🛡️ Privacy Policy
Effective Date: July 27, 2026
Your privacy is paramount to Flyb.
FlyB Digital Solutions LLC (“FlyB,” “we,” “us,” or “our”) provides tools that empower users to build, share, and deploy web applications and automations using natural language prompts (AI). Our mission is to simplify software development through innovative tools, seamless integrations (including Google, Stripe, WhatsApp, and Email systems), and collaborative features, while prioritizing the privacy and security of your data.
We are committed to fostering a vibrant builder community and ensuring compliance with applicable privacy laws, including those in the United States (state privacy statutes), the European Economic Area (GDPR), the United Kingdom (UK GDPR), Switzerland (nFADP), Canada (PIPEDA), and Brazil (LGPD).
1. Scope and Agreement
This Privacy Policy (“Policy”) outlines how FlyB collects, uses, shares, and otherwise processes Personal Data from users, including developers, entrepreneurs, and visitors (“User,” “you,” or “your”) of our website, software, and platform (collectively, our “Services”).
By using our Services, you acknowledge and agree to this Policy and our Flight Consumption Hierarchy. This Policy is incorporated into our Terms of Service. If you do not agree with the terms of this Policy, please discontinue your use of our Services immediately.
2. Service Plans and Applicability
Please note: This Privacy Policy applies to all tiers of service provided by FlyB, including the Free, Plus, and Prime plans.
3. Data Processing and AI Usage
As part of our Services, FlyB processes data to execute AI-driven commands. You acknowledge that:
- Prompt Data: Content submitted to our AI for the purpose of generating websites or automations is processed to deliver the requested service.
- Flight Logs: We track and log “Flight” consumption to manage subscription quotas, prevent fraud, and ensure accurate billing for Plus and Prime tiers.
- Third-Party Integrations: When you utilize our integrations (e.g., Google Calendar for scheduling, Stripe for payments, or WhatsApp for CRM automations), your data is also subject to the privacy practices of those specific third-party providers.
Data obtained from Google APIs is expressly excluded from AI processing. Google user data is never submitted to any AI model and is never used to develop, improve, or train generalized or standalone artificial intelligence or machine learning models. See Section 5 for full details.
4. Collection and Use of Information
4.1 Information You Provide Directly:
When you create an account, purchase a subscription, open a support ticket, or otherwise use our Services, you may supply Personal Data such as your name, business email address, phone number, and payment information.
Payment Processing: All financial transactions are processed via Stripe. FlyB does not store full payment card details; Stripe serves as the sole “source of truth” for billing records and transaction data. For details on how your financial data is handled, please refer to Stripe’s Privacy Policy.
Usage Data and “Flight” Metering: For our usage-based ecosystem—including IA Site Generation, CRM activities, and WhatsApp/Email automations—we collect and process Usage Data (e.g., API calls, prompt volumes, message counts, and storage usage). This data is used to meter consumption against your Flights:
- For Plus and Prime Plans: Usage is metered against a monthly Subscription Quota. You acknowledge that these Flights are provided on a “use-it-or-lose-it” basis per billing cycle.
- For Free Plans: Usage is metered against a one-time Initial Balance.
Project Artifacts and AI Processing: We collect content generated or provided by you, such as natural-language prompts, code snippets, CRM data, and deployment configurations (“Project Artifacts”). These artifacts are used exclusively to:
- Serve your workspace: Ensure your sites and automations function as intended.
- Meter Consumption: Verify the computational effort required to execute your requests (Flight consumption).
- Improve Service: Once anonymized or aggregated, to improve our internal models and platform stability.
Crucially: Your Project Artifacts are never used to train general-purpose AI models that benefit other customers without your explicit, written permission.
4.2 Information Collected Automatically:
When you interact with our Services, we automatically collect technical data, including but not limited to: IP addresses, browser type and version, geographic location (country/city), URL parameters, pages visited, timestamps, and system error logs.
