Privacy Policy and Cookie Notice
DRAFT. Prepared 2026-08-08 without external legal review. To compensate, every clause is deliberately drafted on the most consumer-protective setting available. Administrative actions required before this policy goes live are tracked in 00-OWNER-CHECKLIST.md.
Effective date: 2026-08-12 Version: draft 1.0
This policy explains what personal data Nocturnal Studios collects, why, on what legal basis, who else sees it, and what you can do about it. It is written to be read, not skimmed past. If anything here is unclear, write to support@cyvril.com and we will explain it in plain words.
It covers the Nocturnal Studios website, the membership and community, and the Software (our web applications for AI-assisted image, video, and music-video creation).
1. Who is responsible for your data
1.1 The controller is:
Caglar (Charly) Tekin, sole proprietor Altmannstrasse 16, 9012 St. Gallen Switzerland trading as Nocturnal Studios Email: support@cyvril.com
1.2 We are a Swiss controller. This policy is written to satisfy the revised Swiss Federal Act on Data Protection (FADP) and, where it applies to you, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1.3 We have not appointed a Data Protection Officer. No DPO is required at this scale: we are a one-person business, our core activity is not the monitoring of people, and we do not process sensitive data on a large scale. Whether or not a DPO is required, every request under section 8 reaches the controller named in section 1.1 directly, and is answered by a person.
2. EU and UK representatives
2.1 EU representative (GDPR Art. 27). Because we offer services to people in the European Economic Area from outside it, we have appointed the following representative in the EEA:
[EU-REP-NAME] [EU-REP-ADDRESS] [EU-REP-EMAIL]
You may contact the representative on any matter relating to the processing of your personal data, as an alternative to contacting us directly. The representative is appointed in writing and will be named here before the first sale to a person in the EEA; we do not sell into the EEA while this section is unfilled.
2.2 UK. A separate representative under Art. 27 UK GDPR will likewise be appointed and named here before the first sale to a person in the United Kingdom. Until then, UK residents can reach us at the address in section 12, and we answer UK requests on the same terms and in the same time as every other request.
3. What we collect
We collect the following categories of personal data.
3.1 Account data. Your name, email address, country of residence, chosen username or handle, password (stored only as a salted hash), and your membership tier and status.
3.2 Payment data. We use Stripe to take payment. Stripe collects and processes your card or payment-method details directly. We never see or store your full card number. We receive from Stripe: the fact and amount of a payment, the currency, the last four digits and brand of the card, the billing country, your billing name and address where you provide it, the subscription or invoice status, and any dispute or chargeback record.
3.3 Community content. Anything you post in the community: messages, comments, replies, shared work, profile information, reactions, and any files you upload. Other members can see this. Treat community posts as public within the membership.
3.4 Generation inputs and outputs. What you put into the Software and what comes out of it: prompts, reference images, audio and video you upload, project settings and styleboards, and the images, videos, and music videos generated from them, together with the associated project metadata.
3.5 Usage and access logs. Records of how the service is used: login times, IP address, browser and device information, session identifiers, pages and features used, generation requests and their credit cost, error events, and the outcome of each request. We keep access and payment-linked activity logs specifically so that we can defend a payment dispute or chargeback with evidence that an account was created, accessed, and used. We say this openly because it is a real purpose, not an incidental one.
3.6 Support and correspondence. Emails you send to support@cyvril.com, the content of support conversations, and messages you send us through the community or other channels.
3.7 Marketing data, if you opt in. Your email address and engagement with our emails (opened, clicked), where you have subscribed to updates.
3.8 We do not knowingly collect data from anyone under 18, and membership is not offered to minors. We do not intentionally collect special categories of data (health, religion, political opinion, sexual orientation, biometric or genetic data). If you put such data into a community post or a generation prompt, you do so on your own initiative and you are responsible for it.
4. Why we process it, and on what legal basis
| What we do | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account, give you access to the community, courses, and Software | 3.1, 3.3, 3.4 | Performance of a contract, Art. 6(1)(b) |
| Take payment, manage subscriptions, installments, refunds, and invoices | 3.1, 3.2 | Performance of a contract, Art. 6(1)(b); legal obligation for accounting records, Art. 6(1)(c) |
| Run generations, including sending your prompts and reference material to AI model providers | 3.4 | Performance of a contract, Art. 6(1)(b) |
| Provide support and answer your questions | 3.1, 3.6 | Performance of a contract, Art. 6(1)(b) |
| Keep the service secure, prevent abuse, enforce fair use, detect account sharing | 3.1, 3.5 | Legitimate interests, Art. 6(1)(f): protecting the service and other members |
| Keep evidence to defend payment disputes and chargebacks | 3.1, 3.2, 3.5 | Legitimate interests, Art. 6(1)(f): establishing and defending legal claims |
| Improve the service, fix bugs, understand which features are used | 3.5, aggregated where possible | Legitimate interests, Art. 6(1)(f) |
| Meet tax, VAT, and bookkeeping obligations | 3.1, 3.2 | Legal obligation, Art. 6(1)(c) |
| Send marketing emails | 3.7 | Consent, Art. 6(1)(a), withdrawable at any time |
4.1 Under Swiss FADP, processing of personal data by a private person is lawful without a specific justification unless it breaches the principles of the Act or the data subject's expressed will. The bases above are stated in GDPR terms because they are the stricter standard and because they apply directly to our members in the EEA.
