Privacy and Data Processing Policy (Version 3.2)
Effective August 25, 2026; last updated August 26, 2026
1. Controller, scope, and age
dy, previously known as DmGby, is the same service and domain name used by Danilo Esteban Guzman Martinez, a natural person acting as data controller. The rename does not create a new platform, service, data controller, or legal entity, and it does not invalidate, replace, or reset existing authorizations, consents, requests, contracts, or records associated with the former name. dy is not a separate legal entity. Identification document No. 1071433821. Notice address: Cl 138 #159 A 8. Telephone: 3178102435. Legal and privacy email: guzmandanilo791@gmail.com.
The operator, through dy's privacy and support channel, is the area responsible for consultations and claims. This policy covers natural-person data processed through the public website, authenticated dashboards, PWA/APK web surface, support form, and related infrastructure.
The public catalog can be viewed without an account. Creating an account and carrying out creator, brief, or future purchase activity is limited to people who declare that they are at least 18 years old. Signup records that affirmation but does not currently perform documentary age or identity verification. dy does not offer a parental-consent account flow; if dy learns that an account belongs to a minor, it may restrict the account and assess deletion or preservation required by law.
2. Conditional map of data actually processed
- If you create an account, then D1 stores your normalized account email from password signup or a verified Google email. D1 also stores first and last name when supplied, selected self-service role (creator or ecommerce), optional profession, avatar, account dates, and the version, language, date, and adult affirmation associated with the signup clickwrap. Agency and administrator roles are provisioned separately.
- If you keep an externally hosted HTTPS avatar, then the avatar URL is stored with the profile and a browser that displays it can request the image directly from that host, which can receive ordinary network data such as IP address, user agent, and request time under its own controls. The dashboard's normal file selector instead stores a validated inline image; dy does not represent every legacy or Google-supplied avatar as locally proxied.
- If you create or change a password, then new credentials are normalized and stored as salted, versioned PBKDF2-HMAC-SHA256 verifiers. Legacy verifiers may remain until a valid sign-in upgrades them. dy never needs the plain-text password after verification.
- If you sign in, then the browser receives a signed session JWT in an HttpOnly, SameSite=Lax cookie, marked Secure in production and usable for up to seven days. Authorization checks also compare current account claims and a session version.
- If you request a password reset, then dy processes the account email and stores a signed, single-use reset token that is usable for ten minutes and is sent through Resend. A historical provider-only account can establish a local password only when its linked identity recorded a verified email that still matches the account. Historical identity metadata is not itself a sign-in method. An expired database value can remain until it is consumed, replaced, or the account is deleted.
- If you browse or interact with the feed, then dy may process IP-derived security/rate-limit data, country code, device/request data, video identifiers, and view, skip, share, like, or favorite events. An authenticated event may be tied to the account; an anonymous event is stored with no user ID. Aggregate counters and retention signals influence ranking. The current anonymous interaction route is not gated by the optional-analytics choice.
- If you are signed in and have likes, favorites, or purchases, then those records and niche affinity may be used to rank a personalized feed and to compute a transient taste vector. This recommendation has no legal or financial effect and does not decide whether a user may buy, publish, or withdraw funds.
- If you search, then the browser sends the bounded catalog query to dy's same-origin search endpoint. DeepSeek V4 Flash may receive only that sanitized query to interpret its semantic intent; it receives no conversation history, account role, profile, private media, payment data, or user-specific tool context. Cloudflare Workers AI may also create a transient semantic embedding. Explicit filters selected by the user remain authoritative, and the server applies allowlisted filters and catalog predicates before returning videos. A validated derived interpretation may remain for up to five minutes in a SHA-256-keyed edge cache solely to keep pagination consistent and avoid repeated provider calls; the raw query is not placed in that cache key. dy does not intentionally write the query, interpretation, or embedding to D1 or Vectorize through this flow, although normal security and provider logs may apply. Do not place passwords, wallets, payment details, identity documents, confidential media, or other sensitive information in the search box.
- If you upload a video, then dy stores the original in private R2 together with its file key, SHA-256 duplicate fingerprint, tags, niche, creator-selected content type, price, status, technical identifiers, and audit result. Video bytes, tags, and niche are sent to Gemini for the platform audit.
