Privacy Policy
Last updated: 15/09/2026
1. Overview
MYRTE is a video editing application installed on your Windows computer. A macOS version is planned as described in our Roadmap. Your projects, media and exports are stored locally on your machine. An online account is used solely for authentication, managing your subscription and credits, and for AI generation features.
This policy also covers the contact form on our website: information you submit through it is collected solely to process your request and get back to you about a MYRTE demo.
2. Data Controller
Myrte acts as data controller for Personal Data we process to operate the Platform (accounts, security, support, analytics):
Myrte SASU 97 grande rue,78240 Chambourcy, France admin@myrte.io
Information submitted through the contact/demo request form is likewise processed under the responsibility of Myrte SASU as data controller.
If you use MYRTE in a professional context, you remain responsible for any personal data present in the briefs, text or images you import or use as generation references ("Inputs"). Avoid including third-party personal data in your Inputs unless you are legally authorized to do so.
3. Data we collect
| Category | Examples |
|---|---|
| Account | Email address, password (or Google identifier if signing in via Google). |
| Billing | Subscription status, credit balance. Payment methods are processed and stored exclusively by Stripe — we never receive your card number. |
| Usage and technical data | Log of AI generations launched, credits consumed, name and last-opened date of your projects (for the recent projects list). |
| AI Inputs and Outputs | Text prompts, reference images or videos submitted for a generation, and the resulting generated content. |
| Communications | Support messages and associated metadata (date, subject). |
Your projects, imported media and exports remain stored locally on your machine and are never collected by MYRTE, except when you submit them yourself for an AI generation (see section 5).
4. How and why we use your data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service, accounts and features | Performance of a contract |
| Billing, subscriptions and credits | Performance of a contract |
| Security, abuse prevention, service integrity | Legitimate interest |
| Legal and accounting obligations | Legal obligation |
| Non-essential communications (e.g. product news) | Consent, where applicable |
Where we rely on legitimate interest, you may object to it — see section 8.
5. AI processing
When you launch a generation (image, video, audio or 3D model), your text prompt and, where applicable, your reference images or videos are sent to our AI generation providers (including Fal.ai) to carry out your request. Prompts are processed in transit and are not stored in the MYRTE database. Temporary reference files are deleted from our storage once the generation is complete; a server-side cleanup process retries any residual file after a client interruption and never removes a reference while its generation is still active.
For delivery and recovery, the MYRTE database may retain a bounded result manifest containing the provider result URL and basic media metadata for up to ninety (90) days. It does not retain the raw prompt, provider request payload, provider logs or headers in that manifest. The copy stored in your project and its local AI history remains under your control on your computer.
We do not use your Inputs or Outputs to train our own models. Use by our third-party AI providers is governed by their own terms, listed in section 7.
6. Retention
- Account identity, credit balance and registered project names are retained while your account exists and are deleted when you delete the account.
- Reference files submitted for an AI generation are deleted from our storage immediately after the request is processed. Residual files caused by an interruption remain tracked for automatic deletion retries.
- AI result recovery manifests and detailed terminal job records are retained for up to ninety (90) days. They are then reduced to a minimal operational record, which is deleted no later than one (1) year after the job became terminal.
- Technical usage logs and completed reconciliation logs are retained for up to one hundred and eighty (180) days.
- Processed Stripe event and compensation records are reduced after one (1) year. Minimal accounting and credit-ledger records are kept for ten (10) complete accounting years where required by French law, then deleted. If you delete your account during that period, the retained ledger is detached from your account, pseudonymized and stripped of free-form metadata. Pseudonymized records remain protected as personal data.
- Stripe may retain billing data independently in accordance with its own accounting and tax obligations.
- Information submitted through the contact/demo request form is retained for a maximum of three (3) years from our last contact with you, unless you become a customer, in which case it is then retained under the account data rule above.
7. Recipients and transfers
We do not sell your data. It is shared only with the providers strictly necessary to operate the service:
- Supabase — hosting of your account, credit balance and database (eu-central-1, Frankfurt,Germany).
- Stripe — payment, subscription and invoice processing.
- AI generation providers (including Fal.ai) — running your image, video, audio and 3D model generation requests.
- IONOS — email delivery for messages submitted through the contact/demo request form.
A full list of our subprocessors is available on request. Where data is transferred outside the European Economic Area, we rely on appropriate safeguards (for example, European Commission standard contractual clauses). We may also disclose data where required by law or a competent authority.
8. Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to withdraw your consent at any time where consent is the basis for processing. You can delete your account and all associated data directly from the application.
To exercise these rights, contact us at the address listed in section 12; we respond within one month, extendable where necessary under the conditions provided by law. You may also lodge a complaint with your local data protection authority — in France, the CNIL (www.cnil.fr).
9. Cookies
This showcase website does not use any tracking cookies or advertising trackers; it only sets cookies strictly necessary for it to function, where applicable. The desktop application does not use cookies: your session is managed via an authentication token stored locally on your machine. Should non-essential functional or analytics cookies be introduced in the future, your consent would be requested beforehand, as required by law.
10. Security
We implement appropriate technical and organizational measures. Network communications are encrypted in transit using HTTPS/TLS. Account data is logically isolated through row-level security rules, access is restricted to authorized personnel, and temporary AI reference files are deleted after processing. MYRTE does not itself encrypt local .mytr project files; their protection at rest depends on your operating-system access controls and disk-encryption settings. Protection of server-side files and databases at rest depends on the safeguards configured by the relevant hosting and storage providers. Contact queue files are protected by restricted operating-system file permissions. As no system can be guaranteed 100% secure, we cannot guarantee absolute security.
11. Changes to this policy
We may update this policy to reflect changes to the service or to applicable regulations. The last-updated date is shown at the top of this page; in the event of a material change, we will notify you by email or from within the application.
12. Contact
For any question regarding this policy or your personal data, contact: admin@myrte.io.
MYRTE