Tagly Privacy Policy
Effective date: December 1, 2025 Last updated: August 8, 2026
Summary of Key Points (Plain-Language Overview) This summary is for convenience only. The full Privacy Policy below is the binding document.
- Who we are. Tagly is operated by Flaer, Inc., a Delaware corporation. Tagly connects local businesses with their customers, who can earn rewards for sharing Instagram Stories about them.
- What we collect. Your email and profile details, the Instagram data you explicitly authorize (profile, audience statistics, the Stories you choose to monetize and their performance), and the business information advertisers publish. We never see your Instagram password.
- Location. The customer app uses your device location only to show nearby businesses. Your location is used for the moment of the request and is never stored on our servers.
- Analytics. We use PostHog for anonymous, device-level product analytics. We never link analytics events to your name, email, or account, and in our apps we use no session recording, advertising identifiers, or cross-app tracking. Our marketing website uses common web analytics, described in Section 6.
- Money. Payments and payouts run through Stripe. Card numbers, bank details, and identity documents go directly to Stripe and never reach our systems.
- Sharing. We never sell personal data. Businesses see the content of monetized Shares and aggregated statistics, but never who you are.
- Moderation. Every Share is reviewed by our team before it is shown to the business. Automated checks screen images, text, and links for safety.
- Deletion. You can delete your account at any time in the app. Your remaining balance is paid out to you first, your media and Instagram data are deleted, and financial records we must keep by law are anonymized.
- Contact. legal@taglyapp.com.
1. Introduction
1.1 Who We Are
This Privacy Policy explains how Flaer, Inc., a Delaware C-Corporation operating the Tagly platform ("Tagly," "we," "us," or "our"), collects, uses, stores, shares, and protects personal information. Our registered address is 251 Little Falls Drive, Wilmington, DE 19808, USA.
Tagly operates the following applications:
- Tagly (Customer App), for individuals who connect their Instagram account, share Stories about local businesses, and earn performance-based rewards.
- Tagly Partner (Advertiser App), for businesses that create a business page, load credits or connect a card, and receive promotion from their customers.
- An internal administration application, used only by authorized Tagly staff to operate, support, and moderate the platform.
This Privacy Policy applies to these applications, our websites (taglyapp.com and tagly.cz, and the legacy flaer.app and flaer.cz domains, in each case including all subdomains), the join landing pages, our app redirect pages, and all backend systems that support them.
1.2 Purpose and Scope
This Privacy Policy describes the categories of information we collect, how we use and share them, how long we keep them, how we protect them, and the rights and choices you have. It covers Instagram data, advertiser business information, rewards and payouts, referrals, notifications, location-based discovery, and account deletion.
1.3 Definitions
Capitalized terms not defined here (such as "Share," "Credits," "Estimated Reward," "Final Reward") have the meanings given in the Tagly Terms of Service and Terms of Monetization. In addition:
- "User" means an individual using the Customer App.
- "Advertiser" means a business or its representative using Tagly Partner.
- "Instagram Data" means information retrieved through the Instagram API with your authorization, including profile information, audience statistics, media, and insights.
- "Services" means all Tagly applications, websites, and backend systems.
1.4 Age Requirements
To use Tagly you must meet the minimum age required to hold your own Instagram account under Meta's terms and be able to enter into a binding agreement in your jurisdiction. Receiving payouts additionally requires completing Stripe's onboarding; eligibility for payouts, including any age and identity verification, is determined by Stripe. Additional age rules for the EEA are in Section 15.
1.5 Contact
Flaer, Inc., 251 Little Falls Drive, Wilmington, DE 19808, USA Email: legal@taglyapp.com
2. Data We Collect
We collect only the categories described below.
2.1 Information You Provide
2.1.1 Account Registration
Registration in both apps works with an email address and a one-time code, or with Google or Apple sign-in. There are no passwords. When you register, we collect:
- email address,
- country and language settings,
- your marketing choice (an explicit yes/no for promotional email and push notifications),
- timestamps of your agreement to the Terms of Service and this Privacy Policy.
Users additionally provide:
- full name (required; shown to our staff and, where relevant, used in payout records, never shown to Advertisers),
- optionally a gender ("prefer not to say" is the default),
- optionally up to three interests (used to personalize discovery and rewards),
- optionally a self-reported estimate of how many people view their Instagram Stories (used as a pricing input when no Instagram account is connected).
