Privacy and Data Processing Policy (Version 1.7)

Effective and last updated: July 27, 2026

1. Controller, scope, and age

DmGby is the service and domain name used by Danilo Esteban Guzman Martinez, a natural person acting as data controller; DmGby is not a separate legal entity. Identification document No. 1071433821. Notice address: Cl 138 #159 A 8. Telephone: 3178102435. Legal and privacy email: guzmandanilo791@gmail.com.

The operator, through DmGby's privacy and support channel, is the area responsible for consultations and claims. This policy covers natural-person data processed through the public website, authenticated dashboards, PWA/APK web surface, support form, and related infrastructure.

The public catalog can be viewed and the common Dycademia unit can be played without an account. Creating an account and carrying out creator, brief, or future purchase activity is limited to people who declare that they are at least 18 years old. Signup records that affirmation but does not currently perform documentary age or identity verification. DmGby does not offer a parental-consent account flow; if DmGby learns that an account belongs to a minor, it may restrict the account and assess deletion or preservation required by law.

2. Conditional map of data actually processed

  • If you create an account, then D1 stores your normalized account email from password signup or a verified Google email. D1 also stores first and last name when supplied, selected self-service role (creator or ecommerce), optional profession, avatar, account dates, and the version, language, date, and adult affirmation associated with the signup clickwrap. Agency and administrator roles are provisioned separately.
  • If you create or change a password, then new credentials are normalized and stored as salted, versioned PBKDF2-HMAC-SHA256 verifiers. Legacy verifiers may remain until a valid sign-in upgrades them. DmGby never needs the plain-text password after verification.
  • If you sign in, then the browser receives a signed session JWT in an HttpOnly, SameSite=Lax cookie, marked Secure in production and usable for up to seven days. Authorization checks also compare current account claims and a session version.
  • If Google credentials have not been configured, then that additional sign-in option remains disabled and DmGby sends no authentication request or account data to Google through that flow.
  • If you first select creator or ecommerce and continue with the configured Google option, then DmGby starts a Google Authorization Code flow with PKCE, state, and nonce. A signed ten-minute HttpOnly, SameSite=Lax transaction cookie holds the role and protocol values, while D1 stores a one-use SHA-256 state hash. Google receives the authentication request. After a valid callback, D1 stores the provider, issuer, stable subject, verified Google email, and creation or last-use dates; DmGby does not store Google access or refresh tokens. The stable identity is provider + issuer + subject, never the email: an email match does not automatically link accounts, and a returning account keeps its existing role. Google sign-in requires an email_verified claim.
  • If you request a password reset, then DmGby processes the account email and stores a signed, single-use reset token that is usable for ten minutes and is sent through Resend. An expired database value can remain until it is consumed, replaced, or the account is deleted.
  • If you browse or interact with the feed, then DmGby may process IP-derived security/rate-limit data, country code, device/request data, video identifiers, and view, skip, share, like, or favorite events. An authenticated event may be tied to the account; an anonymous event is stored with no user ID. Aggregate counters and retention signals influence ranking. The current anonymous interaction route is not gated by the optional-analytics choice.
  • If you are signed in and have likes, favorites, or purchases, then those records and niche affinity may be used to rank a personalized feed and to compute a transient taste vector. This recommendation has no legal or financial effect and does not decide whether a user may buy, publish, or withdraw funds.
  • If you search, then the query is processed by the search endpoint and may be sent to Cloudflare Workers AI to create a transient semantic embedding. The query and its embedding are not intentionally written to D1 or Vectorize by that flow, although normal security and provider logs may apply.
