favst

Privacy Policy

How Favist Inc. collects, uses and shares information when you use Favist.

Effective September 15, 2026Last updated August 30, 2026

This policy explains what Favist Inc. does with information when you use favist.ai and related services. Using the Service means you accept this policy and our Terms of Service.

1. What we collect

2. What we use it for

3. Who we share it with

We do not sell your personal information. We share it with:

4. Google user data and Limited Use

If you connect Google we request only the scopes the feature needs: normally your basic profile and email for sign-in, and where you enable a feature that requires it, read only access to the specific Drive files you choose. Favist's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features you ask for, do not use it for advertising, do not sell it, and do not share it except as needed to run the Service, with your consent, or where the law requires. You can review or revoke access at any time in your Google account security settings.

5. Files you upload and files people send you

When you upload a file, or accept one sent to you through a file drop link or your file inbox, we store it so we can show it back to you. Files are held in our object storage, encrypted in transit and at rest.

We scan them. Files are checked for malware and for content prohibited by our Terms. This is automated. Where a scan flags something, a small number of authorised staff may review it in order to act on it.

Who can see them. Files stay private to your account unless you publish or share them. Someone who sends you a file through your inbox cannot see anything else in your account, and cannot see your email address unless you reply.

How long we keep them. Files stay while your account is active. Files delivered through a file drop link expire after 30 days unless you save them. We may delete content in accounts inactive for 24 months, after at least 30 days notice by email. Deleted files leave active systems promptly and leave backups within [TO BE COMPLETED: backup retention window].

Reporting obligations. Where a scan or a report identifies apparent child sexual abuse material, we report it to the National Center for Missing and Exploited Children and preserve the related material as United States law requires. That obligation overrides the deletion timelines above.

6. Media retrieval

When you use a retrieval tool, we process the address you submit in order to fetch the file and deliver it to you.

What we keep. Where you ask us to save the file to your account or publish it, we store it like any other file of yours. Where you do not, we keep it only for the brief period needed to deliver it, and then it goes. Separately, we log the request itself, meaning the address submitted, a timestamp, and the account or IP it came from, for abuse prevention, security and rate limiting. Those logs are kept for [TO BE COMPLETED: retrieval log retention window] and are not used to build a profile of you.

8. Delivery addresses

If you use gift delivery, we store the delivery address you give us. We disclose it only to the carrier or fulfilment service needed to complete a delivery you have authorised. We never disclose it to the person sending you the gift, which is the entire point of the feature.

You can remove a stored address at any time. We keep delivery records for 12 months so we can help with support questions and disputes.

9. Cookies

We use essential cookies for sign-in and sessions, a short lived preferences store, and an affiliate attribution cookie. You can control cookies in your browser, though disabling the essential ones will break the Service.

10. Retention and deletion

We keep information while your account is active, or for as long as we need it to run the Service and meet legal, accounting and fraud prevention obligations. Deleting your account removes your profile and content from active systems. Residual copies can persist in backups for a limited period. Some records, including copyright notices and reports we are legally required to preserve, outlive account deletion.

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, port or restrict your personal data, and to object to some processing. To use them, write to privacy@favist.ai. We will not treat you differently for exercising them.

12. Security

We use reasonable technical and organisational measures, including row level access controls and encrypted transport, to protect your information. No method is perfectly secure and we cannot guarantee absolute security.

13. Children

The Service is not directed to children under [TO BE COMPLETED: age threshold, matching the Terms], and we do not knowingly collect their personal information. Where we learn that we hold information from a child below that age without the consent the law requires, we delete it. If you believe a child has given us information, write to privacy@favist.ai.

14. International transfers

We and our providers may process information in countries other than yours. Where required, we use appropriate safeguards for those transfers.

15. Changes

We may update this policy. Material changes are posted here with a new effective date, and we give notice in the product or by email where the change is significant.

16. Contact

Controller
Favist Inc., a Delaware corporation
Privacy contact
privacy@favist.ai