← Flyls

Privacy Policy

Last updated: September 2026

Flyls is operated by Abdulaziz Nasser Bin Muzayil, an individual based in Saudi Arabia. This policy describes what the service collects, why, how long it is kept, and who else sees it. It covers the Flyls website, the browser extension, and the API.

What Flyls collects

DataWhy
Your name and email addressTo create and identify your account.
A hash of your passwordTo sign you in. The password itself is never stored and cannot be recovered from the hash.
The subject line and recipient addresses of emails you choose to trackSo the dashboard can show you which message an open belongs to.
Open events: the time, a device category (desktop or mobile), and an approximate countryThis is the product.
Clicks on links you chose to track, with the link's labelBusiness plan feature.
Sign-in records: time, approximate location, and browserSo you and we can spot access you do not recognise.
How this website is used: which parts of a page were on screen and for how long, how far it was scrolled, what was clicked or hovered over, which windows were opened and how they were closed, how long a form field was in use, page-speed timings and error reports. Never what is typed into a field.To find what is confusing or broken on this site and fix it. See below.

How we learn what is confusing on this site

When you use flyls.com, the page records what you do on it, in order and with timings: the sections you read, the buttons you press, the ones you hover over and leave, a window you close, a field you start and abandon. It is how we find the part of a page that loses people, which nobody ever writes in to report.

What Flyls does not collect

About the people you email

If you track a message, Flyls records that address, and records when that message was opened. Those people have not agreed to this — you have. You are responsible for having a lawful basis to track them, and in some places that means telling them. Flyls gives you the tool; the obligation to use it lawfully is yours.

A recipient who wants their data removed can write to support@flyls.co and it will be deleted.

How long it is kept

Who else sees it

Flyls does not sell data and does not share it for advertising. It is processed by these services, and only for the purpose given:

ServiceWhat it receives
CloudflareHosting, the database and the CDN. All data sits here. See where it is stored.
PaddlePayments. Receives your email address and billing details; acts as merchant of record.
ResendTransactional email — verification codes, password resets, notifications.
GeoJSReceives an IP address to return a country code. Nothing else, and nothing is stored there by us.
GoogleOnly if you choose to sign in with a Google account.

Data may also be disclosed where the law requires it.

Where it is stored

The database runs on Cloudflare's network with its primary location in Eastern Europe. Static files — the site itself, images, scripts — are served from Cloudflare's global network and are cached in many countries, but those files contain nothing about you.

Flyls is operated from Saudi Arabia, which means your data is held outside the Kingdom. This is stated so that it is known before an account is created rather than discovered afterwards.

Saudi data protection law

Because the operator is in Saudi Arabia, the Personal Data Protection Law (PDPL) applies to how this service handles personal data. Under it you may ask to see the data held about you, to have it corrected, to have it deleted, and to withdraw a consent you previously gave. Those are the same rights listed under your choices below, and they are honoured on request whether or not the law in your own country grants them. Write to support@flyls.co.

If you are in the EU or the UK, the GDPR terms for the same ideas are access, rectification, erasure and withdrawal of consent, and they are handled the same way.

Your choices

Security

Passwords are stored as PBKDF2 hashes with a per-account salt. API keys and refresh tokens are stored as SHA-256 hashes, so a copy of the database does not yield a working credential. Traffic is encrypted in transit. Sessions can be revoked, and revoking one ends every token issued before it.

No service can promise it will never be breached. If one occurs and it affects you, you will be told.

Children

Flyls is not intended for anyone under 16 and accounts are not knowingly created for them.

Changes

If this policy changes materially, the date above changes and account holders are notified by email.

Contact

Write to support@flyls.co for anything in this document, including a request to see or delete your data.