Skip to content

Privacy Policy

Last updated:

This Privacy Policy explains what personal data Factorly collects, how and why we use it, who we share it with, and the rights you have over it. It applies to the Factorly AI app builder and our related websites and services.
On this page
This document is a template provided for convenience and is not legal advice. It should be reviewed and adapted by qualified privacy counsel for your entity, your processing activities, and the jurisdictions you operate in. Bracketed placeholders such as [Controller legal entity] must be completed.

Introduction & scope

Factorly (“Factorly,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard personal data when you use the Factorly websites, applications, APIs, and related services (the “Service”), and the choices and rights you have.

For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), the data controller is [Controller legal entity], [Registered address]. Where we process personal data on your behalf as part of running your projects (for example, data you put into an application you build), we generally act as a processor and you are the controller.

This Policy should be read together with our Terms of Service.

Data we collect

We collect the following categories of personal data:

  • Account information — such as your name, email address, password (stored hashed), profile details, and, if you sign in via a third-party identity provider, the basic profile information it shares.
  • Project content & code — the prompts and instructions you submit, the files and data you upload, and the source code and applications generated for you, together with related metadata (such as project names and checkpoints).
  • Usage & device data — information about how you interact with the Service, including log data, feature usage, build activity and credit consumption, IP address, browser and device type, and timestamps.
  • Payment information — when you subscribe to a paid plan, billing details and transaction records. Card details are collected and processed by our payment processor (Stripe); we do not store full card numbers.
  • Support & communications — the content of messages you send us (for example, support requests or emails) and our responses.
  • Cookies & analytics data — information collected through cookies and similar technologies, as described in the Cookies section below.

You can choose what to put into your prompts and projects. Please avoid submitting sensitive personal data (such as health, biometric, or government-ID data) unless it is necessary and you have an appropriate legal basis and safeguards in place.

How we use your data

We use personal data to:

  • Provide, operate, and maintain the Service — including running the AI agent, building and previewing your applications, and storing your projects and checkpoints;
  • Authenticate you, manage your account, and provide customer support;
  • Process payments, manage subscriptions, and prevent payment fraud;
  • Monitor, secure, and improve the Service, debug issues, measure performance, and develop new features;
  • Enforce our Terms, prevent abuse of our AI and compute resources, and protect the rights, safety, and security of Factorly, our users, and others;
  • Communicate with you about service updates, security notices, and — where permitted — relevant product information, which you can opt out of;
  • Comply with legal obligations and respond to lawful requests.

We do not sell your personal data, and we do not use the content of your private prompts or code to train our own foundation models.

How AI processing works

To deliver the core functionality of the Service, the prompts you write and relevant portions of your project code and context are transmitted to large language model providers that generate the agent’s responses and code. These providers may include AWS Bedrock and the model vendors made available through it (for example, Anthropic and others), and may include other model providers as the Service evolves.

These providers process your Input as our subprocessors, under contractual terms intended to restrict their use of the data to providing inference to us. We select providers that, under their enterprise/API terms, do not use submitted prompts or outputs to train their foundation models. The specific provider used for a given request can depend on the model you select and on availability.

Because AI output is generated probabilistically, it may be inaccurate or incomplete; how we handle output and your responsibility to review it are described in our Terms of Service.

Data sharing & subprocessors

We do not sell personal data. We share it only as needed to run the Service and as described here, with categories of recipients including:

  • Service providers / subprocessors who process data on our behalf under appropriate data-protection terms. As representative examples:
Representative subprocessors and their purpose
SubprocessorPurpose
Amazon Web Services (AWS)Cloud hosting, compute, storage, and AI inference (Bedrock)
LLM providers (e.g., Anthropic, OpenAI)Model inference to generate agent responses and code
StripePayment processing and subscription billing
GitHubSource-control integration when you export or connect a repository

The list above is representative, not exhaustive; we may add or change subprocessors as the Service evolves and will maintain appropriate safeguards. We may also disclose personal data: to comply with law or valid legal process; to protect the rights, property, or safety of Factorly, our users, or the public; and in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

Cookies & tracking

We use cookies and similar technologies to keep you signed in, remember your preferences (such as theme), secure the Service, and understand usage. Strictly necessary cookies are required for the Service to function; analytics and other optional cookies are used only where permitted and, where required, with your consent.

You can control cookies through your browser settings and, where offered, through our cookie controls. Disabling some cookies may affect how the Service works. We honor recognized opt-out signals where legally required.

Data retention

We retain personal data for as long as needed to provide the Service and for the purposes described in this Policy. Account and project data are generally retained while your account is active. After you delete a project or close your account, we delete or anonymize associated personal data within a reasonable period, except for limited residual backups and data we must keep to comply with legal, tax, accounting, or security obligations or to resolve disputes.

Retention periods depend on the type of data and the reason we hold it; we apply criteria such as the data’s purpose, sensitivity, and applicable legal requirements. You can export your code to GitHub before deletion.

Data security

We implement technical and organizational measures designed to protect personal data, including encryption in transit, encryption of secrets, access controls, network and sandbox isolation for build environments, and monitoring. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

You are responsible for using strong, unique credentials, protecting your account, and managing the secrets and data you place into your projects. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities as required by applicable law.

International data transfers

We and our subprocessors may process personal data in countries other than your own, including the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), or other lawful transfer mechanisms — to protect your data. You may request more information about these safeguards using the contact details below.

Your rights

GDPR / UK GDPR rights

Subject to applicable law, you have the right to:

  • Access a copy of the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data (the “right to be forgotten”) in certain circumstances;
  • Restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
  • Port your data — receive it in a structured, commonly used, machine-readable format;
  • Withdraw consent at any time where processing is based on consent;
  • Lodge a complaint with your local data protection authority.

California (CCPA/CPRA) rights

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion of your personal information, to correct inaccurate information, and to not be discriminated against for exercising your rights. We do not sell or “share” personal information as those terms are defined under California law.

To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by applicable law and may need to verify your identity. You may use an authorized agent where permitted.

Children's privacy

The Service is not directed to children, and you must be at least 18 years old (or the age of majority in your jurisdiction) to use it. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice — for example, by posting the updated Policy with a new “Last updated” date and, where appropriate, by notifying you in the product or by email. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy where permitted by law.

Contact & data protection

If you have questions about this Policy or how we handle your personal data, or if you wish to exercise your rights, contact our privacy team at [email protected].

Data controller: [Controller legal entity], [Registered address]. If we have appointed a Data Protection Officer or an EU/UK representative, their contact details will be provided here. These details are placeholders to be completed for your entity.