Privacy Policy
PYLON Privacy Policy
This Privacy Policy explains how PYLON Film Pty Ltd (ABN: 14 698 990 215) (PYLON, we, us, our) collects, uses, shares, retains and protects personal information when you use the PYLON streaming service at https://pylon.video and our associated applications and APIs (the Service). It also explains the rights you have over your personal information and how to exercise them.
This Policy is a companion to the Terms of Service, Cookie Policy, Do-Not-Sell page and Children's Privacy Notice.
Table of contents
- Who we are
- The personal information we collect
- How we collect personal information
- Why we use personal information (and our legal bases)
- Who we share personal information with
- International transfers
- How long we keep personal information
- Your rights
- Cookies and similar technologies
- Children
- How we secure personal information
- Breach notification
- Contact us; complaints
- Changes to this Policy
1. Who we are
The data controller (or, in Australian terms, the APP entity) for the Service is:
PYLON Film Pty Ltd Level 2, 111 Harrington Street, THE ROCKS NSW 2000, Australia ABN: 14 698 990 215
For privacy enquiries, contact our Privacy Officer at [email protected]. We do not currently have an EU representative or a UK representative under Article 27 GDPR / UK GDPR; we will appoint one and update this Policy if and when we cross the relevant establishment-or-volume threshold.
2. The personal information we collect
We deliberately practise data minimisation. We collect only what we need to operate the Service, comply with the law and provide you with the features you request.
2.1 Account identity
- Email address, verified by magic link or by your OAuth provider (Google, Apple). Required for sign-in and for transactional communications.
- OAuth provider identifier, when you sign in with Google or Apple, we receive a stable user identifier from that provider. We do not receive your provider password.
- Display name, optional; you set it on your profile.
- Avatar image, optional; either an image you upload or the avatar attached to your OAuth account.
- Date of birth (DOB), required for age verification, Australian Online Safety Act compliance, age-classification gating and to refuse service to children under thirteen.
- Locale and country code, your locale for UI language and formatting; your country code derived from Cloudflare's IP-geolocation signal at first sign-in. Used for jurisdictional features (classification, tax, payment availability, age rules).
- Role, viewer, creator, curator, senior_curator or admin. Most users are viewer.
- Two-factor authentication state, whether you have enrolled, whether your current session has cleared the 2FA challenge, and a hashed copy of your one-time recovery codes.
In some EU/UK jurisdictions, your date of birth, in combination with other data we hold, may be treated as an indicator of age and (for users under sixteen) as special category data subject to GDPR Article 9. We process DOB only on the legal basis of contract performance and legal obligation (age-restricted content, child-safety law).
2.2 Subscription and payment
- Subscription status, plan, billing period, cancel-at-period-end, pause and downgrade flags, held in our database for entitlement checks.
- Stripe customer ID and Stripe subscription ID, opaque tokens we use to communicate with Stripe.
- Payment method metadata, last four digits, card brand, expiry month/year, postal code or country (received from Stripe). We do not see, store or process your full primary account number, CVC, banking credentials or full bank-account number. Stripe is the processor of record; see Stripe's privacy notice at https://stripe.com/privacy.
2.2A Keepsakes (purchases and personalization)
If you buy a Keepsake (Terms of Service §7A) we collect and create:
- Purchase records, product type (frame / poster / folio), price, currency, payment channel (web / iOS / Android), timestamp, the title collected, edition number, and the payment-processor transaction identifier. These are financial records and are retained accordingly (section 7).
- Personalization inputs, the collector name you choose for the plate, and (for frames) the timestamp of the moment you selected.
- Generated personalized artifacts, the rendered Keepsake files themselves, which embed your collector name and edition number. These are stored in your Collection for re-download and are personal information because they identify you.
- Collection-library records and download logs, which Keepsakes are in your Collection, entitlement state, and when you download or re-download them (used for delivery, abuse prevention, and support).
- Render pipeline intermediates, temporary working files created while producing your Keepsake, retained only for the short window in section 7 and then deleted.
- Your Backers Roll election, whether you chose public display or anonymity, the display name shown, and any later withdrawal. Public display reflects your election at the time of purchase, and you can withdraw at any time in Account → Privacy & Data.
- Collector Note content, the private order message you attach, which is screened before delivery to the Creator. Do not include personal information about anyone else in a note.
- Where the Keepsake is bought as an Apple in-app purchase, Apple is the merchant of record and processes your payment under Apple's own privacy policy; we receive the SKU, a receipt token and entitlement state, not your payment details.
2.3 Streaming and product behaviour
- View progress, for each title you watch, we store your last position, percentage complete, and last-watched timestamp so we can resume playback and populate Continue Watching.
- View events, playback start, pause, seek, complete, error and similar events, with the device class (web/iOS/Android/CTV) and DRM system used. Used for billing accuracy (creator pro-rata payouts), fraud detection and aggregate analytics.