4.2 We do not use your generation inputs or outputs to train our own AI models, and we do not sell your personal data to anyone.
4.3 We do not carry out automated decision-making that produces legal or similarly significant effects on you.
4.4 Where we rely on legitimate interests, you can push back and we keep the bar low. For dispute-evidence logging in particular, we keep only what a payment provider actually asks for in a dispute (that an account was created, accessed and used, and when), we do not use those logs for marketing, profiling or any other purpose, and we delete them on the schedule in section 7. If you object under section 8.1(f), we stop unless we are in an open or reasonably anticipated dispute with you about that specific payment, and we tell you which it is.
5. Who else sees your data
We use a small number of service providers. Each processes data on our instructions under a data processing agreement.
5.1 Payments: Stripe. Stripe Payments Europe Ltd and its affiliates process your payment data. Stripe acts as our processor for the payment we take, and as an independent controller for its own fraud-prevention and regulatory purposes. See Stripe's own privacy policy.
5.2 Hosting and infrastructure. Three providers between them run the service:
- Vercel Inc. hosts the web application itself.
- Supabase Inc. hosts the database and handles account authentication, so it holds your account data and the metadata of your projects.
- Cloudflare, Inc. provides the network layer, content delivery and protection against attacks, and therefore sees connection data such as your IP address.
5.3 Email and web hosting: Hostinger International Ltd. Hosts our website and our mailboxes and sends transactional and, where you opted in, marketing email.
5.4 AI model providers: OpenAI, Google and Anthropic. When you run a generation, the prompt, the settings, and any reference material you uploaded are transmitted to the model provider that produces the output. Different features route to different providers. Those providers process the request under their own terms, which may permit them to retain the request for a period for abuse monitoring. We choose providers that do not train on our API traffic by default, but we cannot control their internal processing and we do not warrant it. If we add a model provider that is not on this list, we name it here before your data is sent to it.
5.5 Community. Community discussion and member profiles run inside our own application, on the infrastructure named in 5.2. If we later move the community onto a third-party platform, we will name that platform here and tell members before any of their data is placed on it.
5.6 We also disclose data where we are legally required to (to a court, a tax authority, or a regulator), where necessary to establish or defend a legal claim, and to professional advisers (accountant, lawyer) under a duty of confidence.
5.7 If the business is sold or transferred, member data may transfer with it. We will notify you before that happens and your rights under this policy will continue to apply.
5.8 The list in this section is the complete list. Each provider named above processes data on our instructions under that provider's data processing agreement, and we do not add a new processor without updating this section first.
6. Where your data goes
6.1 Our processors are located in Switzerland, the European Economic Area, the United Kingdom, and the United States.
6.2 Transfers to the United States and other countries outside Switzerland and the EEA are made on the basis of the European Commission's Standard Contractual Clauses (with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner), the UK International Data Transfer Addendum where relevant, or, for US recipients that are certified, the EU-US and Swiss-US Data Privacy Framework.
6.3 In practice, for the providers named in section 5 the position is this: where the provider is certified under the EU-US Data Privacy Framework (and its Swiss-US and UK extensions), the transfer relies on that certification; where it is not, the transfer relies on the Standard Contractual Clauses with the Swiss addendum and, for the United Kingdom, the International Data Transfer Addendum. We do not send member data to a provider that offers neither.
