Privacy Policy

Last updated: September 14, 2026

1. Introduction

AffRev is a product of KYROS SOFTWARE LTD ("we", "us", or "our"), a company registered in England and Wales under company number 16915277, with its registered office at 82a James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, United Kingdom, IP28 7DE. KYROS SOFTWARE LTD is the data controller responsible for your personal data.

We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.

2. Information We Collect

Information you provide directly:

  • Email address (used for authentication, transactional email, and marketing communications)
  • Name and profile image (if provided via Google or account setup)
  • Funnel content and prompts you enter into the AI chat
  • Domain names you connect to the Service
  • Payment information (processed and stored by Stripe — we never see raw card data)
  • Instagram professional account details when you connect Instagram (username, account ID, profile picture)
  • Encrypted Instagram access tokens used to act on your behalf
  • Instagram comments, direct messages, and media metadata needed to run features you enable (publishing, comment replies, Auto DM)
  • Email addresses a commenter types in an Auto DM flow, if you turn that capture on

Information collected automatically:

  • IP address and approximate location
  • Browser type and version
  • Device type and operating system
  • Pages visited and time spent on the Service
  • Referring URLs
  • Session tokens for authentication

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service
  • Authenticate your identity via email OTP codes
  • Process payments and manage your subscription
  • Connect your Instagram professional account and keep that connection working
  • Publish content, reply to comments, and send Instagram DMs that you configure
  • Send transactional emails (login codes, account notifications)
  • Add your email to our mailing list when you create an account (product updates, tips, and marketing from AffRev) — you can unsubscribe at any time
  • Respond to support requests and enquiries
  • Monitor usage to prevent abuse and ensure security
  • Analyse usage patterns to improve features
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your content to train AI models.

When you sign up with Google or email OTP, we subscribe your account email in Plunk so we can send product updates and marketing related to AffRev. Transactional messages (such as login codes) may still be sent regardless of marketing subscription status. You can unsubscribe from marketing emails at any time using the unsubscribe link in those emails or by contacting us.

4. AI and Content Processing

When you use AI features, your prompts and related inputs are sent to our AI routing provider (OpenRouter) for processing by the model providers OpenRouter selects for that request. This is necessary to generate content. Please note:

  • Prompts are processed by third-party AI infrastructure via OpenRouter
  • We do not use your prompts to train any AI models
  • You should not enter sensitive personal information (passwords, financial data, PII) into prompts
  • Generated content and published assets may be stored in our PostgreSQL database and on Cloudflare (including R2) for hosting

5. Third-Party Services

We only share or process personal data with the following providers, and only as needed to operate AffRev:

Plunk

Transactional email (OTP codes and account notifications) and our marketing / product update mailing list. Creating an AffRev account subscribes your email in Plunk; you can unsubscribe via links in those emails or by contacting us.

Privacy policy: useplunk.com

PostgreSQL database host

Primary application database for accounts, funnels, connections, and related product data (hosted on our secure infrastructure)

Privacy policy: N/A — infrastructure under our control

Stripe

Payment processing and subscription management

Privacy policy: stripe.com

Meta / Instagram

Instagram Login, content publishing, comment management, and Instagram messaging on your behalf

Privacy policy: privacycenter.instagram.com

OpenRouter

AI routing and content generation (your prompts are sent to OpenRouter to fulfil AI features)

Privacy policy: openrouter.ai

Cloudflare

DNS, content delivery, hosting (including object storage such as R2), and DDoS protection

Privacy policy: cloudflare.com

Google

Google Sign-In / OAuth for account authentication when you choose to sign in with Google

Privacy policy: policies.google.com/privacy

PostHog

Product analytics and usage insights to improve the Service (events such as page views and feature usage)

Privacy policy: posthog.com/privacy

Each third party is responsible for their own data handling practices under their respective privacy policies.

6. Instagram

If you connect an Instagram professional account, we receive an access token from Meta and store it encrypted. We use that token only to provide AffRev features you turn on:

  • Read your account profile and media so you can pick posts and schedule publishing
  • Publish posts and reels you create in AffRev
  • Read comments on your media and post public replies you configure
  • Send Instagram DMs you configure (including Auto DM after someone comments)
  • Read inbound DMs and button taps only to continue a flow you set up (for example sending a link after they reply)

We do not sell Instagram data. We do not message people except as part of a flow you created. You can disconnect Instagram at any time from Connections in the dashboard, which deletes the stored token for that account. Instagram users can also request deletion via Meta's data deletion callback, which removes the matching Instagram connection from AffRev.

7. Data Storage and Security

Your data is stored in our PostgreSQL database. Published assets and related files may be stored on Cloudflare (including R2). We implement appropriate technical and organisational measures to protect your data including:

  • Encryption of data in transit via TLS/HTTPS
  • Instagram access tokens encrypted at rest
  • Session-based authentication with secure tokens
  • No passwords stored (email OTP only)
  • Row-level access controls so you can only access your own data
  • Regular security reviews

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

8. Cookies and Tracking

We use essential cookies and session storage for authentication and to maintain your session. We also use PostHog for product analytics (which may set cookies or use local storage to distinguish visitors). We do not use advertising cookies or social tracking pixels. The cookies and similar technologies we use include:

  • Session cookies for authentication (expire when you close your browser or after 30 days)
  • CSRF protection tokens
  • PostHog analytics identifiers (to understand product usage and improve the Service)

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Portability: Request your data in a machine-readable format
  • Restriction: Request that we limit how we process your data
  • Objection: Object to certain types of processing
  • Withdraw consent: Where processing is based on consent (including marketing emails)
  • Unsubscribe: Opt out of marketing emails via the unsubscribe link or by emailing us

To exercise any of these rights, please contact us. We will respond within 30 days. Note that we may need to verify your identity before processing your request. If you are in the UK and are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory reasons. Published funnel content is removed within 30 days of account deletion. Anonymised, aggregated analytics data may be retained indefinitely.

11. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a prominent notice on the Service. Your continued use of the Service after any changes constitutes your acceptance of the updated policy. We encourage you to review this page periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us. We take all privacy enquiries seriously and will respond as promptly as possible.

KYROS SOFTWARE LTD
Company No. 16915277
82a James Carter Road, Mildenhall,
Bury St. Edmunds, Suffolk,
United Kingdom, IP28 7DE
Email: [email protected]