If you use Google or Apple sign-in, we receive a signed token from the provider containing your provider account identifier, email address, email-verification status, and name. We store the provider, the account identifier, and the email to link your sign-in method; the name is used only to prefill the profile form and is not stored by us.
2.1.2 Instagram Connection (Users)
Connecting Instagram is optional and uses Instagram's official login. We request only the instagram_business_basic and instagram_business_manage_insights permissions. We never receive your Instagram password. The data we then collect is listed in Section 2.3.
2.1.3 Payout Information (Users)
Payouts use Stripe Connect. We store only your Stripe account identifier and whether payouts are enabled. Bank account numbers, card numbers, identity documents, and tax details are provided by you directly to Stripe and never reach our systems. When creating your Stripe account we pass Stripe your name and email address.
2.1.4 Business Information (Advertisers)
Advertisers provide the content of their public business page: business name, description, category, postal address, banner and photos, and optionally opening hours, phone number, contact email, Instagram handle, and website, menu, and reservation links. This information is published to Users in the app; provide only business contact details you intend to make public.
We also keep advertiser billing records: credit purchases and their timestamps, Stripe payment identifiers, credit balances, and amounts reserved for Shares. As with Users, card details never reach our systems (Section 2.1.3).
2.1.5 Ratings and Reports (Advertisers)
Advertisers may rate a Share (a one-time star rating) or report it. We store the rating or report, its timestamp, and the outcome of our review.
2.1.6 Referral Codes
When you use or share a referral code we store the code, which account created it, and which account used it, so referral rewards can be attributed.
2.1.7 Support and Feedback Messages
Messages you send through the in-app support and feedback forms are emailed to our team together with your account reference and app version. They are not stored in our database.
2.1.8 Website Forms
If you use the contact, sales, support, or careers forms on our website, the details you enter (such as name, email, message, and for job applications an optional CV link) are emailed to the relevant team inbox and are not stored in a website database.
2.2 Information Collected Automatically
2.2.1 Device and App Information
We store, together with your push notification registration: the push token, platform (iOS/Android), your device's time zone (used to send notifications at reasonable local times), a vendor-scoped device identifier (Apple's identifierForVendor or the Android app-scoped ID; never an advertising identifier), and when the app was last opened. We do not collect advertising identifiers and do not show App Tracking Transparency prompts, because we do not track you across apps.
2.2.2 Location (Customer App)
With your permission, the customer app reads your device location in the foreground to show nearby businesses, sort search results by distance, display the map, and detect when you may have visited a participating business. Coordinates are sent with those requests, used to compute the results, and discarded; we never store your location on our servers, we keep no location history, and there is no background location tracking. Discovery requests round your position to roughly street-block accuracy. You can use large parts of the app with location off.
2.2.3 Operational Events
We keep functional records needed to run the platform: logins and account events, Instagram token refreshes, Share creation and processing states, reward calculations, payout statuses, notification deliveries, and moderation outcomes.
2.2.4 Anonymous Product Analytics (PostHog)
We use PostHog to understand how the apps are used: onboarding steps, screen views (as screen names, not content), and feature events. These analytics are anonymous and device-level: we never call any identification function, events are not linked to your name, email, or account profile, session recording is disabled, and no advertising identifiers are involved. Our backend additionally records pseudonymous operational telemetry (for example "a promotional email was sent" and error diagnostics), referenced by an opaque account identifier and configured so no person profile is built from it.
2.2.5 Attribution (AppsFlyer)
The apps include the AppsFlyer SDK for install attribution and referral deep links (so a referral code survives the app-store install step). AppsFlyer processes device information, IP address, and install metadata under its own privacy policy. We read only the referral code from its results and do not send it custom events.
2.2.6 IP Addresses
We do not maintain IP-address profiles or browsing logs. IP addresses are used transiently for rate limiting (kept for about a minute in an in-memory store) and appear in short-lived operational security logs when a request causes an error. These logs exist to keep the platform secure and reliable.
2.3 Information We Collect From Instagram (Users)
With your authorization we collect:
Profile and account data: Instagram account ID, username, display name, profile picture URL, account type, and follower count (refreshed when you open the app).