6.4 You may request a copy of the safeguards in place for a specific transfer, and the current basis for a specific provider, by writing to support@cyvril.com.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | For as long as your membership is active, then 12 months after it ends |
| Projects, generation inputs and outputs | For as long as your membership is active, then at least 30 days so you can export, then deleted within 90 days of membership ending unless you ask us to delete sooner |
| Payment records, invoices, accounting data | 10 years, as required by Swiss commercial bookkeeping law (Art. 958f CO) |
| Access and usage logs | 12 months, extended for a specific record where it is needed as evidence in an open or reasonably anticipated dispute |
| Support correspondence | 3 years from the last message |
| Enforcement records (warnings, timeouts, removals, and the reports behind them) | 24 months from the decision, or until any appeal or legal claim about it is finally resolved if that is later. Legal basis: legitimate interests, Art. 6(1)(f): running a fair and consistent enforcement process and defending the decisions taken |
| Community posts | Retained while the community exists; on account deletion we anonymise your posts rather than delete them, so that conversations remain readable, unless you ask us to remove specific content |
| Marketing consent and email engagement | Until you unsubscribe, then a suppression record indefinitely so we do not email you again |
7.1 Backups are kept on a rolling basis and are overwritten within 30 days. Data deleted from the live system may persist in backups until that cycle completes.
7.2 How the 10-year bookkeeping period interacts with erasure. It applies only to the accounting records themselves: invoices, payment records and the data on them that Swiss law requires an invoice to carry. It is not a reason to keep anything else. If you ask us to erase your data, we erase your account, your projects, your generations, your logs and your support history on the normal schedule, and what remains is the accounting record alone, which we do not use for any other purpose.
7.3 Community posts: anonymised by default, deleted if you ask. On account deletion we anonymise your posts by default so that other members' conversations do not fall apart. That is a default, not a refusal: if you ask us to delete your posts rather than anonymise them, we delete them, in whole or in part, whichever you ask for. You do not need to give a reason.
8. Your rights
8.1 You have the right to:
(a) access your personal data and obtain a copy of it;
(b) have inaccurate data corrected;
(c) have your data erased, where we no longer have a valid reason to keep it (note that accounting records under section 7 must be kept regardless);
(d) restrict processing while a dispute about accuracy or legitimate interests is resolved;
(e) receive the data you gave us in a portable, machine-readable format, and have it sent to another provider where technically feasible (portability);
(f) object to processing based on our legitimate interests, including profiling, on grounds relating to your particular situation;
(g) withdraw consent at any time, where processing is based on consent. Withdrawal does not affect processing already carried out;
(h) unsubscribe from marketing email at any time, using the link in every message.
8.2 To exercise any of these, write to support@cyvril.com. We will respond within 30 days. We may ask you to confirm your identity first. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
8.3 You can export your projects and generated media at any time from within the Software, or by asking support.
8.4 Complaints. If you think we have handled your data wrongly, please tell us first so that we can fix it. You also have the right to complain to a supervisory authority:
- Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
- EEA: the data protection authority of the country where you live, work, or where the issue arose.
- UK: the Information Commissioner's Office (ICO).
9. Security
9.1 We use encryption in transit (TLS), encryption at rest for stored member content, hashed passwords, access controls limiting who can see member data, and logging of administrative access.
9.2 No system is perfectly secure, and the Software is in pre-public testing with limited security protections, as stated in the Beta Software Terms (document 06). Please keep your own copies of work that matters to you.
9.3 If a data breach occurs that is likely to result in a high risk to your rights, we will notify you and the relevant authority as required by law.
10. Cookies
10.1 We keep cookies minimal. We use:
- Strictly necessary cookies: to keep you logged in, to maintain your session, to remember your interface preferences, and for security (for example, protection against cross-site request forgery). These are required for the service to work and are set on the basis of our legitimate interest in providing the service you asked for. They do not require consent.
- Payment cookies: set by Stripe on the checkout page for fraud prevention. These are necessary for the payment to complete.
10.2 We do not use advertising cookies, cross-site tracking, or third-party marketing pixels.
10.3 If we later add analytics that are not strictly necessary, we will ask for your consent first through a cookie banner and update this notice.
10.4 You can block or delete cookies in your browser, but the service will not work correctly without the strictly necessary ones.
10.5 The rule we hold ourselves to. Nothing that is not strictly necessary is set on your device before you have said yes to it. That covers cookies set by us and cookies set by anything we embed, including our hosting and network providers and any embedded video player. If any such cookie appears, we list it here and ask for your consent through a banner first, with refusing as easy as accepting.
11. Changes to this policy
11.1 We may update this policy. If we make a material change, we will notify members by email and in the community at least 30 days before it takes effect.
11.2 The version and effective date at the top of this document tell you which version applies. We keep previous versions available on request.
12. Contact
Questions, requests, and complaints: support@cyvril.com
Postal: Caglar (Charly) Tekin, Altmannstrasse 16, 9012 St. Gallen, Switzerland.
EEA members may also contact our Art. 27 representative, [EU-REP-NAME], as set out in section 2.
Prepared 2026-08-08 without external legal review. It is not legal advice and is not in force.