Privacy Policy
Last updated: September 2026
Flyls is operated by Abdulaziz Nasser Bin Muzayil, an individual based in Saudi Arabia. This policy describes what the service collects, why, how long it is kept, and who else sees it. It covers the Flyls website, the browser extension, and the API.
What Flyls collects
| Data | Why |
|---|---|
| Your name and email address | To create and identify your account. |
| A hash of your password | To sign you in. The password itself is never stored and cannot be recovered from the hash. |
| The subject line and recipient addresses of emails you choose to track | So the dashboard can show you which message an open belongs to. |
| Open events: the time, a device category (desktop or mobile), and an approximate country | This is the product. |
| Clicks on links you chose to track, with the link's label | Business plan feature. |
| Sign-in records: time, approximate location, and browser | So you and we can spot access you do not recognise. |
| How this website is used: which parts of a page were on screen and for how long, how far it was scrolled, what was clicked or hovered over, which windows were opened and how they were closed, how long a form field was in use, page-speed timings and error reports. Never what is typed into a field. | To find what is confusing or broken on this site and fix it. See below. |
How we learn what is confusing on this site
When you use flyls.com, the page records what you do on it, in order and with timings: the sections you read, the buttons you press, the ones you hover over and leave, a window you close, a field you start and abandon. It is how we find the part of a page that loses people, which nobody ever writes in to report.
- Nothing you type is recorded. A form field is recorded as used, for how long, and whether it ended up empty or not — never what was in it. Password fields are treated the same way.
- Nothing from your dashboard's contents. The subjects and recipients of your tracked emails are never part of it.
- It stays with us. It is stored by Flyls on the same infrastructure as everything else here, and is not sent to any analytics or advertising company.
- It is tied to a random identifier your browser keeps for this site, not to a fingerprint of your device. Clearing this site's data in your browser removes it. If you are signed in, the record is linked to your account.
- It is kept for 90 days and then deleted automatically.
- It respects Global Privacy Control. If your browser sends that signal, nothing is recorded at all.
What Flyls does not collect
- The contents of your emails. The extension reads the recipients and the subject of a message you are composing, and inserts a tracking image. It does not read, transmit or store the body.
- Raw IP addresses. When an email is opened, the reader's IP address is used to derive an approximate country and is then hashed with a secret salt. The hash is what is stored; the address itself is not.
- Your browsing. The extension runs only on the mail sites listed in its permissions and on flyls.com. It has no access to any other page you visit.
- Payment card details. These go to Paddle and are never seen by Flyls.
About the people you email
If you track a message, Flyls records that address, and records when that message was opened. Those people have not agreed to this — you have. You are responsible for having a lawful basis to track them, and in some places that means telling them. Flyls gives you the tool; the obligation to use it lawfully is yours.
A recipient who wants their data removed can write to support@flyls.co and it will be deleted.
How long it is kept
- Open and click records: 12 months. A daily job deletes anything older.
- Sign-in and account activity records: 12 months.
- Your account: for as long as it exists. Deleting it removes your pixels, their tracking records, and your activity history.
Who else sees it
Flyls does not sell data and does not share it for advertising. It is processed by these services, and only for the purpose given:
| Service | What it receives |
|---|---|
| Cloudflare | Hosting, the database and the CDN. All data sits here. See where it is stored. |
| Paddle | Payments. Receives your email address and billing details; acts as merchant of record. |
| Resend | Transactional email — verification codes, password resets, notifications. |
| GeoJS | Receives an IP address to return a country code. Nothing else, and nothing is stored there by us. |
| Only if you choose to sign in with a Google account. |
Data may also be disclosed where the law requires it.
Where it is stored
The database runs on Cloudflare's network with its primary location in Eastern Europe. Static files — the site itself, images, scripts — are served from Cloudflare's global network and are cached in many countries, but those files contain nothing about you.
Flyls is operated from Saudi Arabia, which means your data is held outside the Kingdom. This is stated so that it is known before an account is created rather than discovered afterwards.
Saudi data protection law
Because the operator is in Saudi Arabia, the Personal Data Protection Law (PDPL) applies to how this service handles personal data. Under it you may ask to see the data held about you, to have it corrected, to have it deleted, and to withdraw a consent you previously gave. Those are the same rights listed under your choices below, and they are honoured on request whether or not the law in your own country grants them. Write to support@flyls.co.
If you are in the EU or the UK, the GDPR terms for the same ideas are access, rectification, erasure and withdrawal of consent, and they are handled the same way.
Your choices
- See your data. The dashboard shows everything recorded against your account.
- Export it. Business plans can retrieve it through the API.
- Delete it. Delete a tracked email to remove its records, or write to support@flyls.co to close the account entirely.
- Stop tracking. The extension's toggle turns it off per message, and removing the extension stops it completely.
Security
Passwords are stored as PBKDF2 hashes with a per-account salt. API keys and refresh tokens are stored as SHA-256 hashes, so a copy of the database does not yield a working credential. Traffic is encrypted in transit. Sessions can be revoked, and revoking one ends every token issued before it.
No service can promise it will never be breached. If one occurs and it affects you, you will be told.
Children
Flyls is not intended for anyone under 16 and accounts are not knowingly created for them.
Changes
If this policy changes materially, the date above changes and account holders are notified by email.
Contact
Write to support@flyls.co for anything in this document, including a request to see or delete your data.