Privacy Policy
Effective date: August 22, 2026Last updated: August 22, 2026
This Privacy Policy explains what information Flypify collects, how we use and share it, and the choices you have. It applies to flypify.com, the Flypify web app, the Flypify mobile app, and the Flypify API (including the MCP endpoint) — together, the “Service.”
1. Who we are
Flypify is a product of PositivityTools, a DBA of TFT GROUP LLC (“Flypify,” “we,” “us,” or “our”). We are the controller of the personal information described in this policy. For privacy questions or requests, contact us at mikail@flypify.com.
2. Information we collect
We collect only the information we need to run the Service. We do not buy personal information about you from data brokers.
Account information
When you create an account you provide an email address and a password (we store only a one-way hash of your password, never the password itself). If you sign in with Google, we receive and store your verified email address and your Google account identifier (the “sub”) — we do not collect your Google name, profile photo, contacts, or other Google profile data. If you sign in with Apple, we similarly store the identifier Apple provides.
Subscription & billing information
Paid plans are processed by Stripe, our payment processor. Stripe collects and stores your payment-card details directly; we never receive or store your full card number, expiry, or security code. We store the Stripe customer ID and subscription ID associated with your account, along with your plan, status, and entitlements, so we can grant access and manage renewals. Subscriptions purchased through a mobile app store are processed by that store and our billing partner RevenueCat.
Connected Shopify store
If you connect a Shopify store, we complete a Shopify OAuth authorization and store the resulting access token and your store domain so we can create draft products in your store at your request. The token grants only the permissions you approve during connection (reading and writing products). You can disconnect at any time, and the token is cleared if Shopify revokes our access.
API & MCP keys
Paid users can generate API keys to use Flypify from an AI agent via our MCP endpoint. We show the full key to you once at creation and store only a SHA-256 hash of it — we cannot retrieve or display the key again. We also record key metadata (a short prefix, a label you choose, creation and last-used timestamps) and per-day API usage counts to enforce plan limits.
Product activity
We store records of the products you draft or push to your connected store and the product opportunities you reveal, so we can provide the feature and enforce your plan’s daily limits.
Ad Studio content
When you use the Ad Studio to generate video ads, we collect and store what you give it and what it produces: the product or store links you paste; the public page content we fetch from those links (product titles, descriptions, prices and images); images, logos, brand details and any voice or reference media you upload; the prompts, scripts and instructions you type; your conversation history with the Studio; and the generated storyboards, images, audio and finished videos. Generated media files are stored with our hosting provider so you can play and download them.
This content is processed by third-party AI providers on our behalf, as described in section 6. Please do not paste personal information about yourself or anyone else into a prompt — the Studio needs product information, not personal details, and anything you type is sent to those providers to generate your ad.
Technical & log information
Like most online services, our servers and our infrastructure providers automatically log technical data such as IP address, request timestamps, and basic device/browser information for security, debugging, and abuse prevention.
Cookies and analytics
The Flypify marketing site and web app do not use third-party analytics, advertising pixels, or tracking cookies.
We do not currently collect product analytics. Beyond the technical logs described above, no product analytics event — no page view, click or funnel event — is recorded; there is no endpoint that would receive one. If we ever add optional cookies or third-party analytics, we will update this policy first.
To keep you signed in, the web app stores a session token in your browser’s local storage. It also keeps small functional items in local and session storage — things like your theme and layout preferences, which view you last chose for a list, the winners you have saved, and answers you have typed into a form you have not finished — so the app works the way you left it. Those items stay in your browser, and nothing stored this way is used to track you across other sites.
3. How we use information
- To create and manage your account and authenticate you.
- To provide the Service — including curated product research, reveals, and one-tap drafting of products to your connected Shopify store.
- To process subscriptions, renewals, and refunds through our payment partners.
- To generate the ads you ask for in the Ad Studio — which means sending the content you provide to the AI providers listed in section 6, and storing the results in your account.
- To operate the API/MCP endpoint and enforce per-plan rate limits.
- To communicate with you about your account, transactions, security, and support requests.
- To secure the Service, prevent fraud and abuse, and debug problems.
- To comply with legal obligations and enforce our Terms of Service.
4. Legal bases (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR: performance of a contract (to provide the Service you sign up for and process payments); our legitimate interests (to secure the Service, prevent abuse, and improve our product); compliance with legal obligations; and your consent where required (for example, for any optional communications).
6. AI processing and AI sub-processors
The Ad Studio is built on third-party AI models. We do not train or run our own models. To produce an ad, we send the content described in section 2 — the links you paste and the page content we fetch from them, the images and media you upload, and the prompts you type — to the providers below, who process it on our behalf solely to return a result to you.