- If you configure and approve license offers for your video, then D1 stores the creator, video, one-time product type (Standard, Category Exclusivity, or Catalog Buyout), any 7/30/90-day option, the platform's USD 49.99 Standard default or the creator-entered Premium price, currency, draft/active/paused/retired state, revision, scope and Terms versions, and approval and rights-attestation dates. Publishing an offer alone does not identify a buyer, collect money, reserve exclusivity, or grant a license.
- If you create a Video Studio job, then D1 stores the account owner, eligible source-video or prior-job reference, prompt of up to 1,000 characters, mode, aspect ratio, audio and fit choices, trim values, job-specific video-studio-rights-v1 confirmation and date, fixed credit cost, provider and model, status and checkpoints, progress, attempts, provider file or interaction references, private output references, bounded error details, refund date, and timestamps. The server selects the source from the user's own AVAILABLE or private Studio videos, or matching captured/paid marketplace records without a recorded reversal; this flow does not accept an arbitrary source URL. Technical eligibility does not itself prove a license, settlement, or authority to edit.
- If you publish a brief or submit a proposal, then D1 stores the brief title, description, budget, status, agency, and dates, or the creator, selected available video, status, and dates of the proposal. Briefs are visible to authenticated users; proposal identity, avatar, and video are visible to the owning agency and administrators.
- If you file a support, privacy, billing, copyright, or technical request, or privately describe an agency content need for the founding cohort, then D1 stores the supplied name, email, category, subject, message, status, public response, dates, and a hash of the private tracking code. For the agency-need form, the subject also carries limited source, campaign, and CTA labels; dy does not publish the submitted need as a Brief. If Resend is configured, the acknowledgement sent to you and the private copy sent to the operator's Gmail mailbox contain the message, reference, readable private tracking code, and those limited acquisition labels.
- If you enable Web Push, then dy stores the push endpoint and the p256dh/auth encryption keys for that browser and transmits encrypted notifications through the browser's push service. Unsubscribing or deleting the account removes the matching D1 subscription.
- If a creator voluntarily saves a Lightning or Bitcoin address, then D1 stores that destination, creates an internal security notification with masked destinations, and may use Resend to alert the account email after a change. Saving an address only prepares the profile: it does not activate checkout, create a balance, request a withdrawal, or move money.
3. Purposes, authorization, and legal grounds
dy uses the data above to create and secure accounts; operate, moderate, publish, interpret queries, search, and recommend catalog content; privately edit eligible videos and account for creative-service credits; manage briefs and proposals; respond to a privately submitted content need; provide support and notifications; prevent abuse and fraud; preserve licensing and legitimate historical evidence; record an optional nominative billing request for the requested fiscal purpose; and administer PayPal Checkout orders, verified captures, delivery, receipts, refunds and reversals when the marketplace checkout is shown as available. Creator withdrawals and paid brief awards remain separate, disabled flows.
For processing governed by Colombia, dy must rely on the holder's prior, express, and informed authorization unless Law 1581 of 2012 or another applicable rule provides an exception. Publishing this policy does not itself create authorization. For anonymous feed events that can still identify or reasonably associate a natural person, dy must obtain valid authorization or document a specific applicable exception; otherwise that flow must be limited to genuinely non-personal or irreversibly anonymized information. Contract performance and pre-contractual steps apply only when the user requests the relevant service. Legal duties support processing only to their actual scope. If another regime applies, additional grounds such as legitimate interests may be used only after the assessment required by that regime; this phrase is not a blanket substitute for authorization under Colombian law.
Account forms do not request sensitive personal data. A video can nevertheless contain faces, voices, health information, minors, or other third-party data. If a creator uploads such material, the creator must have the permissions and legal basis required for dy to host, audit, publish, license, and distribute it. Sensitive data must not be submitted unless its processing is lawful and strictly necessary.
4. Publication, artificial intelligence, and automated ranking
- If an upload passes the platform audit and becomes AVAILABLE, then it is copied to Cloudflare Stream for signed HLS playback and dy then attempts, as a best-effort effect, to embed its tags and niche with Cloudflare Workers AI (bge-m3) and store a vector keyed by video ID in Vectorize. Publication can succeed even if that later indexing attempt fails. The approved video, tags, niche, creator display name or fallback alias, avatar, and profession can be shown publicly without requiring sign-in.
