Privacy Policy
Last updated: October 6, 2026
This page explains in plain language which personal data Cocuyo handles when you use the AI creation Studio or access the catalog with a previous account, how we use it and what control you have over it. The short version: we keep the minimum needed to provide the service, never sell your data, and third-party measurement is described in the cookie policy (Google Analytics, Google Ads, PostHog, and the Meta and TikTok pixels).
1. Who we are
Cocuyo (cocuyo.ai) is an AI audiovisual creation Studio: images, videos and audio. You can explore for free; generating requires an account and credits, with optional plans.
This policy also covers catalog data, access and previous Cine subscriptions. Pausing new Cine web subscriptions does not change your privacy rights.
The data controller for your information is Cocuyo LLC, located in Homestead, Florida (USA). For any privacy questions, you can write to us at hola@cocuyo.ai.
2. What data we collect
We apply strict data minimization: we only store what’s necessary for your account to work. Specifically:
- Your email — it identifies your account and allows us to contact you about it.
- Your name — optional; only if you decide to give it to us.
- Your account access — you can sign in with a one-time code or a link sent to your email. If you set a password, we store its secure hash to verify it—never the password in plain text.
- Your plan and the status of your subscription — to see whether your account is active and what it includes.
- Your active sessions — which devices you’ve signed in on, for account security and to enforce the limit on simultaneous playbacks.
- Your activity within Cocuyo — saved or unlocked series and episodes, and playback events (start, progress, and end).
- Your creation activity — when you submit a generation, we process the prompt, the selected options, the assigned provider and model, the job status, and the generated result. Completed creations are stored as private media associated with your account.
- Your use of the Tools — we keep on your account how many of your 30 welcome uses you’ve spent, just that number, and, when a use costs a credit, the entry in your credit history with the tool’s name. All of this is deleted when you delete your account. Daily counters from the previous system are deleted after 7 days.
- Your acceptances — the version and date on which you accepted the Terms when you created your account (legal age, Terms, Privacy and the declaration about what you upload) or, if your account is older, when you accepted that declaration. For each image you upload we also keep its technical fingerprint (SHA-256) linked to that acceptance. They serve to prove your consent, are included in your data download and are deleted with your account.
- Your billing and payment data — Stripe processes payments for the website. When you purchase inside an app via Google Play or Apple, the corresponding store processes the payment. Cocuyo receives customer and transaction references, amount, currency, payment status, and the necessary tax information, but does not store your full card data. To verify a store purchase, we retain its protected technical reference, the product, the subscription status, and the subscription’s validity, linked to your Cocuyo account.
- Temporary technical logs — we may register the IP address, user agent, dates, routes, and technical results for a limited time to protect accounts, investigate errors, and prevent fraud or abuse. We do not use these logs for advertising or to build profiles about you.
- Your local projects and drafts — the organization of the Create space may be saved in local storage (
localStorage) in that browser or device. When calculating the cost, generating or using a help feature, the data needed for that request is sent; not all your drafts are sent to the provider. You can delete local data by clearing site data on your device. - Support and notices — the messages you send us and, if you enable notifications, the inbox and the technical push keys of your browser.
- Community requests — if you request an “Appear in Cocuyo” proposal, we keep the interest linked to your account, language, date and follow-up. The team may draft a quote with content, deliverables, terms and likeness permission. An enquiry does not authorize use of your likeness or make a payment. You can check the status from that page; your request data is included in your data download and deleted with your account.
- The source of your first visit — if you accept measurement and arrived via a link with a campaign tag (utm) or another site, we store that tag and the referring domain in our own cookie (
cocuyo_origen, 90 days) and, if you create an account, we associate it with your account. It tells us which channels work; it is first-party measurement only, with no third parties and no tracking you across other sites.
What we DO NOT collect:
- Not your phone number.
- Not your postal address to use the catalog or Create; when you make a purchase, Stripe may request the minimum necessary billing data to process it and calculate taxes.
- Not your date of birth.
- Not your browsing history on other websites as a product. Yes, we use Google Analytics to see what’s viewed within Cocuyo (ad signals disabled, except for measuring conversions from Google Ads on the premiere and payment confirmation pages) and the Meta pixel to measure whether an ad led to a Stripe payment. The pixel is not on Sign In or Create. Details in Section 5 and in the cookie policy.
3. What we use your data for
We use that data only to operate and improve the service:
- Provide the service: so you can sign in to your account and play the catalog.
- Generate images, videos or audio: send your request to the selected AI provider, receive the result, and deliver it privately within Cocuyo.
- Manage payments for subscriptions and creation purchases through Stripe, without Cocuyo storing your full card data.
