Legal

Privacy Notice

How FactNot processes personal data, the lawful bases and recipients for each purpose, and how to exercise privacy rights.

01

Controller and contact

FactNot is operated by Factnot LLC, which acts as controller for the product account, workspace, safety, and privacy-rights processing described here. Submit a request at /privacy/request or email privacy@factnot.com.

  • A suitable public postal notice address will be published on /contact only after it is approved for that use; EU invitations remain closed until that evidence is complete.
  • Counsel must decide whether an EU representative or data protection officer is required. FactNot will publish the applicable contact if either role is required.
  • This notice describes current processing; it is not a claim that every GDPR launch condition has already passed.
02

Your choices and privacy rights

Depending on the law and the processing, you may ask for access, a portable copy, correction, deletion, restriction, or an objection, and may withdraw consent for optional processing without affecting earlier lawful processing.

  • Logged-in requests use the confirmed primary email on the active account. Requests from another address use the logged-out verification flow.
  • You may complain to the data-protection supervisory authority for your habitual residence, place of work, or the place of an alleged infringement.
  • Some information may be withheld, retained, corrected, restricted, pseudonymized, or deleted after review to protect other people, preserve security, comply with law, or maintain shared records.
03

Purpose matrix — Accounts, authentication, and access

Data categories — Email address, username, profile settings, authentication records, session data, OAuth identifiers, and account-security events.

  • Lawful basis — Performance of the service agreement; legitimate interests in securing accounts and preventing misuse; legal obligations where applicable.
  • Recipients — Fly.io; Google when a user chooses Google OAuth; Resend for account and security email; Cloudflare Turnstile on protected authentication routes.
  • Retention — Kept while the account is active and then erased, revoked, minimized, or pseudonymized under the account-lifecycle process. Expired credentials are removed by scheduled cleanup.
04

Purpose matrix — Workspace, collaboration, and user-requested product features

Data categories — Facts, sources, notes, messages, files, comments, searches, collaboration records, and related metadata.

  • Lawful basis — Performance of the service agreement and legitimate interests in operating, troubleshooting, and improving the requested service.
  • Recipients — Fly.io for application and database hosting; Tigris Data for private objects; collaborators or the public only when the user or an authorized workspace member shares or publishes material.
  • Retention — Kept while the workspace or record remains active. Private single-user material is deleted when the applicable erasure disposition requires it; shared records may be retained with pseudonymized attribution.
05

Purpose matrix — AI assistance, embeddings, and transcription

Data categories — Prompts, selected workspace context, source excerpts, files or media chosen for processing, outputs, embeddings input, and request metadata.

  • Lawful basis — Performance of a user-requested feature and legitimate interests in providing and securing that feature; not blanket consent for unrelated processing.
  • Recipients — OpenRouter and its approved downstream endpoints for enabled AI routes; OpenAI for transcription only after the protected production switches and vendor-evidence gate are approved.
  • Retention — Follows the source or workspace lifecycle inside FactNot. Provider retention and deletion terms must be evidenced before private-content AI or transcription can be enabled.
06

Purpose matrix — Service communications and optional marketing

Data categories — Email address, communication preference, message content, delivery, bounce, suppression, and unsubscribe metadata.

  • Lawful basis — Performance of the service agreement and legal or security obligations for transactional messages; affirmative consent for optional product marketing and newsletters.
  • Recipients — Resend for transactional and opted-in email; Namescheap Private Email for role-based support, privacy, security, copyright, and legal inboxes.
  • Retention — Transactional evidence is kept only as operationally or legally needed. Optional communications stop when consent is withdrawn; suppression data may remain to honor the opt-out.
07

Purpose matrix — Security, abuse prevention, diagnostics, and service reliability

Data categories — Redacted error details, normalized routes, request and release identifiers, IP or device signals used for abuse prevention, service metrics, and security events.

  • Lawful basis — Legitimate interests in protecting users and the service, and legal obligations where incident or abuse records must be preserved.
  • Recipients — Sentry, Cloudflare Turnstile, Fly.io, Fly Managed Prometheus, and Grafana Cloud under the approved production configuration.
  • Retention — Limited to the period needed for incident response, abuse prevention, service reliability, and justified audit evidence. Raw request bodies, credentials, prompts, messages, uploads, and token-bearing route values are excluded from Sentry events.
08

Purpose matrix — Privacy requests, legal compliance, disputes, and audit evidence

Data categories — Request identity and verification evidence, correspondence, decisions, delivery proof, erasure-step evidence, restrictions, and necessary audit records.

