Privacy Policy
Last updated: May 15, 2026
FlyBrand ("we", "our", "us") provides an AI marketing platform that connects to third-party services (Meta, Google, Shopify, Mailchimp, Resend, and others) on your behalf to draft, schedule, and measure marketing work. This policy explains what we collect, why, and how you can control it.
1. Data we collect
- Account data: email, password (hashed), name, workspace settings.
- Connected provider data: when you connect a provider (e.g. Facebook Page, Shopify store, Google Ads account), we receive an OAuth access token and read the data scopes you granted (page posts, ad campaigns, store orders, customers, analytics).
- Content you create: drafts, briefs, prompts, generated copy and images, scheduled posts.
- Usage data: page views, feature usage, error logs — collected to keep the service running.
2. How we use it
- Drafting marketing content (posts, emails, ad creatives) that you review and approve.
- Publishing approved content to the providers you connected, on your behalf, using the tokens you granted.
- Reading analytics from providers to surface insights in your dashboard.
- Improving the product (aggregated, anonymised — never selling raw data).
3. Provider data handling
OAuth tokens are encrypted at rest (AES-256-GCM) and only used to fulfil requests you initiate. We do not sell, share, or use provider data for advertising. You can disconnect any provider at any time from your dashboard — the token is revoked and provider data we mirrored is deleted within 30 days.
4. Meta Platform Terms
When you connect a Facebook or Instagram account, FlyBrand follows the Meta Platform Terms and the Facebook Developer Policies. We only request the permissions needed to read Page metadata, posts, and insights, and to publish content on your behalf. Meta data is retained only as long as needed to provide the service or required by law.
5. Data retention
- Account data: until you delete your account.
- Provider data: while the connection is active, plus 30 days for soft-delete recovery.
- Logs: 90 days.
6. Your rights (GDPR / CCPA)
You can request access, correction, export, or deletion of your data at any time. Email privacy@flybrand.app. We respond within 30 days.
7. Subprocessors
We use the following processors: Google Cloud (hosting), Cloudflare (CDN, network, transactional email), Anthropic / OpenAI (LLM inference for draft generation). Each is bound by data processing agreements.
8. Security
All traffic is TLS 1.3. Provider tokens are encrypted at rest. We run least-privilege access controls and audit logs. Incidents are disclosed to affected users within 72 hours.
9. Children
FlyBrand is not directed to people under 16. We do not knowingly collect their data.
10. Changes
When we update this policy materially, we notify you by email and show a banner inside the dashboard before the change takes effect.
11. Contact
FlyBrand · privacy@flybrand.app
Data deletion callback: https://api-dev.flybrand.app/v1/meta/data-deletion-info