Privacy Policy

Last updated: November 25, 2025

1. Introduction

Welcome to fyltr.ai ("we," "our," or "us"). We are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

fyltr.ai is a privacy-first AI assistant that filters and prioritizes your communications across multiple platforms including email, YouTube, messengers (WhatsApp, Telegram, etc.), and social media. We believe in transparency and user control over data.

Key Privacy Principles:

  • Your data stays with you (self-hosted option available)
  • We never sell your data to third parties
  • You can delete your data at any time
  • End-to-end encryption for sensitive communications
  • Open-source code for full transparency

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Name (optional)
  • Password (encrypted and hashed)
  • Profile preferences and settings

2.2 Connected Platform Data

When you connect third-party platforms to fyltr.ai, we access and process:

📧 Email (Gmail, Outlook, etc.)

  • Email messages (subject, sender, content, attachments)
  • Email metadata (date, labels, read status)
  • Contact information from emails
  • Email drafts (for composition assistance)

Why we need this: To filter, prioritize, and manage your email communications according to your preferences.

🎥 YouTube Data

  • Video subscriptions and channels
  • Video comments (public and your own)
  • Watch history and preferences
  • Liked videos and playlists
  • Channel notifications settings

Why we need this: To filter video content, manage comment notifications, prioritize channels, and reduce information overload from subscriptions.

Google OAuth Compliance: fyltr.ai's use and transfer of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements.

💬 Messenger Apps (WhatsApp, Telegram, Signal, etc.)

  • Message content and metadata
  • Contact information
  • Group chat information
  • Media files (photos, videos, documents)
  • Message read/delivery status

Why we need this: To filter messages, prioritize important conversations, and provide unified inbox management.

Encryption: We preserve end-to-end encryption where supported by the platform. For self-hosted instances, all message data remains on your device.

📱 Social Media (Twitter, LinkedIn, Reddit, etc.)

  • Posts and comments from your feed
  • Notifications and mentions
  • Direct messages (if authorized)
  • Following/followers lists

Why we need this: To filter your social media feeds and prioritize meaningful interactions.

2.3 Usage Data

  • Feature usage patterns and preferences
  • Filter configurations and custom rules
  • AI training feedback (opt-in)
  • Performance metrics (response times, error logs)
  • Device information (browser type, OS, IP address)

2.4 Cookies and Tracking

We use minimal cookies for:

  • Authentication and session management
  • User preferences and settings
  • Analytics (Google Analytics) - can be disabled

3. How We Use Your Information

3.1 Primary Uses

  • Filtering and Prioritization: Analyze and categorize communications based on your preferences
  • AI Processing: Train personalized AI models to improve filtering accuracy (local processing available)
  • Notifications: Send alerts for high-priority messages
  • Composition Assistance: Help draft responses and manage outbound communications
  • Search and Organization: Index and make your communications searchable
  • Analytics: Provide insights into your communication patterns

3.2 We DO NOT Use Your Data To:

  • ❌ Sell or rent to third parties
  • ❌ Display targeted advertising
  • ❌ Train AI models for other users (unless explicitly opted-in)
  • ❌ Share with data brokers
  • ❌ Profile you for marketing purposes

4. Data Storage and Security

4.1 Where We Store Data

You have two options:

  • Cloud-Hosted: Encrypted storage on secure servers (AWS/GCP) in your region
  • Self-Hosted: All data stays on your device or private server (recommended for maximum privacy)

4.2 Security Measures

  • End-to-end encryption for sensitive communications
  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Regular security audits and penetration testing
  • OAuth 2.0 for third-party platform authentication
  • Two-factor authentication (2FA) support
  • Automatic security patches and updates
  • Zero-knowledge architecture for passwords

4.3 Data Retention

We retain your data as follows:

  • Active Account: Data retained while account is active
  • Deleted Account: All data permanently deleted within 30 days
  • Platform Disconnection: Platform-specific data deleted within 7 days
  • Logs and Analytics: Anonymized logs retained for 90 days

5. Data Sharing and Disclosure

5.1 Third-Party Services

We only share data with essential service providers:

  • Cloud Infrastructure: AWS/GCP (encrypted storage only)
  • AI Processing: OpenAI/Anthropic (only if using cloud AI features, can be disabled)
  • Analytics: Google Analytics (can be disabled)
  • Payment Processing: Stripe (for paid plans)

All third-party providers are contractually required to protect your data and use it only for specified purposes.