Audience statistics (periodic snapshots): follower and following counts, aggregated audience locations by city (which we convert to map coordinates), and aggregated audience gender and age brackets. Snapshots are taken when you create a Share and at most about monthly otherwise. These aggregates never identify your individual followers.
Your live Stories list: when you open the Story picker, we fetch your currently live Stories (ID, media type, media URL, thumbnail, timestamp) so you can choose one. Nothing is stored at this step.
Monetized Story media: for a Story you choose to monetize, we download and store the media file exactly as posted, plus a thumbnail, on our servers. Captions and permalinks are not collected.
Story insights: collected once per Share, approximately 24 hours after posting: views, reach, replies, shares, taps forward/back, exits, follows, profile visits, and total interactions.
Access token: a long-lived Instagram access token and its expiry time, stored encrypted (AES-256-GCM) and refreshed automatically. Deleted when you disconnect Instagram or delete your account.
2.4 Information From Other Sources
Stripe: account identifiers, payment and payout statuses, amounts, and timestamps. Stripe may collect identity information from you directly for its legal obligations; it does not reach our systems.
Google and Apple: the sign-in token described in Section 2.1.1.
2.5 Information We Do Not Collect
We do not collect or store: your contacts, private messages, microphone or camera data (the customer app requests no camera access in any flow), biometric data, precise location history, advertising identifiers, cross-app browsing behavior, card or bank account numbers, government IDs, or your date of birth. We do not use device fingerprinting and no facial recognition (our automated image checks detect text and prohibited content, not faces). We do not build or sell identity graphs, and our apps contain no session recording (for website analytics, see Section 6).
3. How We Use Your Data
We use personal data to operate Tagly, run the monetization program, keep the platform safe, comply with our legal obligations, and improve the product. We do not sell personal data and we do not use it for third-party advertising.
3.1 Operating the Customer App
3.1.1 Instagram Connection
We use your Instagram authorization to verify your account, refresh your access token, fetch your live Stories when you ask, take the audience snapshots described above, and process monetized Stories.
3.1.2 Monetization and Rewards
When you monetize a Story we use your media, audience statistics, and insights to:
- check the Story is live on your connected account and visibly references the selected business (an automated image-text check),
- calculate an Estimated Reward when the Share is created (shown as "up to" an amount when the business's remaining budget limits it),
- submit the Share for review by our staff before it becomes visible to the business,
- collect insights once, approximately 24 hours after posting, and calculate the Final Reward from them,
- credit your balance and process withdrawals through Stripe.
Reward calculation uses your audience statistics (size, locations, demographics), your interests, your posting frequency, your quality rating (Section 3.3.2), and the business's settings and funding. Every calculation is recorded with the algorithm version and inputs used, so it can be audited.
3.1.3 Displaying Shares to Advertisers
After a Share is approved, the business it promotes can see the media, posting and monetization timestamps, prices, and a limited set of aggregate insight metrics for that Share. Businesses never see your name, username, profile, followers, or any identifying information; each Share appears as an anonymous item. See Section 4.2.
3.1.4 Notifications
We use your push token and email for transactional notifications (Share status, rewards, payouts, security and account notices) and, only with your explicit consent, for promotional messages. You can manage notification categories per event type in the app and withdraw marketing consent at any time (unsubscribe link in every promotional email, or in settings). Transactional messages required to operate your account are sent regardless of marketing consent. Promotional messages respect local quiet hours based on your device time zone.
3.1.5 Referrals
We use referral codes to attribute referred accounts and pay referral rewards. Referrers see only counts and totals, never who signed up with their code.
3.2 Operating Tagly Partner
We use advertiser data to publish the business page, geocode the business address into map coordinates, operate discovery (ordered mainly by distance, category, and available budget), maintain credit balances, place and release budget locks, process card charges for pay-as-you-go businesses, and show aggregated performance statistics.
3.3 Safety, Integrity, and Moderation
3.3.1 Content Moderation
We use automated and human moderation:
- every monetized Story passes an automated image-text check confirming it references the selected business, and its media is screened by an automated image-moderation service;
- business images are screened automatically for prohibited content, business texts are screened for profanity, and business links are checked against Google Safe Browsing and approved by our staff before being shown;
- every Share is reviewed by our staff before it is shown to the business and before it can be paid; our staff also review reports submitted by businesses.
