privacy
Privacy notice.
Plain-language summary of what afair stores, where, with whom, and what you can do about it. Long because it has to be honest, not because it has to be hard to read.
- What we store
- Two stores. The waitlist email list before you subscribe (your email plus the date you signed up, plus a confirmation timestamp). And, once you subscribe, the vault itself: every remember, recall, and observe call you make through the MCP server, plus the interpretation layer the worker swarm produces on top (extracted facts, entity graph, embeddings, salience scores). The vault sits on a single-tenant machine in the EU, currently Frankfurt, encrypted at rest. Nothing is sold, profiled, or shared with anyone except the sub-processors named below.
- Sub-processors
- Every external service that touches your data, what they get, and where they sit. We picked EU-residency where the function allowed it; the three LLM providers (Anthropic, OpenAI, Google) operate from the US under Standard Contractual Clauses.
Provider Purpose What goes to them Region / Safeguard Anthropic (Claude) Event extraction, entity disambiguation, conflict resolution, daily consolidation, judge panel Event text and audio, entity name candidates, worker outputs US, Standard Contractual Clauses OpenAI (Whisper, embeddings, GPT) Audio transcription, semantic embeddings for search, judge panel Audio bytes, event text for embeddings, judge metadata US, Standard Contractual Clauses Google (Gemini) Judge panel (one of three votes in the self-improvement loop) Worker output metadata (no raw event text after the 2026-06-03 minimization) US, Standard Contractual Clauses MailerSend Transactional email delivery (confirmation, invite, welcome) Email address, mail body content EU (Lithuania) Stripe Subscription payments and customer portal Email address, payment method (billing only — not the vault) EU/US, Standard Contractual Clauses Fly.io Infrastructure hosting (per-user dedicated machine + database) Encrypted vault data (the key is held by afair, not by Fly; see Encryption below) EU (Frankfurt) Cloudflare DNS, TLS termination, edge protection, cookieless web analytics HTTP request metadata (IP, user agent, headers), aggregate page metrics EU/US edge PostHog Privacy-respecting product analytics on the marketing site (not the vault) Page views, click events, masked session recordings (no input or text content) EU (Frankfurt) Clerk Customer authentication for the hosted product (sign-up, sign-in, the vault's OAuth identity) and admin sign-in on the control plane Email address, login identity, session data US, Standard Contractual Clauses / Data Privacy Framework Sentry (Functional Software, Inc.) Error monitoring on the vault machines and the control plane Error telemetry (stack traces, request metadata), scrubbed of PII and vault text before it leaves the process, ingested via the EU endpoint (de.sentry.io) US, Standard Contractual Clauses / Data Privacy Framework - What goes to AI providers (and what does not)
- The MCP-server design means foundation models you connect see your vault content during normal use — that is the point of the product. Beyond that, afair itself calls AI providers for background work. The table above lists each call shape. Two specific minimizations: the judge panel only sees worker output metadata (not raw event text), and we cap the audio sent to Whisper at the file the user uploaded (no continuous capture). We do not feed your vault into any training run, ours or theirs; the contracts with these providers explicitly disallow training on the API input.
- Encryption
- SQLCipher whole-file AES-256 on the database. AES-256-GCM per file in the object store. On top of Fly.io's platform-level volume encryption. Today the key lives in our infrastructure; a user-managed-key option lands in Stufe 2 of the encryption roadmap. The contents are unreadable to Fly in the ordinary course and to attackers with disk access. Being honest about the limit: because afair holds the key, a legal order served on afair could compel decryption until user-managed keys ship.
- Your rights
- GDPR Art. 15 (access), Art. 16 (correction), Art. 17 (deletion), Art. 20 (portability), Art. 21 (objection). Full vault export is available at any time through the MCP tool, with no field truncation and no opaque format: JSON Lines, every event, every interpretation, every blob hash. A deletion request triggers vault destruction within 30 days plus removal from all backups within 90 days. Write to hello@afair.ai for any of these, we reply within 72 hours.
- AI processing transparency (EU AI Act)
- afair is a deployer of an AI system with limited-risk transparency obligations under EU Regulation 2024/1689 Art. 50. The cold-path agents (extractor, entity canonicalizer, conflict resolver, daily consolidator, judge panel) call third-party LLMs to turn raw events into structured material. No automated decision is made about you, no biometric processing, no Annex III high-risk use case. The full per-provider breakdown sits in the sub-processor table above; the matching service-terms section is in our terms of service.
- Backups and recovery
- Hourly encrypted volume snapshots of every user vault, retained for 14 days and scoped to the user. On account deletion the vault machine, its volume, and its snapshots are destroyed and the key escrow is wiped, so no readable copy survives. A dependency-free reader ships alongside the service so you can open a full export of your vault with your own tools, without afair's infrastructure (the bus-factor guarantee: even if afair the company stops, your data is yours).
- Data residency
- The vault, the early-access database, the email delivery, and the hosting all sit in the EU. The three AI providers and Stripe operate from the US under SCCs. We never transfer your data outside these jurisdictions.
- Cookies and tracking
- The marketing site runs PostHog for product analytics in a privacy-respecting setup: cookieless (no tracking cookies, in-memory only), hosted in the EU, Do-Not-Track respected, no profile for anonymous visitors, and every input and all text masked in session recordings. You can turn it off for this device with the toggle below. We also run Cloudflare Web Analytics, which is cookieless by design: it sets no cookies, stores nothing on your device, uses no fingerprinting, and records only aggregate page metrics that cannot identify you. The control plane uses Clerk for admin sign-in, which sets its own session cookies. No third-party advertising cookies, no fingerprinting, no advertising identifiers.
- Contact and supervisory authority
- The controller's name, address and legal form are listed in the imprint. For any of the rights above, reach us at hello@afair.ai. Supervisory authority: your local data protection authority. For German residents that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, datenschutz-berlin.de.
Last updated: 1 July 2026