the database, every project file and every log sit in their data centreRenting us the server the whole service runs onHOSTGW SRL, Buftea, Romania. The machine it rents us stands in the Netherlands: the block of internet addresses our server sits in is registered to eCompute with the Netherlands as its country
CloudflareAll web traffic: your IP address, the addresses of pages you open, headers and cookiesProxy, encryption in transit, protection against attacks and botsCloudflare, Inc., San Francisco, United States. Traffic is handled at whichever of its edge locations is nearest you, in more than three hundred cities; it states that the metadata it processes for customers sits in data centres in the United States and Europe
Backblaze B2 (backup storage)The whole database, and one archive per project holding that project's files — both encrypted on our server before they are sent, with a key we hold and never give them. Backblaze stores ciphertext it cannot readKeeping the backup somewhere other than the server, so a lost machine does not lose your projectBackblaze, Inc., San Francisco, United States. Our bucket is in Backblaze's US East region — Reston, Virginia — checked on the machine that writes the backup. Kept: ninety days — database copies rotate out on that schedule, and a project's archive is removed ninety days after the project itself is gone (section 8.4)
Meta (advertising measurement)Only if you accepted it. The address of the page you are on, the address you came from, your IP address, your browser's description, and the name of one of the eight events listed in section 5 of the Cookie Policy. No name, no e-mail address, no phone number, no brief, no projectTelling us which advertisement brought a customer, so an advertising budget is spent on what worksMeta Platforms, Inc., Menlo Park, United States; for people in the European Economic Area, the United Kingdom and Switzerland, Meta Platforms Ireland Limited, Dublin. Meta states that it stores and processes data in data centres around the world, including in the United States
Have I Been PwnedThe first five characters of a hash of a password you are choosing — never the password, and nothing that identifies youRefusing a password that already appears in a public breach listSuperlative Enterprises Pty Ltd, Queensland, Australia. It states that it holds its data in a Microsoft Azure data centre in the western United States, and the lookup itself is served from Cloudflare's network

This list is complete. No other company receives personal data from the service.

Five things worth spelling out:

  • Polar is the payment provider, and it is the merchant of record. Your purchase contract for a project or a plan is with Polar: Polar takes the money, sends the receipt, pays any refund, and works out and pays over the sales tax or VAT due where you are. We do not issue our own tax invoice. Stripe stays wired into our code and sits underneath Polar as its card processor; it is not the payment provider you buy from. If that ever changes, this page will say so.
  • The Higgsfield workspace is one account held by us. Every customer's scenes and images sit in that single workspace, not in a separate space per customer.
  • We have no contract with Tripo. We reach it only as a tool inside Higgsfield.
  • Phone sign-in is not offered. The entry is closed in our code, not merely hidden on the page: the sign-in screen does not show it, and the two addresses behind it refuse every request. No number reaches Telegram Gateway. Sign in with Google, with Apple, or with an e-mail address and a password. Numbers given while the entry was offered are held and deleted as the rest of this policy describes.
  • Meta is the only entry on this list that is optional. Every other company above is part of running the service; Meta is there because you agreed, and it disappears from your own copy of this list the moment you decline.

Every entry in the last column is taken from that company's own published terms or privacy notice, read on the date printed at the top of this page. Two are not: the country our server stands in comes from the public register of internet addresses, and the Backblaze region comes from the machine that writes the backup. Where a company publishes nothing, the column says so. Nothing in it is guessed.

6. Training of the providers' models

Anthropic's commercial terms do not claim ownership of what you send or of what comes back, and do not take your input for training.

Higgsfield is different. On the account level we use — which is not their enterprise level — their terms allow them to use inputs and outputs to train their own models. That means the phrase written from your brief, the images of your project and its geometry may be used to train that provider's models. We cannot switch this off from our side on the account we hold.

We tell you this because the Terms give you the rights to your concepts, and that promise would be worth less if you did not know where the material behind it goes.

