Privacy Policy

Last updated September 25, 2026

This policy explains what YouZag Inc. ("First Light", "we") collects when you use First Light, why, who we share it with, how long we keep it, and the choices you have. It covers makefl.com, the builder, and our status page. It does not cover the apps our customers build: for those, the app's owner decides what is collected and we handle it on their behalf (see section 7).

1The short version

  • We collect what we need to run your account and build and host your apps: your email, your apps and what you tell the builder, and your billing details (held by Stripe, not us).
  • We use AI providers to build your apps. What you send the builder goes to them for that purpose.
  • We do not sell your information, show you ads, or use advertising or analytics trackers.
  • We use only the cookies needed to keep you signed in.
  • You can see, export, change or delete your information. Deleting your account deletes your apps and data.

2What we collect

Account details. Your email address, and if you provide them, a display name and avatar. If you add a passkey, we store its public key (never your fingerprint or face data, which stay on your device). If you sign in with Google, we receive your verified email, name and Google account identifier.

Sign-in and security. One-time sign-in codes (stored only as a scrambled hash and deleted after 10 minutes), your active sessions with a coarse device label such as "Chrome on Mac", and the times you signed in. We use your IP address to limit abuse; we store it only in a scrambled, shortened form and not in your session record.

What you build. Your descriptions and messages to the builder, the files and images you upload, and the apps First Light builds, including their pages, settings and history. Each image you upload is described by an AI model so the builder can use it.

Payments. When you save a card, you enter it into a form run by Stripe. We never see or store your full card number. We keep a record of your purchases, credit, top-ups, refunds and renewals, and Stripe keeps your card and payment details.

Domains. The domain names you search for, buy or connect, and their setup status.

Team and transfers. Email addresses you invite to your apps or offer an app to, and the roles you give them.

Messages from you. What you send us when you contact support.

Status page subscriptions. If you subscribe to incident updates, your email address, stored encrypted.

Technical logs. Our hosting provider records requests to our servers (such as time, address requested and response) to keep the Service running and secure.

3How we use it

  • To create and secure your account and sign you in.
  • To build, host, publish and run your apps, and to show you previews and thumbnails of them.
  • To charge you for what you buy, send receipts and billing notices, and prevent fraud.
  • To send service email: sign-in codes, invitations, ownership offers, billing and domain notices, and incident updates you subscribed to. We do not send marketing email without your consent.
  • To provide support, investigate problems, and keep the Service safe, including enforcing our Terms and Acceptable Use Policy.
  • To comply with law.

For people in the EEA and the UK, our legal bases are: contract (account, building, hosting, billing), legitimate interests (security, abuse prevention, improving the Service), legal obligation (financial records), and consent where we ask for it.

We do not use your content to train AI models, and our AI providers do not use it to train theirs.

4Who we share it with

We share information only with the service providers that help us run First Light, only as needed, and under contracts that require them to protect it:

ProviderWhat forWhat they receive
ProviderCloudflareWhat forHosting, storage, databases, email delivery, domain registration and DNS, image processing, page screenshots, bot protection, and routing of AI requestsWhat they receiveAll data stored in or passing through the Service
ProviderOpenAIWhat forBuilding apps, generating images, describing uploaded imagesWhat they receiveYour builder messages, your app's current content, and the images you attach or generate
ProviderAnthropicWhat forStandby builder and fallback image descriptionsWhat they receiveThe same as OpenAI, only when used
ProviderStripeWhat forCard payments and saved cardsWhat they receiveYour card details (entered directly with Stripe) and payment amounts. We identify you to Stripe only by an account number, not your name or email
ProviderGoogleWhat forSign in with Google, if you use itWhat they receiveThe sign-in exchange

We also share information when the law requires it, to protect people's safety or our rights, or as part of a merger or sale of our business (you would be told). If you are on a team, your teammates can see your email and role on that app. An app's new owner receives the app's data in a transfer.

5Cookies and similar technology

We use only strictly necessary cookies:

NamePurposeLasts
Name__Host-fl_sessionPurposeKeeps you signed inLastsUntil you sign out, after 24 hours of inactivity, or 7 days at most
Name__Host-fl_oauth_statePurposeProtects sign-in with GoogleLasts10 minutes

Your browser also stores a note that this device has a passkey, and your unsent builder message so it survives a reload. Stripe's card form may set its own cookies to prevent fraud. We use no analytics, advertising or tracking cookies, so there is nothing to opt out of. See our Cookie Notice.

6How long we keep it

InformationKept
InformationSign-in codesKept10 minutes
InformationSessionsKept24 hours of inactivity, 7 days at most, or until you sign out
InformationInvitations and ownership offersKept7 days
InformationYour account, apps and contentKeptUntil you delete them or your account
InformationBackups of app dataKept30 days
InformationDeleted imagesKeptUp to 30 days in backups
InformationPayment and financial recordsKeptUp to 7 years, as tax and accounting law requires. After you delete your account, they no longer identify you
InformationSecurity and audit recordsKept1 year
InformationHosting and AI request logsKept7 days for hosting logs; up to 30 days for AI request logs

7Data in the apps you build

When your app collects information from its visitors (for example sign-ups, bookings, form entries or member accounts), you control that information and decide how it is used. We process it on your behalf to run your app, as your service provider, only on your instructions. Visitors should contact the app's owner about their information; we will help owners respond. You are responsible for giving your visitors a privacy notice. Published apps cannot set their own tracking cookies through First Light.

8Your choices and rights

  • See and change: your account details and apps are in your settings and dashboard.
  • Sign out devices: review and end sessions under Settings, Security.
  • Delete: delete any app, or your whole account, from Settings. Account deletion removes your apps, content, data, passkeys and sessions and deletes your saved card at Stripe. Remaining credit is forfeited. We keep payment records the law requires.
  • Export: request a copy of your information at privacy@fl.app..
  • Other rights: depending on where you live you may have rights to access, correct, delete, restrict or object to processing, and data portability, and to complain to a data protection authority. Contact privacy@fl.app and we will respond within the time the law requires. We will not treat you differently for using these rights.

We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined in California law.

9Security

Data is encrypted in transit. Sign-in codes and session tokens are stored only as hashes. Keys you give your apps for other services are encrypted and never sent to a browser. Our staff can access customer systems only through a signed-in, passkey-protected console, and every staff action is recorded. No system is perfectly secure; if a breach affects you, we will tell you as the law requires.

10International transfers

Personal data collected from outside the United States is transferred to and processed in the United States using recognized legal mechanisms such as Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. Individuals located in regions like the EEA, the UK, or specific U.S. states retain statutory rights regarding data access, correction, deletion, and restriction. Section 8 explains those rights and how to use them.

11Children

First Light is not for children under 13, and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.

12Changes

We will post any change here and update the date above. If a change is material, we will tell you by email or in the product before it takes effect.

13Contact

YouZag Inc., 1127 Lake Legro Ct., Orlando, FL 32835. Email privacy@fl.app.