# FictionCore Privacy Notice

> Version `2026-09-27.1`. Effective from 27 September 2026.

This notice covers https://fictioncore.app, the available functions of the
FictionCore Android app, and correspondence about accounts, data rights and
security. This limited release offers account creation, Google sign-in,
initial setup and account and notification settings. Publishing, public
profiles, partner discovery, media uploads and other community features are
not open. We will explain any new processing before enabling the
corresponding feature.

## 1. Who is responsible

The controller is Sofuwaru OÜ, with address Ehitajate tee 68-125, 12915 Tallinn, Estonia and
registry code 17059718. Contact us about personal
data at [sofuwaru@gmail.com](mailto:sofuwaru@gmail.com). You do not need an app account to make a request.

## 2. What we process and why

| Data and source | Purpose | Legal basis under GDPR |
|---|---|---|
| The Google sign-in proof you choose to send and the verified Google account identifier | verify the sign-in attempt and recognise your FictionCore account | steps you request before a contract and performance of the account contract, Article 6(1)(b) |
| Your chosen display name and handle; account dates; language preferences; setup status; the versions, languages and dates of Terms acceptance, Privacy Notice delivery and your 18+ declaration | create and operate the account, apply your choices and keep evidence of the account agreement | Article 6(1)(b); necessary evidence for resolving a dispute, Article 6(1)(f) |
| Session identifiers and credentials, session dates and the app version/build sent with API requests | keep you signed in, allow sign-out and session revocation, and maintain compatible and secure access | Article 6(1)(b); our legitimate interest in preventing misuse, Article 6(1)(f) |
| Notification preferences and, if you enable push registration, an installation/device identifier and messaging token | remember your settings, register the device and deliver the notifications you request | Article 6(1)(b); any separate permission required by applicable law is requested before the relevant use |
| Website/API request metadata, such as IP address received by the host, requested resource, time, status, app/browser information and diagnostic identifiers | deliver the requested page or service, diagnose failures and prevent abuse | our legitimate interest in operating a reliable and secure service, Article 6(1)(f) |
| Your email address, message and necessary supporting details when you contact us; relevant information supplied by another person about an account or security concern | answer the request, investigate the concern and exercise or defend legal claims | Article 6(1)(b) for account support; Article 6(1)(c) for an applicable legal duty; Article 6(1)(f) for proportionate security and claims handling |

Google may include email, name or other profile claims in its sign-in proof.
FictionCore uses the verified provider identifier to recognise the account;
the current account model does not save those Google profile claims or a copy
of the raw Google sign-in token. It does not receive your Google password or
request access to Gmail, Drive or your contacts. The Google account you choose
is separate from your chosen FictionCore display name.

Google sign-in does not create an account automatically. Registration
requires your separate **Create account** action. The required
fields and 18+ declaration are shown before submission. We do not collect an
exact date of birth or an identity document during registration. Declaring
that you are at least 18 does not constitute verified proof of age.

The current release does not make profiles or writing publicly browsable.
The display name and handle are intended to identify you when community
features open; we will explain their visibility before that change. Do not
use a password or other secret as a public name.

Send only the information needed for your request. Do not attach passwords,
Google credentials, unnecessary identity documents, unnecessary private
information about other people or suspected illegal images. If we reasonably
need more information, we explain what is necessary and why. Access to
correspondence is restricted to people who need to handle it.

We do not routinely request sensitive information, such as health or sexual
life information, or criminal-offence information. We remove unnecessary
unsolicited details. If sensitive information is necessary to establish,
exercise or defend a specific legal claim, the grounds are Article 6(1)(f)
and Article 9(2)(f). Criminal-offence information is processed only where
authorised by applicable EU or national law with its required safeguards.

## 3. Providers, device storage and international transfers

The current services involved are:

| Service | What it does and the data involved |
|---|---|
| Google sign-in | handles the Google authentication interaction and supplies the sign-in proof; Google's own account processing is described in its [Privacy Policy](https://policies.google.com/privacy) |
| Heroku / Salesforce | hosts the FictionCore API and database in the selected EU region; processes data sent to the API and the technical information needed to host and secure it |
| Cloudflare | hosts the public website and provides domain-name services; handles website requests and their technical metadata |
| Google Fonts | supplies app fonts when they are not already cached; the font service receives the network request, including the source IP address |
| Google Firebase Cloud Messaging | handles device registration and delivery of requested notifications when you explicitly enable push |
| Google (Gmail) | handles messages sent to our contact address and the replies |

The Android release has Firebase Analytics collection disabled. The website
does not include advertising or audience-analytics scripts. Necessary
hosting and sign-in requests still involve the providers above. The app
stores session credentials in device-protected storage and remembers local
settings, such as your language; these are used to provide the service.

Push registration is optional and starts only after you enable it. It sends
installation information to Google to register the device and deliver the
notifications you request. You can turn push off in the app; operating-system notification
settings separately control whether notifications can be displayed.

The API's primary database and Heroku's physical disaster-recovery copies
are in the selected EU region. Heroku's separately captured logical database
backups are stored in the United States, including for EU databases. Google
and Cloudflare operate internationally, so authentication, font, website,
messaging and email processing can involve the United States and other
countries outside the European Economic Area (EEA).

