Privacy Policy

Last updated: September 09, 2026

1. Introduction

NEMO ENTERPRISES INC. (“Own. App” “we”, “us”, and “our”) respects your privacy and we are committed to protecting it through our compliance with this privacy policy (the “Privacy Policy”). The term “you” refers to the person visiting this website or mobile application  (collectively, the “Website”).

This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit the Website and our practices for collecting, using, maintaining and organizing, protecting, deleting and disclosing that information (collectively, “process” information). Some of this information may be considered “personal information” or “personal data” under applicable law, which is information that is about any individual, or from which any individual is identifiable (“personal information”).

Some sections in this Privacy Policy apply only to persons subject to Regulation EU 2016/679 (the “GDPR”), namely residents of or persons located in the European Economic Area.

Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Website. By accessing or using this Website, you agree to this Privacy Policy.

2. persons Under the Age of 18

2.1 Minimum Age

The Service is not intended for individuals under 16 years of age. Users must be at least 18 years old, or between 16 and 18 years old with parental consent, to use the Service. Own. App does not knowingly collect personal information from children under 16. If we learn that we have inadvertently collected information from a child under 16, we will delete that information. If you believe we may have collected information from a child under 16, please contact us at support@iown.app

2.2 Note to Parents and Guardians

Because it is difficult for us to verify a person’s age online, it is entirely YOUR responsibility to supervise your child’s online activities at all times. Parental control tools like filtering software and hardware are commercially available to help you limit a child’s access to potentially harmful material on the Internet. If you discover that your child or any other minor has obtained an Account on the Service without a parent or guardian approval, please contact us immediately via email at support@iown.app

3. Type of INFORMATION We Collect, PURPOSE AND LEGAL BASIS

3.1 What Personal Information Do We Collect?

The categories of personal information and sources that we may collect are as follows:

  • Personal and Authentication Information: We collect identity data that you provide to us when creating and accessing an Own. App account, including your email address, date of birth, phone number, and information from third-party authentication services (Apple Sign Up, Google Sign Up). The purpose of collecting this information is to create and manage your Own. App account, authenticate users, provide access to services, and secure your account. 

  •  Device Details: We collect device type, operating system, browser type and settings, IP addresses, unique identifiers (such as VIN, MAC address and IDFA), language settings, dates and times of connection to our website and other technical communication.  This information is used to ensure platform compatibility, optimize user experience, enhance security, detect fraudulent activity, and analyze technical issues for service improvements. We may collect this information through use of cookies and other related technologies, as is further described in the “Cookies and Other Related Technologies” in section 9 below.

  • Usage Details: We collect records of your use of our website, including page views, clicked pages or links, content interactions, and communication preferences. This data is collected and stored in a fully anonymized format that does not identify individual users. We may collect this information through use of cookies and other related technologies, as is further described in the “Cookies and Other Related Technologies” in section 9 below. This anonymized data helps us improve website functionality, personalize content, analyze engagement trends, and tailor our services to user needs.

  • Payment details: We do not directly collect or store your payment information such as credit card numbers, cardholder names, card security details, or card expiry dates. When you make purchases, these transactions are processed through the Apple App Store, Google Play Store, or Stripe (for in-app gifting and creator monetization features), which handle all payment details according to their own privacy policies. We may receive confirmation of completed transactions and retain transaction records as required by Stripe’s compliance requirements and applicable financial regulations, but we do not have access to your complete payment information. This arrangement helps us process transactions, manage billing, and comply with financial regulations while enhancing payment security.

  • Opinions, views and interests: We collect comments, ratings, reviews, or feedback provided through our platform or social media. This information is collected and stored in an anonymized format that does not identify individual users. This anonymized data is used to facilitate community engagement, gather user feedback, improve our services, and enhance customer support interactions.

  • Information collected from Third Parties: We collect information from public sources, such as your public social media information; we may collect information about you directly from our distributors, sales representatives, suppliers, vendors or our third party processors who collect information on our behalf, such as authentication data from Google/Apple Sign In. This information is used to validate identity, improve service offerings, and facilitate authentication processes.

  • Identity Verification: In the event of a dispute only, we may collect government-issued ID and selfie images to verify user identity, prevent fraud, comply with regulatory requirements, and enhance account security. This information is not collected during normal account creation or usage and is only requested and retained when necessary to resolve specific disputes.

