Privacy Policy
Plain-language information about what we collect, why, and how you stay in control.
Chadi Hub is an online service operated personally by Chadi El-sayed and based in Switzerland. The service was formerly known as Chadi El-sayed World. Chadi El-sayed is the controller responsible for the personal data described here; the service is not presented as an incorporated company. Privacy requests can be sent to [email protected] . This Policy applies to the website, accounts, Playverse, videos, cinema, demo reservations, connected community services, the Chadi Hub iOS application, and the Bananaverse virtual-reality application distributed through the Meta Quest Store.
1. Our Privacy Commitments
We do not sell personal data, rent user lists, or use personal data for cross-context behavioural advertising. We collect only data reasonably needed to operate, secure, and improve the service. We do not ask for passwords, payment card numbers, or identity documents by email or private message.
2. Data We Collect
Account data. Email address, username, password hash, profile image, permanent account country, preferred interface language, private spoken-language selections, account roles, verification state, account creation and update times, and security or ban status. Spoken-language selections may be used to support language-aware planning and participation for LAN parties and other events, but are not displayed on public profiles. During registration, we use a country code supplied by our trusted network infrastructure to determine whether account creation is available and assign the private country of the account. We do not continuously track country changes after registration.
Optional public profile data. Pronouns, gender identity, sexual orientation, profile image, badges, and other details you deliberately choose to publish. Sexual orientation and some identity information may be sensitive personal data. Providing it is optional, requires an explicit choice, and it can be removed at any time.
Technical and security data. IP address, browser or user-agent information, session and authentication identifiers, login attempts, page requests, security events, and operational logs. Authentication tokens are stored in hashed form where designed to be verified without retaining the original token.
Chadi Hub iOS app data. Selected interface language, requested video or subtitle identifiers, and ordinary network-request information. If you optionally link an account, the app receives the account ID, username, email address, profile-image URL, and preferred language. The account-link process also uses a short-lived user code, a random device token, status and expiry times, and a one-way hash of the requesting IP address for abuse prevention.
Community activity. Video likes or dislikes, comments, Playverse applications and membership decisions, moderation history, reports, and communications with support.
Connected game data. Minecraft Java username and UUID when you request to link an account. The submitted username is checked through the official Mojang/Microsoft profile service. Bananaverse can process the linked Chadi Hub account ID and username, an opaque PlayFab custom identifier, game profile and progression, multiplayer session information, game settings, moderation or report information, and security events.
Bookings and purchases. Cinema selection, showtime, seats, ticket number, Stripe Checkout session reference, and transaction status. Vision Pro demo reservations may contain visitor name, email address, phone number, selected time, location, attendance, and cancellation status.
Identity verification. The limited local and Stripe-hosted information described in Section 9.
3. How We Receive Data
Data comes directly from you, automatically from your browser and security interactions, from staff actions, and from service providers when needed to complete a payment, verification, email, game-account check, or abuse-prevention process. We do not buy personal profiles from data brokers.
4. Bananaverse Meta Quest App
When you install or use Bananaverse on a Meta Quest device, the app may receive or process: your linked Chadi Hub account ID and username; an opaque identifier used to connect that account to PlayFab; game profile, progression, settings, session and multiplayer state; interactions with other players; moderation reports or enforcement records; IP address; app version; general device, operating-system and network information; and crash, performance or diagnostic information when generated by the app, Meta platform, PlayFab, or hosting services. Meta may also process store, entitlement, Meta account, device, and platform information under Meta's Privacy Policy.
Headset, controller, hand, and movement inputs can be processed in real time to provide virtual- reality controls, locomotion, avatar movement, and multiplayer synchronisation. These gameplay inputs are not used by Chadi Hub to create an advertising profile or intentionally retained as a biometric identity template. If a released Bananaverse feature uses the microphone, voice is processed only after device permission is granted and as needed to provide that feature; the feature will identify any separate recording or moderation retention before it occurs.