3.3.2 Quality Rating and Enforcement
Each User has an internal quality multiplier that adjusts future reward calculations. It moves with business ratings of your Shares, Share rejections, and upheld reports, within fixed bounds; you can see its effects in your reward estimates and you are notified when a rating changes it. To protect the platform we may also suspend accounts and maintain a block-list of Instagram accounts connected to banned accounts, so a ban cannot be evaded by re-registering; this list is retained as long as necessary for fraud prevention.
3.3.3 Security
We use operational logs, rate limiting, and error diagnostics (Section 2.2.6) to protect accounts, prevent abuse, and keep the Services reliable.
3.4 Legal Compliance
We process data to comply with Meta platform policies, Stripe and payment regulations, tax and accounting law, app-store requirements, and valid legal requests, disclosing only the minimum necessary.
3.5 What We Do Not Use Your Data For
We do not use your data for third-party advertising, sale or rental of data, data brokering, cross-app tracking, or automated decisions with legal effects beyond the reward and moderation processes described in this Policy (see Section 15.8 for your right to human review).
4. How We Share Your Data
We do not sell personal data. We share it only with the processors and integrations needed to run Tagly, with the recipients described below, or when the law requires it.
4.1 Service Providers
| Provider | Purpose | What it receives |
|---|---|---|
| Stripe | Payments, payouts, KYC | Account identifiers, amounts, statuses; your name and email at payout-account creation; identity data you give Stripe directly |
| Meta / Instagram | Instagram login and API | Authorization requests, token refresh, the API calls you authorize |
| Amazon Web Services | Hosting and storage (us-east-1) | Platform data, media files, databases (encrypted) |
| AWS Rekognition | Automated image checks | Business images and monetized Story media, referenced for scanning; results are not stored |
| Amazon Location Service | Geocoding | Business postal addresses; Instagram audience city names. Never User locations |
| Expo | Push notification delivery; app update checks | Push tokens and notification content; anonymous update-check metadata |
| Resend | Email delivery | Recipient address, message content, and delivery labels (an opaque account reference, never your name) |
| PostHog | Product analytics and operational telemetry | The anonymous and pseudonymous events described in Section 2.2.4 |
| AppsFlyer | Install attribution, referral deep links | Device and install metadata under its own policy |
| Google / Apple | Sign-in | The sign-in exchange described in Section 2.1.1 |
| Google Safe Browsing | Link safety | Business-supplied URLs only |
| Apple Maps / Google Maps | In-app maps | Map tile requests from your device (viewport, IP), per the platform's own policy |
| Frankfurter (frankfurter.dev) | Currency display | A rate lookup from your device (your IP is visible to it; no identifiers are sent) |
Each provider receives only what its function requires and is bound by its own privacy obligations and, where applicable, our data-processing agreements.
4.2 What Advertisers See
For each approved Share about their business, Advertisers see the media, posting and monetization timestamps, the prices, and a limited set of aggregate metrics for that Share (reach, views, replies, shares, follows, profile visits, total interactions). Across all Shares they see totals: number of Shares, total reach, average price, and unique-customer counts. Advertisers never see your name, username, profile, picture, follower data, location, who viewed your content, or any identifying information, and they may not attempt to identify you.
4.3 What Other Users See
Users see published business pages (including the business contact details the Advertiser chose to publish). There are no public user profiles, feeds, or user-to-user visibility.
4.4 Internal Staff Access
Authorized Tagly staff use a role-restricted internal application to operate the platform: reviewing Shares and reports, supporting users, and managing accounts. Staff can view account details (including email, name, connected Instagram profile, balances, and payout records) strictly for these purposes.
4.5 Legal, Safety, and Business Transfers
We may disclose data to comply with law, respond to lawful requests, resolve disputes involving payments or withdrawals, prevent fraud or harm, or enforce our Terms, limited to the minimum necessary. In a merger, acquisition, or asset sale, personal data may transfer to a successor bound to protections at least as strong as this Policy.
4.6 With Your Consent
Any sharing beyond this Policy happens only with your explicit consent, which you may withdraw at any time.
5. Monetization and Insights Processing
This section describes the data flows of the monetization program in one place.