  • Lawful basis — Legal obligations and legitimate interests in proving, securing, and resolving requests and disputes.
  • Recipients — Authorized FactNot operators, counsel when necessary, infrastructure providers, and authorities or counterparties only where disclosure is legally required and appropriately scoped.
  • Retention — Active cases are kept through fulfillment. Closed cases are minimized by scheduled retention processing while preserving the evidence needed to prove the response and applicable legal decisions.
09

Purpose matrix — Public or shared content, including information about other people

Data categories — Names, claims, citations, profile information, source material, and other personal information a user chooses to add, share, or publish.

  • Lawful basis — Performance of sharing and publication features, legitimate interests in operating collaborative research, and any lawful basis the submitting user must have for third-party information.
  • Recipients — Selected collaborators, link recipients, API or MCP clients authorized by the user, or the public when the material is deliberately published.
  • Retention — Follows the workspace, sharing, publication, moderation, and erasure disposition. A request may result in correction, restriction, removal, or pseudonymization rather than deletion where other people's rights or legal duties apply.
10

Automated and AI-assisted processing

FactNot uses automated systems to support search, extraction, summaries, classification, verification, recommendations, and moderation. Outputs can be inaccurate and are not used by FactNot to make solely automated decisions with legal or similarly significant effects about users.

  • Private-content AI and transcription are production-disabled until the applicable contract, transfer, retention, deletion, subprocessor, and no-training evidence is current.
  • Model selection can change the downstream provider path; a public model name alone does not identify every processor.
  • Do not use FactNot output as the sole basis for legal, medical, financial, employment, housing, credit, insurance, or other consequential decisions.
11

Essential cookies and browser storage

FactNot currently has no advertising network and does not use third-party advertising cookies. It uses essential session, security, and first-party preference storage.

  • _fuu_key — Encrypted, HTTP-only session cookie; Keep the user signed in and protect authenticated requests; retained for Session/account-security lifecycle.
  • Cloudflare Turnstile storage — Essential abuse-prevention browser storage or cookies; Complete a challenge on protected authentication routes; retained for Cloudflare's challenge and security lifecycle.
  • FactNot local and session storage — First-party browser storage; Remember theme and layout preferences, navigation state, policy-notice dismissal, and user-authored local drafts; retained for Until replaced, cleared by the user, or removed by the related feature.
12

International transfers

FactNot's providers may process data outside the country where a user lives. Before EU invitations open, each applicable provider record must identify the actual processing regions and a counsel-approved transfer mechanism.

  • Depending on the provider and route, safeguards may include an adequacy decision, the EU-U.S. Data Privacy Framework, Standard Contractual Clauses, and supplementary measures.
  • A provider privacy or security page is supporting material, not a substitute for the agreement and account-specific evidence required by the release gate.
  • Contact privacy@factnot.com to ask about safeguards applicable to a specific provider or feature.
13

Exports, deletion, and backups

A verified export is delivered as an encrypted archive through a one-time link. Erasure runs as a resumable set of source-specific steps and does not mark the account erased while a critical step has failed.

  • Export objects expire after seven days; one-time download links expire after 72 hours and can be reissued while the object remains available.
  • Exports exclude secrets, OAuth tokens, raw embeddings, and other people's private information; operator review may withhold additional material and records the reason.
  • Deleted data may remain in protected backups until expiry. If a backup is restored, erased-account steps must be replayed before normal service resumes.
14

Notice changes

FactNot versions this Privacy Notice. A privacy-notice-only change is acknowledged and shown as a non-blocking update; it does not turn every processing purpose into consent or silently rewrite an earlier Terms acceptance.

  • Binding Terms or community-rule changes use a separate binding policy bundle and may require renewed acceptance.
  • Optional product marketing and newsletters use separate, off-by-default affirmative choices that can be withdrawn.
  • Material notice changes are dated and the prior version remains available from the policy archive.