We use Bananaverse data to authenticate the player, connect the correct Chadi Hub profile, save and restore progression, operate multiplayer gameplay, provide support, enforce community rules, prevent cheating and abuse, diagnose failures, secure the service, and improve reliability. We do not sell Bananaverse user data or use it for cross-context behavioural advertising. Data is disclosed only as needed to Meta for Quest platform and distribution services, Microsoft PlayFab for game account and backend services, infrastructure providers, and authorised administrators handling support, security, or moderation.
To request deletion of Bananaverse data, email [email protected] from the address associated with your Chadi Hub account and state that you want your Bananaverse data deleted. Include your Chadi Hub username or numeric account ID so we can locate the correct record. We may ask you to sign in or otherwise verify account control. A valid request deletes or anonymises the linked game profile, progression, PlayFab link and other app data under our control, and we will request corresponding deletion from processors where required. Uninstalling the app does not by itself delete server-side data. Limited security, moderation, legal, dispute, backup, or fraud-prevention records may remain only where retention is necessary and lawful. We aim to complete valid deletion requests within 30 days or explain any lawful delay or exception.
5. Chadi Hub iOS App
The Chadi Hub iOS app can be used without creating or linking an account. The app requests the public video catalogue, video details, streams, available quality levels, and subtitle files from the Chadi Hub platform. It also checks a public endpoint for the minimum supported app version and build. These requests disclose ordinary connection information, including the IP address and user-agent or app/network information needed to deliver and secure the request. The selected app language and the public identifier of requested content can be sent so that the correct content and subtitles are returned.
Account linking is optional and starts in Chadi Hub, but authentication and approval take place on chadielsayedworld.com/link. Chadi Hub never receives the account password. The server creates a random device token and a separate six-character user code, stores only one-way hashes of those values, and associates the pending link with the account only after the signed-in user approves it on the website. Once approved, the app receives the account ID, username, email address, profile-image URL, and preferred language so it can show the connected profile and choose an appropriate interface or subtitle language.
On the iPhone, a local account-link marker and linked-profile fields are stored in the iOS Keychain, and the selected interface language is stored in the app's local preferences. Choosing Sign out removes the locally stored link marker and profile fields from Chadi Hub; it does not delete the website account. Uninstalling the app normally removes app-local preferences, subject to Apple's device, backup, and Keychain behaviour. A website-account deletion request can be made as described in Section 13.
Chadi Hub does not request access to the photo library, camera, microphone, contacts, precise location, health data, or advertising identifier. It does not upload a user's photos or videos, and it currently contains no third-party advertising or behavioural-analytics SDK. Streaming publisher videos or downloading the selected profile image is not treated by us as collecting the user's own photos or videos. We do not use Chadi Hub data for tracking across apps or websites.
Apple independently processes App Store, download, update, device, diagnostics, and platform information under App Store & Privacy and Apple's applicable terms. Chadi Hub does not receive a user's Apple Account password. Any aggregated App Store information Apple makes available to developers is governed by Apple's platform rules and is not combined by us with Chadi Hub profiles for advertising.
6. Why We Use Data and Our Legal Grounds
We process data to create and authenticate accounts, deliver requested content and bookings, operate Playverse, process payments, communicate service information, prevent fraud and abuse, enforce community rules, protect users, maintain records, and comply with law.
Account registration, authentication, requested bookings, purchases, and delivery of account features are processed to perform the requested service or contract. Security logs, login controls, moderation, duplicate-account prevention, and service integrity rely on our legitimate interests in protecting users and the platform, balanced against individual rights. Payment, tax, accounting, sanctions, safety, and lawful disclosure records are processed where needed to meet legal obligations or establish, exercise, or defend legal claims.
Optional gender identity and sexual-orientation details are processed and displayed only after an explicit choice for that purpose and can be removed from Account Settings. Identity and age verification is initiated only at the user's request for a restricted feature. It relies on the requested verification service, fraud-prevention and safety interests, and, where special-category or biometric consent is legally required, the express permissions presented during the Stripe flow. Consent can be withdrawn for future processing without affecting processing already performed lawfully, although withdrawal may make an optional restricted feature unavailable.