- Protect your account: detect unusual access, manage your sessions, and prevent unauthorized use.
- Help you and understand the catalog: respond to your inquiries and measure, in-house, which titles start or end.
News and offers emails. Free tools remain free and do not depend on this choice. If you tick the optional box when you create your account, we may send you Cocuyo news and offers by email; the legal basis is your consent. We store your choice with its date, the version of the text you accepted and how you gave it (sign-up by email, with Google or with Apple, or from your account). You can unsubscribe at any time from the link in any of those emails or from your account, and we record the date you unsubscribed. Your choice is included in your data download and deleted with your account. We do not sell your data.
We do not sell your data or build a profile of what you see in the catalog to advertise other things to you. The Meta pixel is only used to determine whether an ad brought a paid subscription.
Legal basis (GDPR, Art. 6). To provide the service and manage payments we rely on performance of the contract; to protect the platform and keep your sessions secure, on our legitimate interest. Optional measurement by Google Analytics, Google Ads, Meta and TikTok relies on your acceptance, which you can withdraw. Basic PostHog measurement runs in memory, without cookies, storage or person profiles, and stops if you choose “No, thanks”. Necessary tax records are kept to meet legal obligations.
4. Who the data is shared with
We share the necessary data with the providers of the features you use. Their role and terms depend on the service; a model developer and the intermediary receiving the request may be different companies:
- Stripe — processes payments for the website. Your card data goes directly to Stripe and never touches our servers: we neither see nor store it.
- Google — Google Analytics (measurement within Cocuyo) and Google Ads (conversions on the premiere and payment confirmation pages); details are in the cookie policy. Google Play also processes and verifies purchases made using its system within the Android app.
- PostHog — analytics for visits and verified purchases, without cookies or storage on your device and without person profiles; you can disable it by choosing “No, thanks”. It receives temporary page identifiers and a hashed payment identifier, not emails, forms, prompts or private files. No session recordings or measurement inside the apps. Project hosted in the United States; details in the cookie policy.
- Apple — processes and verifies purchases made using its system within the iOS app.
- Bunny.net — delivers the video you play (content delivery network).
- Hostinger — hosts our website and servers.
- Meta — only with your acceptance, the pixel and, if configured, the Conversions API, to measure ad campaigns. It receives visits from public pages and the Purchase event when Stripe confirms a charge (amount, currency and payment session identifier; the email, if sent, is hashed). It is not on Sign In or Create.
- TikTok — only with your acceptance, the pixel to measure ad campaigns, with the same scope as Meta: visits to public pages and the purchase event when Stripe confirms a charge. With automatic advanced matching and expanded data sharing disabled, so it does not receive emails or your detailed activity. It is not on Sign In or Create.
- Directly connected AI services — depending on the enabled model or feature, requests are sent to OpenAI (images and moderation), Google through Vertex AI (images and video), ElevenLabs (speech and audio tools), Alibaba Cloud / Model Studio (video and Qwen speech), xAI (Grok), Black Forest Labs (FLUX), PixVerse, MiniMax (video and speech), Kling or sync (video and lip sync). Each route receives the prompt, options and references needed for that task; it does not receive all your projects or drafts.
- AI intermediaries — Atlas Cloud receives requests for Seedream, Seedance and other enabled features in its catalog, and may forward them to the model provider, such as ByteDance. Runware is kept for enabled routes that use it and for checking previous tasks. Kie receives text queries from features that use it, including the Claude, Gemini, Grok and GPT families. A model name does not mean that Cocuyo has a direct connection or contract with its developer.
- Quotes and assistance — data may be sent to the provider when calculating the cost, before pressing Generate, or when requesting text assistance. For example, Atlas receives the request’s prompt, options and references to quote it. For generation or editing, the data needed to produce the result is sent. Retention, access by other providers and data use depend on the terms of the route used; we do not offer a common no-training guarantee for all intermediaries.
- Content filter — OpenAI’s automated moderation checks the text and, on routes requiring it, the references before generation. A blocked request does not start generation. A prior quote may already have sent the necessary data to its provider. Providers may also keep technical records or review requests to prevent abuse under their terms.
We never sell your data. To anyone, under any circumstances.
International transfer. Cocuyo operates from the United States. Providers may process data in other countries: the PostHog project and the Atlas services described are hosted in the United States, and this integration’s direct Alibaba routes use Singapore. Other destinations and downstream providers depend on the model and service. You can write to hola@cocuyo.ai to request information about processing, recipients and the safeguards applicable to your request.
5. Cookies
We use essential first-party cookies: one for your session, another to securely recognize the device when applying the screen limit, and a technical signal when the website is functioning as an installed app. We also use local storage for interface preferences, technical PWA data, and the organization of Create projects or drafts on that device. Meta and TikTok ad measurement cookies are explained in the next paragraph.
