Cómo tratamos tus datos

Política de Privacidad

Última actualización: 26 de julio de 2026

Los encabezados y avisos están traducidos; el texto legal extenso se ofrece en inglés. En caso de discrepancia, prevalece la versión en inglés.

Esta política explica qué datos recopila MPower Space, por qué los recopilamos, quién más los recibe y cuánto tiempo los conservamos. Describe el sistema tal y como está construido realmente.

1. Quiénes somos

MPower Space operates the MPower Space app and network from the United Arab Emirates. We are the controller of the personal data described here. We decide why and how it is processed, and we are responsible for it. Contact details are in section 18.

2. Cómo funciona realmente el servicio

Three facts about the architecture shape everything else in this policy.

  • Calls run through our servers. Voice and video calls are not peer-to-peer. Every call is carried by our switching servers. Our infrastructure sits in the media path for the whole call. This is how we connect app calls to regular phone networks, apply your balance, and provide live translation.
  • Messages are stored on our servers. Chat messages are held in our database so they can be delivered and kept in sync across your devices. They are not end-to-end encrypted. Message bodies are encrypted at rest in our database, but the key is held on our servers, so our systems can decrypt them. In transit they are protected by TLS. Technically, we can read them. Section 10 explains the limits we place on that.
  • Media you send is stored on our servers. Photos, videos, voice notes and files you send are stored on our server filesystem and delivered to recipients over HTTPS.

3. Qué datos recopilamos

We collect the following categories of data:

  • Account and identity. Your phone number, its verification status, your display name, your profile photo if you set one, your app language, and the date the account was created. Your phone number is your account identifier and how other MPower Space users see you; calls you make to regular phone numbers go out on an MPower Space number. If you give us an email address for invoices or for two-step recovery, we store that too.
  • Contact matching data. If you grant contact permission, the app reads your device address book and sends normalised phone numbers to our server so we can tell you which of your contacts already use MPower Space. See section 7.
  • Messages and media. The text of your chat messages, and the photos, videos, voice notes, files and locations you choose to share, together with sender, recipient, timestamps and delivery status.
  • Call detail records. For each call: the calling and called numbers, direction, start and end time, duration, the route used, how the call ended, and the amount charged.
  • Call recordings. Audio recordings of calls carried by the platform. Recording is enabled on our network. See section 5.
  • Payment and balance data. Top-up amount, currency, date, the transaction reference from Stripe, the card brand and last four digits Stripe returns to us, your prepaid balance, and the charge applied to each call. We never receive or store your full card number.
  • Device, presence and location data. Your push notification token from Google Firebase or Apple, device model, operating system version, app version, the network address your device connects from, and the time you were last active, which is shown as your last seen status subject to your privacy setting. If you turn on a feature that needs your position, the app sends your latitude and longitude to us and we store the most recent point on your account, overwriting the one before it. We do not keep a location history.
  • Usage and diagnostic data. Sign-in and registration events, connection and server logs, error and crash reports, and technical records of how the app and the network performed.
  • Support content. What you write to us for support, including questions you type into the in-app AI assistant.

4. Cómo usamos los datos y nuestra base legal

Under UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, we process data on the bases listed below.

  • To provide the service. Routing and connecting calls, delivering messages and media, syncing your history across devices, sending push notifications. Basis: performance of our contract with you.
  • To verify your number and protect accounts. Sending one-time passcodes by SMS, detecting fraud, blocking abuse, and investigating security incidents. Basis: performance of our contract and our legitimate interests in a secure network.
  • To bill you. Applying rates, charging your prepaid balance, processing top-ups, resolving disputes, and keeping accounting records. Basis: performance of our contract and compliance with legal obligations.
  • To match your contacts. Showing which of your contacts use MPower Space. Basis: your consent, given through the device permission, which you can withdraw in your device settings.
  • To provide AI features. Live translation, transcription and the support assistant. Basis: your consent when you turn the feature on, and performance of our contract for support requests. See section 6.
  • To record calls. Recording is applied at platform level for regulatory compliance, billing and fraud disputes, and abuse investigation. Basis: compliance with legal obligations that apply to telecommunications operators in the UAE, and our legitimate interests in preventing fraud and abuse. See section 5.
  • To operate, maintain and improve the network. Diagnosing faults, monitoring capacity and call quality, and fixing bugs, mainly using technical logs and aggregated figures. Basis: our legitimate interests in a service that works.
  • To meet legal and regulatory obligations. Retaining and disclosing data where UAE law requires it, and responding to valid legal orders. Basis: compliance with legal obligations. See section 11.

