Your media. Your device.
Privacy information for the current website preview and the planned commercial service.
Controller details, service providers, retention periods and rights-request procedures must be completed before the commercial service opens.
Editing media
The SDK processes editing and export on-device. Host applications control any subsequent uploads or sharing and must provide their own privacy information.
This website preview
Account authentication uses Supabase to process your email, password credentials and session. Account profiles store your name; role records control access. Payments are processed by Paddle when purchasing is available. Registered app identifiers, subscription records and license-key digests and encrypted license keys are stored in Supabase. Analytics are not integrated. When you send a contact inquiry, Supabase stores your name, reply email, optional company, topic, message, submission date and its read status. Only authorized administrators can view the inbox. We use this information to respond to your inquiry. Contact-message retention and rights-request procedures must be finalized before commercial launch.
Abuse prevention
Authentication forms use Cloudflare Turnstile security checks, with verification by Supabase. The contact form also uses Turnstile, with tokens verified directly by our website server before storing an inquiry. We store hashed email or account identifiers for request limits; counters older than 24 hours are removed on the next counter operation. To prevent repeat app evaluations, we retain platform identifier hashes and claim dates separately from account records, including after account deletion. These hashes are not guaranteed anonymous. Retention and rights procedures for this abuse-prevention history must be finalized before commercial launch.
Online license checks
The SDK sends a license key and the app’s bundle ID or application ID to Fayblu over HTTPS to check access. It does not send editing media, device advertising IDs or end-user account details. The licensing application does not log raw keys or request bodies; hosting providers may process network metadata. Production providers, legal bases, log retention and rights procedures still need to be finalized.
Before launch
The final policy must identify the responsible company and privacy contact, explain applicable rights and transfers, and describe actual production logging and storage. This draft is not a statement of GDPR compliance.