Role and Purpose: This “Service Data” is processed by FlyB as an independent controller. This processing is necessary for:
- Security and Fraud Prevention: Detecting multi-account abuse to protect the Flight economy and ensuring platform integrity.
- Billing and Quota Management: Aligning technical usage with your Plus or Prime subscription limits.
- Analytics and Optimization: Improving the efficiency of our AI generation and system response times.
- Error Resolution: Identifying and fixing bugs in the site-building and automation engines.
Note: We use cookies and similar tracking technologies to collect this information. For more details, please refer to our Cookie Policy.
4.3 Data Sharing and Third-Party Integrations
FlyB does not sell your Personal Data. We only share information with third parties when it is necessary to provide our Services, comply with the law, or protect our rights.
1. Essential Service Providers (Sub-processors) We share data with service providers who perform critical functions on our behalf. These parties are contractually obligated to keep your data confidential and use it only for the purposes for which we disclose it to them. Our current primary sub-processors include:
| Name | Use/Function | Location | Compliance Information |
|---|---|---|---|
| AWS | Hosting and Email infrastructure. | US | AWS Privacy Policy |
| Stripe | Payment processing and subscription management. | US | Stripe and the GDPR |
| Google Cloud Platform | AI Model processing and infrastructure. | US | Google Cloud Privacy |
| Google Analytics | Platform usage analytics and optimization. | US | Google Analytics Data Privacy |
2. User-Directed Integrations (Third-Party APIs) The FlyB ecosystem allows you to connect third-party services (e.g., your own Google account, WhatsApp Business account, or Stripe account).
- Role of FlyB: In these instances, FlyB acts as a Data Processor (or “Service Provider” under the CCPA) for any data processed through these integrations.
- User Responsibility: When you enable these integrations, you direct us to share data with these third parties. You are responsible for reviewing the privacy policies of those services. FlyB is not responsible for the data handling practices of platforms you choose to connect to your workspace.
- Google Integrations: Data received from Google APIs is governed by the additional, more restrictive commitments set out in Section 5 of this Policy, which prevail over any conflicting provision elsewhere in this document.
3. Legal Compliance and Protection We may disclose your information if required by law (e.g., a subpoena) or if we believe such action is necessary to:
- Prevent credit card fraud or abuse of the Free Plan (50 Flights).
- Protect the safety of our users or the public.
- Enforce our General Terms of Service.
4.4 Children’s Data
Children’s Data: FlyB’s Services are intended for professional use and are not directed to individuals under the age of eighteen (18). We do not knowingly collect or solicit Personal Data from anyone under this age. By using our Services, you represent that you are at least 18 years old or the age of majority in your jurisdiction. If we discover that we have inadvertently collected Personal Data from a minor without verifiable parental consent, we will take immediate steps to delete that information. If you believe we may have collected such data, please contact us at [email protected].
4.5 Sensitive Data
Sensitive Data: FlyB does not intentionally collect, and specifically instructs Users not to upload or process, “Special Categories of Personal Data” (as defined by GDPR), including but not limited to: biometric identifiers, health information, racial or ethnic origin, political opinions, or precise geolocation.
User Responsibility: As FlyB provides a CRM and communication ecosystem (WhatsApp/Email), you acknowledge that if you choose to process sensitive data belonging to your own clients through our Services, you do so at your own risk and are solely responsible for compliance with applicable privacy laws. FlyB reserves the right to delete any data it identifies as sensitive without prior notice to protect the integrity of its systems.
5. Google User Data, OAuth Scopes, and Limited Use
This section describes exactly how FlyB requests, accesses, uses, stores, shares, and deletes data obtained from Google APIs. It applies in addition to the rest of this Policy, and prevails over any conflicting provision elsewhere in this document.
5.1 Limited Use Disclosure
FlyB’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, and without limitation, FlyB affirms that:
- We do not use Google user data for serving advertisements of any kind, including retargeting, personalized advertising, or interest-based advertising.