If you are outside the UAE, your local law may give you rights similar to those in the GDPR. We handle those requests as described in section 14.

5. Grabación de llamadas

Call recording is enabled on our platform. Calls carried by our network can be recorded, and recordings are written to our server. Authorised staff can play them back from our administration console.

Why this exists: telecommunications operators in the UAE are subject to retention and lawful-interception obligations, and recordings are also used to settle billing disputes, prove fraud, and investigate reports of abuse.

What it means for you: assume that a call you make or receive through MPower Space may be recorded. If the law where you or the other party are located requires participants to be told that a call is recorded, telling them is your responsibility. This is set out in our Terms of Service.

Recordings may be converted to text using OpenAI Whisper when a written record is needed. See section 6.

6. Funciones de IA y qué sale de nuestros servidores

None of our AI processing happens on your device. In each case below, data is sent from our servers to a third-party AI provider that processes it for us: OpenAI, and, for synthesised speech, ElevenLabs.

  • Live call translation. When translation is on, your call audio is streamed to the OpenAI Realtime API during the call, and synthesised speech is played back into the call. OpenAI also produces a text transcript of what you said in order to translate it. If the cloned-voice option is enabled on your account, the translated text is then sent to ElevenLabs, which speaks it using a voice model built from a sample of your own voice. Your voice and the words you speak leave our server and are processed by these providers. If you do not want that, do not use live translation.
  • Transcription. When a written record of a recording is needed, the recording is sent to OpenAI Whisper and returned as text.
  • In-app AI assistant. Questions you type into the support assistant are sent to OpenAI to generate an answer. Do not type passwords, card numbers or other sensitive details into it.

7. Contactos de tu dispositivo

If you grant the contacts permission, the app reads your address book and sends normalised phone numbers to our directory service so we can return the list of your contacts who already use MPower Space. Contact data does leave your device. Any policy that told you otherwise would be wrong.

We use those numbers to return matches and to show familiar names in your call and chat lists. We do not build advertising profiles from them, we do not sell them, and we do not pass contact lists to third parties for marketing.

You can refuse or revoke the permission in your device settings. The app still works. You can dial and message numbers manually.

8. Quién más recibe tus datos

We use a small number of service providers. Each receives only what it needs for its function.

  • Twilio. Connects calls to and from regular phone networks, and delivers one-time passcodes by SMS. Receives your phone number, the number you dialled, and call metadata such as time and duration. For SMS, it receives your number and the passcode.
  • Stripe. Processes card payments. Your card details go directly to Stripe. We never receive the full card number. Stripe receives the amount, currency, transaction identifiers and the information it needs for fraud checks.
  • OpenAI and ElevenLabs. OpenAI receives call audio during live translation, recordings sent for transcription, and the text you type into the AI assistant. ElevenLabs receives the translated text to be spoken during live translation and, if the cloned-voice option is enabled on your account, a sample of your voice and the voice model built from it. Both are AI providers located outside the UAE. See section 6.
  • Google and Apple. Google Firebase and Apple deliver push notifications, and receive your device push token and the notification payload needed to alert your device, for example that a call is incoming. Google Firebase is also used to verify a phone sign-in token during registration, so Google can receive your phone number. Email we send you, such as an invoice, is delivered through Google's SMTP service, which handles your email address and the contents of that message.
  • Hosting. Our systems run on dedicated servers on Hetzner infrastructure in Germany. Hetzner provides the facility, hardware and network. The systems and the data on them are operated by us.
  • Authorities and legal advisers. Where the law requires disclosure, or to establish or defend legal claims. See section 11.