- If a public direct-detail page or API lookup is requested with an upload ID, then dy returns public metadata only when the asset is AVAILABLE. A non-public record is returned by the API only to its authenticated owner or an administrator and is sent with private, no-store caching; all other callers receive the same not-found response used for an unknown ID.
- If Gemini rejects or the pipeline cannot complete an upload, then it does not enter the public feed through the normal publication query. dy stores the status and reason so the creator can review it or file a traceable request. Gemini file deletion is requested after the audit, but provider-side retention and failed cleanup remain subject to Google's terms and controls.
- If an administrator triggers the current re-audit of an AVAILABLE asset, then Gemini processes the stored video and metadata again; if that review rejects it, the administrative route can delete its database rows and attempt to delete the R2 original. That route does not by itself guarantee deletion of every Stream copy, Vectorize record, cache, backup, or external index.
- If public pages are crawlable, then search and AI crawler rules, the sitemap, and IndexNow can expose approved page URLs and public metadata to third parties. dy does not intentionally train its own public foundation model on creator content, but it cannot promise that third-party crawlers or providers will never index or use publicly accessible material under their own rules.
The automated audit checks platform signals such as technical quality, NSFW or graphic content, apparent trademarks/trade dress, tag coherence, negative space, and AI artifacts. Approval, rejection, semantic ranking, and a human review are platform decisions—not legal clearance, a guarantee of Brand Safety, or proof of ownership.
5. Video Studio data and private AI editing
- If you upload a private MP4 inside Video Studio, then dy stores the file in private R2 under an account-scoped key and keeps a D1 source row with its status and server-computed SHA-256 duplicate fingerprint. The server reads the upload, limited to 25 MB, to verify its MP4 signature and fingerprint. It is not sent to the marketplace audit or Google through this upload alone; it is sent to a processor only if you later request the corresponding Quick or Generative job.
- If you request a Quick Video Studio edit, then Cloudflare Media Transformations processes the authorized source, prompt-derived transform specification, aspect ratio, audio choice, fit, and bounded trim instructions. The output is written to private R2 and may be copied to Cloudflare Stream for authorized signed playback.
- If you request a Generative Video Studio edit, then Cloudflare Media Transformations first creates a private, prompt-selected scene of no more than ten seconds in the requested aspect ratio. dy sends that normalized scene and prompt—not an arbitrary source URL—to Google's Gemini Omni Flash preview through the Gemini API and Files service. The temporary normalized R2 input is deleted best-effort after processing. Google may retain uploaded or generated Gemini Files for up to 48 hours under the provider's current service behavior; dy makes a best-effort deletion request after a durable private copy is stored or the job fails, but failed cleanup and provider-side logs remain subject to Google's controls.
- If the generative provider processes or returns a result, then Google applies its safety controls, may reject the request, and generated media can carry SynthID or other provenance signals. Provider preview status means behavior, availability, and safeguards may change; dy does not remove or promise the absence of those signals.
- If a Video Studio job succeeds, then the result remains a private service artifact in R2 and authorized Stream playback. It is not automatically published, placed in the feed, marked AVAILABLE, offered for sale, licensed, or treated as an approved marketplace upload. Publishing requires the ordinary upload and audit flow.
- If a Video Studio job reserves, spends, refunds, or holds credits, then D1 maintains an integer credit account, append-only job ledger, per-user daily generative usage, and a global daily counter. A definitive failure records one exact refund; an ambiguous provider outcome remains requires_review and holds the debit until reconciled. These credits are service units, not cash, a payout balance, or a marketplace payment.
6. Financial data and checkout status
One-time catalog licenses and separately gated paid Brief awards use PayPal Checkout only when the interface reports it as available. PayPal offers its wallet and, only where it marks it eligible, debit or credit card funding in USD. An offer, Brief, proposal or quote alone creates no subscription, automatic renewal, payment, hold, award, buyout or grant. Lightning, Wompi, ePayco, BTCPay Server, LNbits, creator payouts and credit purchases remain disabled or preparatory and are not represented as connected payment services.
