Back to top
Privacy Policy
Controller: DV Capital Ventures Inc. Application: ME. (“ME.”, “the app”, “the Service”, “we”, “us”, “our”) Website: me4us.com Privacy Contact: privacy@dvcapitalventures.ca Data Protection Officer / LGPD Encarregada: Daphne Pollini Amadeu — privacy@dvcapitalventures.ca
Effective date: July 17, 2026 Last updated: July 15, 2026 Version: 1.0
Table of contents
Introduction
Who we are
Definitions
Data we collect
How we use your data
Legal basis for processing
Who we share data with (sub-processors)
International data transfers
Data retention
Information security
Your rights
Minors
Cookies, identifiers, and trackers
Use of Artificial Intelligence
Automated decision-making
Changes to this Policy
Contact and complaints
1. Introduction
This Privacy Policy explains how ME., an application developed and operated by DV Capital Ventures Inc. (“DV Capital”, “we”), collects, uses, stores, shares, and protects users’ personal data.
This Policy applies to: - The marketing website me4us.com and related subdomains; - The ME. mobile application available on the Apple App Store and Google Play Store; - All official communication channels (support email, contact forms, waitlists).
ME. is an AI-based digital companion application offering conversations with AI personas (such as “Amber”) for the purposes of companionship, self-reflection, journaling, and casual conversation.
ME. is NOT a mental health service, therapy platform, clinical counselling service, medical diagnosis tool, or treatment for any condition. If you are in crisis, please contact emergency services (911 in Canada, 192 SAMU in Brazil) or support lines such as Talk Suicide Canada (1-833-456-4566) or CVV Brazil (188).
By using ME., you agree to this Policy. If you do not agree, please do not use the Service.
2. Who we are
Legal name: DV Capital Ventures Inc. Entity type: Federal Canadian Corporation Corporation Number (CBCA): 17831846 Registered office: 1706 – 708 Farrow Street, Coquitlam, BC V3J 0P2, Canada Jurisdiction: Canada (with technical operations in Brazil via contracted partner)
We are the data controller for personal data processed through ME.
For technical development, we rely on Proxy Systems Ltda. — EPP (Brazilian CNPJ 02.097.394/0001-73, registered office at Rua Anchieta, 164, Jundiaí — SP, Brazil, postal code 13201-804), acting as a contracted data processor under a Service Agreement and Intellectual Property Assignment Agreement, both signed on May 18, 2026. All intellectual property in ME. belongs exclusively to DV Capital Ventures Inc.
3. Definitions
Personal data / personal information: any information relating to an identified or identifiable natural person.
Sensitive data: data revealing racial or ethnic origin, religious beliefs, political opinions, health data, sexual life, genetic or biometric data (LGPD Art. 5, II).
Data subject / individual: the natural person to whom the personal data relates.
Processing: any operation performed on personal data (collection, use, storage, sharing, deletion, etc.).
Controller: the entity deciding on the purposes and means of processing — in our case, DV Capital Ventures Inc.
Processor / sub-processor: an entity that processes personal data on behalf of the controller — in our case, Proxy Systems Ltda. and the sub-processors listed in Section 7.
4. Data we collect
4.1 Data you provide
On the me4us.com website: - Waitlist: email address, and optionally name/nickname, to receive launch notifications. - Contact form: name, email, and the content of your message. - Newsletter (optional): email address, if you opt in to receive periodic communications.
In the ME. app: - Account: name (or nickname), email address, password (stored as bcrypt hash), date of birth, country/region. - Conversation content: messages you exchange with ME.’s AI personas, including text, mentioned entities (people, places, topics), and expressed emotions. - Preferences: chosen persona, personalization settings, preferred tone, memories flagged as important. - Feedback: ratings, bug reports, support messages.
4.2 Data collected automatically
Technical data: IP address, device type, operating system, app version, language, timezone.
Usage data: session timestamps, message counts, screens visited, features used.
Identifiers: device ID (Android Advertising ID / IDFA — only with your consent), internal user ID.
Error logs: stack traces and technical crash metadata (via Grafana).
4.3 Payment data
When you subscribe to ME. Premium or Founding Member, we collect: - Payment method (Pix, credit card, debit card). - Transaction status (approved, pending, declined). - Amount and currency.
Full card data is processed directly by Stripe (PCI-DSS Level 1 certified) and is not stored on ME.’s servers.
4.4 Data we do NOT collect
We do not collect biometric data, precise geolocation, contacts, photos, or camera without explicit per-feature consent.
We do not knowingly collect data from users under 16 (see Section 12).