7. Where your data is

  • One server, in the Netherlands. The application, the database and every project file live on that single machine. We rent it from HOSTGW SRL, trading as eCompute, a Romanian company; the machine itself stands in the Netherlands.
  • Cloudflare sits in front of it. All traffic passes through their network before it reaches us.
  • Backups leave the machine. A backup is taken nightly, encrypted before it touches the disk, and copied to Backblaze B2 — into their US East region, in Virginia. It carries both the database and the project files: the images, exterior options, scene frames, 3D models and PDF booklets. Each project is a separate encrypted archive, rewritten when the project changes.
  • Backblaze cannot read any of it. Encryption happens on our server, before anything is sent, and the key stays with us. What sits in their region is ciphertext: the storage company holds it, we hold the only means of opening it.
  • The backup copy is deleted on a schedule too. The nightly database dumps rotate out, and a project's archive is removed ninety days after the project stops existing on the server. The clock starts at deletion, not at the last time the project changed, so an archive of a project you have not touched in a year is not thrown away while you still have it.

8. How long we keep it

8.1 Deletion the service actually performs

DataWindowHow it happens
Ended sign-in sessionsNinety days after they endA job that runs once a night
The log of e-mail we sentNinety days after sendingThe same nightly job
Database backups on the serverFourteen daysRotated out by the backup job
Encrypted database backups at Backblaze B2Ninety daysDeleted by the same job
Encrypted project-file archives at Backblaze B2Ninety days after the project is goneDeleted by the backup job

8.2 Data that has no expiry

Your account, your projects, their files, the error log and the sign-in protection counters are kept until you delete your account. Nothing removes them on a timer. The ledger and the payment records are the exception: they have a period, and it is in section 9.

Deleting a project hides it. It disappears from your list and stops being served. The record and every file stay on the server until someone removes them by hand. There is no restore button either — a deleted project cannot be brought back by you, only by us, and only while the files are still there.

We name no date by which a deleted project is erased, because nothing in the service performs one. If that changes, this page will change with it.

Application log files rotate by size, not by age. There is no fixed period after which they are gone, so this policy states none.

8.3 Deleting your account

You can delete your account yourself in the Account section. When you do:

Erased outright — all your projects together with their folders of files; team invitations you were sent and never accepted; your linked Google and Apple accounts; any pending e-mail change, password reset or phone verification; your booklet branding including the logo image; and every logged e-mail we sent to your address.

Made anonymous in place — your e-mail address is replaced with a placeholder at a domain that can never receive mail; your phone number, name, picture, password hash and administrator second-factor secret are cleared; the account is closed. Any balance left is spent down to zero and that is recorded.

Kept — the balance ledger and payment records (section 9); your team membership record, so the team's own spending history still adds up; the advertising source recorded on the account at registration, described in section 2.5; and your sign-in history, including the IP addresses and browser descriptions, until the ninety-day window in section 8.1 removes it. Your identifier in the error log is cleared.

The advertising source is kept because, on a row whose e-mail and name have been replaced, it names no person: it is a campaign word we wrote ourselves, a website's address and a path. It stays so that the count of what an advertising campaign produced does not silently shrink every time somebody closes an account. If you would rather it went too, write to [email protected] and we will clear it — it is a single field and removing it costs us nothing but the count.

Deleting your account does not cancel a paid subscription. Cancel the subscription first, through the billing portal linked from your account page, or it keeps renewing at the payment provider after the account is gone.

8.4 Backups

A deletion cannot reach into a backup that has already been written: those files are encrypted and are not opened to edit single records. Data you delete can survive in backups until they rotate out under the windows in section 8.1.

Project-file archives have the same window. Deleting a project, or deleting your account, removes the project's files from the working storage straight away, as section 8.3 describes. The encrypted archive of that project at Backblaze B2 is removed within ninety days: the backup job notices that the project no longer exists, starts a ninety-day clock, and deletes the archive when it runs out. So deletion in the working storage is immediate, and the data leaves the backups by ageing out.

9. The billing record and a request to be erased

The balance ledger is append-only, and that is enforced by the database itself, not by our code being careful. An entry cannot be edited or deleted in the running of the service, including by us: the database refuses it, and removing one means turning that guard off on purpose. Each entry carries the account identifier, the amount and what it was for.

We keep it because the accounts have to reconcile and because we have to be able to show what was charged and what was refunded.