- Daily aggregates, a per-day rollup of your viewer-seconds and titles-watched, used for in-app dashboards and creator earnings.
- Q&A RSVPs and chat messages, when you participate in a community feature.
- Newsletter subscription state, segment, verified-at, unsubscribed-at.
2.4 Sessions and security
- Session identifier and Better Auth token, a server-side session record so we can authenticate your subsequent requests.
- User agent string, your browser or app version, for device recognition and fraud detection.
- Hashed IP address, we store the SHA-256 hash of your source IP, not the IP itself. The hash is one-way; we cannot reconstruct the original IP from it.
- Country code, derived once from Cloudflare's IP-geolocation header at sign-in.
- Audit log, actions you take that have a security or compliance signal (sign-in, password / 2FA change, role change, subscription events, data export request, deletion request).
2.5 Creator-only data
If you participate as a Creator (filmmaker, studio, distributor):
- Creator profile, slug, creator type, festival page URL, IMDb URL, personal site URL, social handles.
- Stripe Connect account ID and onboarding/verification status, for payouts.
- Payout country, for tax reporting.
- Tax residency documentation, if you receive payouts: your declared legal name, country of tax residence and address from a signed tax residency declaration (processed through our e-signature provider, SignatureAPI), or your Australian Business Number (ABN — a public business identifier) or "Statement by a supplier" reason. Collected because Australian law (ITAA 1936 s 128B and PAYG withholding rules) requires us to withhold tax on certain royalty payments to non-residents at a rate that depends on your documented country of tax residence, and to report payee identity to the Australian Taxation Office annually.
- Earnings, payouts and minimum-guarantee ledger entries, internal accounting records.
- Keepsake royalty ledger entries, per-sale royalties, reserve state, true-up adjustments, clawbacks and set-offs, plus per-Title licence-activation records (accepted version, clearance attestation) — internal accounting records reported to tax authorities where the law requires (section 5.2).
- AI provenance attestations and clearance representations, for the AI Provenance Attestation and the Filmmaker Distribution Agreement.
- Submission metadata, duration, resolution, source, status.
2.6 Mobile application data
When you use the PYLON Cinema mobile app on iOS or Android we collect a small additional set of identifiers required for native app functionality:
- Push notification token, an opaque identifier issued by Expo (a
managed wrapper around Apple Push Notification service and Firebase
Cloud Messaging), the platform (iOS / Android), the app version, and
an internal OS build identifier (
Device.osInternalBuildId). The push token is stored locally in the OS keychain and on our server; it is deleted when you sign out and purged automatically after 180 days of inactivity. The internal OS build identifier is used only for diagnostics and is not shared with advertising partners. - Advertising identifier and attribution (only with your permission). On iOS we present Apple's App Tracking Transparency (ATT) prompt before accessing your advertising identifier. If you allow tracking, the app may access your device advertising identifier (Apple's IDFA or Android's Advertising ID) and share it, together with app, install and campaign events, with our mobile-measurement partner AppsFlyer (to attribute installs and measure advertising) and with advertising partners including Google (to serve and measure ads on the free, ad-supported tier). If you decline the ATT prompt, we do not access the advertising identifier and do not use it to track you across other companies' apps and websites; any ads you see on the free tier are then not personalised using a cross-app advertising identifier. Whether the ads themselves are personalised is governed separately by your in-app Marketing consent (off until you opt in, in every region: the mobile app applies no region defaults) and your region. You can change ATT at any time in iOS Settings › Privacy & Security › Tracking.
- In-app purchase receipts and entitlement state, validated and cached on-device by the RevenueCat SDK. RevenueCat receives your user ID, the app version and the platform; it does not receive payment card data (Apple and Google handle that on their own infrastructure).
- Referral code (if you arrived via a referral link), stored locally in the OS keychain and attributed to your Account on first sign-in.
- Aggregate product analytics via PostHog, which is off until you opt in, in every region, under the mobile app's per-purpose consent prompt. Unlike the web, the app does not apply region defaults: analytics stays off until you make a choice. When enabled, your playback events (start, heartbeat, complete, paywall interaction, referral attribution) are sent to our reverse proxy with your user ID, device class, app version and DRM system. PostHog does not receive your advertising identifier. There is no Sentry crash reporting in the mobile app at this time.
2.7 What we do NOT collect
- Your password (we are passwordless).
- Your full payment-card number, CVC or bank-account number (Stripe).
- Your raw IP address (we hash on ingress and discard the raw value).
- Your precise device location (we do not request GPS or device-location permissions).
- Biometric data.
- Race, religion, political opinion or trade-union membership.