We do not systematically collect sensitive data (health, sexual orientation, religion) — though conversation content may incidentally reveal such information. Any sensitive data disclosed in conversations is protected with the same security safeguards as other data and is not used for categorization, targeting, or commercial sharing.
5. How we use your data
We use your personal data to:
Provide the Service: maintain your account, sync your conversations across devices, personalize AI responses based on your history and preferences.
Improve the product: aggregated usage analytics, bug identification, feature prioritization.
Communicate: push notifications (with consent), transactional emails (password reset, billing).
Ensure security: fraud detection, abuse prevention, bot mitigation.
Comply with legal obligations: tax, accounting, and legal requests.
Marketing communications (optional): newsletters, product updates — disabled by default for all users. We send only with your explicit, active opt-in consent (as required by CASL, Canada’s Anti-Spam Legislation, and LGPD). You can withdraw your consent at any time with a single click.
5.1 What we do NOT do
We do not sell your personal data to third parties.
We do not use the content of your conversations to train AI models (LLMs), unless you explicitly opt in. Training opt-in is inactive by default for all users.
We do not share data with advertisers or ad platforms.
We do not perform behavioural profiling for advertising.
6. Legal basis for processing
We rely on the following legal bases:
Purpose | Legal basis |
|---|---|
Account creation, authentication, service delivery | Performance of a contract (LGPD Art. 7, V; PIPEDA meaningful consent) |
Personalization based on conversation history | Performance of a contract |
Security, fraud prevention | Legitimate interest (LGPD Art. 7, IX) |
Direct marketing | Consent (LGPD Art. 7, I; PIPEDA opt-in) |
Training AI models with your conversations | Explicit opt-in consent (LGPD Art. 7, I) |
Tax, accounting, and legal obligations | Legal obligation (LGPD Art. 7, II) |
Non-essential cookies | Consent (LGPD Art. 7, I; Quebec Law 25 explicit consent) |
You can withdraw your consent at any time via app settings or by writing to privacy@dvcapitalventures.ca. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
7. Who we share data with (sub-processors)
We share personal data only with sub-processors that help operate the Service. All sub-processors are contractually bound (via Data Processing Agreements or equivalent terms) to protect your data at a standard equivalent to ours.
7.1 List of sub-processors
Sub-processor | Function | Data involved | Location |
|---|---|---|---|
OpenAI, L.L.C. | Large language model inference (GPT-family models) for AI persona responses | Message content, in real time | United States |
Google LLC | Large language model inference (Gemini-family models) | Message content, in real time | United States |
DigitalOcean, LLC | Database, file, and backup storage (Spaces / S3-compatible) | Account data and conversations | United States / Canada |
Cloudflare, Inc. | CDN, DDoS mitigation, reverse proxy | Request metadata, IP address | Global (Anycast) |
Atlassian (Bitbucket) | Source code repository | No direct user data | United States / Australia |
Grafana Labs | Application monitoring, logs | Error logs, technical metadata | United States |
Google (Analytics for Firebase) | Aggregated usage analytics | Pseudonymized usage events | United States |
Stripe Payments Canada, Ltd. | Subscription processing (credit card and Pix) | Transaction data, email, last-4 of card | Canada / United States |
Google (Firebase Cloud Messaging) | Push notification delivery | Device token | United States |
We may also share your data with other operational service providers (e.g., transactional email, secondary backup) strictly as necessary to operate the Service, always under equivalent data protection agreements.
7.2 Sharing in specific situations
Public authorities: only pursuant to valid court order, legal request, or legal obligation.
Corporate succession: in the event of a merger, acquisition, or corporate restructuring of DV Capital Ventures Inc., your data may be transferred to the successor, subject to the same obligations set out in this Policy.
Emergencies: if we believe in good faith that disclosure is necessary to protect life or prevent serious and imminent harm.
8. International data transfers
Because we operate globally and use sub-processors based outside your country of residence (primarily the United States and Canada), your personal data will be transferred internationally.
8.1 Legal basis for transfers
We justify international transfers based on: - Contractual clauses with sub-processors including security and privacy obligations equivalent to LGPD (Art. 33, II) and PIPEDA. - Specific and prominent consent for transfers where applicable (LGPD Art. 33, VIII). - Contract performance with the data subject (LGPD Art. 33, V). - PIPEDA accountability: we remain accountable for personal information transferred to sub-processors and require them to provide comparable protection.
8.2 Countries involved
United States (OpenAI, Google, DigitalOcean, Cloudflare, Grafana).
