Privacy and data handling
This notice explains the current development implementation. It is not yet an approved live-service privacy policy because the legal operator identity, public privacy contact, retention periods, launch countries, and final hosting arrangements are still being confirmed.
Last updated 12 September 2026
Data faibl handles
Account data includes your email address, display name when provided, Firebase identity subject, membership, and settings. Author data includes projects, manuscript prose, outlines, story knowledge, characters, world and continuity facts, versions, feedback, and exports.
- Billing records include Stripe customer/subscription references, plan and entitlement state, credit balances, and transaction history; faibl does not receive full card details from Stripe Checkout.
- AI records include request context, prompt snapshots, generated candidates, task/model/provider identity, usage, cost, and decisions.
- Operational records include request/support IDs, route templates, status, timing, safe error classes, release identity, and aggregate health signals—not manuscript or prompt text.
Why the data is used
The data is used to authenticate you, provide and recover the writing workspace, generate optional AI candidates, enforce account limits and credits, process subscriptions, secure and diagnose the service, and meet legal obligations. faibl does not currently operate advertising, analytics tracking, or a marketing email list.
Service providers and overseas processing
The current development service uses Google Firebase for authentication, Google Cloud for application hosting and secrets, Neon for the PostgreSQL database, OpenRouter and eligible model providers for AI requests, and Stripe for hosted checkout and billing. These providers may process data outside Australia. Firebase Authentication is operated from US data centres.
The development hosting audit confirmed that the application and Neon PostgreSQL database run in Singapore: Google Cloud asia-southeast1 and AWS Singapore respectively. These are the current development locations, not an approved launch hosting arrangement or a promise that all processing stays in Singapore. Final hosting and overseas-processing disclosures still require approval.
AI processing
Relevant manuscript content is transmitted when you choose an AI action. Hosted routes require OpenRouter Zero Data Retention endpoints and deny data collection, while faibl itself retains prompt snapshots and candidates for provenance, history, and author review. See the dedicated AI and data page for the exact boundary.
Storage, retention, export, and deletion
Authors can export a manuscript and a complete project backup. Projects can be permanently deleted after confirmation. The account-level retention schedule, backup retention, deletion from backups, and privacy-request procedure are not yet approved and must be completed before wider beta access.
Access, correction, complaints, and incidents
You can edit manuscript and profile-adjacent project information in the product. For an account data request, correction, complaint, or suspected incident, private-beta participants must use their invitation channel until a named public privacy contact and response process are approved.