- If a creator affirmatively submits or reconfirms a proposal for a paid Brief award, then dy processes the creator, Brief, persisted USD budget, exact proposal and video, content origin, clean-file SHA-256, current Terms version, one-time 92/8 allocation and disclosed commercial scope. D1 stores the consent schema version, immutable JSON snapshot, SHA-256 hash and server attestation timestamp. Earlier proposals without that evidence remain ineligible for paid checkout until the creator reconfirms them; migration does not fabricate consent.
- If the buyer affirmatively requests an invoice in a personal or organization name, then the unchecked optional form collects only identification type and number. A separate unchecked confirmation authorizes their exclusive use for the official one-to-one billing lookup and to prepare, deliver and retain the requested fiscal document; D1 records the current Privacy version, legal locale and server timestamp with the checkout intent. Name or legal name and registered email must be completed by the official lookup when the fiscal channel is configured; this form does not collect them, an address, phone number, physical RUT copy or additional profile, and does not send the identification to PayPal. No fiscal provider is currently configured, so the request remains evidence for the pending fiscal process and the dy commercial receipt is not represented as a tax invoice.
- If the buyer opens PayPal or the eligible card option, then the browser loads PayPal's SDK and PayPal may receive ordinary network/device data, its own cookies or storage, the PayPal account interaction or card details entered in PayPal's controlled surface, and fraud/security signals. dy sends only the server-owned USD total, order and reservation references, license description and transaction identifiers. dy does not receive or store the full card number, card security code or PayPal password.
- If a buyer selects a one-time catalog license or consented paid Brief proposal and asks the server to create an order, then For catalog, dy processes the exact offer/revision, Standard/Category Exclusivity/Catalog Buyout type, platform or creator-entered price, category and 7/30/90-day term. For a Brief award, dy processes the exact Brief, submission, server-persisted budget, creator-consent version/hash and winner/rejected states. Both process USD, video/file hash/specifications, creator, buyer and disclosed client, prior-grant count, legal language and Terms/Privacy/scope versions, three buyer confirmations and dates, immutable reservation/grant snapshots and hashes, activation/delivery dates, PayPal order/capture/event references and statuses, payer details returned by PayPal, actual processor fee when returned, settlement, refund/reversal and receipt evidence. This is not recurring-billing data.
- If PayPal returns a verified completed capture, then dy atomically records the sale, active license grant, authorized clean-file delivery and integer-cent 92/8 gross entries. The creator amount remains pending until provider settlement and reconciliation. A verified partial or full refund or reversal revokes the indivisible delivery authorization and appends separate evidence without rewriting prior entries; a redirect or apparent browser success never grants access.
- If PayPal or a payment record must be retained, then limited order, capture, payer, nominative billing request, sale, intent, verified webhook, ledger, receipt, refund/reversal and reconciliation evidence may remain for accounting, invoicing, fraud, chargeback, licensing, dispute, legal-defense, regulatory and data-subject purposes under the retention rules below. A never-submitted local billing request may be deleted with its failed local attempt; a request already tied to provider or accounting evidence is retained or placed under review. Card credentials remain with PayPal; dy does not use PayPal transaction data for unrelated advertising.
This policy does not determine VAT, withholding, invoicing, reverse-charge, or document-support obligations. Those depend on current law and the facts of each transaction; a receipt is not represented as a tax invoice where a separate valid tax document is required.
7. Processors, recipients, and international processing
Depending on the condition that the user triggers, data may be transmitted to processors or other recipients outside Colombia. dy distinguishes an international transmission to a processor acting on its instructions from a transfer to another controller and applies the authorization, transmission agreement, adequate-protection rule, statutory exception, declaration, or other mechanism required by Colombian law and the applicable provider relationship.
- If you use the core service, then Cloudflare processes infrastructure data through Workers/edge, D1, R2, Stream, Images, KV/cache, queues, Durable Objects, Workers AI, Vectorize, and operational logs/traces.
- If you upload content for audit, then Google processes the video and supplied tags/niche through the Gemini API. This condition alone does not load optional analytics or send a support message.
- If you request a generative Video Studio edit, then Google processes the eligible source video, prompt, aspect ratio, Gemini file references, interaction, and generated result through the Gemini API, Gemini Files, and the Gemini Omni Flash preview model. dy requests best-effort file deletion after durable private storage or failure; provider logs, failed cleanup, and retention of up to 48 hours remain governed by Google's current controls.
