Privacy Policy
Last updated: July 20, 2026 · Version 2.0 · pursuant to Articles 13–14 GDPR
This policy explains how Bouncyloop Technologies S.r.l. (Italy — the "Controller", "we") processes personal data in connection with the Favilla service. It covers two very different groups: our users (Section A) and the creators and commenters whose public content we analyze (Section B). Contact for anything in this policy: privacy@favilla.ai.
Section A — Users of the Service
1. Data we process about users
- Account data: email address, authentication identifiers (including Google sign-in via Supabase), plan and preferences.
- Billing data: subscription and payment records. Card details are processed by Stripe; we never see or store card numbers.
- Usage data: searches you run, reports generated, credits ledger, API-token usage, technical logs and — if an error occurs — diagnostic data in our error-tracking tool (no personal profiling, no PII beyond what the error context strictly contains).
- Agency branding (optional): the name and logo you upload for white-label exports.
2. Purposes and legal bases (users)
- Providing the Service, billing and support — performance of a contract (Art. 6(1)(b) GDPR).
- Transactional email (report ready, monitoring alerts, weekly digest for channels you monitor) — performance of a contract; you can stop monitoring at any time.
- Security, abuse prevention, error tracking — legitimate interest (Art. 6(1)(f)).
- Legal obligations (tax, accounting) — legal obligation (Art. 6(1)(c)).
3. Cookies
Favilla uses one strictly-necessary cookie (your session token) and no advertising, profiling or third-party tracking cookies. For this reason no cookie banner is required. If this changes, this policy and the site will be updated first.
Section B — Creators and audiences analyzed
4. What we collect and why it is lawful
When a user requests an analysis, we collect publicly available content and metadata about the requested channel/profile from platform APIs and reputable data providers: video/post metadata and statistics, public transcripts or speech-to-text of public videos, thumbnails, on-screen text, public comments (author display name, text, like counts) and public profile information. We do not access private accounts, private messages, or any data behind a login.
Legal basis: our and our users' legitimate interest (Art. 6(1)(f) GDPR) in market, media and competitive research on content that the data subjects themselves directed to the general public. Balancing safeguards we apply: only public data; analysis for professional research purposes; claims in reports are tied to verbatim quotes of what was actually published; spam and low-value personal chatter are discarded from analyses; comment authors are not profiled individually — comments are analyzed in aggregate to describe an audience, not a person.
Assessments of creators (e.g. brand-safety scans) quote the exact public passage on which every flag is based, are labelled as automated signals requiring human review, and are contractually restricted: our Terms prohibit using them for employment, credit, insurance, housing or any similar eligibility decision.
5. Information notice to analyzed persons (Art. 14 GDPR)
Given that analyses cover potentially very large numbers of data subjects (e.g. tens of thousands of comment authors per channel), notifying each person individually would involve disproportionate effort within the meaning of Art. 14(5)(b) GDPR. This publicly available policy serves as the public information notice. Creators who are analyzed can exercise all rights below at any time.
6. Your rights if you are an analyzed creator — removal
If you are a creator (or commenter) and object to the processing of your public data by Favilla, write to privacy@favilla.ai from an address or account that lets us verify you control the channel/profile concerned. We will handle objection and erasure requests (Arts. 17 and 21 GDPR) within 30 days: on acceptance we delete the stored analyses and raw data for your channel and exclude it from future analyses and from our anonymous benchmark corpus. Note that we cannot remove your content from the platforms themselves, and aggregate, fully-anonymized statistics that no longer relate to you may be retained.
Section C — Common provisions
7. Processors and recipients
We use a small number of processors, bound by data-processing agreements:
- Fly.io (application hosting — Frankfurt, EU region)
- Supabase (database, authentication, file storage)
- Vercel (website hosting)
- Stripe (payments)
- Anthropic (AI analysis of the collected public content)
- OpenAI (speech-to-text of public videos, where enabled)
- Apify and other data providers (collection of public platform data)
- Resend (transactional email)
- Sentry (error tracking — EU ingestion)
- Upstash (job queue)
We do not sell personal data and we do not share it with advertisers or data brokers.
8. International transfers
Some processors are located in the United States. Transfers rely on adequacy mechanisms: the EU–US Data Privacy Framework where the provider is certified, or Standard Contractual Clauses with supplementary measures. Copies of the relevant safeguards can be requested at privacy@favilla.ai.
9. Retention
- Account and billing data: for the life of the account and then as required by tax law (10 years for accounting records in Italy).
- Analyses and collected public data: while the Service operates, so reports remain consultable — or until an accepted removal request (Section 6) or account deletion.
- Technical logs and error events: up to 90 days.
- Benchmark corpus: aggregated, channel-level metrics without user linkage; removed channels are excluded.
10. Your GDPR rights (everyone)
Access, rectification, erasure, restriction, portability and objection (Arts. 15–22 GDPR) — write to privacy@favilla.ai. You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la Protezione dei Dati Personali — or the authority of your habitual residence.
11. United States residents
We do not sell or "share" (for cross-context behavioural advertising) personal information, and we do not use it for automated decisions producing legal effects on consumers. If a US state privacy law (e.g. the CCPA/CPRA) applies to you, you may exercise rights of access, deletion and correction via privacy@favilla.ai; we will not discriminate against you for doing so. Analyzed public data may fall under the "publicly available information" exemption of those laws; we honour removal requests regardless, as described in Section 6.
12. Security
Data is encrypted in transit; secrets are stored in managed vaults; access is restricted and logged; API tokens are stored only as hashes; payments never touch our servers. No system is perfectly secure: if a breach affects your data we will notify you and the competent authority as required by Arts. 33–34 GDPR.
13. Children
The Service is not directed to minors and accounts are restricted to users 18+. Public content analyzed may incidentally include comments by minors published on public platforms; such data is processed only in aggregate and can be removed on request.
14. YouTube API Services
Favilla uses YouTube API Services for YouTube data. By using those features you acknowledge the Google Privacy Policy. Favilla does not access private YouTube account data of analyzed channels.
15. Changes and contact
We may update this policy; material changes will be announced on the site with a new "last updated" date. Controller: Bouncyloop Technologies S.r.l. — contact: privacy@favilla.ai.