Privacy Policy
Learn how Cryzstl collects, handles, protects, and permanently purges your personal data.
1 Information We Collect
Cryzstl collects information necessary to deliver high-quality video streaming, secure your identity, and provide community interaction. We collect:
Account Data
Email address, unique username handle, display name, channel biography, profile avatar, and cryptographic password hashes (Argon2id). For users with 2FA, TOTP secrets are held encrypted.
Content & Social
Video files uploaded for transcoding, video metadata (titles, tags, descriptions), channel follows, comments, video ratings/likes, and playlist configurations.
Telemetry & Player
IP address, digital device fingerprint, User-Agent header, geographic country code, adaptive streaming bandwidth metrics (DASH/HLS), and VAST ad impression telemetry.
2 How We Use Your Information
We use the collected information for the following operational and security purposes:
- Video Delivery: Transcoding source video files into multi-bitrate DASH/HLS segments and serving them reliably through content delivery pipelines.
- Account Authentication & Defense: Protecting accounts with Argon2id password hashing, enforcing brute-force lockouts, validating CSRF tokens, and verifying TOTP challenges.
- Personalization & Community: Displaying your channel profile, subscriptions, follower streams, and personalized video recommendations.
- Monetization & Compliance: Operating VAST ad campaigns, tracking view counts, preventing fraudulent traffic, and enforcing our Community Guidelines.
3 Cookies & Local Storage
Cryzstl uses strictly necessary cookies and local storage tokens to maintain authenticated sessions and optimize player performance:
- Session Cookies (HTTP-Only, Secure, SameSite=Lax): Maintains your authenticated status securely across page requests and prevents cross-site script access.
- CSRF Protection Tokens: Cryptographic tokens rotated on elevation to protect your account against cross-site request forgery attacks.
- Player Preferences: Local storage is used to remember your volume preferences, chosen streaming resolution, and theater mode settings.
4 Data Retention & The 15-Day Account Deletion Grace Period
We believe in full transparency regarding data retention. When you choose to close your account, our platform executes an automated lifecycle with a 15-day grace period:
Account Removal & Erasure Process
Account status is set to deleted. Your public profile, uploaded videos, and comments are immediately unlisted and hidden from platform search. Active sessions are terminated across all devices.
Your data is kept in a soft-deleted staging state. If you log in with your valid credentials during this 15-day window, you can cancel deletion with a single click and restore your channel.
Our database cascades permanently and irreversibly eradicate your records from users, user_registry, sessions, and media catalogs. Once purged, recovery is technically impossible.
The standard 15-day grace period and right to erasure do not shield illegal conduct. In matters involving Child Sexual Abuse Material (CSAM/CSAE), Animal Abuse, Cruelty, or Blood Sports, active violent threats, or cyber attacks against platform infrastructure:
- All account telemetry, user registration credentials, uploaded raw media assets, access logs, and IP connection timestamps are immediately preserved and permanently exempt from purge routines.
- Cryzstl proactively discloses and transfers all preserved evidence directly to municipal animal control agencies, local police departments, state and federal prosecutors, and child protection organizations (NCMEC) to facilitate criminal prosecution under applicable laws.
5 Security Architecture & Data Safeguards
We implement defense-in-depth security standards to protect your personal data from unauthorized access, disclosure, or destruction:
- Modern Cryptography: Passwords are protected using Argon2id hashing algorithms with memory-hard work factors. Legacy hashes are upgraded automatically in-flight upon login.
- Timing-Attack Resistance: Authentication tokens, signatures, and MFA codes are strictly verified using constant-time algorithms (
hash_equals). - SQL Injection Prevention: Database communications exclusively use native prepared PDO queries. Zero dynamic SQL interpolation is permitted in our codebase.
6 Your Privacy Rights (GDPR & CCPA/CPRA)
Depending on your location, you may have specific statutory rights concerning your personal information:
- Right of Access: You can request a summary of the personal data we hold about you.
- Right to Rectification: You may update your profile information, password, and email address at any time through your account settings.
- Right to Erasure (“Right to Be Forgotten”): You may schedule account removal via /account/delete to permanently purge all your personal records following the 15-day grace period.
7 Contacting the Privacy Officer
If you have questions, concerns, or requests regarding your personal data or this Privacy Policy, please contact our Data Protection Team at privacy@shiningashes.net.