- If you use semantic catalog search, then Hangzhou DeepSeek Artificial Intelligence Co., Ltd. processes only the bounded, sanitized catalog query through the DeepSeek API and DeepSeek V4 Flash to return a constrained semantic interpretation. dy does not send conversation history, account or profile context, filter selections, arbitrary URLs, SQL, credentials, signed media, payment data, or destructive actions to the model, and does not intentionally persist the query or interpretation in its database. Provider-side security, abuse-prevention, operational logs, locations, and retention remain governed primarily by the applicable DeepSeek Open Platform Terms and any applicable data-processing arrangement. DeepSeek's general Privacy Policy states that end-user data from applications built on the Open Platform is not governed by that general policy, so its link below is contextual rather than a substitute for the Open Platform terms.
- If you choose PayPal wallet or an eligible card payment, then PayPal, Inc. and the PayPal group entities identified in the applicable Colombian PayPal privacy statement process the checkout interaction, payer/account or card data entered in PayPal's surface, order amount and description, merchant and transaction references, device/network, security, fraud, compliance, capture, refund and dispute data under their own roles and terms. Processing and storage may occur outside Colombia. dy sends the minimum order data described above, verifies PayPal server responses and webhook signatures, and does not receive the full card number or PayPal password.
- If you accept optional analytics, then Microsoft Clarity and Google Analytics 4 load in the browser and may receive navigation/session measurements plus the selected properties checkout_status and checkout_video_id (a catalog video identifier) on the video-detail surface. Together they store the cookies _clck, _clsk, _ga, _ga_C11QNEW1S8. These are the only analytics providers dy loads. Accepting analytics alone loads no advertising tag whatsoever: the Google Tag Manager container is not requested at all in that state, and Google Analytics 4 is served directly from gtag.js instead, so a tag published inside the container cannot reach a visitor who did not accept advertising.
- If you also allow the advertising category, then Google receives the technical request needed to serve the configured Google Tag Manager container, and Meta Pixel (Facebook) may receive page, browser, referrer, campaign, and advertising-event data. Google Tag Manager is a tag container and does not set cookies by itself; the disclosed advertising cookies belong to the tags it deploys.
- If dy sends account, support, agency-need, password-reset, or wallet-change email, then Resend processes the recipient, subject, content, and delivery metadata. Support and agency-need acknowledgements also copy the submitted message, reference, readable private tracking code, and any limited source/campaign/CTA labels to the operator's Gmail mailbox.
- If you create or reset a password, then Have I Been Pwned receives only the first five characters of a locally computed SHA-1 digest using its padded range protocol—not the password, complete digest, email, or account ID. dy does not store the returned range or breach count, and credential creation fails closed if the check is unavailable.
- If you enable push, then the push service selected by the browser or operating system (for example, services operated by Google, Mozilla, Apple, or Microsoft) receives the endpoint and encrypted message delivery data.
Provider processing locations and safeguards can change and are governed by the live provider agreement and account configuration. dy therefore does not certify a particular country or contractual safeguard unless it actually applies to the relevant flow.
9. Retention, deletion, and current technical limits
dy has no single automatic expiry for every table or provider copy. Its databases remain valid while the service operates and each disclosed purpose, existing license, unresolved request, security need, or legal duty remains. Current, category-specific behavior is:
- If you use a session or reset link, then the session is usable for up to seven days and the reset link for ten minutes; expiry makes the credential unusable but does not necessarily erase every stored value at that exact second.
- If you use semantic catalog search, then dy does not create a conversation transcript or server-side search history through that flow and does not intentionally store the query or semantic interpretation in D1 or Vectorize. A validated derived interpretation can remain in the five-minute edge cache described above; provider or infrastructure logs follow the controls and limits disclosed above.
- If your authenticated push-unsubscribe request is successfully processed, then the matching subscription is deleted from D1. Invalid endpoints may also be removed after delivery failure.
- If a creator deletes an unsold video from its dedicated control, then dy deletes dependent D1 rows and attempts to delete the R2 original after the database mutation. The current route does not automatically delete the Stream copy, Vectorize record, provider caches, or search-engine copies; support review may be required.
