Privacy Policy

Effective August 6, 2026 · Last updated August 6, 2026

The short version. We collect what we need to run your workspace: your account details, the TikTok accounts you connect, the media and prompts you put into the product, billing data (card numbers stay with Stripe), and usage analytics. We send prompts and images to AI providers so we can generate your videos. We do not sell or share your personal information, and we do not use your content to train foundation models. You can access, export or delete your data at any time — see Your privacy rights.

1. Scope and who we are

This Privacy Policy explains how Breez Global Group LLC (“Breez Global Group,” “we,” “us”) handles personal information in connection with the Afili website at affili.club, our web and mobile applications, and related services (together, the “Service”). It applies to visitors, account holders and workspace members.

For people in the European Economic Area, the United Kingdom and Switzerland, Breez Global Group is the controller of the personal information described here. Where you use Afili to process information about other people — for example team members you invite, or customers whose orders appear in your commission reports — you act as the controller of that information and we act as your processor.

This policy does not cover TikTok, TikTok Shop, or any other third-party platform you connect. Their handling of your data is governed by their own policies.

2. Information we collect

The table below lists the categories of personal information we have collected in the last 12 months, the examples in each category, where it comes from, and the types of parties we disclose it to for a business purpose.

CategoryExamplesSourceDisclosed to
IdentifiersName, email address, account and workspace IDs, IP address, device identifiers, TikTok account handles and open IDsYou, your device, TikTokService providers, TikTok
Commercial informationPlan, subscription status, credit balance and ledger, invoices, transaction history, products you research and promote, commissions attributed to your postsYou, Stripe, TikTokPayment processor, hosting
Financial informationBilling contact and the last four digits and brand of your payment card. Full card numbers are collected and stored by Stripe — never by usStripePayment processor
Internet or network activityPages viewed, features used, clicks, session duration, referring URL, browser and OS, error tracesYour deviceAnalytics and error-monitoring providers
User contentUploaded footage and images, generated videos and audio, scripts, hooks, captions, prompts, schedules, notes, and emails you forward to us for parcel parsingYouAI providers, storage, TikTok at publish time
Approximate locationCoarse city/region inferred from IP address for security and fraud preventionYour deviceSecurity and hosting providers
InferencesPredicted conversion scores, product-fit ranking, and performance priors derived from your workspace resultsDerived by usNot disclosed externally

Sensitive personal information. We do not intentionally collect government identifiers, precise geolocation, biometric identifiers, health data, racial or ethnic origin, religious beliefs, union membership, sexual orientation, or the contents of your private communications. Please do not upload footage or forward emails containing those categories. If you upload video that shows an identifiable person, you are responsible for having that person’s permission — including any consent required for biometric or likeness laws in your jurisdiction.

Payment cards. We never receive or store full card numbers. Stripe collects card details directly and returns only a token, the brand, and the last four digits.

3. Where the information comes from

We obtain product research data from licensed data partners and from official platform APIs. We do not scrape TikTok or any other platform, and we do not buy personal information from data brokers.

4. How we use information

We do not use your content to build or improve products for other customers except in aggregated or de-identified form that cannot reasonably be linked back to you or your workspace. Where we de-identify data, we maintain it in that form and do not attempt to re-identify it.

5. Legal bases (EEA, UK, Switzerland)

PurposeLegal basis (UK/EU GDPR Art. 6)
Providing the Service, generating and publishing content you request, billingPerformance of a contract — Art. 6(1)(b)
Security, fraud prevention, rate limiting, service improvement, aggregate analyticsLegitimate interests — Art. 6(1)(f)
Non-essential cookies, marketing email where required, optional integrationsConsent — Art. 6(1)(a), withdrawable at any time
Tax records, responding to lawful requests, retention obligationsLegal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we have assessed that our interest in running a secure, reliable service is not overridden by your rights. You may object at any time — see Your privacy rights.

6. AI processing and model training

Afili uses third-party AI models to do the work you ask for. Understanding exactly what leaves our systems matters, so here it is plainly:

7. TikTok and platform data

Afili connects to three separate TikTok identity systems — content posting, Shop affiliate, and Business (ads). For each account you connect, we store an encrypted access and refresh token and the identifiers, metrics and order data the relevant API returns.

8. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose it only as follows:

9. Service providers and sub-processors

Each provider below is bound by a written agreement limiting its use of personal information to providing the service to us. We update this list when it changes; material additions are announced in-app or by email before they take effect.

ProviderPurposeData involvedProcessing location
NeonManaged Postgres database hostingAll application dataUnited States
Hetzner Online GmbHApplication and background-worker computeAll application data in processingUnited States / Germany
Cloudflare, Inc.CDN, DNS, WAF and R2 object storageUploaded and generated media, request metadataGlobal edge
Stripe, Inc.Payments, subscriptions and taxBilling contact, payment method (held by Stripe), transaction historyUnited States
Anthropic PBCLanguage model for scripts, critique, concierge and shipping-email parsingPrompts derived from your product, script and forwarded email contentUnited States
HiggsfieldImage-to-video generationProduct images and generation promptsUnited States
fal.aiVideo generation fallback and speech-to-text captioningProduct images, prompts, generated audioUnited States
Google LLC (Google AI)Veo video generationProduct images and generation promptsUnited States
HeyGenAvatar and product-in-hand video generationProduct images, scripts, avatar selectionsUnited States
TikTok / ByteDance Ltd.Shop Affiliate, Content Posting and Business (ads) APIsAccount identifiers, video files, captions, campaign and order dataUnited States / Singapore
Postmark (ActiveCampaign)Transactional email and inbound shipping-email parsingEmail address, content of messages you forwardUnited States
17TRACKParcel tracking for product samplesTracking numbers and carrier checkpointsHong Kong / Global
SentryError monitoringError traces, workspace and user identifiersUnited States
PostHogProduct analyticsPseudonymous usage events, device and page metadataUnited States

10. Cookies and analytics

We use a small number of cookies and similar technologies:

Where consent is required (for example in the EEA and UK), non-essential cookies are set only after you accept, and you can change your choice at any time from the cookie settings link in the footer. Most browsers also let you block or delete cookies; blocking necessary cookies will prevent you from signing in.

