Legal
Privacy Policy
Last updated
Mo Advice handles two kinds of people's data: senders, who pay us, and recipients, who never asked for an account. Recipients get the stricter treatment.
What we collect
If you send messages
- Your email address — for receipts, confirmations, and sign-in.
- Your orders and plans: which tone, which language, which frequency, which recipient, and when.
- A Stripe customer ID and subscription IDs. We never see or store your card number, expiry, or CVC — those go directly to Stripe.
If you receive messages
- Your email address.
- A first name, only if the sender supplied one.
- A log of which messages were sent to you and when, so we don't repeat one and so we can answer support questions.
- An opt-out token, so the unsubscribe link works.
That's it. No tracking pixels in the messages, no open or click tracking, no profile building, no ad networks.
We do record that a message was accepted, delivered, or bounced — reported to us by our email provider, not by anything embedded in the message you opened.
Anonymity works in one direction only
We know who sent what — we have to, in order to bill and to handle abuse reports. The recipient never learns the sender's identity from us. We do not reveal it on request, and the emails contain nothing that would identify the sender.
The one exception is a valid legal order, or a credible report that the service is being used to harass someone. We will comply with the law.
What we don't do
- We do not sell, rent, or share personal data with advertisers.
- We do not use recipient addresses for marketing. The only mail an address receives is the messages that were paid for.
- We do not add anyone to a mailing list.
Who processes data for us
- Stripe — payments, subscriptions, and billing portal.
- Resend — email delivery.
- Vercel — hosting, scheduled jobs, and cookieless web analytics.
- Our database host — Postgres, storing everything described above.
Each is bound by its own data processing terms. Data may be processed in the United States and the EU.
How long we keep things
- Order and payment records: seven years, because tax law requires it.
- Delivery logs: two years, then deleted.
- Opted-out addresses: kept indefinitely in a suppression list. This is deliberate — it is the only way to guarantee we never send to that address again.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to processing. Email hello@moadvice.com and we'll action it within 30 days.
Recipients: the fastest route is the opt-out link at the bottom of any message. Emailing us works too, and we'll confirm when it's done.
Cookies and analytics
One cookie, used to keep you signed in to the sender dashboard. It's set only after you use a sign-in link, and it expires. There are no advertising cookies and nothing that follows you to other sites.
We use Vercel Web Analytics to count page views and a few steps in the send form. It is cookieless, stores nothing on your device, and does not build a profile or track you across sites.
We also offer Google Analytics, which does set cookies — so it only runs if you accept the banner. Decline and nothing is stored on your device.
Those events record only what was chosen: the plan, the tone, and which step of the form. No email address is ever included — not yours and certainly not the recipient's, who never agreed to anything.
Children
The service is not intended for anyone under 16. If we learn we hold data about a child, we delete it.
Contact
The data controller is Sami Oueslati (NIF 41571545B), c/ Madrazo 46, 08006 Barcelona, Spain. We process sender data to perform the contract you entered into, and recipient data on the basis of our legitimate interest in delivering the message a sender paid for — balanced against the recipient's interests by the one-click opt-out in every message and the permanent suppression that follows.
If you are in the EU or UK and think we have handled your data badly, tell us first — but you also have the right to complain to your national data protection authority. In Spain that is the AEPD.