  • If you ask dy a free-text question, then the browser sends the question, interface language, a general account-role label when available, and a bounded recent in-tab conversation to DmGby's same-origin endpoint. The server selects a limited set of reviewed public DmGby excerpts and sends that text to Google's Gemini 3.5 Flash to produce a sourced answer. DmGby does not intentionally write the question, transcript, or answer to D1; the transcript remains in component memory until the tab reloads or the application is closed. An opaque IP- or account-derived key is used for rate limiting, and normal provider and security logs may still apply. Do not submit passwords, wallets, payment details, identity documents, confidential media, or other sensitive information.
  • If you upload a video, then DmGby stores the original in private R2 together with its file key, SHA-256 duplicate fingerprint, tags, niche, creator-selected content type, price, status, technical identifiers, and audit result. Video bytes, tags, and niche are sent to Gemini for the platform audit.
  • If you create a Video Studio job, then D1 stores the account owner, eligible source-video or prior-job reference, prompt of up to 1,000 characters, mode, aspect ratio, audio and fit choices, trim values, job-specific video-studio-rights-v1 confirmation and date, fixed credit cost, provider and model, status and checkpoints, progress, attempts, provider file or interaction references, private output references, bounded error details, refund date, and timestamps. The server selects the source from the user's own AVAILABLE or private Studio videos, or matching captured/paid marketplace records without a recorded reversal; this flow does not accept an arbitrary source URL. Technical eligibility does not itself prove a license, settlement, or authority to edit.
  • If you publish a brief or submit a proposal, then D1 stores the brief title, description, budget, status, agency, and dates, or the creator, selected available video, status, and dates of the proposal. Briefs are visible to authenticated users; proposal identity, avatar, and video are visible to the owning agency and administrators.
  • If you file a support, privacy, billing, copyright, or technical request, then D1 stores the supplied name, email, category, subject, message, status, public response, dates, and a hash of the private tracking code. If Resend is configured, it sends the acknowledgement and a private copy to the operator's Gmail mailbox.
  • If you enable Web Push, then DmGby stores the push endpoint and the p256dh/auth encryption keys for that browser and transmits encrypted notifications through the browser's push service. Unsubscribing or deleting the account removes the matching D1 subscription.
  • If a creator voluntarily saves a Lightning or Bitcoin address, then D1 stores that destination, creates an internal security notification with masked destinations, and may use Resend to alert the account email after a change. Saving an address only prepares the profile: it does not activate checkout, create a balance, request a withdrawal, or move money.
  • If you start the public Dycademia unit before creating an account, then DmGby sets the essential HttpOnly, SameSite=Lax dmgby_academy_guest cookie, marked Secure in production, with a random opaque value usable for up to seven days. D1 stores only its SHA-256 hash together with expiry, selected route, a limited initial source/campaign/experiment variant, lesson attempts, exercise order, server-verified correctness, content version, and funnel events. It does not store a complete referring URL or free text through this analytics flow.
  • If you complete a Dycademia lesson through the verified attempt flow, then D1 stores the lesson ID, audience world, content version, server-calculated score, pass result, attempt dates, verified Mastery XP or capped Practice XP, current/best streak, last activity day, and earned badge identifiers. Correct answers are not sent with the exercise payload and the self-service export does not include raw answer values. The lesson content itself remains application code rather than a per-user database copy.
  • If you unlock or activate a Dycademia discovery benefit, then D1 stores its source lesson, benefit kind, eligible video or brief selected by you, control/treatment variant, status, activation and expiry times, and qualified outcomes attributed through a short-lived opaque server token. The benefit is labeled as Dycademia discovery, is not paid sponsorship, and does not guarantee views, sales, proposals, hires, or a particular position.

