Privacy Policy

Last updated

In short
  • We don't sell your personal data or share it for advertising.
  • We don't train AI models on your content.
  • Your content is private to your account. We look at it only when you ask us to, or to handle abuse or a legal request.
  • Images, videos and voice are generated by the providers you connect, with your own API keys, under your agreement with them.
  • You can export or delete your data in your account settings, or by email if your subscription has ended.

Who we are

This policy covers phersa.com, app.phersa.com and the Phersa MCP server at mcp.phersa.com (together, the "Service"). Phersa ("we", "us") is the controller of the personal data described here. Contact: support@phersa.com.

What we collect

  • Account: email, name, sign-in identifiers, and session details (device, browser, IP address, approximate location) handled by our sign-in provider.
  • Purchase: your subscription and add-on status, the DM packs you bought, and the membership, payment and customer IDs Whop gives us. Card and billing details go to Whop; we never see them.
  • Your content: everything you upload, write or generate in the Service, such as photos, videos, audio, prompts and projects, and the links and accounts you add.
  • Provider API keys you connect, stored encrypted.
  • Connected social accounts: when you connect an Instagram account or Facebook Page for automations, its name, handle, profile picture and follower count, the automations you set up, the number of DMs sent and comments hidden, and for each automation the comments or messages that triggered it (the person's name and their comment or message) with what was sent.
  • Usage and security data: product usage events linked to your account ID (without your email, name or IP address); IP address and browser for API-key security events; server logs.
  • Public social media data about creators whose public posts appear in the Service. See Creators and public posts.

We need account and purchase data to open your account. What content you add is up to you.

How we use it and why

PurposeDataLegal basis (EU/UK)
Run your account and the Service, including storage, generation requests you start and AI agent accessAccount, content, API keysContract
Check your subscription and keep purchase recordsPurchaseContract; legal obligation
Run the comment automations you set up on accounts you connect, and count DMs against your planConnected social accountsContract
Transcribe and break down videos you addThose videosContract
Keep the Service secure, prevent abuse, enforce limitsLogs, IP address, security eventsLegitimate interests
Understand how features are used and fix problemsUsage events linked to your account IDLegitimate interests
Build and show the video libraryPublic social media dataLegitimate interests
Send service messages (sign-in, security, changes to our terms)EmailContract
Comply with law and respond to lawful requestsAs neededLegal obligation

Where we rely on legitimate interests, you can object (see Your rights). We don't use your content to train AI models, and we don't make automated decisions about you that have legal or similarly significant effects.

Faces and voices

Photos and voices you add are used only to generate what you ask for: we send them to the provider you choose. We don't create faceprints or voiceprints, use them to identify anyone, or treat them as biometric data. The provider processes them under its own terms; we don't store anything it derives from them. They are deleted when you delete them or your account. Upload only faces and voices you have the right to use (see the Terms).

Who we share it with

Service providers

These providers process personal data for us, only on our instructions and under contract, mostly in the United States. Ask us and we'll tell you which companies they are.

Type of providerWhat for
Sign-in and account securitySign-in, sessions, AI agent authorization
Cloud hosting, database and storageRunning the Service, storing and delivering your data and files, logs, rate limits, bot protection
AI processingTranscribing and breaking down videos
Social media messagingConnecting the Instagram accounts and Facebook Pages you add, and sending the DMs and comment replies your automations set up
Public data providerFetching public posts and profiles for the video library and for links and accounts you add
Product analyticsUsage events linked to your account ID only
Font deliveryCaption fonts your browser loads in the editor

Whop

Whop Inc. processes payments for the Service and is merchant of record for card-network purposes. When you subscribe, Whop collects your payment, billing and contact details and uses them as a separate controller under the Whop Privacy Policy. Whop shares with us the confirmation of your purchase, your email and your membership status.

Providers you connect

Generation runs on the AI providers you connect with your own API key. When you generate, we send your prompt, reference images, audio and settings to the provider you picked. That provider handles the data under your own agreement with it, including its retention and training terms, not as our service provider.

Your AI agent

When you connect an AI agent, it can read and change your account data within the permissions you approve. The agent's provider handles what the agent receives under your agreement with it. You can revoke access at any time.

Others

We disclose data when the law requires it, or to protect people, the Service or our rights. If Phersa is merged or acquired, data passes to the successor under this policy. We don't sell personal data.

