How Favist Inc. collects, uses and shares information when you use Favist.
Effective September 15, 2026Last updated August 30, 2026
This policy explains what Favist Inc. does with information when you use favist.ai and related services. Using the Service means you accept this policy and our Terms of Service.
If you connect Google we request only the scopes the feature needs: normally your basic profile and email for sign-in, and where you enable a feature that requires it, read only access to the specific Drive files you choose. Favist's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features you ask for, do not use it for advertising, do not sell it, and do not share it except as needed to run the Service, with your consent, or where the law requires. You can review or revoke access at any time in your Google account security settings.
When you upload a file, or accept one sent to you through a file drop link or your file inbox, we store it so we can show it back to you. Files are held in our object storage, encrypted in transit and at rest.
We scan them. Files are checked for malware and for content prohibited by our Terms. This is automated. Where a scan flags something, a small number of authorised staff may review it in order to act on it.
Who can see them. Files stay private to your account unless you publish or share them. Someone who sends you a file through your inbox cannot see anything else in your account, and cannot see your email address unless you reply.
How long we keep them. Files stay while your account is active. Files delivered through a file drop link expire after 30 days unless you save them. We may delete content in accounts inactive for 24 months, after at least 30 days notice by email. Deleted files leave active systems promptly and leave backups within [TO BE COMPLETED: backup retention window].
Reporting obligations. Where a scan or a report identifies apparent child sexual abuse material, we report it to the National Center for Missing and Exploited Children and preserve the related material as United States law requires. That obligation overrides the deletion timelines above.
When you use a retrieval tool, we process the address you submit in order to fetch the file and deliver it to you.
What we keep. Where you ask us to save the file to your account or publish it, we store it like any other file of yours. Where you do not, we keep it only for the brief period needed to deliver it, and then it goes. Separately, we log the request itself, meaning the address submitted, a timestamp, and the account or IP it came from, for abuse prevention, security and rate limiting. Those logs are kept for [TO BE COMPLETED: retrieval log retention window] and are not used to build a profile of you.
When someone clicks a short link you created, we record the click: a timestamp, the referring page, approximate location derived from the IP address, and coarse device and browser type. We use it to give you aggregate click analytics and to detect abuse.
You see this data in aggregate, not as a list of identified individuals. We do not sell click data and we do not use it for advertising. Raw click logs are kept for [TO BE COMPLETED: click log retention window], after which only aggregate counts remain.
If you use gift delivery, we store the delivery address you give us. We disclose it only to the carrier or fulfilment service needed to complete a delivery you have authorised. We never disclose it to the person sending you the gift, which is the entire point of the feature.
You can remove a stored address at any time. We keep delivery records for 12 months so we can help with support questions and disputes.
We keep information while your account is active, or for as long as we need it to run the Service and meet legal, accounting and fraud prevention obligations. Deleting your account removes your profile and content from active systems. Residual copies can persist in backups for a limited period. Some records, including copyright notices and reports we are legally required to preserve, outlive account deletion.
Depending on where you live, you may have rights to access, correct, delete, port or restrict your personal data, and to object to some processing. To use them, write to privacy@favist.ai. We will not treat you differently for exercising them.
We use reasonable technical and organisational measures, including row level access controls and encrypted transport, to protect your information. No method is perfectly secure and we cannot guarantee absolute security.
The Service is not directed to children under [TO BE COMPLETED: age threshold, matching the Terms], and we do not knowingly collect their personal information. Where we learn that we hold information from a child below that age without the consent the law requires, we delete it. If you believe a child has given us information, write to privacy@favist.ai.
We and our providers may process information in countries other than yours. Where required, we use appropriate safeguards for those transfers.
We may update this policy. Material changes are posted here with a new effective date, and we give notice in the product or by email where the change is significant.