Who we are
Fylow (“Fylow”, “we”, “us”) is a macOS application and related services operated from California, United States. This policy explains what personal information we collect, why, and the choices you have. It applies to the Fylow app, the fylow.ai website, and our checkout and account services.
Questions or requests: privacy@fylow.ai.
The short version
- Your files live on your Mac. Fylow processes them locally by default; file content travels off your Mac only for a specific request you make, only when you have turned Content Access on, and only as the minimal excerpt needed to answer.
- The app contains no analytics, no crash reporting, and no advertising or tracking technology. We do not sell personal information, and the only parties that receive any of it are the service providers that run Fylow, listed below.
- We do store a small set of account records on our servers: your email address, license and subscription status, and usage metering. Those are described in full below.
- Payments are handled by Stripe. We never see card numbers.
What stays on your Mac
The following data is created and kept locally on your device. It is not uploaded to us or anyone else, and we cannot access it:
- Your files and the folder structure Fylow organizes.
- The content index built when Content Access is on (document text and on-device image labels), stored as a local database. Indexing runs entirely on your Mac. Turning Content Access off locks the index.
- Vault copies — the local backups Fylow makes before moving a file, which power undo.
- Chat transcripts— your conversation history with Fylow, stored as files in the app’s container.
- Sorting rules, projects, history, and preferences.
What we collect and store on our servers
To sell licenses and run the service, we keep a deliberately small set of records:
- Account and license records: your email address, license key, subscription tier and status, and the dates those changed. Your license key is delivered to your email address.
- Device registration: a cryptographic public key generated on your Mac when the app first activates, used to authenticate requests from your install. Because it identifies your install and is tied to your license, it counts as a pseudonymous identifier in the legal sense; it cannot read anything on your device.
- Usage metering: counts and costs of AI requests made under your license (numbers only — request sizes, unit counts, and timestamps), including a short report after a bulk folder sort (run id, how many files moved, error codes — kept 90 days). Metering never includes file names, file content, or chat content.
- Billing metadata: Stripe customer and subscription identifiers, and a one-way hash we compute from the card fingerprint Stripe provides, used to prevent free-tier abuse. We do not receive or store card numbers.
- Security data: hashed network-address records used for rate limiting and abuse detection (like spotting a shared license key). Addresses are hashed with a salt that rotates daily — we never store raw IP addresses. Rate-limit counters expire within hours; the license record keeps a rolling 24-hour window of these hashes plus the most recent one, which is replaced on your next request.
- Signup and waitlist emails: if you start a checkout or join a waitlist, we keep the email address you entered for that purpose.
- Correspondence: emails you send us (support, privacy requests) and our replies.
That is the complete list of what we deliberately collect. Beyond it there are only the mechanics of running a service: our hosting providers keep standard, content-free infrastructure logs, and the app checks our server for updates (at launch and roughly daily) — a request that carries only the app version. No behavioral analytics, no crash reports, no advertising identifiers.
File content and AI processing
Fylow’s AI features run through our own servers, which relay requests to an AI inference provider under a contractual zero-data-retention arrangement: request content is processed in memory, is not stored by the provider, and is not used to train models. Our servers verify the provider’s zero-retention confirmation on every model response and refuse responses without it. Voice transcription doesn’t return a per-response confirmation; it is covered by the same contractual arrangement.
- By default (Content Access off), AI requests carry the working context Fylow needs to sort and answer: file names and metadata, your folder names and structure, and the short profile (name, about-text) you typed into Settings — never file contents.
- When you turn Content Access on, Fylow may read file content to serve a specific request you make. For a chat question, that means the single best candidate file and the excerpt needed to answer. For a bulk folder sort you start, it means short text excerpts — and for images, the image itself — from the files in that folder, within hard per-run limits, because that is the job you asked for. There is no background upload and no bulk sync, ever.
- Voice input works the same way. When you speak to Fylow, the audio is sent through our servers to the AI provider for transcription, along with your folder and project names and custom vocabulary so the transcript resolves to the names you actually use — processed in memory under the same zero-retention arrangement, and not stored. We keep the request metering (duration-based cost), never the audio or transcript.
- We do not store file content. Excerpts and audio pass through our servers to the AI provider and are not written to disk, logged, or retained by us.
- Per-file control: anything on your privacy list is never read, regardless of mode.
What we don't do
- We do not sell personal information, and we do not share it for advertising of any kind. The only disclosures are to the service providers listed below, so Fylow can run.
- We do not use your data for advertising, ours or others’.
- We do not train AI models on your files or conversations.
- We do not embed third-party analytics or trackers in the app or on this website.
Service providers
We use a small number of providers to run Fylow. Each receives only what its job requires:
- Stripe — payment processing, checkout, and the billing portal. Stripe handles your card details under its own privacy policy.
- Cloudflare — hosts our servers and this website, and stores the account records described above.
- Resend — delivers license and account emails to your address.
- AI inference provider — processes AI requests under contractual zero data retention, as described above.
Cookies
This website sets no analytics or advertising cookies. Stripe may set cookies on its checkout and billing portal pages as part of payment processing and fraud prevention; those are governed by Stripe’s policies.
How long we keep things
- Account and license records — for as long as your license exists, plus what tax and accounting law requires us to retain about transactions.
- Usage metering — retained to operate billing and abuse prevention, tied to the life of the license.
- Rate-limiting counters— expire automatically within hours; the license record’s hashed-address window covers 24 hours, as described above.
- Card-fingerprint hash— retained for abuse prevention for as long as the free-tier program needs it, including after a license ends, so one card can’t mint endless free accounts.
- File content — not retained at all, by us or the AI provider.
Your rights and choices
You can ask us to access, correct, or delete the personal information we hold about you by emailing privacy@fylow.ai from the address on your account. We answer every request, wherever you live; California (CCPA/CPRA) and EEA/UK (GDPR) residents have these rights by law, including the right to complain to a supervisory authority. We will never discriminate against you for exercising them.
One honest scope note: requests can only cover the server records listed above. Everything on your Mac — files, index, vault, transcripts — is under your control, not ours; deleting the app and its container removes it.
Deleting your account records ends your license, since the license is the record. We may retain transaction records the law requires us to keep.
Children
Fylow is not directed to children under 13 (or under 16 where the GDPR sets that age), and we do not knowingly collect their personal information. The student plan is for higher-education students with a school email address.
International transfers
We operate from the United States, and the records described above are processed there (and on Cloudflare’s global network). If you use Fylow from outside the US, your account information is transferred to the US.
Changes to this policy
If we change this policy, we’ll update it here with a new date. If a change meaningfully affects what we collect or how we use it, we’ll tell license holders by email before it takes effect.
Contact
privacy@fylow.ai for privacy matters, support@fylow.ai for everything else.
See also: Your privacy (the plain-English version) and our Terms of Service.