We do not sell personal data, and we do not share it with advertising networks or data brokers.

9. Dónde se almacenan tus datos y transferencias internacionales

Our servers are located in Germany. We are established in the UAE, so our staff access those systems from the UAE.

Twilio, Stripe and OpenAI are United States companies and may process data in the United States and in other countries. Google and Apple operate global infrastructure for push notifications.

These transfers are made under contracts with each provider that require them to protect the data and to process it only on our instructions, and, where the UAE PDPL requires it, on the basis of your consent to the transfer. Data that crosses a border is also subject to the law of the country it reaches.

10. Acceso del personal y moderación

Some of our staff can access user data through an administration console. It includes a moderation view that can display conversations and shared media, playback of call recordings, call detail records, balances and account status. Staff with the right role can also adjust balances, suspend lines and delete records.

Access is limited by role. Deletions are written to an audit log. We use this access to act on abuse and fraud reports, to resolve billing disputes, to respond to legal requests, and to provide technical support. It is not used to browse private conversations.

We state this openly because a policy claiming that we are unable to see your messages would be untrue, and an untrue policy is worse than an uncomfortable one.

11. Requerimientos legales, deberes de conservación e interceptación legal

We are a telecommunications operator subject to UAE law, including rules made by the Telecommunications and Digital Government Regulatory Authority (TDRA).

UAE law can require us to retain communications data and to disclose it to competent authorities, and to support lawful interception. That can include call detail records, recordings, subscriber data and message content.

We may also disclose data to comply with a valid legal order, to enforce our Terms of Service, to prevent fraud, or to protect the safety of a person. Where we are lawfully permitted to tell you about a request, we will try to.

We will not tell you that we are technically unable to comply when we are able to comply.

12. Cuánto tiempo conservamos los datos

This section describes what actually happens on our systems. Where we state a period, a scheduled job on our servers enforces it. Where we say data is kept until deletion is requested, no automatic deletion job runs today, and you should assume the data stays with us until you ask us to remove it or we close and erase your account. We would rather tell you that than quote a tidy number we do not enforce. Where UAE telecommunications, accounting or tax rules require a minimum period, that period applies regardless.

  • Account data. Kept for as long as your account exists. Closing your account does not erase it automatically. We erase it on request, except for records we are required to keep for legal, tax or regulatory reasons.
  • Messages and media. Kept on our servers for as long as your account exists. No automatic deletion job runs. Deleting a message inside the app removes it from your own view; the service does not currently support server-side message deletion, so our copy remains until you ask us to delete it or we erase your account. Nightly backups hold a rolling 14 days, so anything we do delete leaves the backups within 14 days, unless a legal hold or an open abuse investigation applies.
  • Call detail records. Kept indefinitely. Telecommunications rules require a minimum retention period, and no automatic purge is enabled on our platform, so assume that records of your calls persist until you ask us to delete them and we are permitted to do so.
  • Call recordings. Kept on our servers with no automatic deletion. Our platform has a 90-day file retention setting, but the job that would enforce it is currently switched off, so recordings remain until they are deleted manually or on request. We will not quote a period we do not enforce.
  • Payment and transaction records. Kept for at least the period UAE accounting and tax law requires. No automatic deletion job runs, so these records persist.
  • Contact matching queries. Not stored. The directory service compares the numbers your app sends against our list of users and returns the matches; it writes nothing to our database. Our web server logs record that the request was made, not the numbers inside it, and those logs are rotated away after 14 days.
  • Device and push tokens. Kept while the app is installed and registered, and replaced when your device issues a new token. No job expires stale tokens; they are removed when we erase your account. The last location point, where a feature you use has sent one, is overwritten each time a new one arrives and is removed with your account.
  • Diagnostic and connection logs. This is the one category where periods are enforced automatically: telephony switch logs are purged after 7 days, web server access and error logs are rotated after 14 days, PHP session files after 8 days, and system logs after roughly a month. The system journal is capped by size rather than by age. Note that the live-translation service writes operational log lines that can include short fragments of what was said on a translated call, and those lines sit in that journal.
  • Support and AI assistant conversations. Kept with your account record. No automatic deletion job runs; we remove them on request.