- We do not sell, rent, license, or otherwise monetize Google user data.
- We do not transfer Google user data to third parties, except (a) to the limited sub-processors strictly necessary to operate the feature you enabled, as listed in Section 5.6; (b) where required to comply with applicable law or valid legal process; or (c) as part of a merger or acquisition, subject to your prior notice and consent where required by law.
- We do not use Google user data to develop, improve, or train generalized or standalone artificial intelligence or machine learning models. Google user data is never sent to any AI model, whether operated by FlyB or by a third party.
- Humans do not read Google user data, except: (a) with your explicit, affirmative consent for a specific case (for example, when you open a support ticket and authorize us to investigate); (b) where strictly necessary for security purposes, such as investigating abuse or a suspected breach; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized and is used solely for internal operations.
5.2 Google Sign-In (openid, email, profile)
Why we request it: These scopes are used exclusively for user authentication (“Sign in with Google”) and account creation, providing a seamless and secure login experience without requiring you to create and manage a separate password.
How the data is used: When you choose to sign in or sign up with Google, we receive your Google account identifier, your verified email address, your display name, and your profile picture URL. We use your email address as the unique identifier of your FlyB account, and your name and profile picture to populate your FlyB user profile so the platform can address you correctly.
What we store: Your email address, display name, and profile picture URL, on your FlyB user record. We do not store Google access tokens or refresh tokens for the sign-in flow — the Google credential is verified at the moment of login and then discarded.
What we never do: These scopes are never used to contact your Google contacts, to send marketing email through Google, or for any purpose other than authenticating you and provisioning your account.
5.3 Google Calendar — Read-Only Availability (.../auth/calendar.readonly)
Why it’s needed: We need read-only access to query the user’s existing calendar events.
How it will be used: When a client tries to schedule a meeting or event through FlyB, our system reads the user’s Google Calendar to check existing availability and detect schedule conflicts in real time, preventing double-booking.
How this works in practice: This scope is used for two narrow operations only:
- Listing your calendars once, at connection time (
calendarList), so that you can choose which specific Google calendar FlyB should link to. We read only the calendar’s identifier, display name, time zone, and your access role. - Querying busy time ranges (
freeBusy) for the linked calendar, within the booking window your visitor is viewing. The Google FreeBusy endpoint returns only the start and end timestamps of periods marked as busy.
Important limitation: FlyB does not read the titles, descriptions, locations, attendees, attachments, or any other content of your existing calendar events. Availability is determined solely from opaque busy/free time ranges.
What we store: Nothing. Busy time ranges are held in a short-lived, in-memory cache for up to sixty (60) seconds — purely so that a visitor paging through weeks in the booking widget does not trigger redundant calls to Google — and are never written to our database, logs, or backups. The identifier, name, and time zone of the single calendar you explicitly selected are stored so we know where to sync.
5.4 Google Calendar — Event Management (.../auth/calendar.events)
Why it’s needed: We need permission to create, edit, and delete calendar events managed through FlyB.
How it will be used: When a new appointment or client meeting is booked inside the FlyB platform, FlyB automatically creates and syncs the corresponding event directly into the user’s connected Google Calendar.
How this works in practice: This scope is used for three narrow operations only:
- Creating an event on your linked calendar when a booking is confirmed on FlyB, carrying the appointment title, description, location, start and end times, time zone, and the attendee’s name and email address. Where the appointment is remote, we additionally ask Google to attach a Google Meet conference to that event.
- Updating an event that FlyB previously created, when the corresponding booking is rescheduled or edited on FlyB.
- Deleting an event that FlyB previously created, when the corresponding booking is cancelled on FlyB.
Important limitation: FlyB only ever writes to, modifies, or deletes events that FlyB itself created, identified by the Google event identifier we recorded at creation time. We never modify or delete events created by you or by anyone else.
What we store: The Google event identifier and the generated Google Meet URL, stored against the corresponding FlyB booking record so that we can keep the two in sync and display the meeting link to you and your client. The event content we write originates from the booking data already held in your FlyB workspace.
5.5 Credentials and Security
To keep a connected calendar in sync without asking you to re-authorize on every booking, FlyB requests offline access and stores the resulting OAuth refresh token and short-lived access token against the specific FlyB calendar you connected.
- Tokens are stored in our database on encrypted volumes, are never exposed to the browser or to any client-side code, and are never transmitted to any party other than Google itself when refreshing or using the grant.
- Access is scoped to the organization that owns the calendar; every request is isolated by organization identifier.
- All communication with Google APIs occurs over TLS.
- The OAuth
stateparameter is cryptographically signed and verified on callback to prevent authorization from being bound to the wrong account.
5.6 Sharing of Google User Data
Google user data is not shared with third parties for their own purposes. Within the operation of the feature you enabled, it is handled by:
| Recipient | Role | Google data involved |
|---|---|---|
| Google LLC | Source and destination of the integration. | All of it, by definition. |
| AWS | Hosting infrastructure where FlyB’s database and application servers run. | Stored OAuth tokens, linked calendar identifiers, Google event identifiers, Meet URLs. |
Google user data is not shared with our AI providers, analytics providers, advertising networks, or any other third party.
5.7 Retention and Deletion of Google User Data
- Revoking at any time: You may disconnect Google Calendar from within the FlyB dashboard at any time, on the calendar’s settings screen. Doing so immediately and permanently deletes the stored refresh token, access token, linked calendar identifier, calendar name, connected account email, and time zone from our database.
- Revoking from Google: You may also revoke FlyB’s access directly at https://myaccount.google.com/permissions. Once revoked, FlyB can no longer read availability from, or write events to, your calendar.
- Effect on existing events: Disconnecting does not delete events already created on your Google Calendar — they remain yours. FlyB simply stops syncing.
- Account deletion: If you delete your FlyB account, all Google credentials and Google-derived identifiers are deleted along with your account data, within the periods stated in Section 8.
- No independent retention: FlyB does not retain Google user data beyond what is described above, and does not maintain any separate archive of your calendar contents.
5.8 Consent
Both Google integrations are strictly optional. FlyB is fully usable without connecting a Google account: you may sign in with an email code instead, and you may operate calendars and bookings entirely within FlyB without linking them to Google. Access is requested only at the moment you initiate the connection, and only the scopes described above are requested.
6. Purposes of Processing
We process Personal Data for the following purposes:
- Service Execution: To provide, operate, and maintain the Services, including storing code, generating AI suggestions, and deploying applications;
- Workspace Personalization: To personalize your experience and optimize AI-driven features exclusively within your workspace, unless you withdraw consent by emailing us at
[email protected]; - Flight Metering & Analytics: To analyze usage patterns, monitor Flight consumption, and improve the performance, functionality, and reliability of our infrastructure;
- Security & Integrity: To detect, prevent, and investigate fraud (including multi-account “Flight” farming), abuse, or security incidents;
- Communications: To deliver product updates, measure marketing effectiveness, and provide customer support as permitted by your account settings;
- Scheduling: To operate the calendar and booking features, including checking availability and synchronizing appointments with a calendar you have explicitly connected;
- Financial Transactions: To process payments, manage subscriptions (Plus/Prime), and handle authorized transactions via Stripe;
- Regulatory Compliance: To comply with legal, regulatory, export-control, and sanctions obligations in the jurisdictions where we operate; and
- Accountability: To meet record-keeping, accounting, and audit requirements.
Automated Decision-Making: FlyB does not engage in automated decision-making that produces legal or similarly significant effects on individuals (GDPR Art. 22). While Flight consumption is automated based on your activity, any account suspension for alleged abuse is subject to human review.