7. Public Information
Username, profile image, public roles, verification badges, published identity preferences, and video comments can be visible to anyone viewing a profile or public page. Do not publish information you want to keep private. Email address, phone number, account country, IP address, authentication data, document details, and exact identity-verification results are not displayed publicly.
8. Cookies and Similar Technologies
Essential cookies maintain sessions, authentication, security, cinema seat locks, and form protection. Disabling them can prevent account and booking features from working. Google reCAPTCHA is used during account creation to detect automated abuse and may receive browser, device, cookie, and interaction data under Google's terms. We do not currently use advertising cookies or behavioural-advertising trackers.
9. Age and Identity Verification with Stripe
Stripe Identity may collect a government-issued identity document, selfie, biometric data used to compare the selfie with the document, and extracted information such as name, date of birth, document type, issuing country, and document number. Stripe Identity does not support users under 16. Identity verification is optional for general website use but required for Playverse and any feature expressly marked as identity- or age-restricted.
We use the result to confirm identity, determine whether a user is 18 or older, prevent one person or identity document from verifying multiple accounts, and display badges. We do not copy the legal name, document, selfie, biometric template, document number, or date of birth into our local database. Locally, we store the account ID, Stripe Verification Session ID, live/test mode, result status, 18+ result, timestamps, and keyed non-reversible fingerprints derived separately from the verified document details and from the verified legal name and date of birth. A document match is blocked automatically; a name-and-birth-date match is held for administrator review because two different people can share those details. These fingerprints are used only for duplicate prevention and cannot be decrypted to reveal the source information.
Stripe-hosted information can be accessed only by specifically authorised administrators when needed for support, security, fraud prevention, review, or a rights request. Stripe states that biometric data is generally retained for up to one year and non-biometric verification data for up to three years, subject to consent, deletion, and legal requirements. See the Stripe Identity FAQ and Stripe Privacy Policy.
10. Service Providers and Disclosures
We disclose only the data necessary for a provider's task. Current categories include hosting and infrastructure providers; Apple for App Store distribution and platform services; Meta for Quest Store, entitlement, device, and platform services; Microsoft PlayFab for Bananaverse account linking, game data, and backend services; Stripe for payments and identity verification; Google reCAPTCHA for bot prevention; Infomaniak infrastructure for transactional email; and Mojang/Microsoft for Minecraft profile validation. Authorised administrators can access data needed for support, safety, bookings, and moderation.
We may also disclose information when required by valid law, to protect a person's safety or legal rights, to investigate fraud or security incidents, or as part of a legitimate organisational transfer with appropriate safeguards. We do not provide personal data to advertisers for sale or targeting.
11. International Processing
Providers may process data in Switzerland, the European Economic Area, the United Kingdom, the United States, and Canada according to the provider and feature. Where required, transfers are protected by an adequacy decision, recognised standard contractual clauses, contractual and technical safeguards, or another lawful transfer mechanism. Provider privacy notices linked or identified in this Policy contain their current processing locations and safeguards. Contact us to request available information about the safeguard used for a particular transfer.
12. Retention
Account and profile data is retained while the account is active and then deleted or anonymised after a valid deletion request, subject to limited legal, payment, dispute, backup, and safety needs. Authentication tokens remain only until expiry or revocation. Chadi Hub account-link codes expire after 30 minutes; expired, approved, or cancelled link records are scheduled for deletion shortly afterwards. Hashed account-link attempt records are used for a rolling 15-minute abuse-prevention window and stale records are deleted during subsequent link-request cleanup. Other temporary codes and rate-limit data expire after their configured security window and are removed during routine cleanup. Legal acceptance records contain the account identifier, acceptance time, IP address, user agent, version identifiers, and SHA-256 fingerprints of the accepted documents. Exact archived copies of published legal versions are retained so we can demonstrate which text was accepted. Community content remains until removed, moderated, or the related account or content is deleted.