  • Other Information You Actively Share: We collect any information you share via our platform, including public content posted on your page. This data is used to enable social interactions, facilitate content sharing, and provide platform features that allow users to engage with each other.

  • Payment Processing: Payments are processed by third-party payment processors (such as Apple, Google Play, and Stripe). We do not collect, store, or process your payment card details. Stripe processes payments for in-app gifting and creator monetization features, and we retain transaction records as required by Stripe’s compliance requirements. These third parties may collect payment information subject to their own privacy policies.

OWN XID Verification: When you opt in to OWN XID (our Identity Security System), we use OWN XID to verify and execute monetary transactions. Any personal data required by Stripe or other payment processors for transaction verification is stored according to such processors’ compliance requirements. Transaction records are displayed within the OWN app for your review.

3.2 Legal Basis

This section 3.2 only applies to data subjects that are protected under the GDPR. We process your personal information based on the following legal grounds, depending on the specific context:

  • Account Creation and Authentication: We process personal and authentication information (such as name, email, and authentication data from third-party services) to create and manage user accounts. Legal Basis: Contractual necessity (Article 6(1)(b) GDPR).

  • Service Provision and Customer Support: We use personal, device, and usage details to provide and improve our services, personalize content, respond to user inquiries, offer customer support, and ensure platform security. Legal Basis: Contractual necessity (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)).

  • We register your device's unique identifier (MAC address) to prevent unauthorized access and protect against account hacking. We process device details and usage logs to detect and prevent fraud, ensure security, and comply with legal obligations. Identity verification data may only be collected in the specific case of account ownership disputes. Legal Basis: Legitimate interests (Article 6(1)(f)) and legal obligation (Article 6(1)(c)).

  • Marketing and Communications: We collect opinions, interests, and usage details to send personalized content and promotional materials, subject to user consent. Legal Basis: Consent (Article 6(1)(a)).

  • Website Operations and IT Management: We collect device and usage details to operate, maintain, and improve our website, as well as manage IT security and conduct audits. Legal Basis: Legitimate interests (Article 6(1)(f)).

  • Safety, and Legal Compliance: We process personal information to maintain the safety, security, and integrity of our website, products, databases, and services, as well as comply with applicable legal obligations. Legal Basis: Legal obligation (Article 6(1)(c)) and legitimate interests (Article 6(1)(f)).

  • Analytics and Market Research: We analyze usage details, device information, and anonymized data to assess market trends, optimize our offerings, and enhance user experience. Legal Basis: Legitimate interests (Article 6(1)(f)).

  • Surveys and Feedback: We collect responses, opinions, and reviews from users to understand customer satisfaction and improve our services and products. Legal Basis: Legitimate interests (Article 6(1)(f)).

    3.3 OWN XID Identity Security System

Own. App offers OWN XID, our proprietary Identity Security System that provides self-custodial protection for certain categories of your personal data. OWN XID is an opt-in feature, but is mandatory for certain user actions such as withdrawing funds from your in-app Earnings Wallet to your bank account.

Data Protected by OWN XID. When you enable OWN XID, the following categories of data are protected through private key encryption and held in your self-custody: (a) account access credentials (excluding your initial username and email address); (b) digital assets wallet; (c) personal user data; and (d) your social graph (i.e., your follower relationships). For this protected data, Own. App has zero access to the encrypted information — only you, as the holder of your private key, can access it.

Data Not Protected by OWN XID. The following categories of data are not protected by OWN XID and remain accessible to Own. App: (a) your initial account credentials (username and email address, but not passwords); (b) content you post publicly (i.e., to the OWN App feed or your user profile); (c) content performance and analytics data; (d) data required for legal compliance; and (e) billing and transaction data.

Recovery Key. Upon completing OWN XID verification, you will receive a Recovery Key containing a seed phrase. You are solely responsible for safeguarding your Recovery Key in a secure location. Your Recovery Key can fully restore your account even in the event of total device loss. Own. App does not have access to your Recovery Key and cannot recover your account or OWN XID-protected data if you lose your Recovery Key.

