Privacy Policy
Last revised: 23 September 2026 · Data controller: XynStudios · Contact: arizen@aris-swift.com
1. Who we are
XynStudios ("we", "us") operates this website, including game pages, AI tools, QR generator, subscriptions, and license services. For data-protection purposes XynStudios is the data controller. Contact: arizen@aris-swift.com.
2. Notice before collection (Ghana Act 843 §23)
Before you give us personal data, you have the right to know the following — this policy is that notice:
- What we collect: §3 below.
- Why: §4 below (a purpose is stated for every category).
- Mandatory or voluntary: account registration, purchase email/payment verification, and DRM login are mandatory for those features — without them the feature cannot work. Contact notes, AI chat messages, and file attachments are voluntary.
- Consequences of refusal: you cannot create an account, buy, activate a license, or use credit-gated tools without the required data.
- Legal basis / authority: your consent (accounts, newsletters), performance of a contract (purchases, licenses, subscriptions), and our legitimate interest in security and fraud prevention.
- Recipients: §6 below. We never sell personal data.
- Your rights: access, rectification, objection, and deletion requests — §8 below.
3. Data we collect
| Category | Examples | When |
|---|---|---|
| Account data | Name, email, password hash, role, credit balance | Register / sign in |
| Purchase data | Email, amount, Paystack reference, plan/reward chosen | Checkout (card data goes only to Paystack — never to us) |
| License & DRM data | Email, device fingerprint, sessions/heartbeats, strike counts, appeal records | Game activation & play |
| Subscription data | Email, license keys, plan, expiry, trial use | Subscribe / renew / verify |
| Tool content | AI humanizer/detector inputs, QR content & settings, attached files | Using AI tools / QR generator |
| Verification data | Emailed sign-in codes, backup-code hashes, trusted-device tokens | Proving inbox control at registration & sign-in |
| Support data | Emails you send us, receipts, dispute info | Contact / refunds |
| Technical data | IP address, browser, pages visited, error logs | Automatic on every visit |
4. How we use it
- Provide accounts, credits, tools, licenses, and subscriptions.
- Verify payments and prevent fraud, ref-reuse, and license abuse.
- Send transactional mail (receipts, license keys, expiry notices).
- Operate DRM security (device checks, strike/block enforcement, appeals).
- Improve reliability and support (logs, diagnostics).
We do not use your data for advertising profiles and we do not sell it. Marketing emails are only sent with consent and always include an unsubscribe option.
5. Retention
- Accounts & licenses: kept while active, plus up to 24 months for dispute/fraud records.
- Payments/claims: kept up to 6 years for accounting and chargeback evidence.
- Support mail: up to 24 months.
- Logs: up to 12 months.
- Deleted accounts: personal identifiers removed or anonymised on verified request, except records we must keep by law.
6. Who receives your data
- Paystack — payment processing (your card data never touches our servers).
- Puter.js — sign-in for the AI chat page.
- NVIDIA NIM / Google Gemini — AI humanizer & detector processing.
- Hosting/FTP providers — infrastructure only.
- Authorities — only where required by law (e.g. Ghana Data Protection Commission, fraud investigation).
7. International transfers
Processors above may handle data outside Ghana (including the US/EU). We use reputable providers with contractual safeguards and only transfer what each feature needs.
8. Your rights
Email arizen@aris-swift.com with subject "Privacy request" to: access your data, correct it, object to processing, or request deletion. We respond within 30 days. Ghana residents may also complain to the Data Protection Commission (dataprotection.org.gh). EU/UK users hold GDPR rights (access, erasure, portability, restriction); California and other US-state residents hold applicable access/deletion/opt-out rights on request.
9. Security
Passwords are hashed, license/session tokens are random and single-use where applicable, admin actions require authentication + CSRF protection, and payment pages run over HTTPS. No method is perfect — report suspected breaches to arizen@aris-swift.com immediately.
10. Children
Accounts, purchases, and credit-gated tools are for users 13 and older. We do not knowingly collect data from under-13s; such accounts are removed on discovery.
11. Cookies
See our Cookie Policy for session cookies and local storage details.
12. Changes
Material changes are announced by updating the "Last revised" date above and, where appropriate, by email. Continued use after changes take effect constitutes acceptance.