Privacy Policy
Last updated: 30 September 2026
This policy explains how feega processes personal data when you use feega.app, its API, CLI and MCP server (the “Service”), under Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003.
1. Controller
Andrea Buttarelli, Italy, VAT no. 16090491008.
Privacy contact: support@feega.app.
When you upload data about other people (for example customers, models or influencers in your brand material), you are the controller of that data and we process it as your processor. The terms are in our Data Processing Agreement.
2. Data we process
Account
What: name, email, password hash or login provider, avatar, language
Source: you
Workspace
What: workspaces, roles, invites (invitee email), API keys (stored hashed)
Source: you, your workspace members
Content
What: prompts, chat messages, canvas nodes, uploaded and generated text, images, video, audio, documents
Source: you, agents acting for you
Brand
What: brand name, website analysis, voice, palette, logo, products imported from your store
Source: you, public web pages and store endpoints
Social
What: connected account handle and profile, access tokens (held by our publishing provider), scheduled and published posts, public posts of profiles you add to a feed
Source: you, the platforms, public sources
Ads
What: Meta ad account identifiers, campaigns, creatives, performance metrics
Source: Meta, on your authorisation
Billing
What: plan, credit balance and ledger, Stripe customer and invoice IDs, billing address/VAT if given
Source: you, Stripe (we never see full card numbers)
Usage logs
What: log of each AI action: action, model, provider, credits, time, acting user or agent
Source: the Service
Moderation
What: for each screened prompt: verdict, category, scores, reason, acting user
Source: the Service
Age verification (NSFW, not yet available)
What: only the result: verified yes/no, provider, method, date — no identity documents
Source: certified verification provider
Technical
What: IP address, browser, device, pages, errors
Source: your device
We do not ask for special categories of data (Art. 9 GDPR). Do not include them in prompts unless necessary.
3. Purposes and legal bases
Provide the Service: accounts, workspaces, canvas, generation, publishing, ads, sharing, API/CLI/MCP
Legal basis: Contract — Art. 6(1)(b)
Billing, credits, invoicing, tax records
Legal basis: Contract; legal obligation — Art. 6(1)(b), (c)
Content moderation, abuse and fraud prevention, security
Legal basis: Legitimate interest — Art. 6(1)(f); legal obligation where applicable
Age verification for NSFW mode
Legal basis: Legal obligation / legitimate interest — Art. 6(1)(c)/(f) [to confirm]
Handling DSA notices and authority requests
Legal basis: Legal obligation — Art. 6(1)(c)
Error monitoring and debugging
Legal basis: Legitimate interest — Art. 6(1)(f)
Anonymous aggregate analytics
Legal basis: Legitimate interest — Art. 6(1)(f)
Full analytics, session replay, advertising measurement
Legal basis: Consent — Art. 6(1)(a)
Service emails (invites, notifications)
Legal basis: Contract / legitimate interest
We do not sell personal data and do not use your content to train AI models. We make no decisions with legal or similarly significant effects based solely on automated processing (Art. 22). Moderation refusals are automated but concern a request, not you; you can contact us to have one reviewed.
4. Recipients (processors)
We share personal data with these categories of recipients, each acting as our processor and only for the purpose shown:
Hosting and database
Purpose: running the Service, storing accounts, content and files, authentication, realtime
Payments
Purpose: subscriptions, top-ups, invoices
AI model providers
Purpose: generating text, images and video from your prompts
Voice and audio AI
Purpose: voice-over, music and sound generation
Content moderation
Purpose: screening prompts before they reach a model
Social publishing
Purpose: connecting social accounts, publishing, reading account metrics and running ad campaigns on your ad account
Data enrichment and scraping
Purpose: reading public websites, stores and social profiles you point us to; web research
Email delivery
Purpose: invites and notifications
Error monitoring
Purpose: detecting and fixing errors (may include user ID, email, IP)
Product analytics
Purpose: understanding how the Service is used (anonymous; full with consent)
Advertising measurement
Purpose: measuring which ads lead to sign-ups (consent)
Age verification
Purpose: NSFW mode, not yet available
The current list of sub-processors is available at https://feega.app/subprocessors.
When you publish, the content goes to the platform you chose (Instagram, Facebook, TikTok, etc.), which becomes an independent controller. When you share a link, anyone holding it can see the shared content. We may disclose data to authorities where required by law.
5. International transfers
Some providers are outside the EEA, mainly in the United States. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses with supplementary measures. Ask us for a copy.
6. Retention
Account, workspace, content
Kept: while the account/workspace exists; deleted within 30 days of closure, backups within 30 days
Deleted canvas nodes
Kept: soft-deleted, then [PURGE PERIOD]
Social access tokens
Kept: until you disconnect the account
Age-verification result
Kept: while the account exists
Invoices and billing records
Kept: 10 years (Italian tax law)
7. Cookies and similar technologies
Strictly necessary: authentication session and preferences. No consent needed.
Anonymous analytics: PostHog in cookieless mode, Vercel Web Analytics, Seline [to confirm cookieless].
With consent only: PostHog with persistent cookies and session recording, Microsoft Clarity session replay, Meta Pixel and the Google gtag.js conversion tag.
You can change your choice at any time via “Cookie preferences”. Details: Cookie Policy.
8. Your rights
You can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest; you can withdraw consent at any time. Write to privacy@feega.app. We answer within one month. You can complain to the Garante per la protezione dei dati personali (garanteprivacy.it) or your local authority.
9. Minors
The Service is for people aged 18 or over. We do not knowingly collect data of minors; if we learn of it, we delete the account. NSFW mode is strictly 18+ and requires verified age.
10. Security
Encryption in transit, row-level access control per workspace, private storage buckets with signed links, hashed API keys, restricted use of privileged credentials, and provider security certifications. No system is perfectly secure; we will notify you and the authority of breaches as required by Art. 33–34 GDPR.
11. Changes
We will update the date above and, for material changes, notify you by email or in the Service.
Questions: support@feega.app