3. Purposes, authorization, and legal grounds

DmGby uses the data above to create and secure accounts, including optional federated authentication when configured; operate, moderate, publish, search, and recommend catalog content; answer voluntary dy questions from reviewed public sources; privately edit eligible videos and account for creative-service credits; manage briefs, proposals, and Dycademia progress; provide support and notifications; prevent abuse and fraud; preserve licensing and legitimate historical evidence; and, only if checkout is later enabled, administer verified payments, balances, refunds, and withdrawals.

For processing governed by Colombia, DmGby must rely on the holder's prior, express, and informed authorization unless Law 1581 of 2012 or another applicable rule provides an exception. Publishing this policy does not itself create authorization. For anonymous feed events that can still identify or reasonably associate a natural person, DmGby must obtain valid authorization or document a specific applicable exception; otherwise that flow must be limited to genuinely non-personal or irreversibly anonymized information. Contract performance and pre-contractual steps apply only when the user requests the relevant service. Legal duties support processing only to their actual scope. If another regime applies, additional grounds such as legitimate interests may be used only after the assessment required by that regime; this phrase is not a blanket substitute for authorization under Colombian law.

Account forms do not request sensitive personal data. A video can nevertheless contain faces, voices, health information, minors, or other third-party data. If a creator uploads such material, the creator must have the permissions and legal basis required for DmGby to host, audit, publish, license, and distribute it. Sensitive data must not be submitted unless its processing is lawful and strictly necessary.

4. Publication, artificial intelligence, and automated ranking

  • If an upload passes the platform audit and becomes AVAILABLE, then it is copied to Cloudflare Stream for signed HLS playback and DmGby then attempts, as a best-effort effect, to embed its tags and niche with Cloudflare Workers AI (bge-m3) and store a vector keyed by video ID in Vectorize. Publication can succeed even if that later indexing attempt fails. The approved video, tags, niche, creator display name or fallback alias, avatar, and profession can be shown publicly without requiring sign-in.
  • If the current direct-detail lookup is requested with a known upload ID, then it can return upload metadata even when the asset is not AVAILABLE because that route does not yet apply an owner, administrator, or publication-status gate. This is a technical access-control limitation—not authorized public publication or permission to reuse the material—and DmGby must restrict it rather than rely on it as authorization.
  • If Gemini rejects or the pipeline cannot complete an upload, then it does not enter the public feed through the normal publication query. DmGby stores the status and reason so the creator can review it or file a traceable request. Gemini file deletion is requested after the audit, but provider-side retention and failed cleanup remain subject to Google's terms and controls.
  • If an administrator triggers the current re-audit of an AVAILABLE asset, then Gemini processes the stored video and metadata again; if that review rejects it, the administrative route can delete its database rows and attempt to delete the R2 original. That route does not by itself guarantee deletion of every Stream copy, Vectorize record, cache, backup, or external index.
  • If public pages are crawlable, then search and AI crawler rules, the sitemap, and IndexNow can expose approved page URLs and public metadata to third parties. DmGby does not intentionally train its own public foundation model on creator content, but it cannot promise that third-party crawlers or providers will never index or use publicly accessible material under their own rules.

The automated audit checks platform signals such as technical quality, NSFW or graphic content, apparent trademarks/trade dress, tag coherence, negative space, and AI artifacts. Approval, rejection, semantic ranking, and a human review are platform decisions—not legal clearance, a guarantee of Brand Safety, or proof of ownership.

5. Video Studio data and private AI editing

  • If you upload a private MP4 inside Video Studio, then DmGby stores the file in private R2 under an account-scoped key and keeps a D1 source row with its status and server-computed SHA-256 duplicate fingerprint. The server reads the upload, limited to 25 MB, to verify its MP4 signature and fingerprint. It is not sent to the marketplace audit or Google through this upload alone; it is sent to a processor only if you later request the corresponding Quick or Generative job.
  • If you request a Quick Video Studio edit, then Cloudflare Media Transformations processes the authorized source, prompt-derived transform specification, aspect ratio, audio choice, fit, and bounded trim instructions. The output is written to private R2 and may be copied to Cloudflare Stream for authorized signed playback.
  • If you request a Generative Video Studio edit, then Cloudflare Media Transformations first creates a private, prompt-selected scene of no more than ten seconds in the requested aspect ratio. DmGby sends that normalized scene and prompt—not an arbitrary source URL—to Google's Gemini Omni Flash preview through the Gemini API and Files service. The temporary normalized R2 input is deleted best-effort after processing. Google may retain uploaded or generated Gemini Files for up to 48 hours under the provider's current service behavior; DmGby makes a best-effort deletion request after a durable private copy is stored or the job fails, but failed cleanup and provider-side logs remain subject to Google's controls.
  • If the generative provider processes or returns a result, then Google applies its safety controls, may reject the request, and generated media can carry SynthID or other provenance signals. Provider preview status means behavior, availability, and safeguards may change; DmGby does not remove or promise the absence of those signals.
  • If a Video Studio job succeeds, then the result remains a private service artifact in R2 and authorized Stream playback. It is not automatically published, placed in the feed, marked AVAILABLE, offered for sale, licensed, or treated as an approved marketplace upload. Publishing requires the ordinary upload and audit flow.
  • If a Video Studio job reserves, spends, refunds, or holds credits, then D1 maintains an integer credit account, append-only job ledger, per-user daily generative usage, and a global daily counter. A definitive failure records one exact refund; an ambiguous provider outcome remains requires_review and holds the debit until reconciled. These credits are service units, not cash, a payout balance, or a marketplace payment.

