Privacy Policy
Version 1.1 - Last updated July 31, 2026
Contents
1. Scope of this Policy
This Privacy Policy explains how fylt, Inc. ("fylt," "we," "us") collects, uses, discloses, and safeguards personal data when you visit fylt.app, use the Studio, Workspace, or Admin applications, or otherwise interact with the fylt platform (collectively, the "Service"). It applies to prospective customers ("Visitors"), account holders and their team members ("Customers"), and the clients of Customers who use fylt Cove or a published fylt Finch storefront ("End Clients").
2. Information We Collect
We collect the following categories of information:
- Account information: name, email address, password hash, phone number, company name, billing address, and preferred currency and timezone.
- Payment information: subscription payment details are processed directly by our payment processor, Razorpay Software Private Limited; fylt does not store full payment card numbers.
- Customer Data: client records, calendar events, invoices, documents, and support tickets that you or your End Clients enter into the Service.
- AI-assisted content: the prompts and relevant business context you choose to submit when using fylt AI, together with the draft returned for your review. This content is processed only to provide the requested AI-assisted workflow.
- Usage data: log data, device and browser information, IP address, pages viewed, and feature interactions, collected via first-party analytics only where you have consented under our .
- Communications: messages you send us through the Contact Us form, support tickets, or email, including any attachments.
3. How We Use Information
We use personal data to:
- Provide, maintain, and secure the Service, including per-app session isolation and fraud prevention;
- Process subscription payments and manage subscriptions through Razorpay;
- Send transactional communications (booking confirmations, invoice notices, ticket replies);
- Respond to support requests and Contact Us submissions;
- Provide optional AI-assisted drafting when you choose to use that feature;
- Improve the Service through aggregated, and where required, consented analytics;
- Comply with legal obligations and enforce our Terms of Service.
4. Legal Bases for Processing (EEA/UK)
Where the UK or EU GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service you signed up for), legitimate interests (to secure and improve the Service), consent (for optional analytics and marketing cookies), and legal obligation (for tax, accounting, and fraud-prevention record-keeping).
5. How We Share Information
We handle personal data carefully and do not sell it. We share personal data only with: (a) sub-processors who help us operate the Service, including Razorpay (subscription payments), cloud hosting and object storage providers, transactional email providers, and the configured AI service provider when you request an AI-assisted workflow, each under appropriate contractual protections; (b) your own organization's team members, to the extent your account roles permit; (c) law enforcement or regulators, where required by valid legal process; and (d) a successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy continuing to apply.
6. International Data Transfers
fylt may process and store data in the United States and other countries where our infrastructure providers operate. Where personal data originating in the EEA, UK, or Switzerland is transferred internationally, we rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism.
7. Data Retention
We retain account and Customer Data for as long as your subscription is active, and for thirty (30) days after cancellation to allow export, unless a longer period is required for legal, tax, or dispute-resolution purposes. Trial account data not converted to a paid plan is deleted thirty (30) days after trial expiration. Audit logs are retained for twelve (12) months.
8. Your Privacy Rights
Depending on your location, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent at any time. To exercise these rights, contact privacy@fylt.app. California residents may exercise rights under the CCPA/CPRA through the same channel; we do not sell personal data as defined by the CCPA. We will respond to verifiable requests within the timeframes required by applicable law.
9. Cookies & Similar Technologies
We use strictly necessary cookies to operate the Service (including per-app session cookies), and, only with your consent, functional, analytics, and marketing cookies. You can review and change your choices at any time using the Privacy choices badge available on every page. See our Data Security page for more on how consent is enforced technically.
10. Children's Privacy
The Service is intended for business use by adults. We do not knowingly collect personal data from children under 16. If we learn we have collected such data, we will delete it promptly.
11. Security
We apply technical and organizational measures described in our Data Security page, including encryption in transit, encrypted storage, per-app session isolation, and role-based access controls.
12. Changes to this Policy
We will post material changes to this Policy on this page with an updated "Last updated" date and, where required, notify you by email or in-product notice.
13. Contact & Privacy Questions
For privacy questions or to exercise your rights, contact our privacy team at privacy@fylt.app or via our Contact Us page.