Legal

Privacy Policy

Who we are

Mystic Realm, Ashley’s Realm, Mystic Cinematica, and their sibling products are operated by Mystic Portal LLC (“Mystic,” “we,” “us”). If you have a question about this policy or want to exercise a right described below, email hello@mysticcinematica.com.

What we collect

We collect only what we need to make the product work and improve it:

  • Account data. Email, name, hashed password (or SSO identifier), and two-factor secret if you enable 2FA. Managed by our authentication provider Better Auth on top of PostgreSQL (Supabase).
  • Session data. Session tokens, device user-agent, and IP address, used for security and for our concurrent-device enforcement.
  • Companion + Realm content. Text, prompts, generated images and videos, audio, companion configuration, and Theater productions you create. Stored in Supabase and object storage (Cloudflare R2).
  • Voice audio. When you use voice, streaming audio is sent to our speech-to-text providers (OpenAI Realtime as primary; Deepgram as fallback) and to our model providers to generate responses. We do not store raw audio by default; short recent-context buffers are held in memory only.
  • Payment data. Card details are handled entirely by Stripe. We receive only the last four digits, brand, expiry, and a Stripe customer ID.
  • Referral + attribution. If a friend’s referral code brings you in, we store the code, timestamp, and referrer link — not their personal information beyond what is needed to pay the commission.
  • Product analytics. Standard page views, errors, and performance traces, either self-hosted or via Vercel Analytics. We do not sell this data.

How we use it

We do not train third-party foundation models on your content by default. A future opt-in program will let creators contribute to model training in exchange for revenue share; you will explicitly enroll, not the other way around.

  • Operate the product — authenticate you, run your companions, render your videos.
  • Bill you — process one-time and subscription payments through Stripe.
  • Protect the platform — detect abuse, enforce our device caps, honor bans.
  • Support you — answer help requests you send us.
  • Improve the product — aggregated, deidentified telemetry only.

Who we share it with

We share data only with the vendors that make the product run and only for the purposes above. Current core sub-processors:

We will publish a complete, versioned sub-processor list — with contract types, data categories, and regions — in the Coming soon section below.

  • Supabase (managed PostgreSQL and file storage).
  • Stripe (payments, subscriptions, refunds).
  • Vercel and Fly.io (application hosting and edge delivery).
  • Cloudflare R2 (long-term storage of generated media).
  • OpenAI and Google (large-language and video model inference).
  • Deepgram (speech-to-text fallback).
  • Resend (transactional email).
  • Picovoice (wake-word detection, when you opt in to “Hey Mystic”).

Where your data lives

Primary data is stored in the United States. Media generation may transit through the regions our model providers operate. When we transfer personal data out of the EU or UK, we rely on the Standard Contractual Clauses or equivalent safeguards.

How long we keep it

  • Account data — for the life of your account plus a short archival window.
  • Payment records — seven years, to meet US tax obligations.
  • Generated media — until you delete it. Intermediate render files, 24 hours.
  • Voice audio — not persisted; short in-memory buffers only.
  • Backups — rolling encrypted backups for up to 30 days.

Your rights

You can access, correct, export, or delete your data at any time by writing to us. If you live in the EU, UK, or California, you also have specific statutory rights — including the right to object to processing and the right to lodge a complaint with your data protection authority. We honor verified requests within 30 days.

Security

Data in transit is encrypted with TLS. Passwords are hashed with a memory-hard algorithm. Sensitive tokens are stored in provider-managed secret systems, not in application code. Two-factor authentication is available to every account and required for administrative roles. We are actively investing in post-quantum-ready cryptographic primitives as part of Mystic’s longer-term security roadmap.

Cookies and similar technologies

We use a small number of first-party cookies for authentication and for locale preferences. We do not run third-party ad-tech trackers on the marketing surfaces of ashleysrealm.com.

Changes to this policy

When we make a material change we will update the “Last updated” date at the top of this page and, for logged-in users, surface a notice inside the product. Older versions remain available on request.

Coming soon

These items are planned and are not currently part of the Services or a contractual commitment.

  • Full sub-processor list with contract types and data residency.
  • EU representative appointment under GDPR Art. 27.
  • Downloadable data-processing addendum (DPA) template for enterprise customers.
  • Children’s privacy statement for the practitioner-supervised minor flow.

hello@mysticcinematica.com · Back to Mystic Realm