Data Minimization: We collect only the Personal Data necessary for these purposes and retain it in line with the retention schedule outlined in this Policy. You may exercise your opt-out or objection rights as described herein.
7. AI Processing and Content Responsibility
7.1. Nature of AI Output FlyB processes Project Artifacts (such as prompts and data) to generate suggestions, code, and web applications. You acknowledge that these suggestions are generated automatically by Artificial Intelligence and are provided on an “as-is” basis.
7.2. User as Data Controller of Deployed Content While FlyB facilitates the creation of content through its AI engine, the User remains the sole Data Controller (or “Owner”) of the final output once it is deployed, published, or otherwise used. You are responsible for reviewing and verifying the accuracy, legality, and safety of all AI-generated content before it is made public or used in a production environment.
7.3. Exclusion of Google User Data Data obtained through Google APIs is never included in Project Artifacts, never submitted to any AI model, and never used to develop, improve, or train generalized or standalone artificial intelligence or machine learning models, as set out in Section 5.1.
7.4. Limitations on Automated Decision-Making FlyB does not engage in automated decision-making that produces legal or similarly significant effects on individuals (GDPR Art. 22). While the deduction of Flights is automated based on your activity, any significant administrative actions, such as account suspension for alleged abuse or fraud, are subject to human review to ensure fairness and accuracy.
8. Retention of Your Information
1. General Retention Principle: We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including providing our Services, complying with legal obligations, and resolving disputes.
2. Specific Retention Periods:
- Active Accounts: Data is retained for the duration of your active subscription (Free, Plus, or Prime).
- Account Termination: Upon account termination or explicit request for deletion, we will delete or anonymize your Personal Data within thirty (30) days, except for information we are legally required to keep (e.g., tax records, fraud prevention logs, or legal defense).
- Canceled Paid Subscriptions: If you cancel a Plus or Prime plan but do not delete your account, we will retain your project data (sites, CRM leads) for a “grace period” of ninety (90) days to allow for reactivation. After this period, we reserve the right to delete non-active project data to optimize our infrastructure.
- Google Credentials: OAuth tokens and linked-calendar identifiers are deleted immediately upon disconnection or account deletion, and are never subject to the grace period described above.
- Backups: Residual data may persist in our encrypted backups for up to ninety (90) days following deletion from our active production servers.
3. Flight Forfeiture vs. Data Deletion: Please note that the expiration or forfeiture of unused Flights at the end of a billing cycle (as defined in our General Terms) does not automatically trigger the deletion of your Personal Data. Your account will simply revert to the Free Tier status until you request full account deletion.
4. Exercise of Rights:
To request the erasure of your data under GDPR, LGPD, or CCPA, please contact us at [email protected]. We will process your request in accordance with applicable Data Protection Laws.
9. Changes to This Policy
FlyB reserves the right to update or revise this Privacy Policy to reflect changes in our practices, legal requirements, or the Services themselves. We will post any revised Policy at https://www.flyb.app/privacy and indicate the “Effective Date” at the top of the document. For material changes that significantly reduce your rights or expand our processing purposes, we will provide at least thirty (30) days’ advance notice via e-mail or a prominent in-product banner. Your continued use of the Services after the new Policy takes effect constitutes your acceptance of the revised terms.
10. Severability
If any provision of this Policy is found to be unlawful, void, or unenforceable under applicable law, that provision will be interpreted to achieve its intent as closely as possible. If such interpretation is impossible, the provision will be deemed severed from this Policy, and the remaining provisions will remain in full force and effect.
11. Contact Details
If you have questions, concerns, or wish to exercise your privacy rights, please contact us at [email protected]. We aim to respond to verified data-subject requests within thirty (30) days, or as otherwise permitted under applicable law (in which case we will notify you of the delay and the reason).
12. Entire Agreement
This Policy, together with the FlyB General Terms of Service, constitutes the entire agreement between you and FlyB regarding privacy and data protection in connection with the Services.