Privacy Policy
Last updated: August 25, 2026
Reflare ("us", "we", or "our") operates the website at https://reflare.io and its subdomains (including app.reflare.io), together with the reflare.io browser extension (the "Service").
Who we are (data controller)
The data controller is Reflare Ltd (registration no. HE 490572), a company incorporated in the Republic of Cyprus. Full corporate details, including our registered office, are available on our Legal Information page. General contact: support@reflare.io — privacy contact: privacy@reflare.io.
This Privacy Policy explains what personal data we collect, how we use it and the rights you have over it. It should be read together with our Terms of Service.
Definitions
- Personal Data: Information identifying living individuals
- Usage Data: Automatically collected information about Service access
- Cookies: Small data files stored on user devices
- Data Controller: Entity determining data processing purposes/methods
- Data Processor/Service Provider: Entity processing data on controller's behalf
- Data Subject: Individual subject to Personal Data processing
- User: Individual using the Service
YouTube and Google Services
Reflare uses YouTube API Services and Google OAuth to operate. By using the Service and connecting your Google account, you also agree to be bound by the YouTube Terms of Service and the Google Privacy Policy.
You can revoke Reflare's access to your Google account at any time via the Google security settings page.
Data collected via YouTube API Services includes:
- Video metadata, statistics and performance metrics
- Channel information and analytics
- Engagement metrics and audience demographics
- Subtitles, captions and thumbnails
- Upload permissions for thumbnail modifications
Purpose: AI-powered content optimization, video analysis, A/B testing and analytics dashboards.
Google profile information: name, profile picture and email are used for account identification only.
Google API usage: we access your YouTube account for video listing, performance analysis and thumbnail updates. Reflare does not share YouTube data with third parties for advertising or other unrelated purposes.
Google API Services User Data Policy — Limited Use
Reflare's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Reflare:
- does not transfer Google user data to third parties for serving ads, including retargeting, personalized or interest-based advertising;
- does not use Google user data to determine credit-worthiness or for lending purposes;
- does not sell Google user data;
- allows humans to read Google user data only with your explicit consent, for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymized.
Reflare's access to and use of YouTube data is also governed by the YouTube API Services Terms of Service and the Google Privacy Policy (linked above).
Personal Data
Types collected: email address, first and last name, cookies, usage data.
Newsletter and promotional materials sent; users may opt out via unsubscribe options.
Usage Data
Collected information: IP address, browser type/version, visited pages, visit timing, time spent, device identifiers, diagnostic data.
Cookies
Reflare uses cookies to run the Service, to measure how the site is used, to credit our affiliate partners, and to run our advertising. Only the cookies needed to run the Service are set automatically. The analytics, advertising and affiliate entries below, whether they are cookies or other storage on your device, are only written after you accept them in our cookie banner, never before.
Cookies we set:
- Authentication / session cookies: keep you signed in to the Service
- Preference cookies (e.g.
reflare_currency, 12 months): remember your interface settings, such as the currency your prices are shown in reflare_referral_id(7 days, on.reflare.io): stores the affiliate referral identifier so the partner is credited if you later subscribe. We only set it once you have accepted marketing cookies and arrived through a partner link, so in the EEA, the UK, and Switzerland nothing is stored until you consent.reflare_discount_code(7 days, on.reflare.io): stores a promotional code passed in the page address (?discount,?codeor?coupon) so it can be applied at checkout- Cloudflare security cookies (e.g.
__cf_bm,cf_clearance): bot detection and challenge resolution, deposited by our edge provider Cloudflare
Storage set by third parties:
- FirstPromoter (Igil Webs SRL, Romania) runs our affiliate program. Its script loads only after you accept marketing cookies, so in the EEA, the UK, and Switzerland it never loads before you consent. It then records referral information in your browser using first-party cookies on our own domain (such as _fprom_tid and _fprom_ref). Its attribution window is configurable per campaign. See the FirstPromoter Privacy Policy.
- Cloudflare Turnstile protects our forms against automated abuse. It runs a privacy-preserving browser check when you reach a form and, unlike a traditional CAPTCHA, does not use cookies or track you across sites, as described in the Cloudflare Privacy Policy. Because it stores nothing on your device, it needs no consent.