How long: seven years. The ledger and our own payment records are kept for seven years, which is the period we hold financial records for and covers the bookkeeping a company in the United Arab Emirates has to be able to produce. Nothing removes them on a timer. The ledger's append-only guard refuses a deletion outright, so clearing entries once their seven years are up is a deliberate act on our side, not a job that runs by itself.

If you ask us to erase your data, or delete your account yourself, those entries stay for that period. What goes is everything that connects them to a person: the account they point to no longer holds your name, e-mail address or phone number, so the entries read as a numbered account with nobody attached. Polar, as the seller of record, keeps its own record of the sale under its own retention rules and its own tax obligations, which we do not control.

10. Your rights

You may ask us to:

  • give you a copy of the personal data we hold about you;
  • correct data that is wrong;
  • erase your data;
  • restrict how we process it;
  • object to processing we base on a legitimate interest;
  • withdraw your consent to advertising measurement — a button on the Cookie Policy page, which needs no e-mail and takes effect at once;
  • give you your data in a machine-readable form so you can take it elsewhere.

How to exercise them. Deleting your account is a button in the Account section and works immediately, as described in section 8.3. For anything else, write to [email protected] from the address on the account — that is how we check a request is yours. We answer an e-mail within one business day, and we answer a formal request under this section within thirty days of receiving it.

What we cannot do. We cannot erase the ledger entries described in section 9, and we cannot reach into backups that have already been written. We will tell you which parts of a request we cannot meet and why.

If you are in the European Union or the United Kingdom, you may also complain to the data protection authority where you live.

11. Sending data abroad

Our server is in the Netherlands. Our company is in the United Arab Emirates. Every recipient in section 5 is an international company, so your data is processed outside the country you live in.

One of them — Meta — is there only because you agreed to it, and declining removes that transfer entirely.

Section 5 names, for every one of them, the company you are actually dealing with and the country it says it processes in, taken from that company's own published terms. Most of them are in the United States. Two — Tripo and the Telegram Gateway — publish no processing country at all, and the table says so rather than filling the gap with a guess.

12. Age

Minfis is a professional tool for people working on housing developments. You must be eighteen or over to use it, and the Terms say the same.

We do not knowingly collect data from anyone younger. We also do not ask your age and have no way to check it, so this is a condition of use rather than a gate we enforce. If you tell us we hold data about a child, write to [email protected] and we will remove it.

13. How we protect your data

In place today:

  • Passwords are stored as bcrypt hashes, never in readable form.
  • A password already known from a public breach is refused. The check sends only the first five characters of a hash of it, so the password itself never leaves.
  • Sign-in is rate limited by IP address, an account locks after repeated failures, and the pause between attempts grows. The answer to an unknown address and to a wrong password is the same, and takes the same time, so the form cannot be used to find out who has an account.
  • One sign-in at a time: signing in ends your other sessions, and the device that was signed out is told why.
  • The sign-in cookie cannot be read by page scripts, is sent only to our own site, and is sent over an encrypted connection.
  • Traffic is encrypted in transit, end to end, including between Cloudflare and our server.
  • Project files are served only to the account that owns the project, or through a single-use key that exists so the booklet can be printed.
  • Backups are encrypted before they are written to disk, so an unencrypted copy of the database or of a project's files never exists outside the running service. The key that decrypts them is held separately from the key that writes them.
  • The ledger cannot be rewritten, as described in section 9.

No service is perfectly secure. If we discover a breach that affects you, we will tell you and the relevant authority as the law requires.

14. Business customers

If your company needs a data-processing agreement before your team uses Minfis, write to [email protected] and say what you need.

We have no standard agreement to hand you yet. What this section promises is a conversation and a written answer about how we process the data your team puts in — not a document by return of post.

15. Changes to this policy

Each revision carries a date, printed at the top of this page. When we change this policy or the Terms in a way that matters, the next time you sign in you are asked to accept the new revision, and the service does not continue until you do. Small corrections are published with a new date and no interruption.

16. Contact

Questions about this policy, and any request under section 10: [email protected]

Anything else — the service, an order, a project that went wrong: [email protected]

ANOMONUS - FZCO, DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates