Privacy Policy
Effective Date: June 12, 2025Last Updated: June 12, 2025Governing Law: Texas, USA
1. Who We Are
Fotyra (“Fotyra,” “we,” “us,” or “our”) is a registered trade name (DBA) operating under the laws of the State of Texas, United States. Our address is 3500 Oaklawn Ave. #460 PMB 5065, Dallas, TX 75219, United States.
Fotyra operates the Fotyra Studio platform, accessible at fotyra.com and app.fotyra.com (the “Platform” or “Service”).
For purposes of GDPR, Fotyra is the data controller for personal data processed through the Platform.
2. What This Policy Covers
This Privacy Policy describes how we collect, use, store, share, and protect personal information when you:
- Visit our website at fotyra.com
- Create an account and use the Fotyra Studio platform
- Connect your social media accounts (Instagram, Facebook, TikTok, YouTube, LinkedIn, and others) to the Platform
- Upload brand assets, product images, voice samples, or video of yourself or authorized individuals for AI model training
- Communicate with us for support or business purposes
This policy applies to individual users and to representatives of businesses and organizations who use our Platform. If you are using Fotyra on behalf of a business, you represent that you have authority to bind that business to this policy.
3. Information We Collect
3.1 Account & Identity Information
When you register, we collect your name, email address, password (hashed), and optionally your business name, website URL, and profile photo.
3.2 Brand & Business Data
To power AI-generated content, we collect and process information about your brand including: your website content (crawled during onboarding with your permission), brand visual identity, tone of voice, product catalogue, product images, and marketing preferences. This constitutes your “Brand DNA” stored within the Platform.
3.3 Social Media Account Data
When you connect a social media account via OAuth, we receive and store:
- Your social media account username, user ID, and profile picture (for display and routing purposes only)
- Encrypted OAuth access tokens and refresh tokens (used solely to publish content you approve)
- The name and ID of connected Pages or Company Pages you authorize
We do not read your followers, messages, post history, audience insights, or any data beyond what is required to authenticate and publish. See Section 5 for full details.
3.4 Uploaded Media — Images, Video, and Voice
If you use the Spokesmodel or voice cloning features, you may upload images, video recordings, or audio samples of yourself or individuals you are authorized to represent. This data is used to create AI-generated visual and audio personas. See Section 6 for our specific rules governing this sensitive data.
3.5 Identity Verification Data
When using biometric features (face or voice cloning), we may collect a short camera-based video verification to confirm you are the person you claim to be, consistent with your consent. This verification data is used solely for identity confirmation and is not retained after verification is complete.
3.6 Usage & Technical Data
We automatically collect log data including IP address, browser type, device identifiers, pages visited, features used, and error reports. This data is used to operate, maintain, and improve the Platform.
3.7 Billing & Payment Data
Payments are processed by Stripe, Inc. We do not store full credit card numbers. We receive and store a Stripe Customer ID, subscription status, billing cycle, and transaction metadata.
3.8 Communications
If you contact us by email or support channels, we retain the content of those communications for support and business purposes.
4. How We Use Your Information
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Provide and operate the Platform | Account data, Brand DNA, social tokens, uploaded media | Contract performance |
| Generate AI creative content on your behalf | Brand DNA, product data, persona data | Contract performance |
| Publish approved content to connected social accounts | Social OAuth tokens, approved assets | Contract performance |
| Identity verification for biometric features | Camera video, voice samples | Explicit consent |
| Process billing and subscriptions | Billing data, email, Stripe identifiers | Contract performance |
| Send transactional emails (receipts, alerts, publishing confirmations) | Email address | Contract performance |
| Send product updates and marketing (optional) | Email address | Legitimate interest / consent |
| Improve and train platform models (aggregated, non-identifiable only) | Anonymized usage patterns | Legitimate interest |
| Comply with legal obligations | Any data required by law | Legal obligation |
| Fraud detection and platform security | Usage data, IP address, billing data | Legitimate interest |
5. Social Media Platform Connections & OAuth Tokens
When you connect a social media account (Instagram, Facebook, TikTok, YouTube, LinkedIn, or others), you grant Fotyra permission via each platform’s OAuth authorization flow to publish content on your behalf.
What we access: Only the minimum permissions required to authenticate your account and publish content you have explicitly approved inside Fotyra. We do not access your followers, direct messages, post history, advertising accounts, or engagement data through publishing connections.
How we store tokens: OAuth access tokens and refresh tokens are encrypted at rest using AES-256 encryption and stored scoped to your individual project. They are never shared with other users or projects.
Token deletion: When you disconnect a social account from Fotyra, all stored OAuth tokens for that account are immediately deleted from our systems. You can also revoke access directly from each platform’s security settings at any time.
Deauthorization: If you revoke Fotyra’s access directly through a social platform (e.g. through Facebook’s App Settings), the platform notifies us via a deauthorization callback. We immediately invalidate and delete the associated tokens upon receipt of that notification.
Data deletion requests: If you submit a data deletion request through a social platform’s interface (such as Meta’s data deletion flow), we will delete all data associated with your social account connection within 30 days and provide a confirmation URL.
6. AI-Generated Content, Voice Cloning & Likeness Data
Fotyra’s Spokesmodel and voice cloning features allow you to create AI-generated visual and audio personas. This section governs how we handle this sensitive data.
6.1 Consent Requirement
Before uploading any image, video, or audio of a real person to create an AI persona, you must:
- Confirm that you are the person depicted or that you have obtained explicit written consent from the individual being cloned
- Agree that the content will be used only for lawful marketing purposes on platforms and accounts you own or are authorized to manage
- Acknowledge that creating an AI clone of a person without their consent may violate applicable law
6.2 Identity Verification
For self-cloning (uploading your own face or voice), we may require a live camera verification step to confirm you are the person in the uploaded media. Verification video is processed in real time and is not retained after the verification decision is made.