5.1 Creating a Share
When you monetize a live Story: we fetch it from Instagram, store the media and a thumbnail, record timestamps and your acceptance of the Terms of Monetization, run the automated business-reference check, calculate the Estimated Reward, and register the Story in a duplicate-prevention registry so each Story can only ever be monetized once. Creation requires the business to be participating (sufficient budget, an active pay-as-you-go card, or platform sponsorship).
5.2 Review, Funding, and Insights
Every Share is reviewed by our staff. On approval, the business's funds are reserved (or, for pay-as-you-go businesses, the card is charged at settlement), and the Share becomes visible to the business. Insights are collected once, approximately 24 hours after the Story was posted; we do not monitor your account continuously. The Final Reward is then calculated and, after a review period of at least 24 hours from creation, paid to your balance in full. Once calculated, a Final Reward is not recalculated.
5.3 When Shares Are Not Rewarded
A Share receives no reward when its insights cannot be collected (the Story was deleted early or Instagram access was lost), when you disconnect Instagram, delete your Instagram data, or delete your account before settlement, when our review rejects it, or when a business report is upheld. In these cases reserved business funds are released, you are notified in the app with the reason where one can be shown, and the Share record remains stored (Section 8). Removing content on Instagram does not delete the copy we already stored: media and insights collected before the removal remain retained as described in Section 8 until you delete your account or request Instagram data deletion (Section 9.3).
5.4 Payouts
Final Rewards are credited to your balance and withdrawable to your own Stripe account (minimum USD 1.00, in USD). If you delete your account, your remaining balance is first paid out to your Stripe account; only unfinalized Shares are forfeited.
5.5 No Resale of Insights
Insights are used only for reward calculation, your own statistics, and the aggregated advertiser statistics described above. They are never sold and never used for advertising or profiling.
6. Cookies, Tracking, and Similar Technologies
In the apps: we use no cookies. The SDKs active in the apps are listed in Section 2.2 (PostHog, AppsFlyer) and run from first launch; PostHog analytics are anonymous and device-level, and none of the SDKs is used for cross-app tracking, retargeting, or advertising profiles built by us.
On our marketing websites (taglyapp.com, tagly.cz): the sites use essential cookies and, for analytics, only what the cookie banner on the site describes; for visitors in the EU, non-essential cookies and analytics load only after you accept the banner (an equal "Reject" option is offered), and you can change or withdraw your choice at any time via the banner or your browser settings. Website analytics are not used to identify you or link visits to a Tagly account.
On the join landing pages (join.tagly.cz, join.taglyapp.com): cookieless, anonymous PostHog analytics only; no cookies are set and no Google tags are used.
Third-party sites (for example Stripe or Instagram pages opened from the app) apply their own cookie policies.
7. Data Storage and Security
7.1 Infrastructure and Encryption
All platform data is stored on AWS in the United States (us-east-1); AWS data centers hold industry certifications such as SOC 2 and ISO 27001. Databases are encrypted at rest (AES-256), stored media uses server-side encryption, Instagram access tokens are additionally encrypted at the application layer (AES-256-GCM), and all connections use TLS 1.2+.
7.2 Media Delivery
Monetized Story media and business images are served through a content delivery network from unguessable URLs so the apps can display them. These URLs are not listed or indexed anywhere, but anyone possessing a URL could fetch the file while it exists; deletion removes the stored object (already-cached CDN copies expire on their own shortly after).
7.3 Access Controls
There are no passwords anywhere in Tagly: all sign-in (Users, Advertisers, and staff) uses one-time email codes or Google/Apple sign-in. Production systems are accessible only to authorized personnel, and staff access to user data runs through the role-restricted internal application (Section 4.4).
7.4 Operational Logging
Application logs do not contain query parameters, tokens, or message content. Error diagnostics include the request path, the client IP address, and the user-agent, and are kept short-term for security and reliability purposes only.
7.5 Backups
Databases are backed up automatically (daily snapshots, retained 14 days, encrypted, same region). Backups expire automatically and do not extend the retention of deleted data beyond Section 8.
7.6 Your Part
On your device, the apps store only your sign-in session (in the operating system's protected storage) and preferences; card details, bank credentials, and identity documents are never stored on your device. Keep your devices secure, protect your email account (it is the key to your Tagly sign-in), never share your one-time sign-in codes, and keep your Instagram account secure. We can never guarantee absolute security, and no method of transmission or storage is perfectly secure.
