Privacy Policy
Last Updated: May 25, 2026 · Flyzle is operated by KROMA UG (haftungsbeschränkt), Bremen, Germany.
Data Controller: KROMA UG (haftungsbeschränkt), Bremen
1. General Provisions
This privacy policy describes how KROMA UG (haftungsbeschränkt) collects, uses and protects your personal data when using the Flyzle service in accordance with the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
2. Data Controller
Responsible for data processing:
KROMA UG (haftungsbeschränkt)
Halberstädter Straße 17
28215 Bremen, Germany
Email: [email protected]
DPO: [email protected]
3. Collected Data
- Account information (email address, display name)
- Generated content and strategies
- Brand settings (logo, name, slogan)
- Technical information (IP address, browser type, visit time)
- Usage data to improve user experience
- Payment data processed by our Merchant of Record (Polar)
Legal Basis: Art. 6 Para. 1 lit. a, b GDPR (Consent, Contract Performance)
4. Use of Data
- Provision and improvement of our AI-powered content generation services
- Personalization of generated content based on your brand settings
- Usage analysis for platform development
- Ensuring service security
- Fulfillment of legal obligations
5. AI-Generated Content
Flyzle uses third-party AI models to generate text and images. Your brand data (name, slogan, URL) is sent to AI providers solely for content generation. We do not use your data to train AI models. Generated content belongs to you and can be used freely for commercial purposes.
6. Data Storage and Security
Your data is stored on secure servers provided by our infrastructure partner. We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
7. Third-Party Services
- Polar — Payment processing (Merchant of Record)
- AI Providers — Content generation (Google, OpenAI)
- Social Media Integration Provider — Processing of social media account connections, post scheduling, publishing, and analytics. When you connect a social media account, your account authorization data (OAuth tokens) is processed by a third-party API provider located within the EU. This provider acts as a data processor under Art. 28 GDPR.
- Hosting Infrastructure — Data storage and processing
7a. Social Media Account Connections
When you connect a social media account (e.g., Instagram, LinkedIn, TikTok), you are redirected to the respective platform's authorization page (OAuth). Flyzle does not access or store your social media passwords. We only receive and store the authorization tokens granted by the platform, which allow us to publish content and retrieve analytics on your behalf.
You may disconnect any social media account at any time through the Platforms tab in your strategy settings. Upon disconnection, authorization tokens are immediately revoked and deleted.
Data processed: Platform username, profile image, authorization tokens, post content and media you choose to publish, and publicly available engagement metrics (likes, comments, reach).
Legal Basis: Art. 6 Para. 1 lit. a GDPR (Consent — granted when you authorize the connection) and Art. 6 Para. 1 lit. b GDPR (Contract Performance — necessary to provide the publishing service).
7b. Sign in with Google
Flyzle offers "Sign in with Google" as an optional authentication method. When you choose to sign in with your Google Account, Google shares a limited set of profile information with us so we can create or look up your Flyzle account.
Google scopes we request: openid, https://www.googleapis.com/auth/userinfo.email, and https://www.googleapis.com/auth/userinfo.profile. We do not request access to Gmail, Google Drive, Calendar, Contacts, YouTube, or any other Google service.
Data we receive from Google: your Google Account email address, name, profile picture URL, and a stable Google user identifier (sub). This data is used solely to (i) create or authenticate your Flyzle account, (ii) display your name and avatar inside the app, and (iii) contact you about service-related events.
How we use this data: Flyzle's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except (a) with your explicit consent, (b) for security purposes (e.g., investigating abuse), (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
Storage and revocation: Google profile data is stored alongside your Flyzle account in our authentication backend. You can revoke Flyzle's access at any time from your Google Account permissions page or by deleting your Flyzle account.
Legal Basis: Art. 6 Para. 1 lit. b GDPR (Contract Performance — necessary to provide you with an account) and Art. 6 Para. 1 lit. a GDPR (Consent — granted when you click "Continue with Google").
8. Your Rights
Under GDPR, you have the right to:
- Access your personal data (Art. 15 GDPR)
- Rectify inaccurate data (Art. 16 GDPR)
- Erase your data (Art. 17 GDPR)
- Restrict processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
To exercise your rights, contact us at [email protected].
9. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Upon account deletion, your personal data will be removed within 30 days, except where retention is required by law.
10. Contact
For privacy-related inquiries:
KROMA UG (haftungsbeschränkt)
Email: [email protected]