FayFly — Privacy Policy
Version 1.0 — Effective date: 19 August 2026
1. Who is responsible for your data
The controller of your personal data is SIA "Vitalik", registration No. 40203219165, legal address Kurzemes prospekts 86A-1, Riga, LV-1069, Republic of Latvia ("we"). Privacy contact: privacy@fayfly.com.
This policy applies to fayfly.com and its subdomains, and covers visitors, registered members and creators.
2. What data we collect
Data you provide:
- Account data: email address, username / display name, password (stored only as a cryptographic hash), date of birth (used to enforce our 18+ rule).
- Profile data: profile photo, bio, links you add to your page.
- Content: posts (images and video), comments, messages in chats, and files you upload for import (for example, Instagram export archives).
- Creator verification data: if you apply to publish as a creator, a short video you record or upload showing a handwritten note with your username. We use it solely to confirm that you control the account; it is not an identity-document or age check. See Sections 4 and 7.
- Communications: messages you send us (support, legal and privacy requests).
Data from Google sign-in (if you choose it): your name, email address and profile picture, as listed on Google's consent screen. We never receive your Google password.
Data collected automatically:
- Server logs: IP address, timestamps, requested pages, browser and device information, referrer.
- Cookies strictly necessary for the service: session and authentication, security, and your cookie choice (see Section 5).
- Error diagnostics: when something breaks, error reports with technical context are collected via Sentry (see Section 3).
Only with your consent:
- Session replay: anonymized recordings of how the interface behaved during your visit (text and inputs are masked, media is blocked), collected via Sentry to help us reproduce and fix bugs. Replay is never active before you opt in.
3. Why we process your data, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing the service: account, publishing, subscriptions, chats, notifications | account, profile, content | Art. 6(1)(b) — contract |
| Enforcing the 18+ eligibility rule | date of birth | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in keeping the platform 18+ |
| Confirming that a creator controls their account | verification video | Art. 6(1)(b) — contract; Art. 6(1)(f) — preventing impersonation |
| Security, abuse and fraud prevention, debugging | server logs, technical data | Art. 6(1)(f) — legitimate interest |
| Error and performance monitoring | error reports, diagnostic data | Art. 6(1)(f) — legitimate interest in a working, secure service |
| Session replay for debugging | masked interaction recordings | Art. 6(1)(a) — consent, withdrawable at any time via Cookie settings |
| Transactional email: verification, security and moderation notices | email address | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation for required notices |
| Content moderation and records of moderation decisions | content, account data | Art. 6(1)(f) — legitimate interest; Art. 6(1)(c) — legal obligation (e.g., statements of reasons) |
| Responding to legal requests; establishing and defending legal claims | relevant data | Art. 6(1)(c); Art. 6(1)(f) |
| Marketing emails (only if introduced, and only with opt-in) | email address | Art. 6(1)(a) — consent |
We do not sell personal data and do not use it for third-party advertising.
4. Who processes data on our behalf
| Provider | Role | Notes |
|---|---|---|
| DigitalOcean, LLC | server hosting (application and database); encrypted off-site backups (DigitalOcean Spaces) | servers located in the EU |
| Bunny (BunnyWay d.o.o.) | media storage and delivery (CDN); video hosting, including creator verification videos | EU-based provider; global edge network |
| Resend | transactional email delivery | US provider; transfers safeguarded per Section 6 |
| Google (Google Ireland Ltd.) | sign-in (OAuth) | EU/US — see Section 6 |
| Sentry (Functional Software, Inc.) | error and performance monitoring; session replay only with your consent | US provider — see Section 6 |
We also use standard internal tools (such as messaging and email) through which our administrators receive operational notifications about the service. Where such a notification identifies an account, it contains a username only.
We conclude data processing agreements with our processors as required by Art. 28 GDPR.
5. Cookies
- Strictly necessary (no consent required): session and authentication cookies, security tokens, and the cookie that remembers your cookie choice.
- Diagnostics (consent required): session replay (Sentry). Enabled only after you opt in via the banner; withdraw at any time via the Cookie settings link in the footer.
We currently use no third-party analytics or advertising cookies.
6. International transfers
Some providers — notably Google, Sentry and Resend — may process data in the United States. Where personal data leaves the EU/EEA, we rely on the provider's certification under the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, with additional safeguards where appropriate.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | while the account exists, + 30 days' grace period after deletion, then erased |
| Content you delete | removed from the service immediately; backup copies expire within 35 days |
| Server logs | 12 months |
| Moderation records and statements of reasons | 3 years |
| Error monitoring data (Sentry) | 90 days |
| Session replay recordings | 30 days |
| Creator verification videos | 90 days after the verification decision, then permanently deleted |
| Consent records (ToS acceptance, cookie choices) | duration of the account + 3 years |
8. Your rights
Under the GDPR you have the right to: access your data; correct it; delete it; restrict its processing; receive a portable copy; object to processing based on legitimate interest; and withdraw consent at any time (withdrawal does not affect processing that already happened).
To exercise your rights, write to privacy@fayfly.com or use the in-account tools. We respond within one month.
You also have the right to lodge a complaint with a supervisory authority — in Latvia: Datu valsts inspekcija (Data State Inspectorate), www.dvi.gov.lv — or with the authority of your country of residence.
9. Automated decision-making
We do not make automated decisions that produce legal or similarly significant effects on you. Creator verification review, account-level moderation decisions and all appeals include human review.
10. Minors
FayFly is for adults (18+). We do not knowingly process the data of persons under 18; such accounts are deleted when identified. To report an underage account: privacy@fayfly.com.
11. Security
We use encryption in transit (TLS), password hashing, access controls and the principle of least privilege, with server infrastructure hosted in the EU. No system is completely secure; if a personal data breach occurs, we will notify the supervisory authority and, where required, affected users, in accordance with Art. 33–34 GDPR.
12. Changes to this policy
We will announce material changes at least 15 days in advance by email and/or an in-product notice. The current version is always available at fayfly.com/privacy-policy.
SIA "Vitalik" · reg. No. 40203219165 · Kurzemes prospekts 86A-1, Riga, LV-1069, Latvia · privacy@fayfly.com