privacy
effective 27 July 2026
This policy explains what personal data RYVESA LTD (“Pirumi”, “we”, “us”) collects when you use pirumi.cy and our mobile apps, why we collect it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and Cyprus Law 125(I)/2018. We are the data controller. We show no advertising, we do not track you across other sites, and we do not sell personal data.
who we are
RYVESA LTD
Terpsichoris 15, Eleftheriou Hill Residence, Flat/Office 202, 2102 Aglantzia, Nicosia, Cyprus
Data-protection contact: privacy@pirumi.cy
General contact: contact@pirumi.cy
We are not legally required to appoint a Data Protection Officer, but you can reach our data-protection contact above for any privacy question.
what we collect and why
- Account details: your email, username, display name and profile picture, managed through our sign-in provider (Clerk), so you can log in and be identified on the platform.
- Creator application data: your bio, motivation and snapshots of the public social accounts you connect for verification, so we can review and approve creators.
- Order and payment data: the request brief, an optional first name to be used in the video, prices, and the payment records and billing country needed to charge you, issue a VAT invoice and pay the creator. Card details are handled entirely by Stripe and never reach our servers. We keep a link to your invoice; it shows your name and billing address because tax law requires it, and only you can open it.
- Videos and thumbnails: the video a creator makes for you and its metadata (via Mux), and listing thumbnails (via Cloudflare), so we can deliver and display them.
- Captions: every delivered video is transcribed automatically, so it works for people who are deaf or hard of hearing. A written copy of what is spoken in the video therefore sits with our video provider next to the video itself. It is shown only in the player, to the people who can already watch that video.
- Watch progress: the playback position of each video you bought (a single number per video, overwritten as you watch), so you can continue where you stopped on the web and in the apps. Only you can see it; creators never can. It is not used for analytics, and you can delete it at any time under settings, then your data.
- Messages: the chat between a buyer and a creator, so you can discuss an order. If you dictate a message in our mobile apps instead of typing it, your device’s own speech service does the transcribing, and on devices without an offline language pack that means the audio is sent to your phone’s vendor (Apple or Google) rather than to us. We never receive the audio, nothing is recorded or stored, and the text only appears in the message box for you to edit or discard.
- Safety records: the reports you submit, and, if we act on a report, what was reported, what we decided and why, and a note on your account if we banned or suspended it.
- Push tokens: if you use our mobile apps and opt in, a device token so we can send you notifications.
- Small settings and signals: your language, your notification choices, whether you have hidden your online status or your profile picture, who you have blocked, whether you are typing, and which app version and device model sent us a push token.
what you have to give us
Your email address is needed to open an account. Without it you cannot have one. You also pick a username, which is how other people see you on Pirumi.
Your brief is needed to make the video. Without it we cannot take the order. The first name to be spoken in the video is optional; leave it out if you prefer.
Your billing country, and the name and address on your invoice, are required by EU VAT and Cyprus tax law. We cannot invoice you without them.
If you are a creator, our payment provider needs proof of who you are before it can pay you. That is a legal requirement on them. Without it we cannot pay out.
checking requests before checkout
Before you pay, we send your brief and the name you asked to be spoken to an external AI provider (OpenRouter), which passes it to whichever hosting provider is fastest at that moment, outside the EU, usually in the United States. Because the routing picks the fastest available host, we cannot fix the country in advance. The provider checks the text against our content rules and against what the creator you chose said they will do, and sends back a yes or no.
We do this to keep the platform lawful and safe, which is our legitimate interest under Article 6(1)(f). The check is automatic. If it says no, we stop that one checkout: nothing is charged, your account is not affected, it is not a sanction, and you can reword the brief and try again. If you think it got it wrong, write to support@pirumi.cy. The check is not always on: if the provider is unavailable, the request goes through unchecked. And it is never the final word on an order: paying at checkout only places a hold on your card, and your money is only taken after the creator has personally read your brief and accepted it.
If a request is stopped, we keep the text, the name and the reason for 90 days so we can spot repeat problems, and then we delete it. We do not use this record to score or rank your account.