Who processes it
- Vercel AI Gateway — routes our text and reasoning requests (scripting and storyboarding your ad, and the Studio’s chat) to the model providers below.
- Anthropic (Claude) — writing and structuring ad scripts and storyboards, and powering the Studio chat.
- MuAPI — our image and video generation provider, which in turn runs models from Google (Veo, Gemini), ByteDance (Seedance) and other model vendors to produce the frames and clips in your ad.
- Creatomate and Shotstack — video rendering: assembling generated clips, captions and audio into the finished video.
- Text-to-speech providers — MiniMax, ElevenLabs, MisoTTS and OmniVoice, where your ad includes a generated voiceover.
- Vercel Blob — storage for the images, audio and videos the Studio generates for you.
We may change or add providers as the product develops — for example if a model is retired — and we will update this list when we do. The specific provider used for a given ad depends on the plan and quality tier you choose.
What this means for you
- We do not use your content to train AI models, and we do not sell it or share it for advertising.
- Each provider handles your content under its own terms and privacy policy. We select providers on business terms rather than consumer terms where available, but we cannot promise how a third party operates its systems, and you should treat anything you put into a prompt as leaving our servers.
- AI output is generated, not verified. Ads, scripts, figures and claims the Studio produces can be wrong or misleading. You are responsible for reviewing anything you publish and for making sure it is truthful and complies with advertising rules and the policies of the platform you post it on.
- Only upload media you have the right to use. Do not upload a real person’s face or voice unless you have their permission.
- No automated decisions with legal effects. We do not use AI to make decisions about you that produce legal or similarly significant effects, and no AI decides your account status, pricing or access.
- Deleting your account removes your Studio content as described in section 7. Note that we cannot recall content already sent to a provider for processing; its deletion is governed by that provider’s retention practices.
7. Data retention
We keep your personal information for as long as your account is active and as needed to provide the Service. After you delete your account, we delete or de-identify your personal information within a reasonable period, except where we must retain certain records to meet legal, tax, accounting, or fraud-prevention obligations (for example, billing records). Hashed credentials and API-key hashes are deleted along with your account.
Ad Studio content — your uploads, prompts, conversation history and the ads the Studio generated for you — is kept while your account is active so you can return to your work, and is deleted with your account. The finished ads can be downloaded from the Studio; download any you want to keep before you delete your account. We do not offer a download of your uploads, prompts or conversation history, and they are not part of the data file described in section 8. As noted in section 6, content already sent to an AI provider for processing is subject to that provider’s own retention practices and cannot be recalled by us.
8. Your privacy rights
Depending on where you live, you may have some or all of the following rights:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your information.
- Receive a portable copy of your information. Part of it is a download you can take from your account page at any time; the rest is on request — see below.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email us at mikail@flypify.com. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights.
Downloading your data
While you are signed in, your account page has a Download my data button. It gives you a JSON file of your account record and the data stored against it — including your plan, connected stores, your products, what you have unlocked, your alert settings and your API-key records. Passwords and stored access tokens are never included.
Ad Studio content is not in that file: your uploads, prompts and conversation history, and the ads the Studio generated. Finished ads can be downloaded from the Studio itself, as described in section 7. For anything that file does not include, use the email address above.
California residents (CCPA/CPRA)
We do not sell or share your personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months. California residents have the rights described above, including the right to know, the right to delete, the right to correct, and the right not to be discriminated against for exercising these rights. You may submit a request using the contact details above.
9. Deleting your account and data
You can request deletion of your account and associated personal information at any time by emailing mikail@flypify.com from the email address on your account. We will verify your request and delete your data as described in “Data retention” above. Disconnecting your Shopify store removes the stored access token; deleting your account removes your stored account data, including credential and API-key hashes.
10. Security
We use reasonable technical and organizational measures to protect your information, including encryption in transit, one-way hashing of passwords, and storing only a hash (never the plaintext) of your API keys. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. International data transfers
We and our service providers are based in, or process data in, the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards (such as the Standard Contractual Clauses) for these transfers.
12. Children
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us and we will delete it.
13. Affiliate disclosure
Flypify participates in the Shopify Affiliate Program through impact.com. Some links to Shopify (for example, the “Start your Shopify store” link) are affiliate links, and we may earn a commission if you sign up — at no additional cost to you. We disclose this at the point each affiliate link appears.
14. Changes to this policy
We may update this policy from time to time. When we do, we will revise the effective date above and, where the changes are material, take reasonable steps to notify you. Your continued use of the Service after an update means you accept the revised policy.
15. Contact us
Questions or requests about this policy? Email mikail@flypify.com. See also our Terms of Service.