3. How we collect personal information
We collect personal information:
- Directly from you when you create an Account, complete a profile, start a Subscription, submit User Content, contact support, fill in a form, or use any feature of the Service;
- Automatically as a consequence of your use of the Service, cookies, analytics, security telemetry, server logs;
- From third-party providers, Google or Apple when you sign in with OAuth; Stripe when you make a payment; SignatureAPI when a Creator signs an agreement; Cloudflare for IP geolocation and bot detection;
- From you when you reach out by email ([email protected], [email protected], etc.); and
- From Creators about your interactions with their titles (aggregated; never individual).
4. Why we use personal information (and our legal bases)
We use personal information for the following purposes. For users covered by the EU/UK GDPR, the lawful basis is shown in brackets per Article 6(1) (or Article 9(2) for special-category data).
| Purpose | Legal basis |
|---|---|
| Create and operate your Account, authenticate sign-in | Contract performance (Art. 6(1)(b)) |
| Provide the streaming Service: deliver Content, gate by age and territory, resume playback | Contract performance (Art. 6(1)(b)) |
| Charge Subscription fees, refund, retry failed payments, handle chargebacks | Contract performance (Art. 6(1)(b)); legitimate interest in fraud prevention (Art. 6(1)(f)) |
| Pay Creators their watch-time pro-rata share | Contract performance with the Creator (Art. 6(1)(b)), your data is aggregated, not shared |
| Render, deliver and store your personalized Keepsakes; process purchases; calculate and pay creator royalties; prevent purchase fraud | Contract performance (Art. 6(1)(b)); legitimate interest in fraud prevention (Art. 6(1)(f)) |
| Display your name on a Backers Roll (only per your election, withdrawable) | Consent (Art. 6(1)(a)), withdrawable at any time |
| Screen and deliver Collector Notes | Contract performance (Art. 6(1)(b)); legitimate interest in user safety (Art. 6(1)(f)) |
| Report creator keepsake royalties to tax authorities (ATO SERR; IRS information returns) | Legal obligation (Art. 6(1)(c)) |
| Verify your age, prevent under-13 access, enforce classification | Legal obligation (Art. 6(1)(c)); contract performance (Art. 6(1)(b)) |
| Send transactional emails (sign-in links, billing receipts, GDPR export ready, DMCA notices) | Contract performance (Art. 6(1)(b)) |
| Send marketing emails and newsletters | Consent (Art. 6(1)(a)) where required (EU/UK/AU); legitimate interest with opt-out (Art. 6(1)(f)) where permitted (US CAN-SPAM) |
| Serve ads on the free, ad-supported tier; measure ad performance; attribute app installs (mobile) so we can fund the free tier, keep the ads you see relevant, and understand which campaigns bring filmmakers an audience | Legitimate interest in funding a free tier (Art. 6(1)(f)) for non-personalised ads; consent (Art. 6(1)(a)) for personalised advertising — granted via your Marketing consent (web cookie banner or in-app privacy settings), withdrawable at any time. On mobile, the App Tracking Transparency prompt separately governs access to your advertising identifier |
| Aggregate product analytics (PostHog) | Consent (Art. 6(1)(a)) where required. On the web: off by default until you opt in in strict-consent regions (EU/EEA, UK, Switzerland, Brazil), on by default with an opt-out elsewhere (e.g. the US). In the mobile apps: off until you opt in, in every region |
| Error and crash monitoring (Sentry) | Consent (Art. 6(1)(a)) where required; off by default until you opt in in strict-consent regions (EU/EEA, UK, Switzerland, Brazil), on by default with an opt-out elsewhere (e.g. the US) |
| Detect and prevent fraud, abuse, DRM circumvention, scraping | Legitimate interest (Art. 6(1)(f)); legal obligation under intermediary-liability laws |
| Comply with court orders, regulatory requests, DMCA takedowns | Legal obligation (Art. 6(1)(c)) |
| Respond to your requests for support | Contract performance (Art. 6(1)(b)) |
| Defend, exercise or establish legal claims | Legitimate interest (Art. 6(1)(f)); legal claims (Art. 9(2)(f) where Article 9 applies) |
| Improve the Service, develop new features | Legitimate interest (Art. 6(1)(f)), only on aggregate or pseudonymous data |
We do not use your personal information for automated decision-making that produces legal or similarly significant effects about you, in the sense of GDPR Article 22.
We do not use your personal information for AI training. Your User Content is not used to train any third-party large language model, image model or video model. Aggregated and de-identified usage statistics may inform internal product analytics but are not provided to AI training pipelines.
5. Who we share personal information with
We share personal information only with the following categories of recipients, and only to the extent necessary for the purpose.
