Privacy Policy
CatchyBox exists to keep what you choose to catch, not to watch you. Here's what data we handle, why, who else processes it, and how long we keep it, with no fine print. The Spanish version of this policy is also our privacy notice (aviso de privacidad) for Mexico.
The short version
- Your screenshots don't train AI: neither we nor our providers use them to train models.
- We don't sell your data or use it for advertising.
- Nobody sees your catches except the people in a box where you share them.
- You can export everything anytime, on any plan.
- If you delete your account, it's deleted right away, for real; backups clear themselves within 30 days at most.
1. Who we are
CatchyBox (catchybox.com, app.catchybox.com, and the CatchyBox bot on Telegram) is a service of Yamil Morales, LLC, a limited liability company organized in the State of Delaware, United States. We are the controller of your personal data. For anything privacy related, email us at soporte@catchybox.com.
Address: c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States
2. What data we handle
Only what CatchyBox needs to work. We don't ask for your location, your contacts, or access to your whole camera roll: we only receive what you choose to upload or send.
- Your account. Your email, your password (handled by Amazon Cognito; we never see it), your language, the age range you declare (we don't ask for your date of birth), and the date you agreed to the use of AI.
- What you catch. The screenshots, images, videos, links, and text you upload or send, and the notes you write.
- What CatchyBox understands from it. The text read from your images, the transcript of your videos' audio, and what is derived from each catch: title, type, category, details, and research sources.
- Your boxes. The boxes you create or join, who is in each one, invitations, and what each person adds.
- Payments. Your plan, its status, and your Stripe customer and subscription IDs. Stripe receives your card details; we never see them.
- Telegram, only if you link the bot. Your Telegram user and chat IDs and what you send to the bot.
- Usage and security. How many catches you process each period (to meter your plan); the IP address and technical data your browser sends when it connects; error and performance logs that don't include the content of your catches; and a security log of important account actions, such as exports and deletions.
- Reports. If you report a catch in a shared box, or someone reports one of yours: the report, its reason, and the outcome.
3. Why we use it
| Purpose | Legal basis |
|---|---|
| Provide the service: save, organize, search, and share your catches, and maintain your account. | Contract (the terms you accept). |
| Understand your catches with AI: read text, transcribe audio, classify, and research. | Your consent, which you can withdraw anytime. |
| Check images before AI to detect sexually explicit content or graphic violence, and handle reports. | Legitimate interest in keeping the service safe, and legal obligations. |
| Bill your plan and meter how many catches you use. | Contract and tax obligations. |
| Protect your account and the service: security, limits, and abuse prevention. | Legitimate interest. |
| Send you service emails: verification, security, and important changes. | Contract. |
All of these purposes are necessary to provide the service. We don't use your data for secondary purposes like advertising, marketing, or commercial profiling, and we don't send you marketing without your permission.
4. AI and your catches
CatchyBox understands your catches with Claude, by Anthropic, and Amazon Nova, through Amazon Bedrock, an AWS service. The models run inside AWS infrastructure: Anthropic doesn't receive your data. Amazon Bedrock doesn't use your content to train models or share it with the companies that make them. We also have AWS's opt-out turned on, so Amazon Rekognition (moderation) and Amazon Transcribe (transcription) don't use your content to improve their models either.
- Before anything is processed with AI, we ask for your consent. You can withdraw it in Settings: CatchyBox keeps working in manual mode, where you save and organize things yourself, and nothing new is processed with AI.
- If a new feature uses AI in a different way, we'll ask for your consent for that feature.
- To research a catch we use its name and details, never your email or account data.
- Before AI, Amazon Rekognition checks every image. If it detects nudity, sexual activity, or graphic violence, we don't process it with AI and we delete it.
- AI output can be wrong, and you can always edit it. We don't use AI to make decisions that have legal effects on you.
5. Who else processes it
We use few providers, all under contract and only to provide the service:
- Amazon Web Services (AWS), our infrastructure. Amazon S3 stores your files (screenshots, videos, and exports), encrypted; Amazon RDS for PostgreSQL stores your catches, boxes, and account; Amazon Cognito handles your account, password, and session, and sends verification emails; Amazon Bedrock runs the AI models (Claude by Anthropic and Amazon Nova); Amazon Rekognition checks images for moderation; Amazon Transcribe turns your videos' audio into text; and AWS Lambda, Amazon SQS, and Amazon API Gateway run and coordinate processing.
- Stripe, which processes payments. It receives your card and billing details and handles them under its own privacy policy.
- Telegram, only if you link the bot. What you send travels through Telegram's servers and is also governed by its privacy policy.
- Public sources for research: AniList, Jikan (MyAnimeList), TVMaze, Wikipedia, Wikidata, GitHub, Open Library, OpenStreetMap (Nominatim), iTunes Search, and Amazon Nova's web search. We send them the catch's name and details, never your account data, and every fact they return is shown with its source.