6.3 How Likeness & Voice Data Is Used
Uploaded images, video, and voice samples are used solely to generate AI personas within your project. They are stored on encrypted object storage (Bunny CDN), scoped to your project, and are never used to train models for other customers, shared with third parties, or used outside the context of your project.
6.4 Deletion
You can delete any uploaded persona media at any time from your project. Upon deletion, the source files are permanently removed from our CDN storage. AI models trained on that data are also deleted within 30 days of the persona being deleted.
6.5 Your Responsibility
You are solely responsible for ensuring you have the right to create an AI persona of any individual and that the content generated and published complies with all applicable laws, platform policies, and the rights of the individuals depicted.
7. How We Share Your Information
We do not sell your personal data. We share your information only in the following limited circumstances:
7.1 Service Providers
We share data with trusted third-party providers who help us operate the Platform, under strict data processing agreements:
- Stripe — payment processing
- Bunny CDN — media storage and delivery
- Google (Gemini API) — AI text and image generation
- OpenAI — AI image generation
- xAI (Grok) — AI video generation
- ElevenLabs — voice synthesis and cloning
- MongoDB Atlas — database hosting
These providers process only the data necessary to deliver their services and are contractually prohibited from using your data for their own purposes.
7.2 Social Media Platforms
When you publish content, we transmit the approved media and associated metadata (caption, hashtags, schedule) to the respective platform API on your behalf. The platform’s own privacy policy governs what they do with that data once received.
7.3 Legal Requirements
We may disclose your information if required by law, court order, or government authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Fotyra, our users, or the public.
7.4 Business Transfers
If Fotyra is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.
7.5 Team Members
If you invite team members to your project, they will have access to your project’s Brand DNA, generated assets, and connected account names (but not OAuth tokens) based on the roles you assign them.
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | For the life of your account, plus 30 days after deletion request |
| Brand DNA and project data | For the life of your project; deleted within 30 days of account/project deletion |
| Generated creative assets (CDN) | For the life of your project; deleted within 30 days of project deletion |
| OAuth tokens (social connections) | Until you disconnect the account or revoke access; deleted immediately on disconnection |
| Persona media (face/voice uploads) | Until you delete the persona; deleted within 30 days of persona deletion |
| Identity verification video | Processed in real time; not retained after verification decision |
| Billing records | 7 years (required for financial/tax compliance) |
| Activity logs | 90 days rolling |
| Support communications | 3 years from last interaction |
9. Security
We implement industry-standard security measures to protect your data, including:
- AES-256 encryption at rest for OAuth tokens and sensitive credentials
- TLS 1.2+ encryption in transit for all API communications
- Role-based access control with per-project data isolation
- Hashed passwords (bcrypt)
- Encrypted media storage on Bunny CDN with signed URLs
- Regular security reviews and dependency audits
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.
10. GDPR — Rights of EU/UK Users
If you are located in the European Union or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data, subject to our legal retention obligations.
- Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests, including direct marketing.
- Rights Related to Automated Decision-Making: Not be subject to decisions based solely on automated processing that significantly affect you.
- Right to Withdraw Consent: Where processing is based on consent (e.g. biometric data), withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@fotyra.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
11. CCPA — Rights of California Residents
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit our use of sensitive personal information (including biometric data) to what is necessary to provide the Service.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
To submit a CCPA request, email privacy@fotyra.com with the subject line “CCPA Request.” We will verify your identity and respond within 45 days. You may designate an authorized agent to make a request on your behalf.
Categories of personal information collected: Identifiers, commercial information, internet/network activity, biometric information (voice/face, with consent), geolocation (IP-level only), and inferences drawn from the above.
12. Cookies & Tracking
We use cookies and similar technologies to operate the Platform, maintain your session, and analyze usage. Specifically:
- Essential cookies: Required for authentication and session management. Cannot be disabled without breaking the Service.
- Analytics cookies: Used to understand how the Platform is used and improve features. You may opt out via your browser settings or our cookie preference center.
- Marketing cookies: We do not currently use marketing or advertising cookies on the Platform.
You can control cookies through your browser settings. Disabling essential cookies will prevent you from using the Platform.
13. Children’s Privacy
Fotyra is a business-oriented platform intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that a minor has provided us with personal information, we will delete it promptly. If you believe a minor has submitted data to us, please contact us at privacy@fotyra.com.
14. International Data Transfers
Fotyra is operated in the United States. If you are located outside the United States — including in the EU or UK — your data will be transferred to and processed in the United States.
For transfers of personal data from the EU/UK to the United States, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission with our data processors
- Our sub-processors (Stripe, Google, OpenAI, ElevenLabs) maintain their own cross-border transfer mechanisms; by using their services we rely on their respective compliance frameworks
By using the Platform, you acknowledge that your data may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last Updated” date at the top of this page. For material changes, we will notify you by email or by a prominent notice within the Platform at least 14 days before the change takes effect.
Your continued use of the Platform after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree to the revised policy, you should discontinue use of the Platform and request account deletion.
16. Contact Us
For any privacy-related questions, data subject requests, or concerns, please contact us:
Fotyra
Privacy & Data Requests
Email: privacy@fotyra.com
Address: 3500 Oaklawn Ave. #460 PMB 5065
Dallas, TX 75219
United States
You may also request deletion of your data at any time by emailing privacy@fotyra.com.