5.1 Service providers (processors)
| Provider | Purpose | Data categories | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, edge computing, CDN, IP geolocation, bot management, R2 object storage, D1 database | Account, session, view, payment-state metadata; encrypted-at-rest videos | US / global edge |
| Stripe, Inc. | Subscription billing, payment processing, customer portal, Connect payouts, Keepsake purchases (web) | Email, name, billing address, payment-card metadata, payout details | US / global |
| Airwallex Pty Ltd | Creator payout rail (bank transfers to creator beneficiaries) | Creator legal name, bank/beneficiary details, payout amounts, country | AU / global |
| Apple Inc. | In-app purchase processing for iOS Keepsakes (Apple is the merchant of record and an independent controller of the payment) | Apple ID-side purchase data (held by Apple); we receive receipt tokens and entitlement state | US / global |
| Google LLC (Google Play) | Android billing/link-out handling where applicable | Play-side purchase data (held by Google); we receive order confirmation state | US / global |
| Mux, Inc. | Video encoding, packaging, DRM token signing, delivery telemetry | View events, device class, DRM system | US |
| Resend | Transactional and newsletter email | Email, name, message content | US / EU |
| SignatureAPI | E-signature for Creator agreements, tax-form collection and tax residency declarations | Name, email, agreement content; for tax documents: declared legal name, address, country of tax residence | EU |
| PostHog (Hogflix Inc.) | Aggregate product analytics. On the web a region-dependent default (off until you opt in in the EEA/UK/CH/BR, on by default elsewhere e.g. the US); in the mobile apps off until you opt in, in every region | Hashed user ID, page views, feature usage (no advertising signals) | US / EU |
| Sentry (Functional Software Inc.) | Error monitoring; region-dependent default (off until you opt in in the EEA/UK/CH/BR, on by default elsewhere e.g. the US) | Stack trace, browser/OS, hashed user ID | US / EU |
| RevenueCat, Inc. | In-app purchase receipt validation, entitlement sync (mobile only) | User ID, app version, platform, purchase history | US |
| Expo (650 Industries, Inc.) | Push notification infrastructure (managed wrapper around APNs and FCM) | Push token, platform, app version | US |
| AppsFlyer Ltd | Mobile install attribution and advertising measurement (iOS/Android; only where you allow tracking via ATT) | Device advertising identifier (IDFA/AAID) where permitted, app/install/campaign events, hashed user ID, IP | Global |
| Google LLC (Google Ads / Interactive Media Ads) | Serving and measuring ads on the free, ad-supported tier | Advertising identifier where permitted, ad-interaction and device signals | US / global |
Google LLC (Google Analytics 4, via server-side Google Tag Manager on tags.pylon.video) |
Aggregate web measurement and conversion attribution; gated on Analytics or Marketing consent (on by the regional default outside the EEA / UK / Switzerland / Brazil, off until you opt in there); never loads in the EEA / UK / Switzerland / Brazil without consent | Pseudonymous client id, page and event data, coarse geo, IP (used for geo then discarded by Google) | US / global |
| Meta Platforms, Inc. | Advertising measurement and conversion attribution via the Meta Pixel (browser) and the Conversions API (server, via tags.pylon.video); gated on Marketing consent (on by the regional default outside the EEA / UK / Switzerland / Brazil), never on playback pages, and never in the EEA / UK / Switzerland / Brazil, where Marketing can never be granted |
Hashed email where available, event data, browser/device signals, IP | US / global |
| X Corp. (X / Twitter) | Advertising measurement and conversion attribution via the X website tag (browser) and Conversions API (server); Marketing consent gated, same region and playback carve-outs as Meta | Hashed email where available, event data, browser/device signals, IP | US / global |
| Reddit, Inc. | Advertising conversion measurement via the Reddit Conversions API (server-side only); Marketing consent gated, same region carve-out | Hashed identifiers where available, event data, IP | US / global |
| TikTok (TikTok Information Technologies UK Ltd / ByteDance) | Advertising conversion measurement via the TikTok Events API (server-side only); Marketing consent gated, same region carve-out | Hashed identifiers where available, event data, IP | US / EU / global |
We have a written data-processing agreement (DPA) with each processor, incorporating the Standard Contractual Clauses (Module 2, controller- to-processor) where the processor is outside the EEA, and equivalent provisions for UK GDPR (the UK IDTA) and Australian APP 8.
Other than the advertising and measurement partners listed above (and, on mobile, only where you allow tracking through the ATT prompt), we do not share with: data brokers, people-search services, marketing-data marketplaces, or AI-training data buyers.
5.2 Other categories of recipient
- Creators (filmmakers), we share aggregate watch data attributed to their titles for the purpose of payouts and analytics. We do not share individual viewers' identities with Creators. A Creator can see, for their title, how many minutes were watched, what region the watch came from and similar aggregates; they cannot see who watched.
- Tax authorities (routine reporting), if you are a Creator who receives Keepsake royalties: we report transaction and identity details of Australian-resident Creators to the Australian Taxation Office under the Sharing Economy Reporting Regime (SERR) to the extent it applies, and we (or our payment processors) file US information returns (for example 1099 or 1042-S series forms) with the IRS where required. If we later enable Keepsakes for EU-resident Creators, DAC7 platform reporting may apply and we will update this Policy first.
