Privacy Policy
This policy explains what data Pyke collects, why we collect it, how long we keep it, and how you can delete it. It applies to https://pykeai.com and to the Pyke application at https://piki.pykeai.com.
Last updated August 7, 2026
1. Who we are
Pyke is operated by Uppzy Software LLC (Türkiye). For any question about this policy or about your data, write to [email protected].
2. Data we collect
Account data
- Email address — your account identifier and how we contact you.
- Password — stored only as a bcrypt hash. We never store or see your plaintext password.
- Google account identifier, display name and avatar URL — only if you sign in with Google.
- Interface language and account type — to render the app and apply your plan limits.
Content you submit
- The video links you paste, and the source video downloaded from that link for processing.
- Media you upload — images, video and audio you add to a clip from the media library.
- Derived artefacts — transcripts, audio/scene analysis data, the clips we produce, and your edits to them.
Social account connections
If you connect a social account, we store the provider name, your account identifier on that provider, the granted permissions, and the access and refresh tokens. Tokens are encrypted at rest (AES-GCM) with keys held outside the database. We never receive your social media password.
Technical and usage data
- Server logs, including IP address and request metadata, used for security and debugging.
- Processing records — job status, durations and cost accounting for your credit balance.
We do not use advertising or third-party analytics trackers, and we do not sell your data to anyone.
3. How we use your data
- To download, transcribe, analyse and render clips from the videos you submit.
- To authenticate you and keep your session secure.
- To track and deduct your credit balance.
- To publish clips to the social accounts you connect — only when you trigger the action.
- To detect abuse, prevent fraud, and meet legal obligations.
Our legal bases are performance of our contract with you (providing the service), your consent (for optional social connections), and our legitimate interest in operating and securing the service.
4. Social media permissions
Connecting a social account is optional and can be revoked at any time. We request only the permissions needed for the features you use:
| Provider | What we do with it |
|---|---|
| YouTube (Google) https://www.googleapis.com/auth/youtube.upload, https://www.googleapis.com/auth/youtube.readonly, openid | Upload the clips you choose to your own YouTube channel and show you which channel is connected. |
| Facebook Page & Instagram (Meta) pages_show_list, pages_read_engagement, pages_manage_posts, business_management, instagram_basic, instagram_content_publish | List the Pages and Instagram Business accounts you manage and publish the clips you choose to them. |
| TikTok user.info.basic, video.upload, video.publish | Show your connected TikTok account and upload the clips you choose to it. |
Google API disclosure. Pyke's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use YouTube data for advertising, and we do not transfer it to third parties except as required to operate the service or by law.
Using the YouTube features of Pyke also means you agree to the YouTube Terms of Service and the Google Privacy Policy. You can revoke Pyke's access to your Google account at any time via Google security settings.
5. Service providers
We share data with a small number of processors, strictly to run the service. Each receives only what its job requires:
| Provider | What it receives |
|---|---|
| Cloudflare R2 | Source video, generated clips, thumbnails and uploaded media (object storage). |
| Groq | The audio track of your video, for speech-to-text transcription. |
| Anthropic | The transcript and analysis signals, to select which segments become clips. |
| RunPod | Video frames and clip data during GPU rendering. |
| Google, Meta, TikTok | Only the clip you choose to publish, plus the token that authorises the upload. |
These providers may process data outside Türkiye and the EEA. We rely on their standard contractual clauses and equivalent safeguards for such transfers.
6. How long we keep data
| Data | Retention |
|---|---|
| Downloaded source video and generated clips | Automatically deleted 7 days after creation. |
| Clips you explicitly save to your project storage | Kept for the period your plan allows (currently up to 30 days), or until you delete them. |
| Media you upload to your library | Kept until you delete it or delete your account. |
| Transcripts and analysis data | Cached so re-processing the same video is faster; deleted with your account. |
| Social access and refresh tokens | Kept while the connection is active; deleted when you disconnect or delete your account. |
| Account record and credit ledger | Kept while your account exists. After a deletion request, permanently erased or anonymised after 30 days. |
7. Security
- All traffic is served over HTTPS.
- Passwords are hashed with bcrypt; social tokens are encrypted with AES-GCM.
- Stored files are private — downloads use short-lived signed URLs, never public buckets.
- Sessions use short-lived access tokens with revocable refresh tokens and reuse detection.
No system is perfectly secure, but we work to protect your data and will notify you of any breach affecting it as required by law.
8. Your rights
Under GDPR and Türkiye's KVKK you may request access to, correction of, or deletion of your personal data, object to or restrict processing, and receive a copy of your data. Exercise these rights by writing to [email protected], or delete your account directly in the app — see Data Deletion. You also have the right to lodge a complaint with your local data protection authority.
9. Children
Pyke is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the service changes. The date at the top always reflects the current version, and material changes will be announced in the app or by email.