· Legal ·
Privacy notice
Last updated · 17 June 2026
This privacy notice describes how Chalyb collects, uses, stores and protects your personal data, in compliance with Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, and the INAI guidelines.
1. Data controller
Chalyb, operating from Mexico, is the controller of your personal data. To exercise any right or ask questions about this notice, write to us through /contacto.
2. Data we collect
We collect strictly what the service needs to operate:
2.1. Account data
- Full name
- Email address
- Profile photo (if you sign up with Google)
- Password hashed with bcrypt — we never store the plaintext
2.2. Payment data
- Transaction ID and amounts processed by Mercado Pago. We do NOT store your card details — Mercado Pago handles those directly under its own privacy notice.
- Tier history (Free / Pro / VIP) and the date of every change.
2.3. Usage data
- AI token consumption events per engine — when, how many, and which engine used them.
- Sign-in records (date and time, IP, browser) — kept for 90 days to detect fraud.
- Active engine selection, bot configuration, execution preferences.
2.4. Content you generate in the Engines
- VODs you upload to ChalyClip, generated clips, transcripts, caption variants.
- Streams routed via ChalybStreamManager, saved layouts, OAuth connections to destination platforms (TikTok, YouTube, Twitch, Kick).
- Prompts, AI persona configurations, saved contexts.
We store your content encrypted and only process it when you ask us to. We do not use it to train public models and we do not share it with third parties without your permission.
3. Purposes of processing
We process your data to:
- Operate the service you signed up for (subscription, engine execution, payments).
- Transactional communication: payment confirmations, quota alerts, security notifications.
- Technical support: answering the requests you send through /contacto.
- Tax invoicing: issuing a CFDI when you request one with your RFC.
- Legal compliance: responding to legally valid requests from authorities.
- Fraud detection: analysing payment and usage patterns to prevent abuse.
- Product improvement: aggregate, anonymous statistics — never with data that identifies you.
We do NOT use your data for: third-party advertising, selling databases, training public AI models, or building profiles for purposes unrelated to the service.
4. Third parties we share data with
We share strictly what is necessary with the providers that help us run the service. All of them are bound by contractual obligations of confidentiality and limited processing:
- Supabase (USA) — database, authentication, storage. Hosts your account and content. SOC2 Type II compliant.
- Mercado Pago (Argentina/Mexico) — payment processing. Receives your email and the amount in order to take the payment.
- Vercel (USA) — hosting for the web platform. Receives anonymised access logs.
- Resend (USA) — transactional email delivery. Receives your email address and name.
- Anthropic (USA) — provider of the Claude model. Receives the prompts you send through the engines, with no account metadata attached. Anthropic does not train on this data.
- Integrated Engines (ChalyClip, ChalybStreamManager): see section 5.
5. Data sent to the Engines
When you activate an Engine, Chalyb creates an account for you on it. We send it:
- Your Chalyb user_id (an opaque identifier).
- Your email address.
- Your display name.
- Your current tier (free / pro / vip) — so the engine knows which features to enable for you.
That information lets the Engine create your workspace and validate your access. Any additional content you generate inside the Engine (VODs, clips, configurations) is governed by that particular Engine’s privacy notice, which you accept when you first activate it.
6. Cookies and similar technologies
We use cookies to:
- Session: keep you signed in (HTTP-only, secure, SameSite=Lax cookie). Essential to use the platform.
- Preferences: remember your language (es/en) and the tier selected in the picker. Expires after 12 months.
- Anonymous analytics (Vercel Analytics): pageview counts without identifying you personally. No third-party cookies, no cross-site tracking.
We do not use advertising cookies, cross-site tracking, or browser fingerprinting.
7. Data retention
- Active account: your data is kept for as long as your account is open.
- After closing your account: we delete your identifiable personal data within a maximum of 30 calendar days.
- Legal exceptions: tax invoices (5 years, required by the SAT), fraud/security logs (90 days after closure), technical backups (up to 90 days after the primary deletion).
- Aggregated/anonymised data: may be kept indefinitely for statistics and service improvement. This data cannot be used to re-identify you.
8. Your ARCO rights
Under the LFPDPPP, you have the right to:
- Access: request a copy of the data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Cancellation: request deletion of your data (subject to the legal exceptions above).
- Opposition: object to a specific use of your data.
In addition, you can:
- Withdraw your consent at any time, which ends your use of the service.
- Limit use to the purposes strictly necessary for the service you signed up for.
- Port your data: export it in structured JSON format to take it to another provider.
To exercise any of these rights, write to us through /contacto with the subject «ARCO rights». We respond within 20 business days, the deadline set by the LFPDPPP. If you are not satisfied with our response, you may file a complaint with INAI (Mexico’s National Institute for Transparency, Access to Information and Personal Data Protection).
9. International transfers
Some of our providers (Supabase, Vercel, Resend, Anthropic) operate from the United States. By using Chalyb you authorise the international transfers necessary for the service to work.
These providers meet standards equivalent to or higher than those the LFPDPPP requires. We maintain contractual clauses obliging them to protect your data to international standards (SOC2, ISO 27001, GDPR where applicable).
10. Security measures
We apply reasonable technical and administrative measures to protect your data:
- Encryption in transit (HTTPS/TLS 1.3) for all communication.
- Encryption at rest for sensitive data in the database.
- Irreversible hashing for passwords (bcrypt).
- Optional two-factor authentication (2FA) for accounts.
- Row-Level Security in Supabase to isolate data between users.
- Service-role keys never exposed to the client.
- Audit logs for administrative actions (tier and role changes, access to other users’ data).
- Automatic daily backups with 7-day retention.
- Production access restricted to authorised staff with MFA.
No security measure is perfect. If a breach puts your personal data at risk, we will notify you within 72 hours, following international best practice.
11. Minors
Chalyb is not aimed at anyone under 18. We do not knowingly collect data from minors. If we find that we hold a minor’s data without parental or guardian authorisation, we delete it immediately. If you are a parent or guardian and believe the minor in your care gave us data, contact us via /contacto and we will sort it out.
12. Changes to this notice
We may update this notice when our practices or the applicable regulations change. For substantial changes (new providers, new purposes, changes to international transfers):
- We notify you by email at least 14 calendar days in advance.
- We publish the new version on this page with an updated date.
- If the changes affect secondary purposes, you will have the option to object before they take effect.
13. Contact
For any question, to exercise ARCO rights, or to report privacy incidents:
- Form: /contacto
- Suggested subject: «Privacy — [your reason]»
We respond within 20 business days for formal ARCO requests and in under 24 business hours for general questions.