- Authorities, when required by valid legal process, regulatory request or law-enforcement request that we have verified. We evaluate every request on its merits, refuse over-broad requests and, where lawful and consistent with the request, notify the affected user. We will publish a transparency report when our request volume warrants it.
- Acquirers, in connection with a merger, acquisition, financing or sale of all or substantially all of our assets, we may transfer personal information to the counterparty subject to a confidentiality obligation and continued compliance with this Policy or its successor.
5.3 "Sale" and "sharing" of personal information
We do not sell personal information for money. However, on the free, ad-supported tier, personalised advertising may constitute "sharing" for cross-context behavioural advertising as that term is defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Cal. Civ. Code §1798.140. Ad personalisation is governed by your Marketing consent, which you set in the cookie banner on the web or the in-app privacy settings on mobile. In the EEA, UK, Switzerland and Brazil, Marketing can never be granted, so ads there are always non-personalised. Elsewhere (for example the US) Marketing is on by the regional default under an opt-out model, so ads may be personalised unless you opt out (see the options below). On mobile, Apple's App Tracking Transparency prompt separately governs whether we may access your advertising identifier for cross-app measurement and install attribution.
You can opt out at any time:
- On the web, switch the Marketing category off in the cookie banner
(in the EEA, UK, Switzerland and Brazil Marketing is always off and can
never be granted; elsewhere it is on by the regional default, so turning it
off is your opt-out), and ads then stay non-personalised (
npa=1). - On iOS, decline the App Tracking Transparency prompt, or later turn tracking off in Settings › Privacy & Security › Tracking. We then stop using the advertising identifier for cross-context advertising.
- Subscribe to Premium, which removes ads from your experience (apart from an occasional sponsor spot shown to everyone on a premiere).
- Record a Do Not Sell or Share preference at any time at /legal/do-not-sell, which forces non-personalised ads on the browser where you set it.
- Send a Global Privacy Control (GPC) signal. We treat an opt-out
preference signal sent by your browser or a browser extension (
Sec-GPC) as a valid request to opt out of the sale or sharing of personal information. When we detect it we turn off marketing pixels, force non-personalised ads and drop analytics sharing on that browser, with no further action needed.
6. International transfers
PYLON is operated from Australia. Personal information is processed at Cloudflare edge nodes around the world, and by service providers in the United States and (in some cases) the European Economic Area.
When we transfer personal information out of the EEA, the UK or Switzerland to a country that does not benefit from a European Commission adequacy decision, we rely on the Standard Contractual Clauses (EU SCCs Module 2; UK IDTA) and we apply supplementary measures where necessary, including encryption in transit (TLS 1.2+) and at rest (AES-GCM for sensitive columns), pseudonymisation (hashed IPs), and contractual assistance with data-subject rights.
Australian Privacy Principle 8 applies to overseas disclosures from Australia: we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to the information.
7. How long we keep personal information
We retain personal information only for as long as we have a lawful basis to do so.
| Category | Retention |
|---|---|
| Account identity (email, DOB, country) | While the Account is active, plus the 30-day deletion grace window if you request deletion |
| Subscription and payment records (incl. invoices, refunds) | Seven (7) years after the end of the Subscription, to comply with Australian tax (ITAA 1997 §262A) and equivalent overseas record-keeping obligations |
| Keepsake purchase and creator royalty-ledger records | Seven (7) years (financial records; ITAA 1997 §262A and equivalent obligations). Retained in de-identified form after account deletion: the ledger row survives, the user pointer is tombstoned |
| Rendered Keepsake artifacts (your Collection) | While your Account exists (they are content you collected under licence). Deleted when your Account is deleted or a purchase is refunded/charged back — the artifact and its licence end together (ToS §7A.4) |
| Render pipeline intermediates (temporary working files) | Ninety (90) days, then deleted |
| Download logs | Twelve (12) months, then aggregated or deleted |
| Collector Notes | Until you delete your Account or ask us to delete the note — the note content is then nulled, while the purchase's financial record is retained per the row above |
| Backers Roll display election | Until you withdraw or delete your Account — the public entry is then anonymised ("Anonymous collector") |
| View progress and view events | While the Account is active; anonymised on deletion (we set the user-id pointer to NULL but retain the aggregate event for analytics integrity) |
| Daily metrics (per-user) | Two (2) years; aggregated permanently |
| Sessions | Until expiry or sign-out, then 30 days for forensic purposes |
| Newsletter subscriptions | Until you unsubscribe, then a tombstoned suppression entry indefinitely (so we never resend to you) |
| Audit log entries | Seven (7) years (legal, compliance and dispute defence) |
| Withholding records (per-payment withholding assessments with residency snapshots, remittance batches, annual-report exports, withholding statements) and the signed tax residency declaration document | Five (5) years minimum after the relevant financial year (ATO record-keeping obligations; GDPR Art. 17(3)(b)). These survive Account deletion tied to the tombstoned account row. Your live tax profile (ABN, declared address) is deleted with your Account; IRS W-form PDFs (which contain TINs) are deleted with your Account |
| Two-factor secret and hashed recovery codes | Until you disable 2FA or your Account is deleted |
| Hard-bounce / suppression flag | Indefinitely (deliverability hygiene) |
| GDPR / privacy-rights request records | Three (3) years from request closure |
| DMCA takedown notices and counter-notices | Five (5) years (litigation defence) |
| Customer-support tickets | Three (3) years from closure |
When you request deletion, we operate a thirty (30) day grace window
during which you can cancel the request by signing back in. After thirty
days, our automated cron deletes or anonymises your personal data per
the cascade documented at apps/api/src/cron/gdpr.ts. Some operational
records (audit log, financial records) are retained per the table above.
