Fayla

Privacy

This describes what the code does. Where a number appears below it is read out of the same place the software reads it, so this page cannot quietly say one thing while the software does another.

The short version

Players have no accounts and never sign up for anything. There is no tracking, no advertising, no analytics script, and nothing on any page that is loaded from anybody else’s server. The only cookie this site sets is the one that keeps an organiser signed in.

If you are running an event

We hold your email address, because that is how you sign in and how an event tells you it went live. There is no password to hold. A sign-in link is stored only as a hash of itself, works once, and stops working after fifteen minutes. Your session is a random value in a cookie that JavaScript cannot read; it lasts thirty days and you can end it from the builder.

We hold the events you build: their names, dates, where they are, what you picked out of the catalogue and the names you typed in. If you are in an organisation with other people, everybody in it can see the events it owns — that is what an organisation is for — and who asked whom in is kept so that question can be answered later.

If somebody sent you a link

Then you are in somebody else’s event and you did not sign up for anything, so the short version is: your name is in it because whoever is running it typed it, and everything else in it is there because you or they put it there. The page for people in an event says it properly, and it is written to be handed to you rather than found by you.

Photographs

A photograph is stripped of its metadata before a single byte is stored — a phone’s photo carries the position of the house it was taken in, and that never reaches us. Faces are stored under a name derived from the bytes themselves, which is what lets a phone fetch one once and keep it.

Photographs and the memories board are kept for 30 days after the event closes on the free tier, for a year after the event closes on Party, and for as long as the event exists on Planner and Business. Before anything is deleted, an export of the whole event is emailed to whoever built it, so nothing goes without somebody seeing it first. The bill keeps its own clock: it goes when it is settled, or twelve months after the event closes.

What is never stored in a form anybody could use

Every credential here is kept as a salted hash and never as itself: the link that signs you in, the link each person in an event gets, and the key that runs an event on the night. Nobody at this end can read any of them back, which is also why a lost one is replaced rather than looked up.

Who else sees it

Cloudflare, which is where this runs and where the database, the photographs and each event’s own storage live. A transactional email provider, which is handed an address and the text of the one email being sent to it. That is the whole list. Nothing is sold or shared with anybody else, and there is no third party watching you read this page.

What we can see

There is one page at this end for running the service, and what it shows is the outside of an event rather than the inside: its name, its dates, which template it started from, what state it is in, how many people are in it, who built it and what they are paying for. That is what answering a question about an account, putting a tier right or stopping something that is being abused takes. It also shows the list of what has happened inside an event as the software recorded it — that a photograph was set, that an expense was added — as actions and player ids, never what was in any of them.

What that page has no way to do: open an event as the person running it, hand back a key or anybody’s link, or read a secret mission, a mark, a photograph, a bill, the memories board or one word anybody wrote inside an event. There is no route for it rather than a rule against it. If there is ever a reason to see inside an event, the export belongs to whoever is running it and asking them is the way.

Everything done from that page is written down — who did it, to what, when, and the reason they gave, which it will not act without — somewhere the person who did it cannot tidy it away.

The waitlist

An address, and optionally what you are planning and roughly when. It is kept for twelve months and then deleted on its own. Put the same address in and press take me off to go sooner.

What you can ask for

A copy of everything in an event: that is the export, and it is a button in the app rather than a request. Anything else — a copy of what your account holds, a correction, or the whole account and its events deleted — is an email to hello@fayla.party and a person doing it. There is no self-service button for deleting an account yet; saying so is more use to you than a page that implies one.

If you are in somebody else’s event, ask whoever is running it first, because it is theirs to change — the app has a way for them to take somebody out. If that gets you nowhere, the address above works for you too.

Where this is run from

Ireland, on Cloudflare’s network. This is written to the strictest rules it is likely to meet, so that the answer is the same wherever you are reading it from.

What Fayla is · Terms · Privacy · For the people in your event · Accessibility
Last changed 2026-09-20. Anything at all: hello@fayla.party.