Canada (DV Capital Ventures Inc. as controller; DigitalOcean may replicate to Toronto).
Other countries via Cloudflare CDN (connection metadata only).
8.3 Safeguards specific to Quebec residents (Law 25)
For personal data of residents of Quebec, we assess whether recipient jurisdictions provide protection equivalent to Quebec Law 25 before transferring, and maintain contractual protection clauses with each sub-processor. Documentation on these assessments is available upon request.
You may request additional information about safeguards adopted by writing to privacy@dvcapitalventures.ca.
9. Data retention
We retain your data for as long as necessary for the purposes described in this Policy.
9.1 Retention schedule
Data type | Retention period |
|---|---|
Website waitlist email | Upon app launch: (a) deleted within 180 days, or (b) if you explicitly opted in to receive marketing communications, transitioned to our newsletter subscription list |
Website contact form submissions | 24 months after last contact |
App account data (name, email, password) | While your account is active |
Conversation content | For the duration of the active account relationship — retained to maintain user-created context, history, and AI persona personalization, or until you manually delete or delete your account |
Technical and security logs | 30 days |
Full database backups | Up to 90 days |
Payment data | As required by tax law (5 years in Brazil, 7 years in Canada) |
Data after account deletion | Removed immediately from production; may persist in backups for up to 90 days until rotation cycle; sub-processor cascade per each processor’s policy (e.g., OpenAI retains logs for ~30 days) |
9.2 Deletion
When you request account deletion: 1. We immediately remove your data from production systems. 2. We initiate a manual deletion cascade across each sub-processor, subject to their individual policies (OpenAI: ~30 days; Google: per Data Processing Amendment; DigitalOcean: immediate for storage, backups up to 90 days). 3. Data retained under legal obligation (tax, accounting) is stored in a segregated, restricted manner.
10. Information security
We implement technical and organizational measures to protect your data:
Encryption in transit: all communication between the app and our servers uses industry-standard encryption (TLS, currently widely-adopted version).
Encryption at rest: data stored in databases and object storage uses configurable AES-256 symmetric encryption.
Access control: access to production data is restricted to authorized personnel (currently: DV Capital and Proxy Systems technical team), with multi-factor authentication and audit logging.
Passwords: stored as bcrypt hashes — never in plaintext. Even administrators cannot retrieve your password.
Monitoring: security logging and anomaly detection via Grafana.
Environment isolation: production, staging, and development environments are segregated.
10.1 Breach notification
In the event of a security incident that may cause relevant risk or harm to data subjects: - We will notify the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil within a reasonable time (industry standard: 72 hours). - We will notify affected data subjects by email or in-app notification when the risk is elevated. - In Canada, we will notify the Office of the Privacy Commissioner of Canada in accordance with PIPEDA and the Commission d’accès à l’information du Québec in accordance with Law 25.
11. Your rights
11.1 Rights under LGPD (Brazilian data subjects — Art. 18)
You may, at any time and free of charge, exercise the following rights:
Confirmation that we process your data.
Access to your data.
Correction of incomplete, inaccurate, or outdated data.
Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data.
Data portability to another service provider.
Deletion of consent-based data.
Information about public and private entities with which we share your data.
Information about the option to refuse consent and the consequences of doing so.
Withdrawal of consent.
Objection to processing carried out on grounds other than consent, in case of LGPD non-compliance.
11.2 Rights under PIPEDA and Quebec Law 25 (Canadian data subjects)
Right of access to your personal file.
Right to correction of inaccurate information.
Right to erasure (Quebec Law 25, in force since September 2024).
Right to data portability (Quebec Law 25, in force since September 2024).
Right to be informed of automated decisions producing legal effects or significantly affecting you.
Right to withdraw consent at any time.
11.3 How to exercise your rights
In-app: Settings → Privacy → My Data (access, export, and deletion flows available).
By email: privacy@dvcapitalventures.ca — we respond within 15 calendar days (LGPD) / 30 days (PIPEDA).
We may request additional information to verify your identity before fulfilling the request.
11.4 Complaints to regulators
If you believe your rights have been violated, you may complain directly to: - ANPD (Brazil): anpd.gov.br - Office of the Privacy Commissioner of Canada: priv.gc.ca - Commission d’accès à l’information du Québec (Quebec residents): cai.gouv.qc.ca
12. Minors
12.1 Minimum age
ME. is intended for users aged 16 and older. We do not knowingly collect data from users under 16.
12.2 Users aged 16 to 18
For users aged 16 to 18, we adopt the following safeguards, in line with LGPD Art. 14: - Simplified data collection interface and age-appropriate language. - Prohibition of profiling for commercial purposes. - Marketing communications disabled by default.