Legal Process Limitations. Due to the self-custodial architecture of OWN XID, if Own. App receives a valid subpoena, court order, or government request for user data, we may be technically unable to provide encrypted personal user data or messaging content and metadata that is protected by OWN XID. In response to valid legal processes, we can provide: (a) transaction history and related technical data; (b) technical connection data such as IP addresses used to connect to our platform; and (c) publicly posted content. Own. App will operate within the legal framework of the countries in which it operates.

No Third-Party Access. OWN XID is a proprietary system developed by Own. App. No third-party services or APIs have access to OWN XID or to data protected by OWN XID.

4. DATA SHARING AND TRANSFERS

4.1 Disclosure of Your Information

We share your personal information only when necessary to provide the core functionality of Own. App and its third-party features. We never share your personal information for advertising purposes or other commercial uses beyond what is required for the service to function properly. We may disclose aggregated information about our users, fully anonymized usage details, and information that does not identify any individual, without restriction.

We may disclose personal information that we collect or you provide as described in this Privacy Policy:

  • To our affiliates.

  • To our trusted contractors and service providers we use to support necessary business operations (such as cloud hosting, security services, payment processing (including Stripe for in-app gifting and creator monetization), and customer support), based on our instructions and in compliance with our Privacy Policy and appropriate confidentiality and security measures.

  • To our sales representatives for the purpose of fulfilling your requests and selling our services.

  • To a buyer or other successor in the event of, or pursuant to negotiations in connection with, a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Own. App’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by Own. App about our Website users is among the assets transferred. We will notify you with any choices you may have regarding your information as a result of such events.

  • With your consent.

  • To comply with any court order, law, or legal process, including investigation of potential violations and to respond to any government or regulatory request. Please note that due to our self-custodial data architecture (see Section 3.3 below), we may be technically unable to provide certain categories of encrypted user data in response to legal process requests. In such cases, we will provide all data that is technically accessible to us, including transaction history, technical connection data (such as IP addresses), and publicly posted content.

  • To detect, prevent or otherwise address fraud, security or technical issues.

  • To enforce or apply our Terms of Service and other agreements, including for billing and collection purposes.

  • If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of Own. App, our customers, or others.

  • For any other purpose disclosed by us when you provide the information.

If we engage third-party processors to process your personal information on our behalf, such third-party processors will be subject to binding contractual obligations to (i) only process the personal information in accordance with our prior written instructions; and (ii) use measures to protect the confidentiality and security of personal information; together with any additional requirements under applicable law. 

4.2 Data Security and Data Breach

We take appropriate technical and organizational measures to ensure the security of your personal data, including encryption, access controls, and regular security assessments. Certain categories of personal data are protected through our OWN XID Identity Security System, which provides self-custodial protection using private key encryption. For data protected by OWN XID, Own. App has zero access to the encrypted information — only you, as the holder of your private key, can access this data. In the event of a data breach, we will comply with legal obligations regarding notification and risk mitigation.

In the event of a data breach involving personal information, we will:

  • Assess the scope and impact of the breach.

  • Notify affected users within 72 hours if required by law.

  • Report the breach to the relevant data protection authority when applicable.

  • Take corrective measures to prevent future occurrences.If you suspect unauthorized access to your data, please contact us immediately at privacy@iown.app

5. INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION

Because of the international nature of our business, we may need to transfer your personal information to third parties as noted above (subject to binding contractual obligations, also considered “standard contractual clauses” where required by applicable law), solely in connection with the purposes set out in this policy. For this reason, we may transfer your personal information to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located.

6. HOW LONG WILL WE KEEP YOUR INFORMATION

We retain only the personal information necessary to activate and use an Own. App account. When you delete your account, all of your information — including all data protected by OWN XID — will be permanently deleted from our systems and cannot be recovered. While your account remains active:

  • Account data: Retained only while your account is active 

  • Payment data: Retained only while your account is active. Transaction records may be retained as required by Stripe’s compliance requirements and applicable financial and tax regulations.

  • Marketing data: Retained until you withdraw consent or delete your account 

  • Other collected data: Retained only while your account is active We are committed to minimizing data retention and ensuring the complete removal of your information upon account deletion.