After the cascade, your users row is tombstoned, email,
display-name, image, DOB, country code and Stripe customer ID are
zeroed; the row itself is retained because non-nullable foreign keys
from retained business records (titles, payouts, audit) reference it.
This is a privacy-preserving design choice: we keep referential
integrity on retained records without keeping any personal data.
The same pattern applies to Keepsakes: on deletion (or on a GDPR
Article 17 request), your rendered Keepsake artifacts are deleted (your
Keepsake licences end with the Account — Terms of Service §7A.4), your
Backers Roll entries are anonymised, your Collector Note contents are
nulled, and the underlying purchase and royalty-ledger rows are retained
for seven (7) years in de-identified form as financial records (GDPR
Art. 17(3)(b) — compliance with a legal obligation).
8. Your rights
Your rights vary by jurisdiction. We honour the following rights to the extent applicable to you. To exercise any right, email [email protected] or use Account → Privacy & Data.
We aim to respond within thirty (30) days. We may extend this by a further sixty (60) days for complex requests; we will tell you if we need to. We do not charge a fee for a first request in any twelve-month period.
8.1 GDPR (EU) and UK GDPR
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the rights to:
- Access the personal information we hold about you (Art. 15);
- Rectify inaccurate or incomplete information (Art. 16);
- Erase your personal information (the "right to be forgotten", Art. 17), subject to our retention obligations;
- Restrict our processing (Art. 18);
- Receive a portable copy of your information in a machine- readable format (Art. 20), our GDPR export tool delivers a JSON archive at the link we email you;
- Object to processing based on legitimate interest, including direct marketing (Art. 21);
- Withdraw consent at any time, without affecting the lawfulness of past processing (Art. 7(3));
- Not be subject to automated decision-making with legal or similarly significant effects (Art. 22), we do not engage in such automated decision-making; and
- Lodge a complaint with your supervisory authority. A list is maintained by the European Data Protection Board at https://edpb.europa.eu. UK residents may complain to the UK Information Commissioner's Office (ICO) at https://ico.org.uk.
8.2 Australian Privacy Act 1988
If you are in Australia, the Australian Privacy Principles (APPs) apply, including:
- APP 1, open and transparent management of personal information;
- APP 5, notification of collection (this Policy is that notification);
- APP 6, limited use and disclosure;
- APP 8, overseas disclosure (see section 6);
- APP 11, security of personal information;
- APP 12, access on request;
- APP 13, correction on request.
You may complain to the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au if you are not satisfied with our handling of your personal information.
8.3 California (CCPA / CPRA)
If you are a California resident, you have the rights to:
- Know what personal information we collect, use, disclose and sell or share (Cal. Civ. Code §1798.110, §1798.115);
- Delete personal information (§1798.105);
- Correct inaccurate personal information (§1798.106);
- Opt out of "sale" or "sharing" of personal information for
cross-context behavioural advertising (§1798.120), see
/legal/do-not-sell. We also honour an opt-out
preference signal sent through Global Privacy Control (
Sec-GPC) as a valid opt-out request under §1798.135(b), with no further action required; - Limit use and disclosure of sensitive personal information (§1798.121), we do not use sensitive PI for any purpose beyond those listed in §1798.121(a)(1)–(8), so this right is auto-honoured;
- Non-discrimination for exercising your privacy rights (§1798.125); and
- Authorise an agent to act for you, subject to verification.
8.4 Other US states
If you are a resident of Colorado (CPA), Connecticut (CTDPA), Delaware, Florida, Indiana, Iowa, Maryland, Minnesota, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas (TDPSA), Utah (UCPA) or Virginia (VCDPA), you have substantially equivalent rights to access, correct, delete and opt-out of targeted advertising and the sale of personal information. Email [email protected] to exercise.
8.5 Canada (PIPEDA)
If you are in Canada, you have the rights of access, correction and withdrawal of consent (subject to legal and contractual restrictions) under the Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial laws. The applicable supervisory authority is the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca.
