Privacy Policy
This Policy explains what personal data Pabyo processes, why it is needed and the choices available to you.
1. Controller and contact
Privacy requests concerning the Pabyo service can be sent to support@pabyo.app.
2. Data we process
- Account and workspace data: email, display name, authentication identifiers, membership and settings.
- Billing data: plan, balance, transaction status, invoice and refund references. Complete payment-card details are handled by the payment provider, not stored by Pabyo.
- Creator content: prompts, uploaded images, video, audio, Characters, references, generated outputs, captions, chat messages and project metadata.
- Technical data: IP address, device/browser information, security events, request logs, errors and service diagnostics.
- Provider connections and integrations: API keys or authorisation tokens you supply, connected account identifiers, selected folders, channels or publishing destinations, connection status and provider job references. For Instagram imports, this includes the link or identifier you submit and the media retrieved for your workspace.
- Usage and attribution data: account activity, lesson views and progress events, selected resource and tool interactions, playback errors, and referral or campaign identifiers linked to registration.
- Support data: messages and files you send when requesting help or account access.
3. Why we use it
- To create and secure your account and workspace.
- To run requested generation, editing, training, storage and publishing workflows.
- To process subscriptions, balance top-ups, refunds and fraud checks.
- To provide support, investigate failures and communicate service changes.
- To meet legal obligations and enforce the Terms and Acceptable Use Policy.
- To improve reliability and product performance using operational data, understand course and feature use, and attribute registrations and payments to referral partners.
4. Legal bases
- Contract: providing your account, membership, saved work, requested generation, editing, training and connected publishing workflows.
- Legal obligations: keeping records required for accounting, taxation and other applicable legal duties, and responding to valid legal requests.
- Legitimate interests: securing the service, preventing fraud, investigating failures, handling support and disputes, and understanding service use, where those interests are not overridden by your rights.
- Consent: optional marketing emails and any other processing for which consent is required. You may withdraw consent without affecting earlier lawful processing. Consent to marketing is separate from use of the service.
These grounds do not replace any separate consent requirements for cookies or similar technologies.
5. Service providers and transfers
Pabyo uses specialised providers for authentication, payments, cloud infrastructure, private media storage, email, analytics/monitoring and AI generation. We send each provider the information needed for the requested function. Stripe processes checkout and payment information. Depending on the workflow, generation providers such as Kie, WaveSpeed or RunningHub may receive prompts, selected reference media and generation parameters.
When you connect Google Drive, Fanvue or Telegram and request an export or publication, Pabyo sends the selected files, accompanying text and destination information needed to complete that action. Instagram import services receive the link or identifier needed to retrieve the content you request. The destination platform applies its own terms and privacy policy to data it receives.
BYOK API keys are stored encrypted and used server-side to authenticate requests to the selected provider. Integration authorisation tokens allow Pabyo to carry out the functions you authorise. Disconnecting an integration does not delete copies of content already delivered to the destination; manage those copies with that service.
Some providers may process data outside the EEA or your country. Locations depend on the provider and selected workflow. You can contact support@pabyo.app for information about the recipients and processing locations relevant to your use of Pabyo.
6. Retention
Retention depends on the type of record and its purpose:
- Account, saved content and support records: kept to provide your account, workspace and support history. You may request deletion. Records needed for an unresolved dispute, security investigation or legal obligation may need to be retained after the account or content is removed.
- BYOK credentials: a disconnected or replaced API key is no longer used for new generation submissions. It may remain available to finish or retrieve already-submitted jobs for up to 30 days. If there are no unfinished jobs, or you choose immediate removal, the stored key is removed without that waiting period. Immediate removal may prevent completion or retrieval of pending results.
- Referral and campaign browser storage: the referral cookie expires after 10 days. Campaign hints use browser session storage. Expiry of browser storage does not itself delete attribution already associated with an account or transaction.
- Billing records: kept where required for accounting, tax, refunds, chargebacks or other legal obligations, including after a membership ends. The relevant period depends on the record and applicable obligation.
Requests to delete personal data can be sent to support@pabyo.app. Deletion may be limited by legal obligations or a need to establish, exercise or defend legal claims. Connected platforms and generation providers have their own retention practices for data they receive.
7. Cookies, local storage and activity records
Pabyo uses cookies or browser storage for sign-in, security, language and product state. When you arrive through a supported referral link, a first-party referral cookie can retain attribution for 10 days. Campaign labels and the entry page can also be stored for the browser session and associated with registration.
For signed-in accounts, Pabyo records service and course activity such as activity timestamps, lesson views, playback or completion events, resource interactions and playback errors. These records help us understand usage, provide course features and investigate problems. They are distinct from optional marketing emails.
You can manage cookies and site storage through your browser. Clearing sign-in storage may sign you out, and blocking storage can affect some features. Browser controls do not erase records already stored with your account; contact support to exercise your data rights. Where consent is legally required for non-essential cookies or similar technologies, describing them in this Policy does not itself constitute consent.
8. Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability or objection, and may complain to your local data-protection authority. Send a request to support@pabyo.app. We may need to verify your identity before acting.
9. Security and children
We use access controls, private media delivery and operational safeguards designed to protect data. No system is completely secure. Pabyo is not intended for children under 18.
10. Updates
We will update this Policy as the product and legal requirements evolve. Material changes will be communicated through the service or account contact where required.
Email updates and preferences
With your optional consent, we send Pabyo news, tips and offers by email. We record your preference, its source, the policy version and when it was recorded. You can withdraw consent at any time in your account settings. Declining does not affect access to the service. Necessary account, security and service emails are separate from marketing.