5.2 Legal Requirements

We may disclose information if required by law:

  • In response to valid legal requests (subpoenas, court orders)
  • To protect our rights, safety, or property
  • To prevent fraud or security threats
  • With your explicit consent

We will notify you of legal requests unless prohibited by law.

5.3 Business Transfers

If fyltr.ai is acquired or merged, your data may be transferred. You will be notified and given the option to delete your account before any transfer.

6. Your Privacy Rights

You have the following rights under GDPR, CCPA, and other privacy laws:

🔍 Right to Access

Request a copy of all personal data we hold about you. Available via Settings → Privacy → Export Data.

✏️ Right to Rectification

Correct any inaccurate personal data. Update directly in your account settings.

🗑️ Right to Deletion

Delete your account and all associated data at any time. Settings → Account → Delete Account.

📦 Right to Data Portability

Export your data in machine-readable formats (JSON, CSV). Available in account settings.

⛔ Right to Restrict Processing

Limit how we use your data. Disable specific features or integrations.

🚫 Right to Object

Object to processing for specific purposes. Contact us to exercise this right.

🔓 Right to Revoke Consent

Disconnect any connected platform instantly. Settings → Connected Apps → Disconnect.

To exercise any of these rights, contact us at privacy@fyltr.ai or use the in-app tools.

7. Google API Services - Specific Disclosures

7.1 YouTube API Services

fyltr.ai uses YouTube API Services. By using our YouTube integration, you agree to be bound by the YouTube Terms of Service.

What We Access:

  • Your YouTube subscriptions and channels
  • Video comments (to manage notifications)
  • Video metadata (titles, descriptions, thumbnails)
  • Channel activity and notifications

How We Use YouTube Data:

  • Filter and prioritize video content from subscriptions
  • Manage comment notifications and replies
  • Provide unified search across video content
  • Create custom filtering rules for channels/topics

Limited Use Disclosure:

fyltr.ai's use of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements. This means:

  • We only use YouTube data to provide and improve fyltr.ai features
  • We do not transfer YouTube data to third parties (except as necessary for providing the service)
  • We do not use YouTube data for advertising or similar services
  • We do not allow humans to read your YouTube data (except with consent for support)

Revoking Access:

You can revoke fyltr.ai's access to your YouTube data at any time via the Google security settings page or through your fyltr.ai account settings.

You can also view Google's Privacy Policy at https://policies.google.com/privacy.

7.2 Gmail API Services

When you connect Gmail to fyltr.ai, we access your email data using Gmail API. This access is subject to Google's API Services User Data Policy.

What We Access:

  • Email messages (subject, body, attachments)
  • Email metadata (sender, recipient, date, labels)
  • Contact information
  • Draft messages

How We Use Gmail Data:

  • Filter and prioritize emails based on your rules
  • Provide unified inbox across all email accounts
  • Assist with email composition and responses
  • Search and organize email content

Revoking Access:

Revoke access via Google security settings or fyltr.ai account settings.

8. International Data Transfers

If you are located outside the United States, your data may be transferred to and processed in the US or other countries where our service providers operate.

We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all third-party processors
  • Compliance with EU-US Data Privacy Framework (when applicable)
  • Regional data center options (EU, Asia-Pacific)

9. Children's Privacy

fyltr.ai is not intended for children under 13 years of age (or 16 in the EU). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@fyltr.ai.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For material changes, we will:

  • Send an email notification to your registered email address
  • Display a prominent notice in the application
  • Require acceptance for continued use (for significant changes)

We encourage you to review this Privacy Policy periodically.

11. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Email: privacy@fyltr.ai

Support: support@fyltr.ai

Data Protection Officer: dpo@fyltr.ai

Address: [Your Company Address]

For EU residents, you also have the right to lodge a complaint with your local data protection authority.

12. Open Source Transparency

fyltr.ai is open-source software. You can review our code and privacy implementations on GitHub:

https://github.com/fyltr

We encourage security researchers to audit our code and report vulnerabilities responsibly to security@fyltr.ai.

Acknowledgment

By using fyltr.ai, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. If you do not agree with this policy, please do not use our service.