How long we keep it

DataKept
Account and your contentUntil you delete it or your account, including after a subscription ends
Provider API keysUntil you remove them
Connected social accounts and their automationsUntil you remove the account or delete your account; DM counts until you delete your account
IP address and browser on security events90 days
Usage analyticsUntil you delete your account
Payment and tax recordsKept by Whop as the law requires
Backups and server logsOverwritten on a rolling basis
Public posts in the video libraryWhile shown in the library, or until a removal request
Public posts from accounts users addUntil no Phersa user follows the account

Deleting your account (in your account settings, or by email) cancels your subscription and deletes your account, content and files.

People who comment on connected accounts

When you connect an account, our messaging provider receives the comments on its posts, and the messages sent to it, so your automations can answer them or hide comments that contain words you chose. For comments and messages that match your keyword, the person's name, their comment or message and the message sent are kept so you can see your automation's activity. For a hidden comment, only the count is kept. They are used only to answer or hide that comment and show you the result, never for anything else. If you commented on a Phersa user's post and want your data removed, email support@phersa.com.

Creators and public posts

Phersa shows a library of short videos posted publicly on social media platforms. Users can also add public posts and accounts themselves.

  • What: the video, caption, account handle and name, public counts (followers, views, likes, comments), post date, and a transcript and breakdown of what is said and shown.
  • Source: publicly accessible profiles and posts on social media platforms, collected through a data provider. Ask us for the exact source of your data.
  • Why: our legitimate interest in helping people study what makes short videos work. We use only public posts and public account statistics, and we don't use them to identify, contact, target or make decisions about the people in the videos.
  • Who sees it: Phersa subscribers and the AI agents they connect, and the service providers listed above.
  • How long: see How long we keep it.
Right to object. If you are a creator, you can object at any time to our use of your public posts. Email support@phersa.com with the link to your account or post. We remove it and take steps to keep it from being added again.

Phersa is not affiliated with any social media platform.

Cookies

We use only cookies and browser storage needed to sign you in, keep the Service secure and remember your choices. They need no consent. We set no advertising cookies. Analytics cookies are off unless you allow them in Cookie Settings; today we use none. Product analytics in the app run on our servers and store nothing in your browser.

NameSet byPurposeDuration
__client, __client_uatClerkKeep you signed inUp to 13 months
__sessionClerkProves you are signed in60 seconds, renewed
cf_clearance, __cf_bm, _cfuvidCloudflareBot protection and rate limitsSession to 1 year
phersa_consent (local storage)phersa.comRemembers your cookie choiceUntil changed or cleared
__clerk_environment, ai:1–ai:3, sso_error (browser storage)app.phersa.comSign-in settings, your last project and display preferences, a short list cache, a one-time sign-in error5 minutes to until cleared

Whop sets its own cookies on its checkout under the Whop Privacy Policy. You can change your choice any time in Cookie Settings (footer), or block cookies in your browser; blocking Clerk's or Cloudflare's cookies stops sign-in.

Security

Data is encrypted in transit. Each provider API key is encrypted with its own AES-GCM key, and the app only ever shows a masked preview of it. Files are served through short-lived signed links. Access to production systems is limited to the people who run the Service. If a breach affects your personal data, we will notify you and the authorities as the law requires.

International transfers

Our providers process data in the United States and other countries. When personal data from the EEA, the UK or Switzerland is transferred, we rely on adequacy decisions, the EU-U.S. Data Privacy Framework or Standard Contractual Clauses. Ask us for a copy of the safeguards we use.

Your rights

Wherever you live, you can ask to access, correct, delete or export your personal data, to restrict or object to how we use it, and to withdraw consent. Most of this is self-serve in your account settings: export your data, sign out devices, delete your account. For anything else, or if your subscription has ended, email support@phersa.com. We answer within one month, or tell you if we need longer as the law allows, and may need to confirm your identity. An authorized agent can ask for you.

We don't sell personal data, share it for cross-context behavioral advertising, or use sensitive data to infer things about you, and we won't treat you differently for using your rights. If we refuse a request, reply to our answer to appeal; we decide within 45 days and tell you how to complain to your data protection authority or state attorney general.

Children

The Service is for people 18 and over. If we learn we hold data from someone under 18, we delete it.

Changes

We update this policy when our practices change and show the date at the top. We tell you about material changes in the app or by email before they take effect.