- Google Analytics (Google LLC, USA) measures how visitors use the site so we can improve it. It sets cookies such as
_gaand_ga_*(up to 2 years), and loads only after you accept analytics cookies. - Google Ads (Google LLC, USA) measures how our ads perform and lets us reach people who have visited the site. It sets cookies such as
_gcl_au(90 days) and may read Google advertising cookies. Loaded only after you accept marketing cookies. - Reddit Ads (Reddit, Inc., USA) measures how our ads on Reddit perform and which visits and sign-ups they lead to. It sets the
_rdt_uuidcookie (3 months). Loaded only after you accept marketing cookies. See the Reddit Privacy Policy. - Fastlane (Possibility Studios Pty Ltd, Australia) tells us how much traffic our marketing campaigns send to the site. Its script loads only after you accept marketing cookies, so in the EEA, the UK, and Switzerland it never runs before you consent. Instead of cookies it uses your browser's local storage, where it keeps a random visitor identifier (
am_vid) and a session identifier (am_sid, with its timestamp inam_st, renewed after 30 minutes of inactivity). Local storage has no expiry date, so the visitor identifier stays until it is removed. It records the pages you open on our site, the page that sent you, theutm_source,utm_mediumandutm_campaigntags in the address, your screen size and browser language, how far down a page you scroll and how long you stay on it. It does not follow you across other websites. If you withdraw your consent to marketing cookies, we delete those three entries. See the Fastlane Privacy Policy.
Under the EU ePrivacy Directive, anything that is not strictly necessary requires your consent before it is stored on your device, whether it is a cookie or another form of storage. When you first visit, Reflare shows a cookie banner where you can accept or reject analytics and advertising cookies, with "Reject all" offered as plainly as "Accept all". In the EEA, the UK and Switzerland nothing non-essential is stored until you accept; elsewhere you can opt out at any time. You can change your choice whenever you like through the "Cookie settings" link in the footer, and we keep a record of your choice so we can honor it. For Google's tags we use Google Consent Mode v2, which stops them reading or writing cookies until you have consented, and we honor the Global Privacy Control (GPC) browser signal.
You can block or delete cookies at any time in your browser settings, though the Service may not work correctly without the ones needed to run it. If you want the affiliate cookies removed from our side, or you have a question about any of this, write to support@reflare.io.
Customer Data
Includes personal information about end users, customers, and website visitors. Processing limited to agreement-specified purposes.
Where you submit personal data relating to third parties (for example, your end users or team members), you warrant that you have the right and any required consents to do so, and you remain responsible for the lawfulness, accuracy and quality of that data. Where Reflare processes such data on your behalf, Reflare acts as a processor and processes it only on your documented instructions and in accordance with applicable data protection law.
Use of Data
Data used for:
- Service provision and maintenance
- Change notifications
- Interactive feature participation
- Customer support
- Service analysis and improvement
- Usage monitoring
- Technical issue detection/prevention
- News, offers, and service information
Aggregated and Anonymized Data
We may create and use aggregated, de-identified or anonymized data — which can no longer be linked to you — for statistical analysis, benchmarking, security and Service improvement. Data obtained via YouTube API Services is excluded from any use that is not permitted by the Google API Services User Data Policy, including its Limited Use requirements.
Retention of Data
We retain Personal Data only for as long as necessary for the purposes set out in this policy:
- Account data (profile, credentials, settings): for the lifetime of your account, then deleted within 30 days after account closure (subject to the grace period described below).
- YouTube data (channel info, video metadata, analytics): refreshed continuously while your account is active, deleted within 30 days after account closure or upon revocation of Google access.
- Generated content and A/B test results: kept for the lifetime of your account, then deleted with the account.
- Billing and invoicing records: retained for up to 10 years to comply with tax and accounting obligations.
- Marketing contacts: retained until you unsubscribe, then kept for up to 3 years for proof of consent purposes.
- Server logs and security data: retained for up to 12 months for security, fraud prevention and incident investigation.
Where a longer retention period is required by law (for example, tax, accounting or litigation hold), the data is kept for the duration of that legal obligation.
International Data Transfers
Your primary application data — including your account, YouTube data, generated content and A/B test results — is stored in the European Union, on Google Cloud Platform in the europe-west1 region (Belgium). Some processing nevertheless takes place outside the EU/EEA — in particular AI image generation, global edge delivery, payment processing, affiliate attribution and campaign measurement — and may involve transfers to the United States, Canada and Australia, where data protection laws may differ from those of your country.