The providers publish the safeguards for this processing. Salesforce's
[Heroku security and privacy description](https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/heroku-security-privacy-and-architecture.pdf)
places Heroku customer data within its processor Binding Corporate Rules
and EU–US Data Privacy Framework scope.
[Google's transfer information](https://policies.google.com/privacy/frameworks)
describes its Data Privacy Framework participation and Standard Contractual
Clauses for transfers where applicable.
[Cloudflare's data-processing terms](https://www.cloudflare.com/cloudflare-customer-dpa/)
describe Data Privacy Framework coverage and Standard Contractual Clauses
for other restricted transfers. An adequacy decision applies only to
transfers within its scope; other transfers require the applicable legal
safeguards. You can request information about a transfer of your data or a
copy of the relevant safeguards at
[sofuwaru@gmail.com](mailto:sofuwaru@gmail.com).

We may disclose information to professional advisers or competent authorities
when necessary for a specific legal obligation or claim. We limit disclosure
to the information needed for that purpose. Optional public sharing and new
external processing are explained before their respective features open.

## 4. How long data is kept

The account record, Google account link, settings, setup status and records
of Terms acceptance, Privacy Notice delivery and your 18+ declaration are
kept while the account is active. On deletion, we remove the account data
that is no longer needed, subject to the limited exceptions below. Closing
the app does not close the account.

An unfinished sign-in registration challenge is usable for ten minutes.
Ordinary access credentials last fifteen minutes; the associated refresh
session has a maximum thirty-day lifetime and can be revoked earlier. These
are access limits, not promises that every related database or backup record
is physically erased at that instant.

Other periods and criteria are:

- **Temporary authentication records.** Recovery records for repeating a
  sign-in or session-refresh request last ten minutes. A reauthentication
  authorisation lasts five minutes. Recovery records for account creation
  and setup changes last 24 hours. Expired challenges, session records and
  recovery records are removed by scheduled cleanup. Cleanup runs at server
  startup and is scheduled every five minutes; a failure is retried, so
  expiry does not promise physical removal at an exact minute.
- **Technical logs.** Heroku's standard application-log buffer keeps the
  most recent 1,500 lines and expires them after one week. Specific diagnostic
  or security records needed to investigate a failure or incident are kept
  until the investigation and necessary corrective actions are complete,
  then removed unless a specific legal reason below applies. Infrastructure
  providers also keep their own security and operational records under their
  published policies.
- **Correspondence.** Support and data-rights correspondence is kept until
  we have delivered the final response and completed the related actions,
  including any necessary follow-up with a provider that holds the data.
  Unnecessary attachments are removed earlier. We then delete the
  correspondence unless the limited legal exception below applies. Gmail
  automatically removes messages from Trash after 30 days; emptying Trash
  removes them from the mailbox earlier. Provider-managed deletion of
  residual copies is a separate process.
- **Backups and provider copies.** Removing data from the active service
  does not immediately erase all physical backup copies. Heroku's physical
  snapshots remain until the provider retires them under its disaster-recovery
  lifecycle. They are not used as live account records. Separately captured
  logical backups remain until they are deleted or replaced; a capture does
  not itself set a time limit. Google describes its deletion process as
  generally taking around two months, and its encrypted backup copies as
  lasting up to six months, with the exceptions explained in its
  [retention policy](https://policies.google.com/technologies/retention).
  These are provider processes, not an extension of the purpose for which we
  use an active account or support message.

Where a specific legal duty or dispute requires longer retention, we isolate
the necessary records, limit their use to that purpose and delete them when
that reason expires. This does not justify retaining a complete account
indefinitely. We explain any applicable exception when answering a deletion
request.

<a id="account-deletion"></a>

## 5. Request account deletion

Email [sofuwaru@gmail.com](mailto:sofuwaru@gmail.com) with the subject **Delete FictionCore account** and
your FictionCore handle or account identifier, if available. Do not send a
password or Google sign-in token. If we have reasonable doubts about the
requester's identity, we ask only for proportionate information needed to
verify authority over the account.

Completed account deletion through the app is not available in this release.
Use the contact route above. Signing out, revoking a session or uninstalling
the app does not delete server records. Deleting FictionCore data does not
delete your Google account.

We tell you the outcome, any information that must remain and the reason and
retention period or criteria for it. We also explain the applicable treatment
of backups and provider copies described in section 4.

Public deletion instructions are at
https://fictioncore.app/privacy?locale=en#account-deletion.

## 6. Your rights and how to exercise them

Subject to the GDPR's conditions, you may request access and a copy of your
data, correction, erasure, restriction and portability. Where processing is
based on consent, you may withdraw that consent without affecting earlier
lawful processing. Accepting the Terms and receiving this notice are not
consent to analytics or other unrelated purposes.

**Right to object.** You may object, for reasons relating to your particular
situation, to processing based on legitimate interests. We must stop that
processing unless we demonstrate compelling overriding grounds or need it
for legal claims.

Send requests to [sofuwaru@gmail.com](mailto:sofuwaru@gmail.com). We respond without undue delay and
normally within one month. If the complexity or number of requests requires
an extension, we explain the reason within the first month; the extension
can be up to two additional months. Requests are normally free. Any refusal
or permitted charge must be explained, including how to complain.

You may complain to the Estonian Data Protection Inspectorate
([Andmekaitse Inspektsioon](https://www.aki.ee/en)) or the supervisory authority
competent for your place of residence or work, or the alleged infringement.

The current limited release does not make solely automated decisions with
legal or similarly significant effects about you. If someone else provides
information about you in a report or message, the source is that sender and
their material; where required, we provide the relevant information directly
to you. We do not treat this general notice as a substitute for that duty.

## 7. Changes

We update this notice when processing changes. Where required, we inform you
before the new processing begins and seek any necessary separate permission.
The version and effective date appear at the top of the published notice.