Chadi Hub's local link marker and profile fields remain on the iPhone until the user signs out or removes them through normal app or device controls. The app's local language preference remains until it is changed or the related app data is cleared. Temporary network caches are controlled by iOS and the app's networking components and are not used to build an advertising profile.
Bananaverse cloud profile and progression data is retained while the linked account or game service remains active and is then deleted or anonymised following a valid deletion request, subject to the limited exceptions described in Section 4. Local settings stored only on the headset remain under the user's device controls and are normally removed when app data is cleared or the app is uninstalled. Processor and backup deletion may complete on their normal secure cycles.
Security logs, IP and user-agent records are retained only for the period reasonably needed to investigate abuse, maintain service integrity, and defend legal claims, with longer retention limited to an active incident or legal requirement. Booking, ticket, and payment records are kept for operational, accounting, tax, chargeback, and legal retention periods. Identity records remain while needed for the verification feature and duplicate-fraud prevention. Retention is reviewed when an account is deleted; data that no longer has a valid purpose is deleted or anonymised.
Retention is determined by the account relationship, token or code expiry, security risk, applicable limitation periods, tax and accounting requirements, unresolved disputes, and backup rotation. Stripe's identity retention periods are described in Section 9. A valid request may result in earlier deletion or Stripe redaction unless continued retention is necessary for security, fraud prevention, legal compliance, or legal claims. Published legal-document archives contain the documents themselves; acceptance records linked to an account are retained only for accountability and legal evidence.
13. Your Privacy Rights
Depending on applicable law, you may request access, a portable copy, correction, deletion, restriction, or objection; withdraw consent; and appeal a refused privacy request. You may also complain to the Swiss Federal Data Protection and Information Commissioner or the competent authority where you live. California and other eligible US residents may exercise applicable rights to know, access, correct, or delete data without discriminatory treatment. Because we do not sell or share personal data for targeted advertising, there is no sale or advertising share to opt out of.
EEA and United Kingdom users may complain to the supervisory authority where they live, work, or believe an infringement occurred. Canadian users may contact the Office of the Privacy Commissioner of Canada or the applicable provincial authority. Eligible United States residents may exercise rights provided by their state law, including applicable rights to know, correct, delete, obtain a copy, or appeal. These regional rights apply only where the relevant law covers the processing.
All formal account and privacy requests must be sent to [email protected]. This includes requests to access or receive a copy of your data; correct, update, or remove account or profile information; recover or change account access; review access to a feature or service; and close or delete an account. Where a secure self-service control is available in Account Settings, support may direct you to use it.
Social networks, private messages, informal chats, and in-person conversations are not secure formal channels for authorising access to, disclosure of, correction of, or deletion of account data. If a request is mentioned through one of those channels, we will direct the requester to the official support email. We will not make the requested account or data change until the request is received through the support process and account control is reasonably verified. Urgent safety reports and communications that applicable law requires us to recognise may still be recorded and handled appropriately, but identity verification remains necessary before personal data is disclosed or an irreversible account action is completed.
We may request proportionate information to verify that you control the account before acting or disclosing data. We aim to respond within 30 days. If applicable law provides a different deadline, extension, or appeal process, that rule will be followed and any permitted extension will be explained. Requests involving roles, permissions, moderation decisions, age requirements, or access to restricted services are reviewed under the Terms of Use, eligibility rules, and security requirements; submitting a request does not guarantee that special access will be granted.
To provide accountability and avoid misunderstandings, we keep a limited support record that may include the request date, account reference, request category, verification steps, actions or decision, staff handling the request, and completion time. We do not need or want identity documents sent through social networks. Support records are accessible only to authorised staff and retained only as long as reasonably needed for the request, security, dispute handling, legal compliance, or the establishment, exercise, or defence of legal claims.
14. Regional Privacy Information
Switzerland. The Swiss Federal Act on Data Protection applies to processing covered by Swiss law. You may ask whether we process personal data about you, receive the legally required information and a copy, correct inaccurate data, request deletion or destruction, object to or restrict unlawful processing, and request release or transfer of data where the statutory conditions are met. You may contact the Federal Data Protection and Information Commissioner (FDPIC). We identify the purposes, recipients, destination regions, safeguards, and retention criteria in this Policy. High-risk data-security breaches are reported to the FDPIC, and affected persons are informed, when Swiss law requires it.
