Privacy Policy
How Fizyonops Yazilim Limited Sirketi handles data on figments.live, in the dashboard, and in the embed widget we serve to your visitors.
Last updated 21 August 2026
The short version
We do not ask you to create an account, we do not run advertising or analytics trackers, and we do not sell data. The widget on your site does not set cookies or profile your visitors. Card details never reach us — Paddle handles payment.
1. Who is responsible
Fizyonops Yazilim Limited Sirketi is the data controller for the personal data described here. Registered address: Bursa, Turkiye. You can reach us at [email protected].
2. What we collect from you
Because there are no accounts, what we hold about a feed owner is deliberately thin:
- Feed configuration — the feed name you choose, the Instagram username or YouTube channel you point it at, and your styling settings.
- A generated slug and manage key. The manage key is the secret that authorises changes to your feed.
- Subscription records for paid feeds — the Paddle subscription and customer identifiers, the plan status, and renewal dates. Not your card details.
- Server logs of requests to our API, including IP address, kept for security and debugging.
We do not ask for your name or email address to use Figments. If you email support, we hold that correspondence so we can answer it.
3. What we collect from the social platforms
When you create a feed we fetch publicly available data for the account you nominated: the profile name, handle, avatar, follower or subscriber counts where the platform exposes them, and recent posts with their captions, thumbnails and engagement counts.
We cache that payload and mirror the thumbnail images onto our own servers, so your widget keeps rendering when the upstream platform rate-limits us and so your visitors’ browsers are not making requests to Instagram or YouTube. Cached copies refresh periodically and are deleted when the feed is deleted.
If the account you nominate is not yours, the people whose content appears are third parties whose data you have asked us to republish — you are responsible for having the right to do that.
4. Your website visitors
The embed script renders inside a Shadow DOM on your page and fetches one JSON document from our API. In doing so, and as with any request to any server, we receive the visitor’s IP address and user agent in our server logs.
- The widget sets no cookies and writes nothing to local storage.
- It does not fingerprint, profile, or track visitors across sites.
- It loads no third-party scripts, ad networks, or analytics.
- Images are served from our domain, not from Instagram or YouTube, so those platforms do not see your visitors.
Paddle’s checkout, which does use cookies, only loads in our own dashboard when you choose to upgrade — never on your site.
5. Payments
Paid plans are processed by Paddle.com Market Ltd as merchant of record. Paddle collects your payment details, billing address and tax identifiers directly, and is an independent controller for that data under its own privacy policy at paddle.com/legal/privacy.
We never see or store card numbers. What comes back to us is the subscription status, the identifiers needed to link it to your feed, and renewal dates.
6. Why we are allowed to hold it
We process feed configuration and subscription data to perform the contract you entered when you created a feed or subscribed. We process server logs and abuse signals on the basis of our legitimate interest in keeping the service secure and working. Where we rely on legitimate interests, we have considered your rights and keep the data minimal.
7. Who else sees it
We do not sell personal data or share it for advertising. We use a small number of processors to run the service:
- Paddle — payments, invoicing, tax and the billing portal.
- Our hosting and infrastructure providers, which store the database, cached media and logs.
- Cloudflare, which sits in front of the site and sees request metadata.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
8. How long we keep it
- Feed configuration and cached content: until you delete the feed, then removed.
- Subscription records: kept while the subscription is live, and afterwards for as long as tax and accounting rules require.
- Server logs: a short rolling window, typically measured in weeks.
9. Your rights
Depending on where you live you may have the right to access, correct, export, or erase your personal data, to object to or restrict processing, and to complain to your data protection authority.
You can act on most of these yourself: edit your feed in the dashboard, or delete it, which erases its configuration and cached content. For anything else, email [email protected]. Because we hold no identity data, we may need you to prove control of a feed — normally by producing its manage key — before we act on a request about it.
10. International transfers and security
Our providers may process data outside your country. Where that happens we rely on the safeguards those providers offer, such as standard contractual clauses.
We serve everything over HTTPS, keep manage keys out of logs and URLs, and verify the authenticity of every billing notification we receive. No system is perfectly secure, and we do not claim otherwise.
11. Children
Figments is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes
If we change this policy the date at the top of the page changes with it. Material changes will be announced on the site before they take effect.