13. Seguridad

What we do: traffic between the app and our API is encrypted in transit with HTTPS and TLS, and so is traffic to our service providers. Message bodies are encrypted at rest in our database with AES-256-GCM, using a key held on our servers separately from the data, which our systems can use to decrypt them. Administrative access is role-based and restricted, destructive actions in the admin console are written to an audit log, and our servers are hardened with administrative access limited. The payment flow is separated so that card numbers reach Stripe and not us. Backups are taken nightly, kept for 14 days, and readable only by the system administrator.

What we do not claim: MPower Space is not end-to-end encrypted. Your messages, media and call recordings are readable on our servers by our systems and by authorised staff. Call signalling and call audio between your device and our switch are not currently carried over SIP TLS or SRTP, which means call media is not encrypted on that leg, and a party able to observe the network path between you and us could in principle intercept it. This is a known limitation of the current network configuration, and it is stated here rather than hidden. No system is completely secure, and we do not promise that ours is.

If a breach affects your personal data, we will notify you and the competent authority as UAE law requires.

14. Tus derechos

Under the UAE PDPL you have the following rights over your personal data:

  • Access. Ask what we hold about you and get a copy.
  • Correction. Ask us to fix data that is wrong or incomplete.
  • Deletion. Ask us to delete your data, subject to what we must keep by law.
  • Objection and restriction. Object to processing based on our legitimate interests, or ask us to limit processing while a dispute is resolved.
  • Portability. Receive the data you gave us in a structured, machine-readable format.
  • Withdraw consent. Turn off features you consented to, such as contact matching or live translation, at any time. Withdrawal does not undo processing already carried out.
  • Complain. Raise a complaint with us, and with the UAE Data Office.

To exercise a right, email us from the address linked to your account or write from your registered number, with the subject line Privacy request. We verify your identity before we act, normally by sending a passcode to your registered number. We reply within 30 days.

Some data we cannot delete on request: call detail records, invoices and recordings held under a retention obligation, a legal hold or an open investigation. Where that applies, we will tell you which data is affected and why.

15. Lo que no hacemos

Each statement below is true of the system as built.

  • We do not sell your personal data.
  • We do not share your data with advertising networks or data brokers.
  • We do not use the content of your messages, calls or recordings to target advertising. There is no advertising in the app.
  • We do not give your contact list to third parties for marketing.
  • We do not track your location in the background for our own purposes, we do not sell or publish it, and we do not build a location history. Where a feature you use sends your position, we store only the most recent point and overwrite the one before it. Location you share in a chat is sent only when you choose to share it.
  • We do not train our own AI models on your calls, messages or recordings.
  • We do not read private conversations out of curiosity or for product analytics. Staff access is limited to the operational reasons set out in section 10.
  • We do not require a social media login, and we do not pass your identity to social networks.

16. Menores

MPower Space is for people aged 16 and over. We do not knowingly create accounts for anyone younger. If we learn that an account belongs to a child under 16, we will suspend it and delete the data. A parent or guardian can contact us at any time about an account they believe belongs to a child.

17. Cambios en esta política

We update this policy when the service changes. The date at the top shows the current version. If a change materially affects how we use your data, we will tell you in the app or by message before it takes effect. Continuing to use the service after that date means the updated policy applies to you.

18. Contacto

For privacy questions, data requests and complaints, write to us with your registered phone number so we can identify your account. For security reports, use the security address. You also have the right to complain to the UAE Data Office.

Privacidad y solicitudes de datos:
contact@mpowerspace.ai
Informes de seguridad:
security@mpowerspace.ai

MPower Space, United Arab Emirates.