FictionCore Privacy Notice
Version
2026-09-27.1. Effective from 27 September 2026.
This notice covers https://fictioncore.app, the available functions of the FictionCore Android app, and correspondence about accounts, data rights and security. This limited release offers account creation, Google sign-in, initial setup and account and notification settings. Publishing, public profiles, partner discovery, media uploads and other community features are not open. We will explain any new processing before enabling the corresponding feature.
1. Who is responsible
The controller is Sofuwaru OÜ, with address Ehitajate tee 68-125, 12915 Tallinn, Estonia and registry code 17059718. Contact us about personal data at sofuwaru@gmail.com. You do not need an app account to make a request.
2. What we process and why
| Data and source | Purpose | Legal basis under GDPR |
|---|---|---|
| The Google sign-in proof you choose to send and the verified Google account identifier | verify the sign-in attempt and recognise your FictionCore account | steps you request before a contract and performance of the account contract, Article 6(1)(b) |
| Your chosen display name and handle; account dates; language preferences; setup status; the versions, languages and dates of Terms acceptance, Privacy Notice delivery and your 18+ declaration | create and operate the account, apply your choices and keep evidence of the account agreement | Article 6(1)(b); necessary evidence for resolving a dispute, Article 6(1)(f) |
| Session identifiers and credentials, session dates and the app version/build sent with API requests | keep you signed in, allow sign-out and session revocation, and maintain compatible and secure access | Article 6(1)(b); our legitimate interest in preventing misuse, Article 6(1)(f) |
| Notification preferences and, if you enable push registration, an installation/device identifier and messaging token | remember your settings, register the device and deliver the notifications you request | Article 6(1)(b); any separate permission required by applicable law is requested before the relevant use |
| Website/API request metadata, such as IP address received by the host, requested resource, time, status, app/browser information and diagnostic identifiers | deliver the requested page or service, diagnose failures and prevent abuse | our legitimate interest in operating a reliable and secure service, Article 6(1)(f) |
| Your email address, message and necessary supporting details when you contact us; relevant information supplied by another person about an account or security concern | answer the request, investigate the concern and exercise or defend legal claims | Article 6(1)(b) for account support; Article 6(1)(c) for an applicable legal duty; Article 6(1)(f) for proportionate security and claims handling |
Google may include email, name or other profile claims in its sign-in proof. FictionCore uses the verified provider identifier to recognise the account; the current account model does not save those Google profile claims or a copy of the raw Google sign-in token. It does not receive your Google password or request access to Gmail, Drive or your contacts. The Google account you choose is separate from your chosen FictionCore display name.
Google sign-in does not create an account automatically. Registration requires your separate Create account action. The required fields and 18+ declaration are shown before submission. We do not collect an exact date of birth or an identity document during registration. Declaring that you are at least 18 does not constitute verified proof of age.
The current release does not make profiles or writing publicly browsable. The display name and handle are intended to identify you when community features open; we will explain their visibility before that change. Do not use a password or other secret as a public name.
Send only the information needed for your request. Do not attach passwords, Google credentials, unnecessary identity documents, unnecessary private information about other people or suspected illegal images. If we reasonably need more information, we explain what is necessary and why. Access to correspondence is restricted to people who need to handle it.
We do not routinely request sensitive information, such as health or sexual life information, or criminal-offence information. We remove unnecessary unsolicited details. If sensitive information is necessary to establish, exercise or defend a specific legal claim, the grounds are Article 6(1)(f) and Article 9(2)(f). Criminal-offence information is processed only where authorised by applicable EU or national law with its required safeguards.
3. Providers, device storage and international transfers
The current services involved are:
| Service | What it does and the data involved |
|---|---|
| Google sign-in | handles the Google authentication interaction and supplies the sign-in proof; Google’s own account processing is described in its Privacy Policy |
| Heroku / Salesforce | hosts the FictionCore API and database in the selected EU region; processes data sent to the API and the technical information needed to host and secure it |
| Cloudflare | hosts the public website and provides domain-name services; handles website requests and their technical metadata |
| Google Fonts | supplies app fonts when they are not already cached; the font service receives the network request, including the source IP address |
| Google Firebase Cloud Messaging | handles device registration and delivery of requested notifications when you explicitly enable push |
| Google (Gmail) | handles messages sent to our contact address and the replies |
The Android release has Firebase Analytics collection disabled. The website does not include advertising or audience-analytics scripts. Necessary hosting and sign-in requests still involve the providers above. The app stores session credentials in device-protected storage and remembers local settings, such as your language; these are used to provide the service.
Push registration is optional and starts only after you enable it. It sends installation information to Google to register the device and deliver the notifications you request. You can turn push off in the app; operating-system notification settings separately control whether notifications can be displayed.
The API’s primary database and Heroku’s physical disaster-recovery copies are in the selected EU region. Heroku’s separately captured logical database backups are stored in the United States, including for EU databases. Google and Cloudflare operate internationally, so authentication, font, website, messaging and email processing can involve the United States and other countries outside the European Economic Area (EEA).