European Economic Area and United Kingdom. Where the GDPR or UK GDPR applies, processing is based, as appropriate, on performance of a requested service or contract, compliance with law, our proportionate legitimate interests in security and service operation, protection of vital interests, or consent for a genuinely optional purpose. You may request access, correction, erasure, restriction, portability, or objection, and may withdraw consent prospectively. You may complain to the supervisory authority where you live or work or where you believe an infringement occurred. International transfers use an adequacy decision or another lawful safeguard described in Section 11. No solely automated decision described in this Policy produces legal or similarly significant effects without the protections required by applicable law.
United States. State consumer-privacy laws apply only when their territorial, business-size, revenue, volume, and other legal thresholds are met. For any covered request, the categories collected during the preceding period, their sources, purposes, and recipient categories are described in Sections 2, 3, 5, and 10. Depending on the applicable state law, eligible residents may have rights to know or access, correct, delete, obtain a portable copy, opt out of sale, sharing, targeted advertising or certain profiling, limit certain uses of sensitive information, use an authorised agent, and appeal a refusal. We will not discriminate against a person for exercising an applicable privacy right. Chadi Hub does not sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising, or use sensitive personal data to infer characteristics. Because those activities do not occur, there is currently no sale, advertising-share, or targeted-advertising choice to opt out of; legally applicable browser-based universal opt-out signals, including Global Privacy Control, will nevertheless be respected for any processing to which they apply.
These regional descriptions do not expand a statute beyond its lawful scope or remove rights available under another applicable law. California and other eligible US residents can submit the requests described above through the support address in Section 13. We use the same verification information only as reasonably necessary to verify and fulfil the request. Canadian residents may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial authority.
15. Children and Teenagers
Chadi Hub services, including the Chadi Hub iOS app and Bananaverse, are not directed to children under 13. Accounts are intended only for users aged 13 or older. Users under 13 must not create or use an account, even with parent or guardian permission. If we learn that an account belongs to someone under 13, we may restrict and ban it and take reasonable steps to delete the associated personal data, except for limited records that must or may lawfully be retained for security, legal, dispute, or age-restriction enforcement purposes.
Where local law requires a higher minimum age or additional permission for a user aged 13 to 17, including when consent is relied on for an optional feature, that higher requirement also applies. In the EEA, the age at which a child can consent to covered online processing varies by Member State from 13 to 16. We do not knowingly collect personal data online from a child under 13 in a manner covered by the US Children's Online Privacy Protection Act without the required parental notice and verifiable consent. If you believe we hold personal data from a user under 13, contact us at [email protected] so we can investigate and take appropriate action.
16. Security and Incident Response
Measures include password hashing, scoped and expiring authentication tokens, secure cookies, request-forgery protection, rate limiting, access controls, audit logging, restricted identity credentials, and data minimisation. No system is perfectly secure. We investigate suspected incidents and notify authorities or affected users when applicable law requires it.
17. Automated Processing
Security tools and Stripe can produce automated risk or verification results. These results can limit access to a protected feature, but Playverse membership is reviewed rather than sold or guaranteed. A document fingerprint match can automatically prevent reuse of the same verified document, while a protected name-and-date-of-birth match is referred for human review. Contact support to express your point of view and request human review when an important result is incorrect.
18. Updates and Contact
We may update this Policy when services, providers, or laws change. Material changes will be highlighted with a new effective date and communicated reasonably when required. We may pause authenticated account access until the complete current legal documents have been reviewed and the required choices have been explicitly confirmed. The service is operated from Switzerland and this Policy also describes additional EEA, United Kingdom, United States, and Canadian rights where those laws apply. Questions, complaints, and rights requests can be sent to [email protected] .
Effective and last updated: 22 September 2026