ferdi / privacy

Privacy Policy

Last updated: September 25, 2026

Ferdi (“Ferdi”, “we”) operates the Ferdi reel generation service. This policy explains what we collect, why, and your rights.

1. Data we collect

2. How we use it

Brand inputs are used only to render reels for your account and to train your private brand model. Voice recordings are used to create your private voice clone and are retained privately so Ferdi can retrain or migrate that clone when newer voice models become available. Ferdi does not use your brand or voice inputs to train shared or public models. Telemetry is used for reliability, security, and product analytics.

If you choose Google sign-in, Google shares your Google account identifier, verified email address, name and profile picture with Ferdi through Supabase. We store these details with your account to authenticate you, create or link your Ferdi account and display your profile. Google processes the sign-in request under its own privacy policy. You can revoke the connection in your Google account settings; this does not delete your Ferdi account. The retention and deletion rights below also apply to these account details.

3. Sub-processors

Ferdi uses the following processors to operate the Service: Supabase (auth, database + private storage), AWS (compute + storage), Fish Audio (voice cloning and voice generation), ElevenLabs (sound-effect generation), HeyGen (avatar generation), OpenAI, Anthropic, Google and DeepSeek (AI content generation and in-product AI assistance), Stripe (payments), Cloudflare (CDN), PostHog (consent-based product analytics, privacy-masked session replay, performance telemetry, and error tracking), Meta Platforms Ireland (consent-based Facebook and Instagram campaign measurement), and Crisp (customer support chat). Each processor handles only the data required to perform its function and is bound by data-processing terms.

When you use Ask Ferdi, your question and only the relevant Help Center excerpts and coarse workspace status you opted to include are sent to the configured AI provider. Ferdi does not include raw provider errors, file paths, URLs, payment identifiers, or customer-authored titles in that workspace status. A configured provider pin is treated as a data-routing boundary; Ferdi does not send the same request to another AI provider unless an operator explicitly enables cross-provider fallback.

When you use Company Knowledge, a voice note is sent only after your explicit confirmation to the OpenAI audio-transcription endpoint configured for EU processing. Ferdi holds the recording only in request memory and does not persist an audio file. Live Voice has a separate confirmation: microphone audio is then streamed by WebRTC to OpenAI Realtime in the EU until you stop the call. Realtime tracing is disabled. Ferdi stores final transcripts, not raw Live Voice audio, and turns the information into facts that you can review, correct, retract, or delete.

4. Retention

The Instagram inbox loads incoming direct messages live without storing their bodies. Ferdi retains replies sent through Ferdi, including their text, recipient, message ID, time and automatic/manual origin, for your workspace reply history and to prevent duplicate automatic replies. Unsending your own reply on Instagram marks this existing record as deleted but does not remove your original Ferdi-authored text. A verified Meta data-deletion or deauthorization request removes these reply records along with the Instagram connection data. You can also request deletion using the contact below.

Brand inputs, retained voice-clone source recordings, and generated reels are retained for the life of your account plus 30 days after deletion to allow restoration on request. Voice source recordings are also removed when the related voice clone is deleted. Telemetry is retained for 90 days.

Ask Ferdi keeps up to 12 recent questions locally in this browser for 30 days, in a namespace tied to the exact authenticated user and company. Clearing the browser's site data removes this history. A confirmed Content Creator handoff uses a one-shot in-memory transfer and does not add another copy of the question to browser storage, the URL, analytics, or a server draft.

Company Knowledge final transcripts are retained for 30 days by default. Derived facts and their version history may remain longer while they are active or required for review and auditability. A workspace administrator can request deletion of a conversation and its derived facts in the product. Ferdi ends an active Live Voice call before redaction. Content already published to an external platform must be deleted separately on that platform.

5. Your rights

You can export or delete your data at any time from account settings. Under GDPR and CCPA you may also request access, correction, portability, or deletion by emailing [email protected]. We respond within 30 days.

6. Cookies & analytics

Ferdi uses essential cookies for session and a small set of analytics cookies for product usage measurement. The support chat uses Crisp session cookies to keep a conversation working across pages and visits. PostHog browser behavior analytics and session replay start only after you choose “Allow analytics”. Replay masks every input and all page text before data leaves the browser; Ferdi does not send prompts, captions, passwords, contact details, auth tokens, or payment-session query values as analytics properties. Ferdi separately records bounded server-side reliability, billing, and delivery outcomes needed to operate and improve the Service, without customer-authored content. You can change your browser analytics choice below at any time. After separate marketing consent, the Meta Pixel (LaunchPixel_02, Pixel ID 1050121351340258) measures page views and completed conversion steps for Facebook and Instagram campaigns. Ferdi stores the analytics and marketing choices for up to one year in a necessary first-party preference cookie shared by ferdi-app.com and hub.ferdi-app.com. After marketing consent, bounded campaign parameters, including Meta's click ID, are carried only between those owned domains to preserve attribution; PostHog does not receive the Meta click ID. Meta's script is not loaded before marketing consent and Ferdi does not use a consent-independent noscript pixel. We do not sell personal data.

Analytics: not chosenMarketing: not chosen

7. Children

Ferdi is not intended for children under 13 and does not knowingly collect their data.

8. Changes

Material changes to this policy will be communicated at least 30 days in advance by email.

9. Contact

Email [email protected]. Ferdi GmbH, Wittelsbacherstraße 20, 80469 München, Germany.