Privacy Policy
Last updated: April 20, 2026 · Effective: April 20, 2026This Privacy Policy explains how FlyPic (“FlyPic”, “we”) collects, uses, discloses, and safeguards personal data when you use flypic.ai and related services (the “Service”). It applies to visitors, registered users, and paying customers worldwide, and is designed to meet the transparency requirements of the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and comparable laws.
1. Who we are (Data Controller)
FlyPic acts as the data controller for personal data processed through the Service. You can reach our privacy team at privacy@flypic.ai. EU/UK users may also reach our representative at the same address.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email, name, profile image, authentication provider (e.g., Google), password hash (handled by Clerk) | You / OAuth provider |
| Billing data | Plan, credit balance, partial card metadata, billing email, VAT ID, purchase history | You / Stripe |
| Content & generations | Prompts, uploaded images, characters, reference files, generated Outputs, workflow definitions | You |
| Usage & device | Pages viewed, features used, IP address (truncated where possible), browser, OS, timestamps, referrer | Automatic |
| Communications | Support tickets, emails, chat messages, feedback surveys | You |
| Cookies & similar | Session, preference, analytics, and (with consent) marketing identifiers. See our Cookie Policy. | Automatic |
We do not ask for, and you should not upload, special categories of data (health, biometric, government IDs) unless strictly necessary. Facial features in uploaded images are processed only to deliver the Output you requested and are not used to build a persistent biometric identifier.
3. How we use your data & legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide the Service, run generations, store your library | Performance of contract (Art. 6(1)(b)) |
| Process payments, invoices, tax | Performance of contract & legal obligation (Art. 6(1)(b),(c)) |
| Prevent abuse, fraud, and policy violations (e.g., CSAM scanning, rate limits) | Legitimate interests & legal obligation (Art. 6(1)(f),(c)) |
| Improve and secure the Service, debug issues, aggregate analytics | Legitimate interests (Art. 6(1)(f)) |
| Send service emails (receipts, security alerts) | Performance of contract (Art. 6(1)(b)) |
| Send marketing emails, show marketing cookies | Consent, which you can withdraw at any time (Art. 6(1)(a)) |
| Comply with law, respond to lawful requests, defend legal claims | Legal obligation & legitimate interests (Art. 6(1)(c),(f)) |
4. AI models & training
To produce Outputs, your prompt and any reference media are transmitted to the model provider you select (for example, Google Gemini / Imagen / Veo, fal.ai, Replicate, OpenAI, and similar). These providers act as processors and are contractually bound to use your content only to deliver the Output to us. We do not use your private prompts, uploads, or Outputs to train FlyPic's or any third party's public generative models without your explicit, revocable opt-in consent. Content you choose to publish to the Community feed is handled according to its publication settings.
5. Automated decision-making
We use automated systems (including AI classifiers) to detect policy-violating content such as CSAM, non-consensual sexual imagery, and fraud. A human reviewer evaluates flagged content before account action is taken, except in clear-cut cases involving illegal content, where we may act immediately to comply with law. You have the right to contest automated decisions at privacy@flypic.ai.
6. Sharing & disclosures
We share personal data only with:
- Service providers / processors acting on our instructions — examples below.
- Other users when you publish to the Community feed or share a generation link.
- Corporate transactions — in the event of a merger, acquisition, or asset sale, subject to confidentiality and your continued rights.
- Law enforcement or regulators when required by a valid legal process or to protect rights, safety, or property.
We do not sell personal data and we do not “share” it for cross-context behavioral advertising as defined by the CPRA.
Key sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Application hosting, edge delivery | US / EU |
| Clerk | Authentication & user management | US |
| Stripe | Payment processing | US / EU |
| Supabase / Postgres provider | Database & storage | US / EU |
| Cloudflare R2 / S3-compatible storage | Media storage & CDN | Global |
| Google (Gemini, Imagen, Veo) | AI image/video generation | US / EU |
| fal.ai, Replicate, OpenAI | AI model inference | US |
| Resend / Postmark | Transactional email | US / EU |
| PostHog / Plausible | Product analytics (aggregated) | EU / US |
7. International transfers
We transfer data to countries outside the EEA/UK (primarily the United States). Transfers are protected by Standard Contractual Clauses, the UK Addendum, or an adequacy decision, plus supplementary technical measures (encryption in transit and at rest, minimization, access controls). A copy of the SCCs can be requested at privacy@flypic.ai.
8. Retention
| Data | Retention period |
|---|---|
| Account profile | Until account deletion + 30 days for backups |
| Generations & uploads in your library | Until you delete them, or 90 days after account deletion |
| Deleted generations | Purged from primary storage within 30 days; 90 days in encrypted backups |
| Moderation evidence (policy violations) | Up to 24 months to detect repeat offenders and cooperate with authorities |
| Billing & invoicing records | 7 years (tax & accounting law) |
| Support tickets | 3 years from last interaction |
| Server logs | 30 days; 90 days for security events |
9. Security
We use TLS 1.2+ in transit, AES-256 at rest, least-privilege access controls, SSO+MFA for employees, isolated per-user storage namespaces, and regular penetration testing. No system is perfectly secure, however. Report vulnerabilities to security@flypic.ai.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a portable copy.
- Correct inaccurate or incomplete data.
- Delete your data (“right to be forgotten”), subject to legal exceptions.
- Restrict or object to certain processing, including profiling.
- Withdraw consent where processing is based on consent.
- Opt out of sale/sharing and of targeted advertising (California, Colorado, Virginia, etc.). We do not sell or share.
- Not be discriminated against for exercising your rights.
- Lodge a complaint with your data protection authority (e.g., Ireland's DPC, the UK ICO, or your state AG).
To exercise a right, email privacy@flypic.aior use the in-product “Export my data” and “Delete my account” controls. We will respond within 30 days (45 days for California requests if an extension is needed). We may need to verify your identity before acting.
11. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, email privacy@flypic.ai and we will delete it.
12. California notices (CCPA/CPRA)
In the last 12 months, we have collected the categories of personal information listed in Section 2. We disclose those categories to service providers only for business purposes. We do not sell or share personal information for cross-context behavioral advertising, and we do not knowingly sell or share the personal information of minors. California residents may designate an authorized agent and submit verifiable requests via privacy@flypic.ai.
13. Changes
We will post any material changes to this Policy on this page and, where required, notify you by email or in-product notice at least 14 days before the changes take effect.
14. Contact
FlyPic Privacy Team — privacy@flypic.ai