LEGAL

Privacy Policy

Last updated: 2026-07-03

Draft pending review by a licensed attorney. This is not legal advice; the final version will be reviewed by counsel before Sysstem launches.

The party responsible for processing your personal data is Diego Uribe Villalobos (an individual), creator and operator of Sysstem. This notice follows Mexico's LFPDPPP Art. 16 (integral notice), with GDPR art. 13/14 transparency language incorporated so it also serves users in the European Union.

1. Identity and address of the controller

The party responsible for processing your personal data is Diego Uribe Villalobos (an individual), creator and operator of Sysstem, with an address for receiving notices at [address to be confirmed], Mexico.

For anything related to your personal data and the exercise of your rights, contact us at support@sysstem.ai.

2. Personal data we collect

Sysstem is a gamified personal-development platform. To operate, we process the following categories of personal data.

Identification and account data: email address and password (stored encrypted, never in plaintext); Google and Apple sign-in identifiers (including Apple “Hide My Email”); and date of birth, requested at sign-up and used only to confirm you meet the minimum age of 18 (age assurance), never for marketing or profiling (see §10).

Profile data: bio, mantra, hobbies, bucket list; profile photo, banner, and up to 6 profile photos; public handle (@username) and visibility settings.

Sensitive data (LFPDPPP Art. 9). The following categories are sensitive personal data; their processing requires your express consent, which we request separately: health and emotional-wellbeing data (mood entries, introspective logs, and conversations with Syss, which may reveal your mental and emotional state); physical-health data from wearables (heart rate, sleep, heart-rate variability (HRV), steps, workouts), obtained via Apple Health (HealthKit) and Android Health Connect, only with your explicit, revocable consent; financial data (debts: balance, interest and credit limit; gross and net income, tax rate, payday, and derived metrics such as debt-to-income ratio and credit utilization); voice data (audio you record for transcription, see §5); and location data (approximate or precise position for the map features / Map Missions), optional and off by default.

Usage and activity data within Sysstem: goals, milestones, missions, achievements, and attributes (derived from your activity); content you create and share (Paths, goals, rituals, missions, ratings, and public comments in the creator economy); and your social graph (friends, groups/guilds, mission invitations).

Technical data: IP address, device identifier, timestamps, usage events, session counts, crash logs, and push notification tokens.

3. Purposes of processing

Primary purposes (necessary to provide the service): create and manage your account and profile; personalize your experience by generating missions, analyzing your logs, tracking your progress, and accompanying you through Syss (our AI assistant, see §4); operate the social features and creator economy you enable; send you transactional communications (email verification, password reset, service notices); verify that you meet the minimum age of 18 (age assurance) and keep minors out of the service; and ensure security, prevent fraud and abuse, and comply with legal obligations.

Secondary purposes (optional): the following are not necessary for the service; we process them only with your consent, and you may object at any time (see §7): marketing communications and product updates, and aggregated, anonymized statistical analysis to improve Sysstem.

If you do not want us to process your data for the secondary purposes, you can tell us in the app or by writing to support@sysstem.ai. Your refusal will not be grounds to deny you the service.

4. AI processing and international transfers

For features such as Syss chat, mission generation, and log analysis, we send relevant, minimized portions of your content to AI providers strictly to generate your response. Where your content is processed, and under what safeguards, depends on your region.

Routing by region. European Union / EEA: DeepSeek V4 via Microsoft Azure AI Foundry (EU data zone), processed within the European Union. United States: DeepSeek V4 via Microsoft Azure AI Foundry, processed in the United States. Mexico and the rest of the world: DeepSeek (direct API), processed in China.

Users in the European Union and the United States (processing via Microsoft Azure). For this route we have contractual safeguards: a data-processing agreement (DPA) with Microsoft that prohibits using your content to train models and sets a limited retention window; for EU users, processing takes place within the European data zone, so there is no international transfer outside the EU. Other AI providers we may use on this route (Anthropic, OpenAI) also operate under data-processing agreements with a no-training commitment and, where applicable, Standard Contractual Clauses.

Users in Mexico and the rest of the world (DeepSeek, direct API, China) — important notice. On this route, your content — including sensitive data (mood, health, finances, and conversations with Syss) — is transferred to DeepSeek in China. Unlike the route above, for this route we do not have a data-processing agreement (DPA) or Standard Contractual Clauses with DeepSeek, and China does not have a data-protection adequacy finding. This means DeepSeek may process the content we send it under its own terms, which may include retaining it (currently around 30 days) and using it to train and improve its models. We request your express consent for this international transfer to China and for this processing; without it, we do not send your content on this route. We are seeking a written no-training commitment from DeepSeek for this route, but we cannot guarantee it today.

Your control. You can use Sysstem's core features without AI personalization if you prefer not to give this consent. We never sell your personal data and never share it for advertising. Your health data is used only within the app to support you, never for marketing and never sold.

