Privacy Policy
Last updated: June 18, 2026
1. Overview
This Privacy Policy explains how FISYCO ("Service") collects, uses, and processes personal data.
2. Data We Collect
Account Information
- Email address
- Name
- Workspace information
OAuth Data
- Access tokens
- Repository metadata
- File metadata
Generated Data
- Pull request metadata
- Synchronization logs
- Drift detection results
Uploaded / Stored Files
- Screenshots
- Avatars
- Preview assets
Technical Data
- IP address
- Browser type
- Usage logs
3. Payment Data
Payments are processed by Paddle.com Market Limited as Merchant of Record.
FISYCO does not store full payment card details.
4. How We Use Data
We use collected data to:
- Provide the Service
- Generate pull requests
- Detect design and repository changes
- Authenticate users
- Improve system functionality
- Ensure system security
We do not sell user data.
5. Sub-processors and Infrastructure Providers
We rely on the following third-party sub-processors to operate the Service. Each processes only the data required for its function, and integrations are activated only with your authorization.
- Render.com — application hosting
- Cloudflare R2 — file and asset storage
- Managed Redis — background job queues and caching
- GitHub, GitLab, Bitbucket — repository integrations (OAuth)
- Figma — design source integration (OAuth tokens, file and component metadata)
- Paddle.com Market Limited — payment processing (Merchant of Record)
When AI-assisted features are explicitly enabled, OpenAI is used as a sub-processor to generate change summaries, and only the limited change metadata needed for the summary is sent. AI features are disabled by default and transmit no data while off.
OAuth integrations operate only with user authorization.
6. Data Retention
Data is retained only while the account is active.
Upon account deletion, associated data is permanently deleted from our systems without retention, except where required by law. As part of deletion we also, on a best-effort basis, remove the third-party webhooks we created and delete stored integration assets. Where the provider supports it (for example GitHub and GitLab), we revoke the OAuth access tokens we held; for providers that do not offer a token-revocation API (for example Figma and Bitbucket), the tokens are deleted from our systems and expire according to the provider.
7. Security
We implement:
- Encrypted connections (HTTPS)
- Secure storage of OAuth tokens
- Access control mechanisms
8. User Rights
Users may request:
- Access to their data
- Correction of inaccurate data
- Deletion of personal data
Requests may be submitted to privacy@fisyco.com.
9. International Transfers
Data may be processed outside the user’s country, including in jurisdictions where our sub-processors and infrastructure providers operate. Where data is transferred internationally, we rely on the safeguards and contractual terms offered by those providers.
10. Changes to This Policy
We may update this Privacy Policy periodically. Continued use of the Service after updates constitutes acceptance of the revised Policy.
11. Contact
- privacy@fisyco.com
- legal@fisyco.com