Only with your acceptance, since August 28, 2026 we also use Google Analytics 4 to understand which pages and which “worlds” are shown, and thus decide what to produce. Google acts as the data processor and sets two of its own cookies (_ga and
_ga_<id>). We have it configured in
only analytics: ad signals, remarketing, and ad personalization are disabled.
Only with your acceptance, since August 29, 2026 we use the Meta pixel
(identifier 1577380453882195) on cocuyo.ai’s public pages—not on Enter or Create—to measure ads. The event Purchase is triggered only when Stripe confirms a charge. Meta places the cookies _fbp and, if you came from an ad, _fbc: You have the details, and how to disable it, in our cookie policy.
6. Your rights
Your data belongs to you. You can exercise these rights at any time:
- Access: know what data we have about you.
- Rectification: correct it if it’s inaccurate.
- Portability: download a copy of your data in a readable format, including the information available about your generations.
- Erasure: delete your account and the associated private creation data and media. Drafts that exist only on your device are deleted from your browser or app settings.
- Objection: object to a specific use of your data.
The fastest way to exercise these rights is from your own Profile, where you can download your data and delete the account yourself. You can also write to us at hola@cocuyo.ai and we’ll handle it.
These rights apply to you wherever you live: we apply the GDPR if you’re in the European Union, the CCPA if you’re in California, and equivalent data protection laws in Latin American countries. In practice, we give everyone the same level of control.
7. How long we keep your data
We keep data while your account exists or while it’s necessary to provide the service. If you cancel your subscription, we will aim to keep your creations for about 30 days so you can download them (indicative period and no guarantee, as the Terms state). When you delete your account, we remove from active systems the associated data and private creation media, except what we must keep by legal obligation or to resolve security incidents. AI providers may keep limited technical logs according to their own terms and our agreements with them.
Projects or drafts stored only on your device remain there until you delete them or delete the site’s or app’s local data.
The only exception is billing data that tax law requires us to keep for the statutory periods (for example, records of your payments). After that period, it disappears too.
8. Security
We protect your data with serious technical measures:
- All communication with Cocuyo is sent encrypted (HTTPS).
- Email access codes and links expire after a short time. If you set a password, it is protected using a secure hash; it is never stored in plain text.
- We apply the principle of data minimization: only the people who need it to operate the service can access the data, and only the absolutely necessary data.
- AI provider keys are kept on our servers; results are served from a private Cocuyo area and require an authorized session.
9. Minors
Create (Estudio) is only for people over 18, because generating with artificial intelligence isn’t the same as watching a movie. For the rest of Cocuyo:
The minimum age to use Cocuyo is 18 years old (adult classification, 18+); you confirm it when creating your account or when subscribing to a plan. We do not offer child accounts or knowingly collect data from children. If you think someone under 18 has created an account, write to us at hola@cocuyo.ai and we will delete it.
10. Changes to this policy
If we ever change this policy, we will post the new version here with its update date. If the change is significant (for example, if it affects what data we collect), we will also notify you by email before it takes effect.
The light your stories bring doesn’t need to know more about you than what’s necessary for Cocuyo to work.
11. YouTube API services
Cocuyo uses the YouTube API Services (YouTube API Services) to manage our own YouTube channel (COCUYO): upload and update subtitles in multiple languages, and the translated titles and descriptions of our videos. By using Cocuyo, you also accept the YouTube Terms of Service, and the processing that Google carries out is governed by the Google Privacy Policy.
- Which data is processed. Only those of our channel (videos, subtitles, titles, and descriptions). This integration does not access, collect, store, or share data from other YouTube users, or from their accounts, channels, or comments.
- Who uses it. Only the channel owner, with their own Google account, through an internal tool. No Cocuyo user signs in with Google or grants permissions over their YouTube account through Cocuyo.
- Retention. We do not store data obtained from the YouTube API beyond the subtitle files we create and upload ourselves.
- Revocation. The account holder may withdraw access at any time from the Google account permissions page.
- Contact. For any questions about this use: hola@cocuyo.ai.
YouTube API Services (English summary). Cocuyo uses YouTube API Services solely to manage its own YouTube channel (uploading subtitle tracks and localized titles and descriptions). By using Cocuyo, you also agree to the YouTube Terms of Service; Google’s handling of data is described in the Google Privacy Policy. This integration does not access, collect, store, or share any data belonging to other YouTube users. No Cocuyo user signs in with Google or grants access to their YouTube account through Cocuyo. Access can be revoked at any time from the Google security settings page. Contact: hola@cocuyo.ai.
Last content review: October 6, 2026.