Subprocessors and Data Retention
Terug naar alle beleidsdocumentenLast updated: September 30, 2026
1. Purpose
This document is the detailed reference the Privacy Policy points to for exactly which third parties process data on Mystrix's behalf (subprocessors) and how long different kinds of data are kept (retention). It does not replace the Privacy Policy, and if the two ever appear to disagree, the Privacy Policy's wording is canonical.
2. Subprocessors
The following third parties receive data to help operate Mystrix, matching Privacy Policy §5:
- Stripe, and PayPal where offered — payment processing for all purchases.
- DeepSeek — the primary processor for reader Story text generation, using deepseek-flash, and the safety verifier for uploaded visual media. For that verification, DeepSeek receives only a reduced derivative of an uploaded image or one extracted poster frame from an uploaded video and returns safety scores. It does not generate or edit images for Mystrix.
Mystrix does not control whether DeepSeek retains or trains on the text or limited visual derivatives it receives;
that handling is governed by DeepSeek's own terms (Privacy Policy §4).
- Groq — the configured distinct fallback for Story choreography. Groq receives fixed creator-authored Story text and reader input only when that fallback is used; it does not write live Story prose.
- Mystrix (self-hosted Ollama) — the processor for general platform text, including support questions and non-story world chat. Its endpoint is bound to loopback on the Mystrix host.
- OpenAI, OpenRouter, and Alibaba Cloud (Qwen) — approved hosted AI providers that Mystrix also supports for text generation, but none is part of the canonical reader route. They receive text only when deliberately selected through the governed provider configuration or an explicit creator session-key action (Privacy Policy §4). OpenAI can additionally receive a bounded scene brief and creator-selected image references when a creator explicitly uses an OpenAI key or the Mystrix image service uses one.
- Google Gemini — receives a bounded scene brief and creator-selected image references only when a creator explicitly uses a Gemini session key or the Mystrix image service uses one. It returns generated pixels or a bounded image-quality verdict for that request; this is separate from Google push delivery.
- Z.ai — receives a bounded scene brief only when a creator explicitly uses a Z.ai session key or the Mystrix image service uses one, and returns one generated image. Its separate image-quality check receives that candidate with the creator-selected image references and returns a bounded verdict.
The optional included house image service also sends the prepared brief, selected references,
and candidate-review images to OpenAI. Those requests follow the house OpenAI account's data
controls rather than an API organization's settings. Mystrix keeps that account's sign-in on the
server and does not distribute it to creators.
- A creator's own text provider, where the creator has configured a credential — authoring requests made with that credential. This route is pinned to the creator-selected provider and does not fall through to the platform reader route.
- Mystrix voice box (first-party, not a subprocessor) — Story speech and optional creator sound-effect generation. Both render on Mystrix's own dedicated voice box: Story speech from the sanitized spoken prose, its language, and the selected in-house designed voice identity; a sound effect from the effect description you write (at most 500 characters) and a requested duration of 10 seconds or less. Neither is sent to a third party. Mystrix measures each generated sound effect and stores it as your ordinary sound asset under account daily limits.
- DeepSeek visual safety verification — the reduced derivative or poster-frame processing described above is separate from DeepSeek text generation. A flagged or unavailable verification leaves the upload unavailable for Story application until human review records an explicit approval; rejection keeps it blocked. OpenAI does not receive these visual derivatives or poster frames.
- Google — delivery of push notifications to the Android apps.
Mystrix does not use a third-party analytics provider; visitor analytics are self-hosted (Privacy Policy §9). Creators can explicitly request image generation or refinement through OpenAI, Google Gemini, Z.ai, or the Mystrix image service where enabled. Generated candidates and retained sources remain private until a reviewed finished frame is applied. Approved reviewed Creator uploads and approved reviewed house-owned images remain valid sources. Creator uploads and private generated sources remain under creator custody; each applied full-frame scene image remains scoped to the exact owning account, Story version, and event (Privacy Policy §4).
3. Retention while your account is active
Mystrix retains account, profile, story, play-session, support, purchase, and financial information for as long as your account is active or as needed to provide the Service (Privacy Policy §7). Some narrower operational records have shorter, code-enforced periods:
- A password-reset capability is valid for one hour. Its stored, one-way hash is scheduled for automatic removal after its individual expiry time.