8. Data Retention
We keep personal data only as long as needed for the purposes above. The actual schedules:
| Data | Retention |
|---|---|
| One-time login codes | Minutes (deleted shortly after expiry) |
| Abandoned registrations (never completed) | 30 days |
| Notification delivery records | 24 hours after delivery |
| Insight/snapshot processing records | 7 days |
| Unfinished media uploads | 24 hours |
| Deleted business pages | 7-day grace period, then purged |
| Account data (profile, Instagram data, media, settings, tokens) | Until account deletion or Instagram data deletion (Section 9) |
| Financial records (ledger, payouts, purchases) | 5–7 years as required by law, anonymized after account deletion (Section 15.7 for Czech periods) |
| Instagram ban block-list; monetized-Story registry (Story ID only, no account link); posting timestamps of paid Shares | Retained for fraud prevention (the registry and block-list have no link to a deleted account) |
| Referral codes and referral history | Retained for financial attribution |
When your account is deleted, your media, insights, Instagram data, tokens, notification data, settings, and identifiers are deleted; Share and ledger records required for accounting are kept with the link to you removed (anonymized).
9. Your Rights and Data Deletion
9.1 Access, Correction, Portability
You can access and update most data directly in the app. You may also request a copy of your data, corrections, or a machine-readable export at legal@taglyapp.com. Corrections to Instagram-sourced fields (such as your username) are made by updating them on Instagram; we mirror them on the next refresh. For any request under this Section 9 we may first verify your identity (for example by email confirmation, account checks, or, for payout matters, Stripe verification), and we never delete financial records the law requires us to keep.
9.2 Account Deletion
You can delete your account at any time in the app settings (confirmed by a one-time email code). If you have a balance, it is paid out to your Stripe account first; deletion is not possible while a withdrawal is in flight, and if you have a balance but no payout account you must withdraw first. On deletion: media, insights, Instagram data and tokens, push tokens, settings, and your profile are deleted; in-flight Shares are cancelled without payment; records we must keep (Section 8) are anonymized. Deletion is permanent.
Advertisers can likewise delete their account in the app (the Terms of Service describe the commercial effects): business pages, images, settings, and contact details are deleted, Shares remain stored in anonymized form with no reference to the deleted account, and financial records are retained per Section 8.
9.3 Instagram Disconnection and Data Deletion
Three separate mechanisms exist:
- Disconnect Instagram (in the app): deletes your Instagram profile data, snapshots, and token; pending Shares are cancelled; paid history and stored media remain until account deletion.
- Deauthorize Tagly (in Instagram's settings): invalidates and deletes our access token; other data remains until you request deletion.
- Instagram Data Deletion request (via Instagram or by email): deletes all Instagram-derived data including stored media and insights. You receive a confirmation code and a status URL. Details: taglyapp.com/instagram-data-deletion.
9.4 Marketing and Notification Choices
Withdraw marketing consent any time (in-app or via the unsubscribe link); manage per-event notification preferences in settings. Transactional notices continue while your account exists.
9.5 Restriction, Objection, Deceased Users, and Inactive Accounts
Beyond marketing choices, you may object to or ask us to restrict specific processing (for example referral attribution or optional profile data) in the app or at legal@taglyapp.com; where we have no overriding legitimate ground, we will comply. On a valid request from an authorized representative or executor of a deceased user, we delete the account's data and retain only legally required records. Accounts inactive for an extended period may be deleted as permitted by law.
9.6 California Residents
California residents may exercise access, deletion, and disclosure rights at legal@taglyapp.com. We do not sell personal data and do not discriminate for exercising privacy rights.
9.7 Response Times
We respond to verified requests within 30 days (GDPR) or 45 days (CCPA), with extensions where the law allows.
10. International Data Transfers
We store data in the United States and use the providers listed in Section 4.1, which may process data in the US or other countries. Where data of EEA/UK/Swiss residents is transferred to countries without an adequacy decision, we rely on Standard Contractual Clauses in our agreements with these providers (and, for transfers from the United Kingdom, the UK International Data Transfer Addendum), together with encryption and access controls. You may request information about these safeguards at legal@taglyapp.com.
