Privacy Policy
Last updated: September 30, 2026
1. Introduction
Mystrix ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our interactive storytelling platform.
2. Information We Collect
Information You Provide
- Account Information: Email address, display name, password
- Profile Information: Bio, preferences, settings
- Payment Information: Processed securely through our payment providers (Stripe, and PayPal where offered)
- Communication: Support requests and feedback
- Content You Create: Story inputs and messages you write during sessions, world chat messages, creator drafts, and any images, audio, or video you upload
Information Collected Automatically
- Usage Data: Pages visited, features used, session interactions
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, access times, referring URLs
3. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Process transactions and manage your account
- Personalize your experience and content recommendations
- Improve our Service and develop new features
- Communicate with you about updates and support
- Ensure safety and security of the platform
- Comply with legal obligations
4. AI Processing of Your Content
When you play a story, ask our support assistant, chat in a world, or use our creator tools:
- Story choreography is primarily processed by DeepSeek using deepseek-flash. Groq is the configured distinct fallback for Story choreography. These services select and arrange fixed creator-authored material; they do not write live Story prose. General platform text, including support questions and non-story world chat, remains processed on the Mystrix host through loopback-only Ollama. OpenAI, OpenRouter, and Alibaba Cloud (Qwen) remain approved hosted providers, but they are not part of the canonical reader route and receive platform-selected text only if deliberately selected and disclosed through the governed provider configuration. If a creator configures their own text-generation credential, authoring requests made with that credential are pinned to the creator-selected provider. Those requests do not fall through to the platform reader route.
- Session transcripts are stored to enable resuming sessions
- Aggregate, anonymized data may be used to improve AI quality
- We do not use your personal interactions to train AI models on other users' content
- For text sent to a third-party AI provider, we do not control whether that provider retains or trains on what it receives. That is governed by that provider's own terms.
- If you turn on Story speech, Mystrix generates it on Mystrix's own voice box: the sanitized spoken prose, its language, and the selected in-house designed voice identity are processed by Mystrix infrastructure and never sent to a hosted speech provider. Story speech is off unless you enable it. Mystrix durably stores each admitted result and reuses it for matching speech recipes and playback, so ordinary replay does not process the text again. If a render's outcome is unknown, the next preparation attempt uses the same content key, so a render the voice box already finished is collected rather than produced again. If you generate a sound effect, it is rendered on the same Mystrix voice box: the effect description you write, at most 500 characters, and a requested duration of 10 seconds or less are processed by Mystrix infrastructure and never sent to a third party, and Mystrix stores the measured result as your ordinary sound asset; generation is limited per day.
- During classifier-backed processing of images and videos you upload, a reduced image derivative or, for video, one extracted poster frame is sent to DeepSeek for automated safety verification. DeepSeek uses those pixels only to return safety scores; it does not generate or edit images. OpenAI does not receive those image derivatives or poster frames. A flagged result, unavailable verification, or classifier outage leaves the uploaded asset unavailable for Story application until human review records an explicit approval; rejection keeps it blocked. Only approved reviewed Creator uploads or approved reviewed house-owned assets can be applied. Automated verification is a moderation aid, not a guarantee that every problematic item is caught.
- Creators can explicitly request Story image generation or refinement with a key they enter for the open authoring session, or use the Mystrix image service where enabled. The selected OpenAI or Google Gemini provider receives the bounded scene brief and reference images the creator selects. Z.ai image generation receives only the bounded scene brief; the Z.ai quality check that reviews its candidate also receives the candidate and the reference images the creator selects. Mystrix does not store creator provider keys in its database; a manual image action keeps a key briefly in worker memory while the action runs. Generated candidates and retained transparent sources remain private working assets until an approved finished frame is applied. DeepSeek remains limited to the safety-verification path described above; it is not an image-generation provider.
- An approved reviewed house-owned discovery or surface image may be reused when its visual specification, rights evidence, and safety review match. Creator-uploaded images remain under the creator's custody and are not turned into shared stock. Each applied full-frame scene image remains bound to the exact owning account, Story version, and event.
5. Information Sharing
We do not sell your personal information. We may share information with:
- Service Providers: Third parties that help us operate. These are our payment processors (Stripe, and PayPal where offered), the AI providers described in section 4, DeepSeek for upload safety verification, and Google for push notifications to our mobile apps. Story speech and creator sound effects are not sent to any third party: they render on Mystrix's own voice box. We do not share your information with a third-party analytics provider; see section 9.
- Creators: Aggregate, anonymized statistics about story performance
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit
- Secure authentication systems
- Regular security assessments
- Access controls and monitoring
7. Data Retention
We retain your information for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time.
8. Your Rights
Depending on your location, you may have rights including:
- Access to your personal information
- Correction of inaccurate data
- Deletion of your data
- Data portability
- Objection to processing
- Withdrawal of consent
To exercise these rights, please contact us through our support system.
9. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your session and authentication
- Remember your preferences
- Analyze usage patterns
- Improve our Service
You can control cookies through your browser settings.
Our visitor analytics are self-hosted on our own servers. We do not use Google Analytics or any third-party analytics provider, and we do not sell or share visitor data. Analytics do not set a cookie: visitors are counted using a rotating one-way fingerprint that we cannot reverse to an IP address, and which stops being linkable to anyone within 24 hours. We honour the Do Not Track and Global Privacy Control browser signals — if your browser sends either, we record nothing at all.
10. Children's Privacy
Mystrix is not intended for children under 13. We do not knowingly collect information from children under 13. If we learn we have collected such information, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on the Service and updating the "Last updated" date.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us through our support system.