Privacy Policy
Last updated: April 2025
1. Who We Are
ButterflyAPI ("we", "us", "our") is the data controller for personal data collected through butterflyapi.com and its associated services. We are committed to protecting your privacy and handling your data responsibly in accordance with the UK GDPR and the Data Protection Act 2018.
For all privacy-related enquiries, contact us at support@butterflyapi.com.
2. Data We Collect
Account data
Name, email address, password (hashed and never stored in plain text), account creation date, and your marketing preferences collected at registration.
Billing data
Subscription plan, credit balance, transaction history, and invoice records. Card details are processed and stored exclusively by Stripe under their PCI-DSS compliance — we never see or store your full card number.
Usage data
API calls made, tools used, credit consumption per operation, timestamps, job history, and API key usage logs.
Content data
Images, prompts, and other content you upload or generate through the Service. This is processed to deliver results and stored temporarily so you can view your history.
Technical data
IP address, browser type, device information, and session data collected automatically when you use the Service.
Communications data
Messages you send us via the contact form or support email.
3. How We Use Your Data
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Provide and operate the Service | Contract performance |
| Process payments and manage billing | Contract performance |
| Send account and security emails | Contract performance |
| Prevent fraud and abuse | Legitimate interests |
| Improve and develop the Service | Legitimate interests |
| Comply with legal obligations | Legal obligation |
| Send marketing emails (opted-in users only) | Consent |
4. Marketing Communications
If you opted in to marketing communications when creating your account, we will send you product updates, feature announcements, and relevant offers by email. You can withdraw consent and unsubscribe at any time by:
- Clicking the unsubscribe link in any marketing email
- Updating your preference in your account settings
- Emailing us at support@butterflyapi.com
Withdrawing consent will not affect the lawfulness of processing before withdrawal, and will not stop transactional emails such as receipts, security alerts, or service notices.
5. Data Processors and Third Parties
We share data with the following third-party processors who act on our instructions and are bound by data processing agreements:
Supabase
Database, authentication, and user account storage.
Processing location: EU / US
Stripe, Inc.
Payment processing and billing. Stripe stores card data under PCI-DSS compliance.
Processing location: US
fal.ai
AI model inference — your images and prompts are processed to generate outputs.
Processing location: US
Cloudflare, Inc.
DDoS protection, bot detection via Turnstile CAPTCHA, and CDN services.
Processing location: US
Vercel, Inc.
Application hosting and edge delivery.
Processing location: US
Resend
Transactional and marketing email delivery.
Processing location: US
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. Where data is transferred outside the UK/EEA, we rely on Standard Contractual Clauses or adequacy decisions.
6. Data Retention
- Account data is retained while your account is active, plus up to 90 days after deletion.
- Billing and transaction records are retained for 7 years to comply with financial regulations.
- Uploaded images and generated outputs are stored for up to 30 days by default, then deleted.
- Support correspondence is retained for up to 3 years.
7. Your Rights Under UK GDPR
You have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data (subject to legal retention obligations)
- Restriction — request we limit processing in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — withdraw marketing consent at any time
To exercise any of these rights, email support@butterflyapi.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
8. Cookies
We use cookies and similar technologies to operate the Service. For full details, see our Cookie Policy.
9. Security
We implement appropriate technical and organisational measures to protect your personal data, including encrypted storage, HTTPS for all data in transit, hashed passwords, and strict access controls. If you believe your account has been compromised, contact us immediately.
10. Children
The Service is not directed at anyone under 18. We do not knowingly collect personal data from minors. If we become aware that a minor's data has been collected, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the Service. The "last updated" date at the top of this page always reflects the most recent revision.