8.6 Brazil (LGPD)
We do not currently offer the Service in Brazil and do not knowingly process personal data of Brazilian data subjects. If we extend the Service to Brazil, we will update this Policy with the Lei Geral de Proteção de Dados (LGPD)–specific rights and the relevant authority (ANPD).
8.7 Verification
Before we act on a rights request, we will verify your identity to a reasonable degree of confidence appropriate to the sensitivity of the data and the nature of the request, typically by requiring you to authenticate to your Account and to confirm the request from the verified email address on the Account.
9. Cookies and similar technologies
The cookies and local-storage entries we use are described in the Cookie Policy. In summary:
- Strictly necessary cookies (session, CSRF, viewing-progress, offline-download tag) are always on. They are required for the Service to work.
- Functional cookies (theme, captions, locale) follow a region-dependent default: off until you opt in in the EEA, UK, Switzerland and Brazil (and other opt-in regions), on by default elsewhere (for example the US), and you can turn them off at any time.
- Analytics cookies and tags (PostHog, Sentry, and Google Analytics 4 loaded through server-side Google Tag Manager) follow a region-dependent default. In the EEA, UK, Switzerland and Brazil (and other opt-in regions) they are off by default and load only after you grant consent. Elsewhere (for example the US) they may be on by default under an opt-out model, and you can turn them off at any time via the cookie banner or a browser Global Privacy Control (GPC) signal, which we honour automatically. Google Analytics never loads in the EEA, UK, Switzerland or Brazil unless you grant consent there.
- Marketing / advertising: with Marketing consent, we load advertising
measurement tags: the Meta and X pixels (browser) and the Meta, X, Reddit
and TikTok Conversions/Events APIs (server-side, via
tags.pylon.video), on non-playback pages only. These measurement tags are gated on Marketing consent and do not fire without it. Marketing's default is region-dependent: in the EEA, UK, Switzerland and Brazil Marketing is always off and can never be granted, so these tags never fire there; elsewhere (for example the US) it is on by default under an opt-out model, and you can turn it off at any time via the cookie banner, a browser Global Privacy Control (GPC) signal, or the "Do Not Sell or Share" control, all of which we honour. Separately, on the free, ad-supported tier, Google's Interactive Media Ads (IMA) fund the free tier. Outside the EEA, UK, Switzerland and Brazil, IMA ads serve regardless of Marketing consent and may set their own cookies when an ad is served; your Marketing consent and region control only whether those ads are personalised (npa), not whether they run. In the EEA, UK, Switzerland and Brazil, IMA ads do not serve by default: ad serving there is held behind an operational flag that stays off until a certified consent-management platform ships, and if it is enabled those ads serve non-personalised. The measurement tags never load on playback (watch) pages regardless of consent. Premium subscribers see no ads and no advertising cookies, apart from an occasional sponsor spot on a premiere. See the Cookie Policy §3.4 for the details. We also honour a browser Global Privacy Control signal as an opt-out of this sharing.
The PYLON Cinema mobile app uses the same per-purpose consent framework (functional, analytics, marketing). Your decision is stored on-device in the OS keychain and synchronised to your Account so it carries across devices. You can review or change your choices at any time in the app under You → Privacy, and on the web using the interactive consent manager at /legal/cookies (also reachable via Cookie settings in the site footer).
You can change your choices at any time using the consent manager at /legal/cookies.
10. Children
The Service is not directed to children under thirteen (13). See the Children's Privacy Notice for our COPPA-compliant approach. If you believe we have inadvertently collected personal information from a child under thirteen, contact [email protected] and we will delete it.
11. How we secure personal information
We implement administrative, physical and technical safeguards designed to protect personal information against loss, misuse and unauthorised access, disclosure, alteration and destruction. These include:
- TLS 1.2+ for all data in transit, with HSTS preloading and modern cipher suites only;
- AES-GCM at rest for sensitive columns (e.g., 2FA secrets, recovery-code hashes, IP hashes);
- Passwordless authentication by default, magic-link or OAuth, to eliminate password-reuse risk;
- Two-factor authentication available to all users; required for privileged roles (admin, senior_curator);
- Hashed IP addresses, we never store raw IPs;
- Allow-list data minimisation in our automated GDPR export, only explicitly listed columns are exported;
- Audit logging of all security-sensitive actions;
- Role-based access control, engineers do not have routine access to user data; access is logged and reviewed;
- Vendor risk review before onboarding new processors;
- Annual review of this Policy and the underlying controls.
We do not currently hold a SOC 2, ISO 27001, HIPAA or PCI DSS certification. We will publish certifications on this page if and when we obtain them. We are PCI DSS out of scope because we never see card data, Stripe handles all PCI scope.
No security control is perfect. We cannot guarantee absolute security.