We use the same AI provider once more after your video has been delivered: the brief (this time without the spoken name) is sent again so the AI can turn it into a short title for your own library, which makes long requests easier to find later. The title is shown only to you, rests on the same legitimate interest (Article 6(1)(f)), and is deleted together with your brief when you delete your account.
our legal bases
We rely on the following legal bases under GDPR Article 6:
- Performance of a contract (Art. 6(1)(b)): running your account, processing orders and payments, delivering videos with their captions, and enabling buyer↔creator messaging.
- Legal obligation (Art. 6(1)(c)): verifying creator identity for payouts (KYC/AML via Stripe), keeping tax and accounting records, handling illegal-content reports as EU law requires, and the yearly tax report about creators described below.
- Legitimate interests (Art. 6(1)(f)): keeping the platform secure, preventing fraud, checking order briefs before checkout, moderating content, fixing errors and crashes, counting visits without cookies, and making sure video playback works. You can object to any of these; see “your right to object”.
- Consent (Art. 6(1)(a)): product analytics (PostHog) and push notifications. You can withdraw consent at any time.
your right to object
Some of what we do rests on our legitimate interests rather than on your consent: error monitoring, counting visits, video playback quality, checking order briefs, and moderation.
You can object to any of it at any time, for reasons connected to your situation. Write to privacy@pirumi.cy. We stop unless we can show compelling grounds that override your interests, or we need the data for legal claims.
analytics and error monitoring
Audience measurement (no cookies). We use Vercel Web Analytics to count page views and see which pages are popular. It sets no cookies and stores nothing on your device, it does not store your IP address, and it cannot follow you across other sites. Visitors are counted via a temporary hash that Vercel discards within 24 hours, and before an event is sent we strip identifiers from the page address (usernames, order and conversation references, and all query parameters).
Playback quality (no cookies). When you play a video, Mux (our video provider) measures technical playback quality, for example start-up time, buffering and playback errors, so we can keep streaming working. We have configured this measurement to set no cookies and store nothing on your device, and it does not build a profile of you.
Product analytics (only with your consent). If you opt in, we use PostHog (hosted in the EU) to understand how the site and our mobile apps are used, so we can improve them. It is off by default and loads nothing until you agree; the apps ask you for the same choice once you sign in. If you are signed in when you opt in, we tag your analytics events with your account id, so we can see a journey rather than isolated clicks. We never send PostHog your email address or your name, we do not record your screen or sessions, we do not capture keystrokes, and we strip identifiers from the pages you visit. You can withdraw at any time, via the “cookies” link in the footer or the analytics switch in the app under settings, then privacy, and capture stops immediately.
Error monitoring. We use Sentry (with EU data residency) to record technical errors and crashes on our website and in our mobile apps, so we can keep them working. It sets no cookies, does not store your IP address, and we remove personal detail (cookies, headers and identifiers) before a report is sent. Reports from the app also include the device model, the operating system version and a randomly generated identifier for the app installation, which is not linked to your account and is reset when you delete the app. There is no session recording.
who we share data with
We share data only with the service providers that help us run Pirumi. Most act on our instructions under a data-processing agreement; the social platforms you can connect for creator verification are independent providers that receive data from you or disclose it to us:
- Clerk: Account sign-in, identity and session management. Holds your email address and password so we never store them ourselves.
Location: United States · Safeguard: Standard Contractual Clauses - Stripe: Card payments, creator payouts, VAT calculation, invoicing and creator identity verification. Card details are handled entirely by Stripe and never reach our servers.
Location: United States · Safeguard: Standard Contractual Clauses; PCI-DSS - Mux: Encodes, stores and streams delivered videos; automatically writes out a text version of everything spoken in a video (the captions the player shows); and measures playback quality without cookies. It receives the video file, the caption text, the order reference and an internal creator reference.
Location: United States (global content-delivery network) · Safeguard: Standard Contractual Clauses - OpenRouter: Runs the automatic check on order briefs before checkout, generates a short library title from the brief after the video is delivered, and translates listing descriptions. It receives the brief text and the name to be spoken (the title generation receives the brief only), plus the creator’s listing description and its languages, and passes each request to whichever hosting provider is fastest at that moment.
Location: Outside the EU; the routing picks the fastest available host, so no country is fixed in advance · Safeguard: Standard Contractual Clauses in the provider’s data-processing terms; there is no adequacy decision for this transfer - Convex: Our application database and backend.
Location: United States · Safeguard: Standard Contractual Clauses - Cloudflare (storage and images): Stores and delivers listing thumbnails (public storefront images).