The providers publish the safeguards for this processing. Salesforce’s Heroku security and privacy description places Heroku customer data within its processor Binding Corporate Rules and EU–US Data Privacy Framework scope. Google’s transfer information describes its Data Privacy Framework participation and Standard Contractual Clauses for transfers where applicable. Cloudflare’s data-processing terms describe Data Privacy Framework coverage and Standard Contractual Clauses for other restricted transfers. An adequacy decision applies only to transfers within its scope; other transfers require the applicable legal safeguards. You can request information about a transfer of your data or a copy of the relevant safeguards at sofuwaru@gmail.com.
We may disclose information to professional advisers or competent authorities when necessary for a specific legal obligation or claim. We limit disclosure to the information needed for that purpose. Optional public sharing and new external processing are explained before their respective features open.
4. How long data is kept
The account record, Google account link, settings, setup status and records of Terms acceptance, Privacy Notice delivery and your 18+ declaration are kept while the account is active. On deletion, we remove the account data that is no longer needed, subject to the limited exceptions below. Closing the app does not close the account.
An unfinished sign-in registration challenge is usable for ten minutes. Ordinary access credentials last fifteen minutes; the associated refresh session has a maximum thirty-day lifetime and can be revoked earlier. These are access limits, not promises that every related database or backup record is physically erased at that instant.
Other periods and criteria are:
- Temporary authentication records. Recovery records for repeating a sign-in or session-refresh request last ten minutes. A reauthentication authorisation lasts five minutes. Recovery records for account creation and setup changes last 24 hours. Expired challenges, session records and recovery records are removed by scheduled cleanup. Cleanup runs at server startup and is scheduled every five minutes; a failure is retried, so expiry does not promise physical removal at an exact minute.
- Technical logs. Heroku’s standard application-log buffer keeps the most recent 1,500 lines and expires them after one week. Specific diagnostic or security records needed to investigate a failure or incident are kept until the investigation and necessary corrective actions are complete, then removed unless a specific legal reason below applies. Infrastructure providers also keep their own security and operational records under their published policies.
- Correspondence. Support and data-rights correspondence is kept until we have delivered the final response and completed the related actions, including any necessary follow-up with a provider that holds the data. Unnecessary attachments are removed earlier. We then delete the correspondence unless the limited legal exception below applies. Gmail automatically removes messages from Trash after 30 days; emptying Trash removes them from the mailbox earlier. Provider-managed deletion of residual copies is a separate process.
- Backups and provider copies. Removing data from the active service does not immediately erase all physical backup copies. Heroku’s physical snapshots remain until the provider retires them under its disaster-recovery lifecycle. They are not used as live account records. Separately captured logical backups remain until they are deleted or replaced; a capture does not itself set a time limit. Google describes its deletion process as generally taking around two months, and its encrypted backup copies as lasting up to six months, with the exceptions explained in its retention policy. These are provider processes, not an extension of the purpose for which we use an active account or support message.
Where a specific legal duty or dispute requires longer retention, we isolate the necessary records, limit their use to that purpose and delete them when that reason expires. This does not justify retaining a complete account indefinitely. We explain any applicable exception when answering a deletion request.
5. Request account deletion
Email sofuwaru@gmail.com with the subject Delete FictionCore account and your FictionCore handle or account identifier, if available. Do not send a password or Google sign-in token. If we have reasonable doubts about the requester’s identity, we ask only for proportionate information needed to verify authority over the account.
Completed account deletion through the app is not available in this release. Use the contact route above. Signing out, revoking a session or uninstalling the app does not delete server records. Deleting FictionCore data does not delete your Google account.
We tell you the outcome, any information that must remain and the reason and retention period or criteria for it. We also explain the applicable treatment of backups and provider copies described in section 4.
Public deletion instructions are at https://fictioncore.app/privacy?locale=en#account-deletion.
6. Your rights and how to exercise them
Subject to the GDPR’s conditions, you may request access and a copy of your data, correction, erasure, restriction and portability. Where processing is based on consent, you may withdraw that consent without affecting earlier lawful processing. Accepting the Terms and receiving this notice are not consent to analytics or other unrelated purposes.
Right to object. You may object, for reasons relating to your particular situation, to processing based on legitimate interests. We must stop that processing unless we demonstrate compelling overriding grounds or need it for legal claims.
Send requests to sofuwaru@gmail.com. We respond without undue delay and normally within one month. If the complexity or number of requests requires an extension, we explain the reason within the first month; the extension can be up to two additional months. Requests are normally free. Any refusal or permitted charge must be explained, including how to complain.
You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority competent for your place of residence or work, or the alleged infringement.
The current limited release does not make solely automated decisions with legal or similarly significant effects about you. If someone else provides information about you in a report or message, the source is that sender and their material; where required, we provide the relevant information directly to you. We do not treat this general notice as a substitute for that duty.
7. Changes
We update this notice when processing changes. Where required, we inform you before the new processing begins and seek any necessary separate permission. The version and effective date appear at the top of the published notice.