MYTE

Privacy Policy

Effective date: 2025-11-22

MYTE is a context engineering platform provided by Myte Group Inc. It helps you curate and work with large bodies of context over time. To operate and improve the platform, we process personal data and the content you choose to share.

Data Use Summary

  • Cloud processing: we process your content on our infrastructure and trusted AI compute providers (including OpenAI Compute) to deliver features you invoke (such as transcription, summarization, retrieval, and code reasoning).
  • Collaboration: if you invite builders, experts, or other collaborators, they can access the workspace content you share with them so they can pick up work across ideation, delivery, and maintenance.
  • Limits: AI outputs are non-deterministic and bound by context window size ("memory").
  • Operational logging: we log minimal security and reliability metadata (e.g., auth errors, rate-limit events, timestamps) to prevent abuse and operate the service. We do not run marketing analytics or behavioral tracking.

Scope

This policy applies to myte.dev, subdomains, the MYTE web app, related APIs and services, and communications with us.

Language and Quebec Notice

This policy is available in English and French to meet Quebec requirements. If you reside in Quebec, the laws of Quebec apply alongside applicable Canadian federal law.

Information We Collect

  • Account data: name, email, organization, preferences, authentication data.
  • Authentication and device trust data: passkey/public-key credential metadata, optional device labels, trusted-device hashes/status, login timestamps, and security events. Your browser or operating system handles biometric or PIN verification locally; we do not receive or store raw biometric templates, fingerprints, face scans, or device PINs.
  • Customer content: information you upload, enter, record, or connect (e.g., notes, proposals, messages, audio for transcription) and related metadata.
  • Integrations: data from services you connect (e.g., GitHub metadata and files as configured), Stripe billing metadata, Google OAuth profile.
  • Operational and security data: service logs, diagnostics, timestamps, and rate-limit/security events needed to operate the service.
  • Payments: processed by Stripe; we receive limited records (e.g., customer ID, status, amounts).
  • API keys and telemetry: project API key prefix/fingerprint, usage counts, last used time/IP, rate-limit events (6 requests/hour/key), and audit entries tied to key metadata (not the raw key, which is only shown once on creation).
  • Cookies: session, authentication, preference, and security cookies.

Speech and Audio Capture

Audio uploaded for transcription (e.g., proposal intake) is processed through our speech pipeline (16 kHz mono WAV, ~0.8–12s). We forward the audio to trusted AI model providers to return transcripts; we may retain short-lived copies for reliability and abuse prevention. Recording can run in a web worker or ScriptProcessor fallback, and transfers may be rate limited.

Retrieval, Snapshots, and Embeddings

When you enable retrieval, we may store repository/project content, embeddings, and snapshot metadata to build context bundles for answers. Retrieval context can become stale; you can remove source data to remove future use in answers. We do not train proprietary foundation models on your Customer Content.

Project API Keys

Project-scoped API keys (e.g., for the Project Assistant) are tied to a single project with one active key at a time. Raw keys are shown once; we store hashed prefixes/fingerprints and usage telemetry (usage counts, last_used_at/IP, rate-limit events). Abuse events may be logged with key metadata for security and fraud prevention.

Secrets Service

The internal Secrets Service stores secret values in MongoDB encrypted with AES-GCM using an envelope key file mounted at runtime. Access is limited to authorized requests; audit trails are retained for sensitive actions. Secret values are not sent to model training and are decrypted only to fulfill explicit operations you invoke.

Integrations and Billing

If you connect third parties (e.g., GitHub, Google OAuth) we access the scopes you grant to deliver features (such as repository metadata/files or profile data). Billing is processed by Stripe; we receive customer/profile IDs, payment method metadata, invoices, portal session IDs, and webhook events to operate subscriptions, wallet balances, and refunds.

How We Use Information

  • Provide and secure the services.
  • Maintain and improve quality, reliability, performance, and safety.
  • Compliance and enforcement (security, fraud prevention, lawful requests).
  • Service communications (updates, onboarding, invoices, security notices).

Lawful Bases

Contract (to provide the service), legitimate interests (improvement, security, fraud prevention), consent (Google OAuth, experimental research, certain cookies), and legal obligations.

Sharing and Disclosure

We share data with service providers to operate the platform (e.g., AWS, MongoDB Atlas, Redis/Celery, Stripe, Google), AI model providers used to fulfill features (e.g., OpenAI), integrations you enable, and as required by law or for business transfers. We also share workspace content with collaborators or experts you invite or authorize in your organization. International transfers use appropriate safeguards.

Cross-Border Transfers

Your data may be transferred outside Quebec and Canada. We use safeguards such as standard contractual clauses, supplier due diligence, and access controls to help ensure comparable protection. You can contact us for details on these measures.

Retention

We retain personal data as long as needed to provide the services and for legitimate business purposes (security, legal, accounting). Examples: short-term retention of audio uploads for reliability/abuse prevention; retrieval embeddings/snapshots while the project is active; API key telemetry for rate-limiting and security; billing records per legal requirements. You can request deletion, subject to legal and operational limits.

Confidentiality Incidents (Quebec Law 25)

If a confidentiality incident presents a risk of serious harm, we will notify affected users and the Commission d'accès à l'information (CAI) as required. We maintain a log of incidents in line with Quebec law.

Your Choices and Rights

  • Access, correction, deletion, portability, restriction/objection where applicable.
  • Request that we limit use of your Customer Content beyond running the features you invoke by contacting support; some functionality or diagnostics may be reduced.
  • Quebec users may request cessation of dissemination or de-indexing where the law applies. You may withdraw consent where processing is based on consent.
  • Manage cookies via browser or available in-app controls.
  • Contact: info@mytegroup.com

AI/ML and the Creation Engine

MYTE operates as a creation engine: we use AI models to transform the inputs and context you choose to share into plans, code, documents, and other outputs. We route your prompts and context to trusted AI providers, including OpenAI Compute, only to perform the inferences you request. MYTE is intended as an accelerator and incubator for business transformations. You can engage with it the way you would talk to ChatGPT, or through our platform to get a structured environment plus builders and experts you invite to pick up where you left off across ideation, delivery, and maintenance. We may develop in-house heuristics, workflows, and routing strategies to make those inferences more reliable, but we do not develop proprietary foundation models using your Customer Content. You can export your work and delete your workspace data subject to legal and operational limits. We do not publish your raw private content. We may generate aggregated or de-identified statistics.

Security

We use technical and organizational measures (e.g., encryption in transit, access controls, monitoring). No method is 100% secure.

Children

Not intended for anyone under 18. By using MYTE you confirm you are at least 18 years old. If we learn we collected personal data from someone under 18, we will delete it.

Changes

We may update this policy and will adjust the effective date. Material changes will be notified.

Contact

Myte Group Inc (MYTE) - info@mytegroup.com

MYTE is a trademark of Myte Group Inc. Myte Group is a trademark of Myte Group Inc in Canada.

Privacy Officer (Quebec)

Privacy officer for Quebec and Canada: info@mytegroup.com. Contact this address for privacy rights requests or questions.