GTXT.TUBE · 15 September 2026
Privacy policy
The data controller is HYBT Technologies, Inc. Contact details are on the Company page. This policy covers the website, PWA, Telegram Mini App and connected MCP clients.
Data and purposes
We process your verified email for sign-in and service notices; your Telegram identifier and display name when you choose Telegram; prompts, generation settings, uploads, results and projects; credit and order records; support requests; and technical information needed to protect and operate the service. We use this information to fulfill requests, maintain access, account for payments, provide support and prevent abuse.
Depending on applicable law, legal grounds include performing a contract, legal obligations, legitimate security interests and consent where required. We do not ask for your Telegram password, codes from other services, full card number or wallet private keys. Payment providers handle payment credentials.
Providers and processing locations
The application server is hosted in AWS Frankfurt. Telegram provides authentication and Stars payments. Generation inputs and files needed for a request are passed to AI processing services and the selected model provider. Stripe handles website payments.
External providers may process data in other countries. Processing entirely inside the EU is not guaranteed. Provider policies also govern their retention and use. Do not upload other people's personal data without a lawful basis.
Email, connected apps and sharing
Your email is used for sign-in codes, credit expiry and rate-change notices sent through Amazon SES. These are service messages, not marketing. We store MCP permissions and hashed tokens; connected clients receive only the account data covered by your authorization. Their own policies apply to data they receive.
MCP material links expire after 15 minutes and stop working when the connection is revoked. Sharing links require your explicit confirmation, expire after seven days and can be revoked in Account. Anyone holding an active link can download the selected material. Revoking a link stops new downloads; it does not erase copies already received. System sharing passes a file to the application you choose on your device.
Email sign-in
A one-time sign-in code expires after 10 minutes. We store a verification value, limit attempts and request frequency, and remove expired challenge and rate-limit records on subsequent requests after their 24-hour retention period. Your verified address remains attached to your account.
Retention and your rights
Materials and history are retained to operate your account. Retention depends on the purpose, payment obligations and dispute resolution. Deletion is separate from cancellation; records may need to be retained for legal obligations or unresolved disputes. We explain any applicable restriction when responding to a request.
Account provides a data export and a channel for correction or deletion requests. Depending on applicable law, rights may include access, objection, restriction, portability, withdrawal of consent and a complaint to the appropriate data protection authority. Identity verification may be required.
Storage and security
See Cookies. Advertising and analytics trackers are not installed in this release. We use HTTPS and access controls; no system guarantees absolute security. Report suspected incidents to support. Material policy changes will be communicated separately.