Our main sub-processors hosting or transiting Personal Data are:
- Google Cloud Platform (Google LLC, USA) — primary hosting and storage of application data in the EU (europe-west1, Belgium); AI image generation may use United States regions
- Google Analytics and Google Ads (Google LLC, USA) — website analytics and advertising measurement, only where you have consented
- Reddit, Inc. (USA) — advertising and conversion measurement for our Reddit campaigns, only where you have consented
- Cloudflare, Inc. (USA) — DNS, CDN and edge security
- Stripe, Inc. (USA) — payment processing
- Igil Webs SRL (FirstPromoter, Romania) — affiliate program attribution and commission tracking
- Possibility Studios Pty Ltd (Australia), which operates Fastlane — measurement of the traffic our marketing campaigns generate, only where you have consented
Legal basis for transfers outside the EEA / UK. Where Personal Data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country that has not been deemed to provide an adequate level of data protection by the European Commission, we rely on appropriate safeguards under the GDPR, including:
- The EU-US Data Privacy Framework (and its UK Extension and Swiss-US Framework) where the recipient is self-certified — this is the case for Google LLC, Cloudflare, Inc. and Stripe, Inc.
- Standard Contractual Clauses (Module 2 / Module 3) approved by the European Commission, executed with each processor as required.
- Where appropriate, additional technical and organizational measures such as encryption in transit and at rest, pseudonymization and access controls.
No transfer of Personal Data takes place to an organization or country unless adequate controls are in place.
You may request a copy of the relevant transfer safeguards at support@reflare.io.
Business Transaction
Merger, acquisition, or asset sale may transfer Personal Data. Notice provided before transfer and new policy disclosure occurs.
Disclosure for Law Enforcement
Disclosure occurs if legally required or for valid public authority requests.
Legal Requirements
Disclosure made to:
- Comply with legal obligations
- Protect Reflare's rights and property
- Prevent/investigate wrongdoing
- Protect user safety
- Prevent legal liability
Security Of Data
Implemented measures:
- TLS/SSL encryption in transit; industry-standard encryption at rest
- Strict access controls and authentication
- Regular security audits and vulnerability testing
- Hosting on Google Cloud Platform (ISO 27001, SOC 2) with Cloudflare edge protection
- Encrypted OAuth token storage
No method of transmission is 100% secure. In the event of a personal data breach, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 GDPR), and will inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR).
"Do Not Track" Signals
DNT not supported. Users can enable/disable via browser preferences.
GDPR Compliance and Your Rights
Legal Basis for Processing
- Consent (YouTube data, marketing)
- Contract Performance (SaaS services)
- Legitimate Interest (improvement, security, fraud prevention)
- Legal Obligation (regulatory compliance)
User Rights
- Right of Access: Request personal data copy
- Right of Rectification: Correct inaccurate data
- Right of Erasure: Delete data under certain circumstances
- Right of Portability: Transfer data in machine-readable format
- Right of Restriction: Limit processing
- Right to Object: Object to processing based on interests/marketing
- Right to Withdraw Consent: Revoke consent anytime
Exercising Rights
Via your account dashboard or by contacting privacy@reflare.io.
Response Time: 30 days of receipt. Delays communicated with reasons.
Account Deletion Process
- Marked for deletion with 30-day grace period
- Account restoration possible during grace period
- Permanent deletion after 30 days
- Email confirmations provided
- Legal compliance data may be retained
Complaint Rights: You have the right to lodge a complaint with a data protection supervisory authority. Reflare's lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy). You may also contact your local data protection authority in your country of residence.
Users in the United Kingdom, Switzerland and Canada
If you are located in the United Kingdom or Switzerland, you benefit from equivalent rights under the UK GDPR and the Swiss Federal Act on Data Protection (FADP), exercisable as described above. If you are located in Canada, we process personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Quebec, the Act respecting the protection of personal information in the private sector (as amended by Law 25); you may exercise your rights of access and correction, or address any complaint, via privacy@reflare.io.
Automated Decisions and AI Processing
Reflare uses artificial intelligence and machine-learning models to analyze your YouTube content, generate thumbnail variants, score their predicted performance and recommend the best-performing options.
These processes assist your editorial decisions but do not produce legal or similarly significant effects on you within the meaning of Article 22 GDPR — the final decision on which thumbnail to publish always rests with you.