Location: European Union · Safeguard: Stored under Cloudflare’s EU jurisdiction - Cloudflare (email): Sends our transactional emails (order confirmations, notices, sign-in codes).
Location: United States · Safeguard: Standard Contractual Clauses - PostHog: Product analytics, only if you opt in.
Location: European Union (Frankfurt) · Safeguard: Processed in the EU; Standard Contractual Clauses cover any access from the US parent company - Sentry: Application error and crash monitoring on our website and mobile apps.
Location: European Union (Frankfurt) · Safeguard: Processed in the EU; Standard Contractual Clauses cover any access from the US parent company - Google (Firebase Cloud Messaging): Push notifications to our mobile apps (on iOS delivered through Apple’s push service, on Android directly by Google).
Location: United States · Safeguard: Standard Contractual Clauses - YouTube / Twitch / TikTok: Optional one-time verification of a creator’s public social account. These are independent providers, not our processors.
Location: United States (Google, Twitch); Ireland, possibly China (TikTok) · Safeguard: They act under their own privacy policies; for TikTok see “sending data outside the EEA” - Vercel: Website hosting and delivery, and cookieless, aggregated audience measurement.
Location: United States · Safeguard: Standard Contractual Clauses
sending data outside the EEA
Several of our providers process data in the United States, and the automatic brief check is routed to whichever host is fastest at that moment, so its country is not fixed in advance. For every transfer outside the EEA we rely on the European Commission’s Standard Contractual Clauses, which are part of our contract with each provider. You can ask us for a copy at any time, at privacy@pirumi.cy.
TikTok verification. If, as a creator, you choose to verify your identity using TikTok, we receive a snapshot of your public TikTok profile (handle, display name, avatar, follower count and account id) from TikTok Technology Limited in Ireland, an EEA company. TikTok, as the source of that data, may process it outside the EEA, including in China, under its own privacy policy and safeguards; China has no EU adequacy decision, and local law there can give authorities access to data in ways that differ from the EU. TikTok verification is optional: you can verify with YouTube or Twitch instead. The verification is a one-time read, and we delete the profile snapshot as soon as your application is decided.
how long we keep data
- Chat messages: Deleted after 12 months of conversation inactivity.
- Deleted messages: Basic details (no content) are kept for 90 days, then deleted.
- Requests stopped by the automatic check: Text, name and reason are deleted after 90 days.
- Mobile push device tokens (iOS and Android): Deleted after 90 days without use.
- Push notifications we sent you (title, text, link): Deleted after 90 days.
- Downloadable video files: Removed 30 days after generation (regenerated on demand).
- Video captions: Kept as long as the video they were made from.
- Watch progress (where you stopped in your videos): Kept while you have access to the video; deleted with your account, and deletable at any time under settings, then your data.
- Messages, your orders, listing and earnings figures, and your creator application draft cached on your own device: At most 7 days; cleared when you sign out, and clearable at any time under settings, then your data.
- Home-screen widget summary on your own device, including, for the continue-watching widget, the title, the artist name and a still frame of the videos you played most recently: Kept until a newer one replaces it; cleared when you sign out or clear the app cache.
- Creator application data: Social-account snapshots are deleted the moment your application is decided; drafts after 7 days of inactivity; the text of a rejected application 30 days after the decision, keeping only the outcome and its date.
- Reports and moderation records: The copy of the reported content is deleted 6 months after we dismiss a report, and 12 months after we act on one, which is how long you have to challenge the decision. Reports about content that may be criminal are held longer, because the evidence may be needed by the authorities. What stays after that is the decision itself: the category, the outcome and its date.
- Error reports (Sentry): Configured to delete after 90 days.
- Analytics events (PostHog): Configured to delete after 12 months; capture stops immediately if you withdraw consent.
- Audience measurement (Vercel): The visitor hash is discarded within 24 hours; what remains are aggregated statistics that cannot identify you.
- Email delivery logs: Kept for a few weeks at our email provider.
- Payment, invoice and tax records: As long as Cyprus tax law requires, which is up to 7 years, and up to 10 years for records covered by the EU One Stop Shop VAT scheme once we register for it.
- Account and order data: Scrubbed when you delete your account; “your rights” below explains exactly what stays.
your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- correct data that is wrong or incomplete;
- have your data erased (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable, machine-readable format;
- withdraw any consent you have given, without affecting past processing.
