Privacy
Privacy Policy
Effective date: June 11, 2026
Backlit is operated by Nyfty.ai, Inc., a Delaware corporation, trading as Backlit ("Backlit", "we", "us"). This policy explains what personal data we handle, why, where it lives, and what rights you have. Privacy questions and requests: reporting@backlit.run.
1. Two roles: whose data, whose responsibility
Backlit handles personal data in two different roles.
We are the controller for the data of app owners: your account, sign-in, billing, and usage of the service, plus visitors to this website. This policy covers that data.
We are a processor for the data inside hosted apps. If you sign in to or use an app hosted on backlit.run, the owner of that app is the controller of your data. The owner decides what their app collects and why, and their privacy notice applies. We process that data only on the owner's instructions, under our Data Processing Agreement. If you are an end user with questions or requests about your data in a hosted app, contact the app's owner. We will help the owner respond.
2. What we collect
Account data. Your email address, name, and an internal user identifier, plus sign-in and authentication events. If you sign in with Google or Microsoft, we receive your email and basic profile from them.
Billing data. Payment is handled by Stripe. We receive billing status, plan, and transaction records. We never see your full card number.
Service and usage data. Glow configuration and metadata, usage counters, request logs, IP addresses, and security and quota alerts. We use these to run, meter, and secure the service.
Support and reports. Anything you send to our contact addresses, including abuse reports and the per-report records we are required to keep.
Website data. This marketing site uses Google Analytics (GA4) to understand traffic. Hosted apps and the console use only strictly necessary cookies and session tokens for sign-in; these do not track you across sites.
3. Why we use it
We use account, billing, and service data to provide the service under our contract with you (GDPR Art. 6(1)(b)); to meet legal obligations such as tax, accounting, and illegal-content rules (Art. 6(1)(c)); and for our legitimate interests in securing the platform, preventing abuse, and improving the service (Art. 6(1)(f)). Website analytics run on consent where the law requires it (Art. 6(1)(a)). We do not sell personal data and we do not use it for third-party advertising.
4. Where data lives
Backlit runs on Google Cloud with a two-plane architecture, and we want to be precise about it.
Data plane. A glow's static assets and end-user application data are stored in the region the owner selects, currently us-central1 (US), australia-southeast1 (Australia), or europe-west1 (EU), and are not replicated across regions.
Control plane. Glow metadata, access allowlists, end-user identity records (including email addresses), and usage counters are stored in a United States multi-region datastore for every glow, whatever region the owner selects.
This means europe-west1 is not full EU data residency. An EU-region glow keeps its app assets and application data in the EU, but its metadata and its end users' email addresses are stored in the US. Owner account data is also stored in the US.
5. International transfers
Where personal data of people in the EU, UK, or Switzerland is transferred to the US or another third country, we rely on: the EU-US Data Privacy Framework (and its UK and Swiss extensions) where the recipient is certified, and otherwise the European Commission's Standard Contractual Clauses (2021/914), supported by a transfer impact assessment. You can request a summary of the safeguards at reporting@backlit.run.
6. Who we share it with
We share personal data only with the providers we need to run the service:
- Google Cloud (Google LLC): hosting, storage, datastore, and console identity. US control plane; US, AU, or EU data plane per glow. DPF certified.
- Cloudflare, Inc.: DNS and edge networking. Network metadata only. DPF certified.
- Stripe, Inc.: payment processing for owner billing.
- Loops (Astrodon Inc.): transactional and product email, including magic-link sign-in messages. US. DPF certified.
The current sub-processor list, with roles and safeguards, is maintained in Annex III of the DPA. We also disclose data where the law requires it, for example to courts, regulators (including the Australian eSafety Commissioner), or law enforcement, and in connection with a merger or sale of the business.
AI assistants and the MCP interface. You can operate Backlit through an AI assistant or agent, including via our MCP interface and connector listings. When you do, the instructions you give and the data you ask us to return (for example a glow's configuration or its stored data) pass through that assistant's provider and are handled under the provider's own terms and privacy policy, not ours. We receive and act on those instructions as your authenticated requests. Choose assistants you trust and review their privacy terms before connecting them.
7. How long we keep it
Account and glow data are kept while your account is active. When you delete a glow or your account, content is soft-deleted and then permanently deleted within 30 days. Historical version retention follows your plan tier. Billing records are kept as long as tax and accounting law requires. Abuse-report records are kept as long as needed to meet our legal obligations.
8. Security
Data is encrypted in transit (TLS) and at rest. Access is least-privilege, per-glow API keys are stored only as hashes, session tokens are short-lived and scoped to a single glow, and secrets live in a managed secret store. The full set of technical and organisational measures is in Annex II of the DPA. If a breach affects your data, we will notify the relevant authority within 72 hours where required, and you without undue delay if the risk to you is high. To report a suspected security vulnerability, email security@backlit.run. Our security contact is also published at https://backlit.run/.well-known/security.txt.
9. Your rights
EU and UK. You can ask for access to, correction of, deletion of, restriction of, or a portable copy of your personal data, and you can object to processing based on legitimate interests. You can complain to your local supervisory authority. We are not established in the EU; you can raise any GDPR request or complaint with us directly at reporting@backlit.run.
Australia. We handle personal information consistently with the Australian Privacy Principles. You can request access and correction, and you can complain to us and then to the Office of the Australian Information Commissioner (oaic.gov.au).
United States. Depending on your state, you may have rights to access, delete, correct, and obtain a copy of your personal data, and to opt out of sale or targeted advertising. We do not sell personal data or use it for targeted advertising.
To exercise any right, email reporting@backlit.run. We will respond within one month, and we may verify your identity first. If your request concerns data inside a hosted app, we will refer it to the app's owner, who is the controller.
10. Children
The service is not directed at children. You must be 18 or older to hold a Backlit account, and our terms prohibit apps directed at children under 16 and the storage of children's data. If you believe a child's data has ended up on the platform, tell us at reporting@backlit.run and we will act on it.
11. Changes
We will post changes to this policy here and update the effective date. For material changes we will notify account holders by email or in the console before the change takes effect.
12. Contact
Nyfty.ai, Inc., trading as Backlit.
Privacy questions, rights requests, and complaints: reporting@backlit.run
Security vulnerability reports: security@backlit.run