11. Marketing, email and SMS

We send transactional messages — receipts, job failures, reauthorisation prompts, security alerts — as part of the Service; these are not marketing and cannot be turned off while your account is active.

Marketing email is sent only where permitted or with your consent, and every message has an unsubscribe link.

SMS. If you opt in to text alerts (for example, the manual-post fallback notification), you consent to receive automated messages at the number you provide. Message and data rates may apply; frequency varies. Reply STOP to cancel or HELP for help. Consent to marketing texts is never a condition of purchase. We do not sell or share phone numbers.

12. How long we keep information

DataRetention
Account and workspace recordsFor the life of the account, then 30 days after deletion request
Uploaded and generated mediaUntil you delete it, or 30 days after account deletion
Platform access and refresh tokensDeleted immediately on disconnect or account deletion
Credit ledger, invoices and tax recordsUp to 7 years, as required by tax and accounting law
Compliance audit trail (disclosure and AI-label decisions)Up to 3 years, to evidence advertising compliance
Security and access logsUp to 12 months
Error traces and analytics eventsUp to 90 days (errors) / 12 months (pseudonymous analytics)
Encrypted backupsRolling window, expires within 35 days

After a deletion request we remove or irreversibly de-identify personal information within 30 days, except where a longer period is legally required or necessary to resolve a dispute or enforce our agreements. Data in encrypted backups is removed as those backups expire.

13. How we protect information

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators without undue delay and, where required, within 72 hours of becoming aware. Report a vulnerability to security@affili.club — we will not pursue legal action against good-faith research that respects user privacy and avoids service disruption.

14. International transfers

We are based in the United States and our providers operate globally, so your information may be processed outside your country, including in the United States. Those countries may not offer the same level of protection as your own.

For transfers from the EEA, UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), together with supplementary technical measures such as encryption in transit and at rest. You can request a copy of the relevant transfer mechanism at privacy@affili.club.

15. Your privacy rights

Depending on where you live, you may have the right to:

How to exercise them

Most actions are self-service in the app: Settings → Privacy lets you export your workspace, delete media, disconnect platform accounts and delete your account. Otherwise, email privacy@affili.club, or write to us at the postal address at the end of this policy. We respond within 45 days (extendable once by a further 45 days where permitted), or within one month for GDPR requests.

We operate exclusively online and deal with you only through the app and email, so email is our designated request channel; we do not maintain a toll-free telephone line for privacy requests.

We verify requests by matching the request to the email address on the account and, for higher-risk requests, by requiring you to complete an action from within a signed-in session. An authorised agent may submit a request on your behalf with written permission and proof of identity; we may still contact you to confirm.

If you are in the EEA, UK or Switzerland you may lodge a complaint with your local supervisory authority. We would appreciate the chance to resolve it first — write to dpo@affili.club.

16. US state privacy disclosures

This section supplements the rest of the policy for residents of California, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia and other states with comprehensive privacy laws.

17. Global Privacy Control and opt-out signals

We honour the Global Privacy Control (GPC) signal. When your browser sends it, we treat it as a valid request to opt out of sale and sharing for that browser, and we disable non-essential analytics cookies. Because we do not sell or share personal information, this signal does not change how your data is used beyond cookie preferences. GPC applies per browser and device; we cannot link it to your account unless you are signed in.

18. Automated decision-making and profiling

Afili scores and ranks products and videos, not people. Conversion scores, velocity rankings, schedule optimisation and boost suggestions are recommendations that you review and approve; they do not produce legal or similarly significant effects concerning you within the meaning of Art. 22 GDPR.

We do use automated checks for security and abuse — for example rate limiting, fraud signals on payments, and blocking activity that breaches platform caps. If an automated control restricts your account, you can contact us at support@affili.club to have a person review it.

19. Children

The Service is for adults. It is not directed to anyone under 18 and we do not knowingly collect personal information from children. If we learn that we have collected information from someone under 18, we will delete it. A parent or guardian who believes their child has provided us information should contact privacy@affili.club.

20. Third-party links and platforms

The Service links to and integrates with third-party sites and platforms — TikTok, TikTok Shop, Stripe’s checkout and billing portal, and carrier tracking pages among them. We are not responsible for their content or privacy practices, and this policy does not apply to them. Review their policies before providing information.

Because there is no consistent industry standard for browser “Do Not Track” signals, we do not respond to DNT headers. We do honour GPC as described in section 17.

21. Changes to this policy

We may update this policy as the Service evolves. When a change is material we will give notice by email or in-app at least 14 days before it takes effect and update the “Last updated” date above. Continuing to use the Service after the effective date means you accept the updated policy. Prior versions are available on request.

22. How to reach us

Breez Global Group LLC
4480 South Cobb Drive SE, Suite H #738, Smyrna, GA 30080, United States
Privacy requests: privacy@affili.club
Data protection contact: dpo@affili.club
Security reports: security@affili.club
General support: support@affili.club

You can also read our Terms of Service.