How Syss works, in plain language. Syss is an assistant based on AI models. So it can understand and help you, we send the provider your messages and the necessary context (first name, amounts, emotional context), minimizing what is not needed. Depending on your region, that provider will process your content under the safeguards described above (with no training on the EU/US route, or under its own terms on the China route). Syss's responses and missions are AI-generated and may be inaccurate or incomplete; Syss does not provide professional medical, psychological, legal, or financial advice: use your own judgment and consult a professional when you need to.

5. Voice data

When you use voice input, your audio is sent to Speechmatics (United Kingdom) solely to transcribe it to text. The audio is discarded after transcription; we keep only the text as part of your log. This processing requires your explicit, versioned consent, revocable at any time in the app.

6. How we protect your data

Per-user encryption: your sensitive data (bio, Syss chats, logs, finances, moods) is encrypted with a unique per-user key (XChaCha20-Poly1305) before storage. That key is protected by a master key managed in AWS and never stored in plaintext.

Encryption in transit: all traffic uses TLS 1.3.

Crypto-shredding: when you delete your account, we destroy your unique key, which makes your sensitive data mathematically unrecoverable, even in backups.

Access logging for sensitive data, authentication rate-limiting, and periodic secret rotation.

7. Your rights (ARCO and additional rights)

You have the right to Access, Rectify, Cancel (delete), and Object to the processing of your personal data (ARCO rights), as well as to withdraw your consent, restrict the use or disclosure of your data, and request the portability of your information.

Access and rectification: in the app, in your profile; or by requesting it at support@sysstem.ai. Cancellation (deletion): in Settings → Account → Delete Account, with immediate crypto-shredding and a deferred purge within 30 days (see §8); also by email. Objection and withdrawal: for secondary purposes and for consent-based processing (health, voice, wearables, location, AI).

How to exercise them: send your request to support@sysstem.ai, stating your name, the right you wish to exercise, and the information needed to verify your identity. We will respond within a maximum of 20 business days (LFPDPPP Art. 32).

If you believe your data-protection rights have been violated, you may contact Mexico's National Institute for Transparency, Access to Information and Personal Data Protection (INAI): https://www.inai.org.mx. EU users may lodge a complaint with their local supervisory authority.

8. Account deletion and propagation

When you delete your account: we perform the crypto-shredding described in §6; we instruct our AI providers to cease any retention of your content under their processing agreements; we delete the memory Syss has built about you; and we complete the purge within 30 days.

What we may retain: information strictly necessary to comply with legal or tax obligations, and anonymized data that no longer identifies you.

Exceptions to deletion under a legal obligation. In two specific cases, certain data is not erased by your request while a legal obligation is in force, on the basis of GDPR art. 17(3) and the legal-obligation exception under LFPDPPP: (a) if content you upload appears to involve the sexual exploitation of a minor, we are legally required to preserve it and the related account data and to report it to the competent authorities; this data is retained for at least one year, or longer if an authority requests, and is not erased while that obligation is in force; (b) if you verified your identity or age, the reference to your verification session at our specialized provider may be retained for a limited period, for safety and to comply with legal obligations, even after you delete your account.

You can also request deletion without installing the app, from our public data-deletion page.

9. Retention period

We retain your data while your account is active and for the period needed to fulfill the purposes described. After deletion, §8 applies. Data we retain due to a legal or tax obligation is kept only for as long as the law requires.

10. Minors

Sysstem is intended exclusively for people aged 18 and over, given that it processes sensitive health and financial data. We do not knowingly collect data from minors. If we detect an account belonging to a person under 18, we will delete it. A version of Sysstem for younger audiences, with its own protection framework, may be offered separately in the future.

We ask for your date of birth at sign-up as a neutral age check and do not create accounts for anyone under 18. Our legal basis for this limited processing is compliance with our legal and app-store obligations and our legitimate interest in keeping minors out of an app that handles sensitive data; we use the date of birth only for age assurance, never for marketing. Once set, your date of birth cannot be changed to make you older without identity verification.

11. Cookies and similar technologies

In the app and website we use essential technical storage (for example, to keep your session and language). See our Cookies Notice for details and to manage your preferences.

12. California privacy rights (CCPA/CPRA)

If you reside in California, you have the right to know what data we collect, to request its deletion or correction, and to opt out of its “sale” or “sharing” for cross-context advertising. Sysstem does not sell or share your personal data for those purposes, nor does it discriminate against you for exercising your rights.

13. Changes to this Policy

We may update this Policy. We will notify you of relevant changes by email and via an in-app notice at least 30 days before they take effect. The “last updated” date will always be visible. A major change may require you to re-accept the Policy at your next sign-in.

14. Contact

For any questions about this Policy or about how we process your data: support@sysstem.ai.

← Back home