OWN XID-protected data: Data protected by OWN XID (including account credentials, digital wallet, personal data, and social graph) is held in your self-custody and will be permanently deleted upon account deletion. Own. App cannot recover OWN XID-protected data after account deletion.

7. Your Rights under the gdpr

This Section 7 applies only to data subjects that are protected under the GDPR. You may exercise your rights at any time by contacting us at privacy@iown.app stating the reason for your request and the right you wish to exercise. To verify your identity, we may require additional information where necessary.

Subject to applicable law, you have the following rights regarding the processing of your personal information:

  • Right to Access - the right to request access to, or copies of, your personal information that we process or control;

  • Right to Rectification - the right to request rectification of any inaccuracies in your personal information that we process or control; 

  • Right to Erasure (“Right to be Forgotten”) - the right to request, on legitimate grounds:

    • erasure of your personal information that we process or control; or

    • restriction of processing of your personal information that we process or control;

  • Right to Restrict Processing - the right to object, on legitimate grounds, to the processing of your personal information by us or on our behalf;

  • Right to Data Portability - the right to have your personal information that we process or control transferred to another controller, to the extent applicable;

  • Right to Object - the right to object, on legitimate grounds, to the processing of your personal information by us or on our behalf;

  • Right to Withdraw Consent - where we process your personal information on the basis of your consent, the right to withdraw that consent; and

  • Right to Lodge Complaints - the right to lodge complaints with a Data Protection Authority regarding the processing of your personal information by us or on our behalf.

8. Links to Third Party websites

This Website may also contain links to websites operated by other companies, including websites operated by our third-party service providers and distributors, and unrelated third parties. This Privacy Policy does not apply to personal information collected on any of these other websites. When you access third-party websites through a link on one of our Website, please review the Privacy Policy posted on that website.

9. COOKIES AND OTHER RELATED TECHNOLOGIES

We comply with the EU ePrivacy Directive and GDPR regarding cookies and tracking technologies. We obtain explicit consent for non-essential cookies and provide users with options to manage their preferences through our cookie management panel. For more details, please refer to our Cookie Policy. We may collect information through the use of “cookies,” tracking pixels, and similar technologies. Cookies are small text files created by websites and stored on your device. They provide a way for us to recognize you and keep track of your settings and preferences. A script is a piece of program code that is used to make our website function properly and interactively. This code is executed on our server or on your device. A web beacon (or a pixel tag) is a small, invisible piece of text or image on a website that is used to monitor traffic on a website. In order to do this, various data about you is stored using web beacons. We use cookies and similar technologies to provide you with a secure experience and to understand, among other things, how you navigate our website, learn what content is popular, recognize repeat users, and save your account information. Our website is not configured to read or respond to “do not track” settings or signals in your browser settings. When you visit our website for the first time, we will show you a pop-up with an explanation about cookies. You do have the right to opt-out, manage and object to the further use of non-functional cookies through our cookie panel. You can also disable the use of cookies via your browser, but please note that our website may no longer work properly.

10. Changes to this privacy policy

We may update this Privacy Policy periodically. If we make material changes, we will update you via our website, by email or other communication. We encourage you to stay up to date about our privacy practices by reviewing this policy periodically. Continued use of our website following notices of changes to this policy indicates your acceptance of such changes and agreement to be bound by the updated policy terms.

11. RIGHT TO LODGE A COMPLAINT

If you believe that your rights regarding your personal data have been violated, you have the right to lodge a complaint with a supervisory authority. In the EU, you can submit your complaint to the data protection authority in your country or region. To find the relevant supervisory authority, please visit the European Data Protection Board website at www.edpb.europa.eu/edpb_en. You can also contact us at privacy@iown.app for assistance regarding your complaint.

12. Contact Information

To exercise your rights, or if you have questions or concerns regarding this Privacy Policy, please contact us at  privacy@iown.app

As we do not have an establishment in the European Union we have appointed a representative based in Sevilla, Spain,  who you may address if you are located in the EU to raise any issues or queries you may have relating to our processing of your personal information and/or this privacy policy more generally. Our EU representative is: José Manuel Caballero located at Plaza del Aljarafe, 13 - 41005. Our EU representative can be contacted directly by emailing them at the following address: gerente@comse.es.

Back

© 2026 by NEMO Enterprises Inc.