6. Financial data and checkout status

Checkout is currently disabled. Card and Lightning methods remain configuration_required; the quote endpoint only reads the creator's persisted USD price and displays a creator amount rounded toward the 92% gross target plus the integer remainder for DmGby. No Wompi, ePayco, BTCPay Server, LNbits, or similar provider account is active, and the retired PayPal create, capture, webhook, and payout routes reject new operations.

  • If checkout remains disabled, then DmGby does not create or capture a new payment, grant a new paid license, select a paid brief winner, credit a balance, or execute a payout. Local checkbox state or a displayed quote is not a payment record.
  • If legacy PayPal records already exist, then limited order, capture, payer, payout-email, sale, payment-intent, webhook/ledger, and reconciliation evidence may remain for accounting, fraud, chargeback, licensing, dispute, legal-defense, or data-subject purposes. PayPal is not an active provider.
  • If DmGby later enables a verified provider, then the policy and checkout disclosure must identify the provider and data flow before use. DmGby may then process server-validated prices, currency or satoshis, parties, product/brief, provider references and statuses, settlement, fees, exchange quotes, refunds, reversals, and the minimum withdrawal destination. DmGby will not request card numbers, wallet seed phrases, or private keys.

This policy does not determine VAT, withholding, invoicing, reverse-charge, or document-support obligations. Those depend on current law and the facts of each transaction; a receipt is not represented as a tax invoice where a separate valid tax document is required.

7. Processors, recipients, and international processing

Depending on the condition that the user triggers, data may be transmitted to processors or other recipients outside Colombia. DmGby distinguishes an international transmission to a processor acting on its instructions from a transfer to another controller and applies the authorization, transmission agreement, adequate-protection rule, statutory exception, declaration, or other mechanism required by Colombian law and the applicable provider relationship.

  • If you use the core service, then Cloudflare processes infrastructure data through Workers/edge, D1, R2, Stream, Images, KV/cache, queues, Durable Objects, Workers AI, Vectorize, and operational logs/traces.
  • If you use the configured Google sign-in option, then the selected provider receives the authorization request and processes its own account, authentication, device, security, consent, and callback data under its applicable controls. DmGby receives the authorization response and the minimum identity claims described above. The other provider receives nothing through that attempt.
  • If you upload content for audit, then Google processes the video and supplied tags/niche through the Gemini API. Google also provides the Tag Manager container only after optional consent, and the operator's Gmail mailbox receives a copy of support submissions sent through Resend.
  • If you request a generative Video Studio edit, then Google processes the eligible source video, prompt, aspect ratio, Gemini file references, interaction, and generated result through the Gemini API, Gemini Files, and the Gemini Omni Flash preview model. DmGby requests best-effort file deletion after durable private storage or failure; provider logs, failed cleanup, and retention of up to 48 hours remain governed by Google's current controls.
  • If you ask dy a free-text question, then Google processes the bounded question, recent conversation context, language, general role label, and reviewed public DmGby excerpts through the Gemini API and the stable Gemini 3.5 Flash model. DmGby does not enable Google Search or arbitrary URL retrieval for this flow and does not intentionally persist the conversation in its database; provider-side security, abuse-prevention, and operational logs remain governed by Google's current controls.
  • If you accept optional analytics, then Microsoft Clarity and Google Tag Manager load in the browser. The remotely configured GTM container must be audited separately; this policy does not authorize an undisclosed processor or purpose merely because GTM can technically load it.
  • If DmGby sends account, support, password-reset, or wallet-change email, then Resend processes the recipient, subject, content, and delivery metadata. Support acknowledgements also copy the submitted message to the operator's Gmail mailbox.
  • If you create or reset a password, then Have I Been Pwned receives only the first five characters of a locally computed SHA-1 digest using its padded range protocol—not the password, complete digest, email, or account ID. DmGby does not store the returned range or breach count, and credential creation fails closed if the check is unavailable.
  • If you enable push, then the push service selected by the browser or operating system (for example, services operated by Google, Mozilla, Apple, or Microsoft) receives the endpoint and encrypted message delivery data.

Provider processing locations and safeguards can change and are governed by the live provider agreement and account configuration. DmGby therefore does not certify a particular country or contractual safeguard unless it actually applies to the relevant flow.