12. Breach notification
If a personal-information breach occurs, we will:
- contain and assess the breach;
- where required, notify the relevant supervisory authority within the statutory window, seventy-two (72) hours for GDPR Art. 33; "as soon as practicable" for the Australian Notifiable Data Breaches scheme (Privacy Act 1988 Part IIIC);
- where required by law or where the breach is likely to result in a significant risk of serious harm to you, notify you directly and provide guidance on protective steps you can take.
We maintain a Data Breach Response Plan internally and exercise it annually.
13. Contact us; complaints
Privacy enquiries and rights requests: [email protected] Postal: PYLON Film Pty Ltd, Level 2, 111 Harrington Street, THE ROCKS NSW 2000, Australia
We will acknowledge your enquiry within five (5) business days and aim to resolve within thirty (30) days.
Supervisory authorities and complaint channels:
- Australia, Office of the Australian Information Commissioner (OAIC), https://www.oaic.gov.au;
- EU, your national data-protection authority (list maintained by the EDPB at https://edpb.europa.eu);
- United Kingdom, Information Commissioner's Office, https://ico.org.uk;
- California, California Privacy Protection Agency, https://cppa.ca.gov;
- Canada, Office of the Privacy Commissioner, https://www.priv.gc.ca.
You have the right to lodge a complaint without contacting us first, though we encourage you to give us a chance to address your concern.
14. Changes to this Policy
We may amend this Policy from time to time. Material changes will be notified by email to your Account address and/or by an in-product notice at least fourteen (14) days before they take effect (or such longer notice as required by applicable law). The most current version is always at https://pylon.video/legal/privacy-policy.
Sibling documents
- Terms of Service
- Cookie Policy
- Do-Not-Sell
- Children's Privacy Notice
- Marketing Communications
- Subscription Agreement
- Refund Policy
- DMCA Policy
Note on Do-Not-Sell. For the canonical Do-Not-Sell mechanism, see the live page at
/legal/do-not-sell.
Version history
| Version | Date | Author | Notes |
|---|---|---|---|
| 1.4.0 | 2026-07-10 | PYLON | Processor + advertising truth pass · §5.1 added the advertising-measurement recipients that actually receive event data (Meta Pixel + Conversions API, X website tag + Conversions API, Reddit Conversions API, TikTok Events API, and Google Analytics 4 via server-side Google Tag Manager), each disclosed as Marketing-consent gated, non-playback only, and never loading in the EEA / UK / Switzerland / Brazil by default. §9 rewritten to name those tags, add Google Analytics under analytics, correct the "manage your choices" link to the interactive consent manager at /legal/cookies, and disclose Global Privacy Control honouring. §5.3 + §8.3 disclose that a browser Global Privacy Control (Sec-GPC) signal is honoured as a valid opt-out of sale/sharing with no further action. Aligned with the digital-content withdrawal-waiver posture: when digital purchases are open, checkout will require a consent tick (express consent to immediate performance and acknowledgement of the loss of the 14-day withdrawal right) before a purchase can complete; that collection is fail-closed behind a flag and off by default (see the Refund Policy §2.2 / Subscription Agreement) |
| 1.3.0 | 2026-07-08 | PYLON | Advertising alignment across the corpus · §2.6 corrected to disclose ATT-gated advertising-identifier (IDFA/AAID) collection + AppsFlyer attribution + Google IMA ads (previously stated no advertising identifier was collected); §4 added an advertising/attribution purpose row (non-personalised = legitimate interest; personalised = Marketing consent + region, with the iOS ATT prompt separately gating advertising-identifier access); §5.1 added AppsFlyer + Google (Ads/IMA) processor rows and narrowed the "no ad-tech/ad-network sharing" statement; §5.3 rewritten from "no sharing" to disclose CCPA/CPRA cross-context "sharing" with ATT-decline / Premium / Do-Not-Sell opt-outs. The Do-Not-Sell flag is now honoured on the web ad path (forces npa=1, non-personalised, on the opted-out browser) in addition to the analytics path |
| 1.2.0 | 2026-07-07 | PYLON | AU royalty withholding — §2.5 tax-residency documentation category (declaration / ABN / NAT 3346), §5.1 SignatureAPI scope + location aligned with the DPA, §7 withholding-records retention row (5-year ATO basis surviving deletion; live profile + TIN PDFs still deleted) |
| 1.1.0 | 2026-07-04 | PYLON | Keepsakes pack — PR 0: new §2.2A data types, creator royalty-ledger bullet, purposes rows, processor rows (Airwallex, Apple, Google, Stripe purpose), tax-authority disclosure, retention rows, deletion-ends-licence note |
| 1.0.0 | 2026-06-15 | PYLON | Live publication |
| 0.2.0 | 2026-04-29 | engineering | Mobile app section added (§2.6), RevenueCat + Expo named as processors, mobile consent framework noted in §9 |