ferdi / privacy
Privacy Policy
Last updated: August 11, 2026
Ferdi (“Ferdi”, “we”) operates the Ferdi reel generation service. This policy explains what we collect, why, and your rights.
1. Data we collect
- Account data: email, password hash, plan tier.
- Brand inputs: the Instagram links, PDFs, photos, briefs and last-30-captions samples you provide so Ferdi can train your private brand voice.
- Voice and avatar inputs: voice-clone recordings and avatar source photos you provide to create private cast assets for your workspace.
- Generated content: the reels Ferdi renders for you.
- Telemetry: standard request logs, IP, user agent, and product analytics events used to debug and improve the Service.
- Support data: messages and files you choose to send through the customer support chat and, when you are signed in, your confirmed account email address so Crisp can identify your support conversation without asking for it again. Ferdi signs that email on the server with a one-way cryptographic signature so support can distinguish a verified account identity; the private signing key is never sent to your browser or included in the support conversation.
2. How we use it
Brand inputs are used only to render reels for your account and to train your private brand model. Voice recordings are used to create your private voice clone and are retained privately so Ferdi can retrain or migrate that clone when newer voice models become available. Ferdi does not use your brand or voice inputs to train shared or public models. Telemetry is used for reliability, security, and product analytics.
3. Sub-processors
Ferdi uses the following processors to operate the Service: Supabase (auth, database + private storage), AWS (compute + storage), Fish Audio (voice cloning and voice generation), ElevenLabs (sound-effect generation), HeyGen (avatar generation), OpenAI, Anthropic, Google and DeepSeek (AI content generation and in-product AI assistance), Stripe (payments), Cloudflare (CDN), PostHog (consent-based product analytics, privacy-masked session replay, performance telemetry, and error tracking), and Crisp (customer support chat). Each processor handles only the data required to perform its function and is bound by data-processing terms.
When you use Ask Ferdi, your question and only the relevant Help Center excerpts and coarse workspace status you opted to include are sent to the configured AI provider. Ferdi does not include raw provider errors, file paths, URLs, payment identifiers, or customer-authored titles in that workspace status. A configured provider pin is treated as a data-routing boundary; Ferdi does not send the same request to another AI provider unless an operator explicitly enables cross-provider fallback.
4. Retention
Brand inputs, retained voice-clone source recordings, and generated reels are retained for the life of your account plus 30 days after deletion to allow restoration on request. Voice source recordings are also removed when the related voice clone is deleted. Telemetry is retained for 90 days.
Ask Ferdi keeps up to 12 recent questions locally in this browser for 30 days, in a namespace tied to the exact authenticated user and company. Clearing the browser's site data removes this history. A confirmed Content Creator handoff uses a one-shot in-memory transfer and does not add another copy of the question to browser storage, the URL, analytics, or a server draft.
5. Your rights
You can export or delete your data at any time from account settings. Under GDPR and CCPA you may also request access, correction, portability, or deletion by emailing [email protected]. We respond within 30 days.
6. Cookies & analytics
Ferdi uses essential cookies for session and a small set of analytics cookies for product usage measurement. The support chat uses Crisp session cookies to keep a conversation working across pages and visits. PostHog browser behavior analytics and session replay start only after you choose “Allow analytics”. Replay masks every input and all page text before data leaves the browser; Ferdi does not send prompts, captions, passwords, contact details, auth tokens, or payment-session query values as analytics properties. Ferdi separately records bounded server-side reliability, billing, and delivery outcomes needed to operate and improve the Service, without customer-authored content. You can change your browser analytics choice below at any time. We do not sell personal data.
7. Children
Ferdi is not intended for children under 13 and does not knowingly collect their data.
8. Changes
Material changes to this policy will be communicated at least 30 days in advance by email.
9. Contact
Email [email protected]. Ferdi GmbH, Wittelsbacherstraße 20, 80469 München, Germany.