8. Cookies, local storage, analytics, and push choice

  • If you play the public Dycademia unit without signing in, then the essential dmgby_academy_guest cookie links the browser to its temporary progress for up to seven days. It is HttpOnly, SameSite=Lax, Secure in production, contains no email or account ID, and cannot be disabled while preserving that guest progress.
  • If you sign in, then the essential dgmby_session cookie authenticates the browser. It cannot be disabled while keeping an authenticated session.
  • If you start the configured Google sign-in, then the essential OAuth transaction cookie is HttpOnly, SameSite=Lax, Secure in production, and expires after ten minutes. It carries the sign-in or signup intent, selected role, provider, return path, PKCE verifier, state, nonce, issue/expiry times, and—only for signup—the acceptance and adult-confirmation flags under a server signature; D1 stores only the one-use state hash needed to reject replay. Consuming or expiring the transaction prevents reuse.
  • If the Android app surface hands an authenticated session to an external browser, then a signed, purpose-bound JWT containing the user ID, session version, and a random jti travels in the URL for up to three minutes, is not single-use, and may remain in the external browser's history or normal request logs. A valid exchange creates the essential seven-day dgmby_session cookie and the JavaScript-readable SameSite=Lax dmgby_ext_checkout marker for two hours. The marker does not prove that a checkout or payment occurred.
  • If you accept or decline the banner, then the value cookie-consent is stored in localStorage until you change it or clear site storage.
  • If you decline optional technologies, then GTM and Clarity are not mounted by DmGby's component and Consent Mode remains denied.
  • If you accept all optional technologies, then GTM and Clarity are mounted and the current code sends granted states for analytics_storage, ad_storage, ad_user_data, and ad_personalization, plus Clarity analytics/ad storage. The current banner uses one accept-all explanation centered on experience and traffic and does not offer a separate advertising-purpose choice; that click must not be treated as informed authorization for a distinct advertising use unless the interface first explains and separates that purpose. No statement here means that DmGby currently sells personal data or runs a paid-ad campaign.
  • If you later revoke consent, then DmGby sends denied states and unmounts the optional scripts for future page operation. Revocation does not guarantee automatic deletion of cookies or records already created by a provider; clear browser storage or submit a request where necessary.

Cookie settings can be reopened from Dy's settings sidebar or the feed privacy control. Push permission is separate from analytics consent and is requested only from the dashboard control. Network delivery, security, and essential storage continue regardless of optional analytics consent.

9. Retention, deletion, and current technical limits

DmGby has no single automatic expiry for every table or provider copy. Its databases remain valid while the service operates and each disclosed purpose, existing license, unresolved request, security need, or legal duty remains. Current, category-specific behavior is:

  • If you use a session or reset link, then the session is usable for up to seven days and the reset link for ten minutes; expiry makes the credential unusable but does not necessarily erase every stored value at that exact second.
  • If you converse with dy, then the visible transcript remains only in the current application tab's memory and is cleared by a full reload or closing the application. DmGby does not currently offer a server-side dy conversation history to export or erase because this flow does not intentionally store the transcript in D1; provider or infrastructure logs follow the controls and limits disclosed above.
  • If an OAuth transaction is consumed or expires, then it cannot be used again and its short-lived D1 attempt is eligible for operational cleanup. These attempt rows are not associated with a user account; a provider identity is associated only after a valid callback completes.
  • If your authenticated push-unsubscribe request is successfully processed, then the matching subscription is deleted from D1. Invalid endpoints may also be removed after delivery failure.
  • If a creator deletes an unsold video from its dedicated control, then DmGby deletes dependent D1 rows and attempts to delete the R2 original after the database mutation. The current route does not automatically delete the Stream copy, Vectorize record, provider caches, or search-engine copies; support review may be required.
  • If you delete your account after recent authentication and no unresolved financial state blocks it, then D1 deletes or anonymizes the account, linked Google identity rows, likes, favorites, identified interactions, notifications, push subscriptions, and unsold content rows. Proposals tied to those unsold videos are deleted; purchased assets, briefs, remaining proposals, payment/license evidence, and sales history are preserved or reassigned/anonymized as needed. Account deletion does not automatically purge R2, Stream, Vectorize, avatar caches, anonymous interactions, support requests, ledger raw evidence, email copies, or third-party indexes.
  • If you use Dycademia as a guest, then the guest credential and session expire after seven days. Expiry prevents further use or account claiming, although physical removal of expired database rows can occur later as part of operational cleanup.
  • If your account has stored or claimed Dycademia data and self-service account deletion succeeds, then D1 deletes verified and legacy academy progress, attempts and answer-verification rows, statistics, badges, practice records, rewards, funnel events, and guest sessions previously claimed by that account. Unclaimed anonymous events or infrastructure logs that cannot reasonably be linked back to the account are not selected by this account-deletion flow.
  • If your self-service account deletion succeeds and no Video Studio job is active or under review, then D1 deletes your Video Studio jobs, private source rows, credit ledger, daily usage, and credit account, then DmGby makes best-effort deletion attempts for the private source files and R2/Stream output references resolved before erasure. An active queued, processing, waiting, or requires_review job blocks self-service deletion until it finishes or support resolves it. Provider logs, failed external cleanup, caches, and backups may require later review or expire under the relevant provider controls.
  • If a payment, payout, capture review, existing license, legal hold, fraud issue, or dispute remains unresolved, then self-service account deletion can be delayed or the necessary record retained until the issue is resolved or the applicable duty expires.

