Privacy Policy
Last updated September 9, 2026
1. Who we are
Fyptic is a campaign platform for music and brand marketing teams. We help teams plan sound campaigns, work with creators, track the posts that go live, and share results with their clients. This policy explains what information we handle, why, and how it is protected. Questions: info@fyptic.com.
2. Account and workspace information
When your team signs up we store the details needed to run your workspace: name, email address, sign-in credentials handled by our authentication provider, your role in the workspace, and workspace settings such as plan, limits, branding, logo and support email.
Each customer gets its own workspace. Staff only ever see the workspace they belong to, and nobody can add themselves to a workspace or promote their own role from the app.
3. Campaign and client data
We store the campaigns, budgets, proposals, lineups, creator lists, drafts, tasks, notes, tracker entries and payout records your team creates. Uploaded files — campaign covers, draft videos, post thumbnails and brand logos — are kept in private storage and only served to people who are authorised to see them.
4. Creator information
For creators in a roster we store handles and profile links, public profile figures such as follower counts and engagement, contact details your team adds (email, phone, messaging handles), agreed rates, payment handles and payout history, plus notes and tags your team writes.
Rates, margins, payment details and internal reliability notes are never shown on client-facing pages or share links.
5. Public social data we collect
To track campaigns we collect publicly available information from TikTok, Instagram, YouTube and X: post links, captions, thumbnails, view, like, comment, share and save counts, posting dates, and public profile statistics. This is gathered by direct page reads and by third-party data providers.
We also support backfilling an entire public page or channel so a fan-page campaign can track its full post history. We do not access private accounts, direct messages, or anything that requires logging in as a creator.
Stats are refreshed automatically on a recurring schedule so campaign reporting stays current.
6. Audio recognition and AI features
To confirm that a post really uses a campaign's song, short audio samples from public posts are sent to audio-recognition services for matching. Samples are used for matching only.
Some features use AI models to summarise or score public comment content (for example sentiment and relevance) and to help with drafting text. Content sent to these models is used to produce the result shown in the app and is not used by us to train models.
7. Client and portal access
Clients do not create accounts. They reach a campaign, proposal or results page through a share link, which can be protected with a passcode. Those pages show masked, client-safe figures only — never influencer cost, margin or payout details. We log which links are opened so your team can see engagement and spot broken links.
8. Messages and notifications
If your team uses outreach, we store the emails and text messages sent through Fyptic along with their delivery status and any replies received, so conversations stay attached to the right creator and campaign.
In-app alerts and browser push notifications are optional. If you turn on push, we store a device notification token so alerts can reach that device, and you can turn them off at any time in your browser or phone settings. Alerts are removed after 60 days.
9. SMS/Text messaging
Fyptic sends SMS/text messages to creators and users who have opted in. Creators opt in by texting a keyword (such as START or YES) to our messaging number, confirming consent before any campaign messages are sent.
Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. Phone numbers are used solely to deliver the SMS messages you have consented to receive, and are processed on our behalf by our SMS provider (Twilio) only to transmit those messages.
Message frequency varies based on account and campaign activity. Message and data rates may apply.
You can opt out of SMS at any time by replying STOP, and you can reply HELP for assistance. Replying STOP will unsubscribe you from further messages.
10. Payments
Subscription billing and creator payouts are processed by Stripe. Card details are handled by Stripe and never stored on our servers. We keep payment records — amount, status, date, related creator and campaign — for accounting and reporting.
11. Service providers
We rely on: Supabase (database, authentication and file storage), Cloudflare (hosting and delivery), Stripe (payments), Resend (email), Twilio (text messaging), Slack (optional team alerts to your own workspace), Firebase Cloud Messaging (browser push), Google (YouTube data and optional Google sign-in), third-party social data providers, audio-recognition providers, AI model providers, and Microsoft Clarity (website analytics).
Each receives only the information needed to perform its function, and acts as a processor on our behalf. Twilio, for example, receives a mobile number only to transmit the messages you have consented to receive, and may not use it for its own purposes. We do not sell personal information, and we do not share mobile opt-in data or phone numbers with third parties for their own marketing or advertising.
12. Cookies and website analytics
We use cookies and similar storage that keep you signed in and remember preferences such as filters and view settings. On our public website we use Microsoft Clarity to understand how pages are used. You can block cookies in your browser, but sign-in will not work without them.
13. How long we keep data
Workspace, campaign, creator and payment records are kept for as long as your workspace is active, and afterwards only as long as needed for legal, tax and accounting purposes. Notifications are removed after 60 days. Performance snapshots are kept to preserve historical campaign reporting. Demo requests are kept until handled and then periodically cleared.
14. Security
Data is encrypted in transit. Every table enforces workspace-level access rules, so a signed-in user only ever reads their own workspace's rows. Uploaded files sit in private storage behind workspace-scoped permissions and are served through authorised links, never public URLs. Sensitive settings such as messaging and email credentials cannot be read from the browser. Access to production data is limited to a small number of people. Report a security concern to info@fyptic.com.
15. Your rights
You can request access to, correction of, export of, or deletion of your personal information, and creators can ask to have their profile and contact details removed from a roster. Email info@fyptic.com and we will respond within 30 days. Where we act on behalf of a customer workspace, we will pass the request to that customer.
16. International transfers and children
Our providers may process data in the United States and other countries, with appropriate safeguards in place. Fyptic is a business tool and is not intended for anyone under 16.
17. Changes and contact
We will update this page when our practices change and adjust the date above. For any privacy question or request, contact info@fyptic.com.