- A creator preview session expires after 30 days. Once expired it is no longer returned as a usable session; its transcript, state, and memories are cascade-deleted when it is next accessed or by the bounded expiry sweep that runs as new preview sessions are created.
- Read notifications, push-notification delivery records, creator analytics, and support-answer outcome records become eligible for automatic deletion 90 days after creation. Unread notifications are not removed by the read-notification timer.
- Community World-chat messages become eligible for automatic deletion 90 days after creation.
Deleting a World removes its complete room transcript and World-scoped chat state sooner;
account erasure removes messages attributed to the account and the complete chat state of any
World the account owns. A signed-in account can export every retained World-chat message
attributed to it as newline-delimited JSON.
- AI usage-accounting records that enforce and audit model-spend limits become eligible for automatic deletion after 365 days. They are also account-erasure targets when they name the account.
- An anonymous campaign-link visit — including the recorded network address, user agent, and referrer — becomes eligible for automatic deletion after 180 days.
- Completed synthesized Story speech clips and tracks are durable and do not have an automatic-expiry timer. Story speech is generated on Mystrix's own voice box from the sanitized spoken prose, its language, and the selected in-house designed voice identity; if a render's outcome is unknown, the next preparation attempt uses the same content key, so a finished render is collected rather than produced again. A clip is keyed by its exact text, licensed voice, model, settings, language, and seed rather than by an owning account or Story, so the same performance recipe can be reused without synthesizing again. Story playback tracks retain Story/version identity and are composed from those durable clips; both stores are separate from creator-owned uploaded media.
Database time-to-live cleanup is asynchronous, so a record can remain briefly after its cutoff before the database removes it.
4. Retention after a deletion request
Signed creator and performer compensation tax documents are stored privately by Mystrix,
separately from public media. Only the payee can submit a document, and only authorized
super-admin reviewers can download the PDF or accept its tax treatment. Documents and
their review history have no automatic-expiry deletion timer and are removed with eligible
account erasure. An unresolved compensation payment or withheld-tax remittance prevents
that erasure until the obligation is settled.
You may request deletion of your account and associated data at any time by contacting us through our support system (Privacy Policy §7-8). When an erasure is carried out, it removes rows that the platform's ownership manifest attributes to the account, including profile and authentication data, reader sessions and their child state, support conversations and messages, purchases, the platform's financial books for that account, creator stories, visual-canon assets, and the other content owned by those stories. It also removes the account from shared party membership without deleting another user's party.
Some records are intentionally not classified as account-owned and can outlive an erasure when retaining the record is necessary for security, fraud prevention, legal obligations, proving that an operator, moderation, payment, or deletion decision occurred, or preserving a shared published artifact. Examples include operator audit trails, moderation decision history, payment-provider notification and deduplication records, an email suppression needed to avoid resuming mail to an address that opted out, and completed synthesized-audio artifacts keyed to their content rather than to an account. These retained records are not an active account and are not used to restore the erased account.
If an account contributed a sound to Public sounds, erasure withdraws that contribution and
removes its independent pool master. Copies other creators already added to their Stories remain
in those creators' asset libraries under the permission the contributor accepted when sharing.
An erasure can be deliberately refused rather than carried out if it would destroy evidence of an unresolved financial obligation: a live subscription still billing your card or unpaid or unscheduled compensation owed to you. Unsettled compensation and withheld-tax obligations cannot be bypassed by an operator's force flag.
If any required deletion step fails, the account row is kept and the operation reports an incomplete erasure instead of reporting success over a partial deletion.
5. Analytics retention
Mystrix's self-hosted visitor analytics do not set a cookie and count visitors with a rotating one-way fingerprint that cannot be reversed to an IP address and stops being linkable to anyone within 24 hours. Sending either the Do Not Track or Global Privacy Control browser signal means nothing is recorded for that visit at all (Privacy Policy §9).
6. Your rights
See Privacy Policy §8 for the full list of rights you may have depending on your location, and how to exercise them.
7. Contact
Questions about a specific subprocessor or a retention period should go through our support system.