You can:
- request more information on the logic involved;
- express your point of view and contest any AI-generated recommendation;
- request human review of any feature output by contacting support@reflare.io.
United States State Privacy Rights
If you reside in a U.S. state with a comprehensive consumer privacy law (including California, Colorado, Connecticut, Virginia, Texas and Utah), you may have some or all of the following rights, subject to the conditions and thresholds of the applicable law:
- Right to know / access: request the categories and specific pieces of personal information we have collected about you
- Right to correct: request correction of inaccurate personal information
- Right to delete: request deletion of your personal information, subject to legal exceptions
- Right to data portability: receive your personal information in a portable format
- Right to opt out of sale, sharing or targeted advertising: Reflare does not sell your personal information for money, but using Google Ads and Reddit Ads to reach past visitors counts as "sharing" for cross-context behavioral advertising under California law. You can opt out at any time through our cookie banner, reachable from the "Your Privacy Choices" and "Cookie settings" links in the footer, and we treat the Global Privacy Control signal as a valid opt-out
- Right to limit use of sensitive personal information: we use sensitive information only as necessary to provide the Service
- Right to non-discrimination: we will not discriminate against you for exercising any of these rights
To exercise these rights, contact support@reflare.io. We will verify your identity and respond within the timeframe required by the applicable law (generally 45 days, extendable once where permitted). Where the applicable law provides for it, you may appeal a decision by replying to our response; we will inform you of the outcome and, if you disagree, of your right to contact your state Attorney General. You may use an authorized agent, subject to proof of authorization.
Marketing Use of Your Content
As described in our Terms of Service, by using our Service you grant us a license to use thumbnails and related content for marketing purposes. This may include featuring your content on our website, social media, case studies, and promotional materials.
You may revoke this marketing license at any time by contacting us at support@reflare.io. For full details, please refer to the "Marketing License" section of our Terms of Service.
Service Providers
Third parties facilitate the Service. Access limited to assigned tasks; disclosure/unauthorized use prohibited.
Analytics and Advertising
With your consent, Reflare uses Google Analytics to understand how the site is used and Google Ads to measure our advertising and reach people who have visited us. These run under Google Consent Mode v2: they read and write no cookies, and receive no advertising identifiers, until you accept the matching category in our cookie banner. In the EEA, the UK and Switzerland they stay off until you opt in; elsewhere you can opt out at any time, and we honor the Global Privacy Control signal.
With your consent, we also use the Reddit Ads pixel (Reddit, Inc., USA) to measure how our advertising on Reddit performs — which visits, sign-ups and purchases our Reddit campaigns lead to. It sets the _rdt_uuid cookie and loads only after you accept marketing cookies, so in the EEA, the UK and Switzerland it never runs before you consent. See the Reddit Privacy Policy.
We also run an affiliate program through FirstPromoter, which is a form of marketing measurement. FirstPromoter records that your visit came from a specific partner link — or that you used a partner's promo code — and matches it to a later subscription so that the partner can be paid a commission. When you subscribe, the referral identifier is sent to Stripe with your checkout session, and FirstPromoter attributes the sale through Stripe's webhooks. FirstPromoter sees which partner sent you and whether you subscribed. It does not follow you across other websites.
Our marketing campaigns are run with Fastlane (Possibility Studios Pty Ltd, Australia), and its tag reports how many people each campaign brings to reflare.io. It only runs if you accept marketing cookies. What it sees is the pages you open here, the site or campaign that sent you and a few technical details about your browser, all under a random identifier stored on your device. It builds no advertising profile and cannot see what you do on other websites. Because Australia has no EU adequacy decision, this transfer relies on the Standard Contractual Clauses.
Payments
Payment card details not stored; provided directly to third-party processors. PCI-DSS standards compliance. Stripe is the payment processor.
Links To Other Sites
Third-party links may appear. Users advised to review external privacy policies. Reflare assumes no responsibility for external sites.
Children's Privacy
The Service is intended for users aged 18 or over and is not directed to minors. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected personal data from a minor, we will delete it. Parents or guardians who believe a minor has provided us with personal data may contact us at support@reflare.io.
Changes To This Privacy Policy
Updates posted on page. Email and prominent Service notice provided prior to effectiveness. Review periodically recommended.
Contact Us
For any question regarding this Privacy Policy or your personal data, please contact us at support@reflare.io (privacy contact: privacy@reflare.io) or by post at our registered office listed on the Legal Information page.