- Authorities, only when the law requires it; for example, to report child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC).
That's everyone: no ad networks, no data brokers, no third-party analytics tools.
6. Where it's stored
We store your data on AWS in the us-east-1 region (Northern Virginia, United States). For AI we use Amazon Bedrock inference profiles limited to the United States, so processing may happen in other AWS regions within the country.
If you use CatchyBox from Mexico, the European Union, or another country, your data is transferred to the United States. We do this under our providers' contractual safeguards, such as the standard contractual clauses included in the AWS and Stripe data processing agreements.
7. How long we keep it
| What | How long |
|---|---|
| Your catches, files, and boxes | As long as you have your account, until you delete them. |
| A catch you delete | 30 days in the trash, in case you change your mind. Then it's deleted for good. |
| Your exports | The file is deleted after 7 days. |
| Transcripts of your videos' audio | 30 days. What CatchyBox understood from the video stays in your catch. |
| Images moderation flags as sexually explicit or graphically violent | Not processed, and deleted when detected. |
| The security log | 1 year. It doesn't include the content of your catches. |
| Database backups | 14 days, encrypted. Then they're deleted automatically. |
| Previous versions of your files | 30 days after they're replaced or deleted. Then they're deleted automatically. |
| Your account, when you delete it | Deleted right away, with all its content and the trash. |
When you delete your account, we also cancel your subscription and delete your customer record at Stripe. This is all we keep:
- Usage and billing records from the last 12 months, with your identifier removed: they can no longer be linked to you. We need them for tax and financial obligations. Stripe also keeps the payment records the law requires of it.
- The security log, with no content, until it reaches one year.
- Evidence of child sexual abuse material, which we preserve and report to the authorities as the law requires.
Database backups (14 days) and previous versions of your files (30 days) are deleted automatically over time. We never use them to restore a deleted account.
8. Your rights
Whatever your plan or wherever you live, you can:
- Access your data and take it with you. In Settings you can export everything: we prepare a ZIP with your original files and all your data in JSON format (in parts of up to 2 GB if it's very large).
- Correct it. Edit any catch, and your change overrides what the AI did.
- Delete it. A catch, a box, or your whole account, from Settings.
- Withdraw your AI consent in Settings, without losing your catches.
- Object to processing or ask us to restrict it, by emailing us.
In Mexico, these are your ARCO rights (access, rectification, cancellation, and opposition), plus revoking your consent and limiting the use of your data. In the European Union and the United Kingdom you also have your GDPR rights, including data portability and the right to lodge a complaint with your data protection authority.
For anything not in Settings, email us from your account's address at soporte@catchybox.com. We reply within 20 business days at most, and exercising your rights is free.
9. Do Not Sell or Share My Personal Information
We don't sell your personal data, rent it, or share it for targeted advertising. We never have, so there's nothing to opt out of. If that ever changed, we'd tell you first and ask for your permission.
10. California residents
The California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you the right to know what personal information we process, to ask us to delete or correct it, to opt out of its sale or sharing (we don't do either), and not to be discriminated against for exercising these rights. In the last 12 months we processed these categories, only for the purposes in this policy:
- Identifiers: your email, your account ID, and your IP address.
- Commercial information: your plan and payments.
- Audio, electronic, or visual information: the screenshots, videos, and text you upload.
- Internet or other electronic network activity: your use of the service and technical logs.
- Sensitive personal information: your account login credentials, used only to let you sign in. We don't use it to infer anything about you.
We didn't sell or share any of them. You can exercise your rights in Settings or by emailing us; an agent you authorize can also do it, with proof of that authorization.
11. Children
CatchyBox is for people 13 and older. We don't allow accounts for children under 13 or knowingly collect their data; if we find one, we delete it. When you create your account we ask for your age range, not your date of birth.
Shared boxes, where you see other people's content, are only for people 18 and over. If you're a minor where you live, use CatchyBox with permission from a parent or guardian. If you think a child under 13 has given us their data, email us at soporte@catchybox.com and we'll take care of it.
12. Cookies and local storage
This site (catchybox.com) doesn't use cookies or trackers. The app (app.catchybox.com) only stores what it needs in your browser to keep you signed in and remember your preferences. We don't use advertising, analytics, or third-party tracking cookies. When you pay, Stripe's checkout page uses its own cookies to prevent fraud.
13. Security
Everything travels encrypted (HTTPS). Your files are stored encrypted and are only shown through signed, temporary links. The database separates each person's data with row-level security, and technical logs don't include the content of your catches. No system is perfect: if an incident affects your data, we'll notify you promptly and as the law requires.
14. Changes to this policy
If we change something important, we'll let you know by email or in the app before it takes effect, and we'll update the effective date above. If the change means using AI in a different way, we'll ask for your consent again.
15. Contact
Yamil Morales, LLC. Address: c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Email: soporte@catchybox.com. If you're not satisfied with our answer, you can contact the data protection authority in your country.
See also our Terms of Service.