On this page
- 1. Introduction & scope
- 2. Data we collect
- 3. How we use your data
- 4. Legal bases for processing
- 5. How AI processing works
- 6. Data sharing & subprocessors
- 7. Cookies & tracking
- 8. Data retention
- 9. Data security
- 10. International data transfers
- 11. Your rights
- 12. Children's privacy
- 13. Changes to this policy
- 14. Contact & data protection
Introduction & scope
Factorly (“Factorly,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard personal data when you use the Factorly websites, applications, APIs, and related services (the “Service”), and the choices and rights you have.
For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), the data controller is [Controller legal entity], [Registered address]. Where we process personal data on your behalf as part of running your projects (for example, data you put into an application you build), we generally act as a processor and you are the controller.
This Policy should be read together with our Terms of Service.
Data we collect
We collect the following categories of personal data:
- Account information — such as your name, email address, password (stored hashed), profile details, and, if you sign in via a third-party identity provider, the basic profile information it shares.
- Project content & code — the prompts and instructions you submit, the files and data you upload, and the source code and applications generated for you, together with related metadata (such as project names and checkpoints).
- Usage & device data — information about how you interact with the Service, including log data, feature usage, build activity and credit consumption, IP address, browser and device type, and timestamps.
- Payment information — when you subscribe to a paid plan, billing details and transaction records. Card details are collected and processed by our payment processor (Stripe); we do not store full card numbers.
- Support & communications — the content of messages you send us (for example, support requests or emails) and our responses.
- Cookies & analytics data — information collected through cookies and similar technologies, as described in the Cookies section below.
You can choose what to put into your prompts and projects. Please avoid submitting sensitive personal data (such as health, biometric, or government-ID data) unless it is necessary and you have an appropriate legal basis and safeguards in place.
How we use your data
We use personal data to:
- Provide, operate, and maintain the Service — including running the AI agent, building and previewing your applications, and storing your projects and checkpoints;
- Authenticate you, manage your account, and provide customer support;
- Process payments, manage subscriptions, and prevent payment fraud;
- Monitor, secure, and improve the Service, debug issues, measure performance, and develop new features;
- Enforce our Terms, prevent abuse of our AI and compute resources, and protect the rights, safety, and security of Factorly, our users, and others;
- Communicate with you about service updates, security notices, and — where permitted — relevant product information, which you can opt out of;
- Comply with legal obligations and respond to lawful requests.
We do not sell your personal data, and we do not use the content of your private prompts or code to train our own foundation models.
Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases under Article 6 for processing your personal data:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service you have signed up for, including processing your prompts and code to generate and run your applications, and to bill you for paid plans;
- Legitimate interests (Art. 6(1)(f)) — to secure, maintain, and improve the Service, prevent abuse and fraud, and understand how the Service is used, balanced against your rights and interests;
- Consent (Art. 6(1)(a)) — for optional cookies and analytics and for certain marketing communications, where required; you may withdraw consent at any time;
- Legal obligation (Art. 6(1)(c)) — to comply with applicable laws, such as tax, accounting, and lawful requests.
How AI processing works
To deliver the core functionality of the Service, the prompts you write and relevant portions of your project code and context are transmitted to large language model providers that generate the agent’s responses and code. These providers may include AWS Bedrock and the model vendors made available through it (for example, Anthropic and others), and may include other model providers as the Service evolves.
These providers process your Input as our subprocessors, under contractual terms intended to restrict their use of the data to providing inference to us. We select providers that, under their enterprise/API terms, do not use submitted prompts or outputs to train their foundation models. The specific provider used for a given request can depend on the model you select and on availability.
Because AI output is generated probabilistically, it may be inaccurate or incomplete; how we handle output and your responsibility to review it are described in our Terms of Service.
Data retention
We retain personal data for as long as needed to provide the Service and for the purposes described in this Policy. Account and project data are generally retained while your account is active. After you delete a project or close your account, we delete or anonymize associated personal data within a reasonable period, except for limited residual backups and data we must keep to comply with legal, tax, accounting, or security obligations or to resolve disputes.
Retention periods depend on the type of data and the reason we hold it; we apply criteria such as the data’s purpose, sensitivity, and applicable legal requirements. You can export your code to GitHub before deletion.
Data security
We implement technical and organizational measures designed to protect personal data, including encryption in transit, encryption of secrets, access controls, network and sandbox isolation for build environments, and monitoring. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
You are responsible for using strong, unique credentials, protecting your account, and managing the secrets and data you place into your projects. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities as required by applicable law.
International data transfers
We and our subprocessors may process personal data in countries other than your own, including the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), or other lawful transfer mechanisms — to protect your data. You may request more information about these safeguards using the contact details below.
Your rights
GDPR / UK GDPR rights
Subject to applicable law, you have the right to:
- Access a copy of the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (the “right to be forgotten”) in certain circumstances;
- Restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
- Port your data — receive it in a structured, commonly used, machine-readable format;
- Withdraw consent at any time where processing is based on consent;
- Lodge a complaint with your local data protection authority.
California (CCPA/CPRA) rights
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion of your personal information, to correct inaccurate information, and to not be discriminated against for exercising your rights. We do not sell or “share” personal information as those terms are defined under California law.
To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by applicable law and may need to verify your identity. You may use an authorized agent where permitted.
Children's privacy
The Service is not directed to children, and you must be at least 18 years old (or the age of majority in your jurisdiction) to use it. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice — for example, by posting the updated Policy with a new “Last updated” date and, where appropriate, by notifying you in the product or by email. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy where permitted by law.
Contact & data protection
If you have questions about this Policy or how we handle your personal data, or if you wish to exercise your rights, contact our privacy team at [email protected].
Data controller: [Controller legal entity], [Registered address]. If we have appointed a Data Protection Officer or an EU/UK representative, their contact details will be provided here. These details are placeholders to be completed for your entity.