Privacy Policy

Last updated: 30 September 2026

This policy explains how feega processes personal data when you use feega.app, its API, CLI and MCP server (the “Service”), under Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003.

1. Controller

Andrea Buttarelli, Italy, VAT no. 16090491008.
Privacy contact: support@feega.app.

When you upload data about other people (for example customers, models or influencers in your brand material), you are the controller of that data and we process it as your processor. The terms are in our Data Processing Agreement.

2. Data we process

Account

What: name, email, password hash or login provider, avatar, language

Source: you

Workspace

What: workspaces, roles, invites (invitee email), API keys (stored hashed)

Source: you, your workspace members

Content

What: prompts, chat messages, canvas nodes, uploaded and generated text, images, video, audio, documents

Source: you, agents acting for you

Brand

What: brand name, website analysis, voice, palette, logo, products imported from your store

Source: you, public web pages and store endpoints

Social

What: connected account handle and profile, access tokens (held by our publishing provider), scheduled and published posts, public posts of profiles you add to a feed

Source: you, the platforms, public sources

Ads

What: Meta ad account identifiers, campaigns, creatives, performance metrics

Source: Meta, on your authorisation

Billing

What: plan, credit balance and ledger, Stripe customer and invoice IDs, billing address/VAT if given

Source: you, Stripe (we never see full card numbers)

Usage logs

What: log of each AI action: action, model, provider, credits, time, acting user or agent

Source: the Service

Moderation

What: for each screened prompt: verdict, category, scores, reason, acting user

Source: the Service

Age verification (NSFW, not yet available)

What: only the result: verified yes/no, provider, method, date — no identity documents

Source: certified verification provider

Technical

What: IP address, browser, device, pages, errors

Source: your device

We do not ask for special categories of data (Art. 9 GDPR). Do not include them in prompts unless necessary.

3. Purposes and legal bases

Provide the Service: accounts, workspaces, canvas, generation, publishing, ads, sharing, API/CLI/MCP

Legal basis: Contract — Art. 6(1)(b)

Billing, credits, invoicing, tax records

Legal basis: Contract; legal obligation — Art. 6(1)(b), (c)

Content moderation, abuse and fraud prevention, security

Legal basis: Legitimate interest — Art. 6(1)(f); legal obligation where applicable

Age verification for NSFW mode

Legal basis: Legal obligation / legitimate interest — Art. 6(1)(c)/(f) [to confirm]

Handling DSA notices and authority requests

Legal basis: Legal obligation — Art. 6(1)(c)

Error monitoring and debugging

Legal basis: Legitimate interest — Art. 6(1)(f)

Anonymous aggregate analytics

Legal basis: Legitimate interest — Art. 6(1)(f)

Full analytics, session replay, advertising measurement

Legal basis: Consent — Art. 6(1)(a)

Service emails (invites, notifications)

Legal basis: Contract / legitimate interest

We do not sell personal data and do not use your content to train AI models. We make no decisions with legal or similarly significant effects based solely on automated processing (Art. 22). Moderation refusals are automated but concern a request, not you; you can contact us to have one reviewed.

4. Recipients (processors)

We share personal data with these categories of recipients, each acting as our processor and only for the purpose shown:

Hosting and database

Purpose: running the Service, storing accounts, content and files, authentication, realtime

Payments

Purpose: subscriptions, top-ups, invoices

AI model providers

Purpose: generating text, images and video from your prompts

Voice and audio AI

Purpose: voice-over, music and sound generation

Content moderation

Purpose: screening prompts before they reach a model

Social publishing

Purpose: connecting social accounts, publishing, reading account metrics and running ad campaigns on your ad account

Data enrichment and scraping

Purpose: reading public websites, stores and social profiles you point us to; web research

Email delivery

Purpose: invites and notifications

Error monitoring

Purpose: detecting and fixing errors (may include user ID, email, IP)

Product analytics

Purpose: understanding how the Service is used (anonymous; full with consent)

Advertising measurement

Purpose: measuring which ads lead to sign-ups (consent)

Age verification

Purpose: NSFW mode, not yet available

The current list of sub-processors is available at https://feega.app/subprocessors.

When you publish, the content goes to the platform you chose (Instagram, Facebook, TikTok, etc.), which becomes an independent controller. When you share a link, anyone holding it can see the shared content. We may disclose data to authorities where required by law.

5. International transfers

Some providers are outside the EEA, mainly in the United States. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses with supplementary measures. Ask us for a copy.

6. Retention

Account, workspace, content

Kept: while the account/workspace exists; deleted within 30 days of closure, backups within 30 days

Deleted canvas nodes

Kept: soft-deleted, then [PURGE PERIOD]

Social access tokens

Kept: until you disconnect the account

Age-verification result

Kept: while the account exists

Invoices and billing records

Kept: 10 years (Italian tax law)

7. Cookies and similar technologies

  • Strictly necessary: authentication session and preferences. No consent needed.

  • Anonymous analytics: PostHog in cookieless mode, Vercel Web Analytics, Seline [to confirm cookieless].

  • With consent only: PostHog with persistent cookies and session recording, Microsoft Clarity session replay, Meta Pixel and the Google gtag.js conversion tag.

You can change your choice at any time via “Cookie preferences”. Details: Cookie Policy.

8. Your rights

You can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest; you can withdraw consent at any time. Write to privacy@feega.app. We answer within one month. You can complain to the Garante per la protezione dei dati personali (garanteprivacy.it) or your local authority.

9. Minors

The Service is for people aged 18 or over. We do not knowingly collect data of minors; if we learn of it, we delete the account. NSFW mode is strictly 18+ and requires verified age.

10. Security

Encryption in transit, row-level access control per workspace, private storage buckets with signed links, hashed API keys, restricted use of privileged credentials, and provider security certifications. No system is perfectly secure; we will notify you and the authority of breaches as required by Art. 33–34 GDPR.

11. Changes

We will update the date above and, for material changes, notify you by email or in the Service.