On the website you can download your conversations and messages, the blocks you have set or received, and reports you filed or that were filed about your messages, under settings, then your data. For a copy of everything else, or if you only use the app, write to privacy@pirumi.cy. You can delete your account from your account settings or by writing to the same address. We respond within one month.
When you delete your account, we remove your profile and your username, and we take the content of your briefs and messages out of our systems. Some things stay:
- your account record itself, kept in a form that no longer identifies you on the platform;
- videos from orders that were already completed and paid, so the buyer keeps what they bought;
- anything a report needs as evidence, including a copy of the reported message or text, kept for as long as the moderation record must be kept;
- basic details of deleted messages, for 90 days;
- if a request of yours was ever stopped by our automatic check, the record that it happened, without the text, until it ages out after 90 days;
- payment and invoice records at our payment provider, which tax law requires us to keep.
information about other people
Sometimes we hold information about someone who is not a Pirumi user, because a user gave it to us.
A buyer can ask for a first name to be spoken in a video. We store that name with the order. It is spoken in the video, and because every video is automatically captioned, it also appears in the written caption text our video provider makes. We hold nothing else about that person.
If someone reports content or a message, we keep a copy of what they reported and what they said about it, so we have a record of why we acted.
We have no way to contact the people this covers, and telling them would mean collecting more data about them than we hold, so we do not write to them. If you think we hold something about you this way, write to privacy@pirumi.cy and we will tell you what we have.
tax reporting about creators
If you earn money as a creator, EU law requires us to report you to the Cyprus Tax Department once a year, and they pass it to the tax authority of the country you live in.
What is reported: your name, your address, your date of birth, your tax identification number and the country that issued it, your VAT number if you have one, the account we pay you into, and how much you were paid and how many videos you delivered in each quarter.
The legal basis is our legal obligation under Article 6(1)(c). We keep these records as long as tax law requires. We send you a copy of what we reported about you by 31 January each year, and we tell you before we report for the first time.
cookies and local storage
We store a small number of things in your browser and on your device. Always on: sign-in and session cookies (set by Clerk) that keep you logged in, checkout state used by Stripe during payment, your language and theme choices, and your cookie decision itself. Each of these is needed for something you asked for, so none of them needs your permission.
Your device also keeps a copy of your most recent messages, conversation details and your creator application draft, so those pages open instantly instead of loading. It stays on your device, we never read it, it is kept for at most 7 days, it is deleted when you sign out, and you can clear it at any time under settings, then your data.
Our iOS and Android apps keep a small summary on your device for their home-screen widgets, so a widget can show something without opening the app. It is written whether or not you have added one. For the order widgets that summary is counts, statuses and deadlines, and for creators your own earnings figures. The continue-watching widget needs more to be useful, so it also keeps the title, the artist name, your position and a small still frame of each of the videos you played most recently. All of it stays on your device, we never read it, it is deleted when you sign out, clearing the app cache in settings removes it, and deleting your watch progress removes the continue-watching part on its own.
Only if you opt in: analytics storage set by PostHog, removed if you withdraw consent. You can change your choice at any time via the “cookies” link in the footer. Our audience measurement (Vercel) and playback-quality measurement (Mux Data) set no cookies and store nothing on your device.
sensitive information in messages
Chat messages and briefs could contain sensitive personal data (for example about health or beliefs). Please share sensitive information only where it is needed for your order.
age
Pirumi is only for people aged 18 or over. We do not knowingly process the data of anyone younger.
how we keep data secure
Data is encrypted in transit (TLS) and at rest. Videos are served through short-lived signed links, so only the buyer, the creator and our moderators can view them. If a data breach is likely to put your rights at risk, we will notify the Cyprus supervisory authority and inform you where required.
complaints
If you think we have mishandled your data, please contact us first at privacy@pirumi.cy. You can also complain to a data protection authority, in particular in the EU country where you live, where you work, or where you think the problem happened. In Cyprus that is:
Office of the Commissioner for Personal Data Protection
15 Kypranoros Street, 1061 Nicosia, Cyprus
+357 22 818 456 · commissioner@dataprotection.gov.cy
dataprotection.gov.cy
changes to this policy
The date at the top shows when the version you are reading took effect.