FISYCO

Public beta
The gapImpactHow it worksProductSecurity
Sign in

Privacy Policy

Last updated: June 18, 2026

1. Overview

This Privacy Policy explains how FISYCO ("Service") collects, uses, and processes personal data.

2. Data We Collect

Account Information

  • Email address
  • Name
  • Workspace information

OAuth Data

  • Access tokens
  • Repository metadata
  • File metadata

Generated Data

  • Pull request metadata
  • Synchronization logs
  • Drift detection results

Uploaded / Stored Files

  • Screenshots
  • Avatars
  • Preview assets

Technical Data

  • IP address
  • Browser type
  • Usage logs

3. Payment Data

Payments are processed by Paddle.com Market Limited as Merchant of Record.

FISYCO does not store full payment card details.

4. How We Use Data

We use collected data to:

  • Provide the Service
  • Generate pull requests
  • Detect design and repository changes
  • Authenticate users
  • Improve system functionality
  • Ensure system security

We do not sell user data.

5. Sub-processors and Infrastructure Providers

We rely on the following third-party sub-processors to operate the Service. Each processes only the data required for its function, and integrations are activated only with your authorization.

  • Render.com — application hosting
  • Cloudflare R2 — file and asset storage
  • Managed Redis — background job queues and caching
  • GitHub, GitLab, Bitbucket — repository integrations (OAuth)
  • Figma — design source integration (OAuth tokens, file and component metadata)
  • Paddle.com Market Limited — payment processing (Merchant of Record)

When AI-assisted features are explicitly enabled, OpenAI is used as a sub-processor to generate change summaries, and only the limited change metadata needed for the summary is sent. AI features are disabled by default and transmit no data while off.

OAuth integrations operate only with user authorization.

6. Data Retention

Data is retained only while the account is active.

Upon account deletion, associated data is permanently deleted from our systems without retention, except where required by law. As part of deletion we also, on a best-effort basis, remove the third-party webhooks we created and delete stored integration assets. Where the provider supports it (for example GitHub and GitLab), we revoke the OAuth access tokens we held; for providers that do not offer a token-revocation API (for example Figma and Bitbucket), the tokens are deleted from our systems and expire according to the provider.

7. Security

We implement:

  • Encrypted connections (HTTPS)
  • Secure storage of OAuth tokens
  • Access control mechanisms

8. User Rights

Users may request:

  • Access to their data
  • Correction of inaccurate data
  • Deletion of personal data

Requests may be submitted to privacy@fisyco.com.

9. International Transfers

Data may be processed outside the user’s country, including in jurisdictions where our sub-processors and infrastructure providers operate. Where data is transferred internationally, we rely on the safeguards and contractual terms offered by those providers.

10. Changes to This Policy

We may update this Privacy Policy periodically. Continued use of the Service after updates constitutes acceptance of the revised Policy.

11. Contact

  • privacy@fisyco.com
  • legal@fisyco.com