12.3 Detecting underage users
If we discover that an account has been created for a user under 16, we will: 1. Suspend the account immediately. 2. Notify the parent/guardian, if identifiable. 3. Delete the collected data, except where retention is legally required.
Parents or guardians who suspect a minor under 16 has created an account may write to privacy@dvcapitalventures.ca.
13. Cookies, identifiers, and trackers
13.1 What we use
On the me4us.com website: - Strictly necessary cookies: for basic site functionality. No consent required. - Analytics cookies: Google Analytics to measure aggregated website traffic — only with your consent via banner on first visit. - Preference cookies: language, theme — with consent.
In the ME. app: - Strictly necessary cookies: for authentication and basic functionality. No consent required. - Analytics cookies (Google Analytics for Firebase): with consent — measure aggregated usage. - Device identifiers: internal ID linked to the user; advertising IDs (AAID / IDFA) are NOT used for advertising, only for fraud prevention, and only if you permit it in your OS settings.
13.2 Managing preferences
You can manage tracking preferences: - In-app: Settings → Privacy → Analytics. - In your OS: Android → Settings → Google → Ads; iOS → Settings → Privacy → Tracking.
14. Use of Artificial Intelligence
ME. uses large language models (LLMs) provided by third parties (OpenAI and Google) to generate the AI personas’ responses.
14.1 Important limitations
AI persona responses are artificially generated and may contain factual errors (“hallucinations”), inaccuracies, or inappropriate content despite our moderation efforts.
The AI is not a substitute for professional advice (medical, legal, financial, psychological).
The AI’s “memory” is a reconstruction based on previously processed content — it may be incomplete, inaccurate, or expire.
The persona (Amber, or others) is a fictional AI character, not a human.
14.2 Sending content to LLMs
When you send a message, its content (including relevant prior messages as context) is sent to the LLM provider (OpenAI or Google) to generate a response. Providers process this data according to their own policies: - OpenAI Enterprise / API Terms: does not use API data to train models by default. - Google Gemini API: per Google Cloud Data Processing Amendment.
14.3 Model training
As described in Section 5, we do not use your conversations to train our AI models by default. If, in the future, we offer this option, it will be strictly opt-in with specific, prominent, revocable consent.
14.4 Sensitive content
We recommend against — and actively discourage — sharing the following with the AI: - ID documents, passwords, full banking data. - Suicidal ideation, psychiatric crisis — in those cases, please seek professional help immediately (Talk Suicide Canada 1-833-456-4566; CVV Brazil 188). - Information about third parties that could violate their privacy.
15. Automated decision-making
ME. uses automated processing to: - Personalize AI responses based on your history. - Moderate content (detecting messages that violate the Terms of Service). - Detect fraud in transactions.
No automated decision produces legal effects or significantly affects you in an irreversible way. If you disagree with an automated decision (e.g., account suspension), you may request human review by writing to privacy@dvcapitalventures.ca.
16. Changes to this Policy
We may update this Policy from time to time. When material changes are made, we will notify you: - By email (if registered). - Via prominent in-app notice on your next opening. - With at least 30 days’ advance notice for changes that reduce your rights.
The date of the last update is always shown at the top. Prior versions are available upon request.
17. Contact and complaints
Data Protection Officer (DPO)
Daphne Victoria Email: privacy@dvcapitalventures.ca
Controller
DV Capital Ventures Inc. Corporation Number: 17831846 1706 – 708 Farrow Street, Coquitlam, BC V3J 0P2, Canada General email: hello@dvcapitalventures.ca
Processor (technical partner)
Proxy Systems Ltda. — EPP CNPJ: 02.097.394/0001-73 Rua Anchieta, 164 — Jundiaí — SP — Brazil, postal code 13201-804
Regulatory authorities
ANPD (Brazil): www.gov.br/anpd
Office of the Privacy Commissioner of Canada: www.priv.gc.ca
Commission d’accès à l’information du Québec: www.cai.gouv.qc.ca
This document is originally drafted in Portuguese (Brazil). An English version is available at me4us.com/privacy-policy-pt. In case of interpretation conflict, the Portuguese version prevails for Brazilian users; the English version prevails for Canadian and other users.
This document was prepared based on industry best practices and requirements of LGPD (Federal Law 13.709/2018), PIPEDA (Personal Information Protection and Electronic Documents Act), and Quebec Law 25 (Loi 25). Review by qualified legal counsel is recommended before final publication.