Where no automatic purge exists, the holder may request review of a specific record through the traceable privacy channel. Deletion from active systems may also take time to propagate to backups, caches, processors, and recipients.

10. Holder rights and the procedure to exercise them

Subject to the law applicable to the request, a holder may know, access, update, and rectify personal data; request proof of authorization where required; ask how the data was used; request deletion or revoke authorization when legally available; access the data free of charge; and complain to the Superintendence of Industry and Commerce (SIC) after completing the direct consultation/claim process. Additional rights such as portability, restriction, or objection apply only when the relevant jurisdiction grants them.

Self-service export: the dashboard endpoint /api/user/export currently returns JSON with the profile, linked sign-in identities (provider, issuer, subject, provider email, verification indicator, and dates), summarized uploaded videos, purchases, sales made, legacy buyer payment intents, likes, favorites, identified interactions, notifications, Dycademia verified and historical progress, attempts without raw answers, stats, practice awards, badges, discovery rewards, funnel events, and claimed guest-session metadata, plus Video Studio credit-account, ledger, job, processing, consent, provider-reference, private-artifact-reference, and daily-usage data associated with the account. It excludes access and refresh tokens, idempotency keys, request fingerprints, leases, credentials, and signed or temporary provider URLs. It is not represented as a complete export of every backend system. Request any omitted category—including briefs/proposals, support, push, audit, hybrid-payment, or provider logs—through the privacy channel.

Correction and deletion: profile fields can be edited in the dashboard. Account deletion is self-service only after a recent sign-in and can return a financial-review or active-Video-Studio-review block. Because the technical limits above apply, use the privacy channel to request review of R2, Stream, Vectorize, Gemini Files, support, cache, or retained-license records.

Consultations and claims: submit the traceable form at Contact and support (it creates a reference and private tracking code) or email the legal/privacy address. Identify yourself, state the right invoked, describe the facts and requested data, provide a contact address, and attach supporting evidence where needed. An incomplete claim may require additional information before it can be decided.

Under Law 1581 of 2012, a consultation is answered within ten business days after receipt; if that is not possible, DmGby will explain the delay and answer within up to five additional business days. A complete claim is answered within fifteen business days counted from the day after receipt; if an extension is necessary, DmGby will explain it and answer within up to eight additional business days. A shorter mandatory period prevails.

11. Effective period, changes, and governing text

This version applies from July 27, 2026. A material change to the controller, purposes, data categories, or recipients will be communicated efficiently before it is used when the law requires notice. If a new purpose requires fresh authorization, DmGby must collect it before relying on that purpose. The current system records version 1.7 for new signups after release; it does not automatically mark every existing account as having accepted this new version. The separate video-studio-rights-v1 confirmation applies only to the individual editing job and does not mark general acceptance of this policy.

The Spanish text is the primary policy for the Colombian controller; the English version is provided for accessibility and should be interpreted consistently with the Spanish text and mandatory applicable law. Database validity lasts only for the periods and purposes described above, subject to legal preservation and verifiable deletion requests.