11. Children's Privacy
Tagly is not directed at children, and we do not knowingly collect personal data from children under 13 (COPPA). You must meet Instagram's minimum age to connect an account, payouts require completing Stripe's verification, and Advertiser accounts must be operated by adults authorized to represent the business. If we learn that an ineligible child is using Tagly, we will disable the account and delete its personal data, retaining only records required for fraud prevention or legal compliance; if Stripe's verification shows a user cannot receive payouts, payouts are not processed and the account may be restricted. Report concerns to legal@taglyapp.com. EEA age rules are in Section 15.9.
12. Changes to This Privacy Policy
We may update this Privacy Policy as the product or the law changes, updating the "Last updated" date above. Changes become effective when posted unless stated otherwise, and continued use of the Services after the effective date constitutes acceptance. For significant changes we notify you in the app and/or by email, and the app may additionally require you to review and accept the updated Policy before continuing. If you do not agree, stop using the Services and delete your account.
13. Contact
Flaer, Inc. 251 Little Falls Drive, Wilmington, DE 19808, United States legal@taglyapp.com
14. Scope
This Privacy Policy applies to all Users and Advertisers of the Tagly Services regardless of country of residence, and remains in effect until replaced. It is drafted in English; translations are provided for convenience only, and the English version prevails in case of any discrepancy.
15. Additional Terms for the European Economic Area and the Czech Republic
Effective date of this Section: August 6, 2026
This Section applies to individuals in the EEA, including the Czech Republic, supplements the Policy above, and prevails in case of conflict for such individuals.
15.1 Data Controller
Flaer, Inc., 251 Little Falls Drive, Wilmington, DE 19808, USA — legal@taglyapp.com.
15.2 Legal Bases (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Operating your account; Instagram connection; monetization; reward calculation; payouts; paying out your balance on account deletion | (b) performance of a contract |
| Marketing email and push; optional website analytics cookies | (a) consent |
| Accounting, tax, payment and AML/KYC obligations | (c) legal obligation |
| Content moderation and Share review; fraud prevention (including the Instagram block-list and the monetized-Story registry); security logging and rate limiting; anonymous product analytics and pseudonymous operational telemetry; install attribution | (f) legitimate interests |
Where we rely on consent you may withdraw it at any time; where we rely on legitimate interests you may object (15.4).
15.3 Marketing Communications
We send promotional messages only with your prior, explicit, freely given consent, collected as a separate unbundled choice at registration; you are never opted in by default. Withdrawal is available at any time, does not affect the lawfulness of processing carried out before withdrawal, and does not affect transactional messages.
15.4 Your Rights
You have the rights of access, rectification, erasure, restriction, portability, and objection (including to processing based on legitimate interests). Contact legal@taglyapp.com; we respond within one month (extendable by two months for complex requests, with notice). You may lodge a complaint with your supervisory authority; in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz).
15.5 Analytics and Attribution
Our product analytics (PostHog) run without an account identity: no identification calls, no session recording, no advertising identifiers, and no cross-app tracking; backend telemetry is pseudonymous and builds no person profiles. The attribution SDK described in Section 2.2.5 operates from first launch under its provider's policies; you may object to this processing (15.4), and the website's non-essential cookies are set only after consent via the banner.
15.6 International Transfers
Transfers outside the EEA rely on Standard Contractual Clauses (Art. 46 GDPR) with our providers, supported by encryption and access controls. A copy of the relevant safeguards is available on request.
15.7 Retention (Czech Periods)
Accounting documents are kept 5 years, financial statements 10 years, and VAT records 10 years (Act No. 563/1991 Coll.; Act No. 235/2004 Coll.), decoupled from your identity after account deletion where possible.
15.8 Automated Processing and Human Review
Final Rewards are calculated automatically from Instagram insights and recorded inputs, and some content checks are automated (Sections 3.3.1). Where a reward is refused or a Share declined, we provide a brief reason in the app where possible, and you may request human review and contest the outcome at legal@taglyapp.com. This does not affect your statutory rights (including under Regulation (EU) 2022/2065).
15.9 Age
In the EEA you must be at least 15 years old to use Tagly on the basis of your own consent; below that age, consent must be given or authorized by the holder of parental responsibility (Section 7 of Act No. 110/2019 Coll.). We make reasonable efforts to verify age.
15.10 Provision of Data
Some data is necessary to perform our contract with you: without a connected Instagram account we cannot evaluate content or calculate rewards, and without the information Stripe requires we cannot pay out earnings. Without such data, the related features are unavailable.