- If you delete your account after recent authentication and no unresolved financial state blocks it, then D1 deletes or anonymizes the account, historical provider identity rows, likes, favorites, identified interactions, notifications, push subscriptions, and unsold content rows. Proposals tied to those unsold videos are deleted; purchased assets, briefs, remaining proposals, payment/license evidence, and sales history are preserved or reassigned/anonymized as needed. Account deletion does not automatically purge R2, Stream, Vectorize, avatar caches, anonymous interactions, support requests, ledger raw evidence, email copies, or third-party indexes.
- If your self-service account deletion succeeds and no Video Studio job is active or under review, then D1 deletes your Video Studio jobs, private source rows, credit ledger, daily usage, and credit account, then dy makes best-effort deletion attempts for the private source files and R2/Stream output references resolved before erasure. An active queued, processing, waiting, or requires_review job blocks self-service deletion until it finishes or support resolves it. Provider logs, failed external cleanup, caches, and backups may require later review or expire under the relevant provider controls.
- If a payment, payout, capture review, existing license, legal hold, fraud issue, or dispute remains unresolved, then self-service account deletion can be delayed or the necessary record retained until the issue is resolved or the applicable duty expires.
Where no automatic purge exists, the holder may request review of a specific record through the traceable privacy channel. Deletion from active systems may also take time to propagate to backups, caches, processors, and recipients.
10. Holder rights and the procedure to exercise them
Subject to the law applicable to the request, a holder may know, access, update, and rectify personal data; request proof of authorization where required; ask how the data was used; request deletion or revoke authorization when legally available; access the data free of charge; and complain to the Superintendence of Industry and Commerce (SIC) after completing the direct consultation/claim process. Additional rights such as portability, restriction, or objection apply only when the relevant jurisdiction grants them.
Self-service export: the dashboard endpoint /api/user/export currently returns JSON with the profile, linked sign-in identities (provider, issuer, subject, provider email, verification indicator, and dates), summarized uploaded videos, purchases, sales made, legacy buyer payment intents, PayPal checkout and nominative billing requests, likes, favorites, identified interactions, notifications, and Video Studio credit-account, ledger, job, processing, consent, provider-reference, private-artifact-reference, and daily-usage data associated with the account. It excludes access and refresh tokens, idempotency keys, request fingerprints, leases, credentials, and signed or temporary provider URLs. It is not represented as a complete export of every backend system. Request any omitted category—including briefs/proposals, support, push, audit, hybrid-payment, or provider logs—through the privacy channel.
Correction and deletion: profile fields can be edited in the dashboard. Account deletion is self-service only after a recent sign-in and can return a financial-review or active-Video-Studio-review block. Because the technical limits above apply, use the privacy channel to request review of R2, Stream, Vectorize, Gemini Files, support, cache, or retained-license records.
Consultations and claims: submit the traceable form at Contact and support (it creates a reference and private tracking code) or email the legal/privacy address. Identify yourself, state the right invoked, describe the facts and requested data, provide a contact address, and attach supporting evidence where needed. An incomplete claim may require additional information before it can be decided.
Under Law 1581 of 2012, a consultation is answered within ten business days after receipt; if that is not possible, dy will explain the delay and answer within up to five additional business days. A complete claim is answered within fifteen business days counted from the day after receipt; if an extension is necessary, dy will explain it and answer within up to eight additional business days. A shorter mandatory period prevails.
11. Effective period, changes, and governing text
This version applies from August 25, 2026. It adds paid-Brief proposal consent, checkout, award, delivery and financial evidence, and preserves the optional purpose-limited nominative billing request introduced in 3.1. Earlier public-profile, optional agency-need and Video Studio purposes remain unchanged. A material later change to the controller, purposes, data categories or recipients will be communicated efficiently and re-authorized when required. The system records version 3.2 for new signups and each new checkout after release; it does not automatically mark every existing account as having accepted this version. Each paid proposal separately records the creator's explicit scope confirmation. Optional analytics and job-specific rights confirmations remain separate.
The Spanish text is the primary policy for the Colombian controller; the English version is provided for accessibility and should be interpreted consistently with the Spanish text and mandatory applicable law. Database validity lasts only for the periods and purposes described above, subject to legal preservation and verifiable deletion requests.