FansaChat

Legal

Privacy Policy — FansaChat

Last updated: 9 August 2026

1. Who is responsible for your data

The data controller is Aminur Rahman Noor, an individual based in Narayanganj, Bangladesh, operating FansaChat at fansachat.com.

Contact: support@fansachat.com

There is no registered company and no data protection officer; a solo operator of this size is not required to appoint one.

EU / UK representative. We are established outside the EU and UK. Where a controller outside those regions offers services to people inside them, GDPR Article 27 (and its UK equivalent) requires a representative to be appointed there, unless the narrow exemption in Article 27(2) applies.

We will appoint a representative before the Service opens to users in the EU or UK, and name them here. We are not relying on the exemption to avoid it: the exemption turns on processing being occasional and small-scale, and a service with ongoing accounts and continuous workflow processing would not qualify — whether or not it is free. Until then, if you are in the EU or UK, email us and we will deal with your request directly.

2. What we collect

Category What it is Where it comes from
Account data Email address, hashed password or Google sign-in identifier, account creation date You, when you sign up
Waitlist data Email address only You, if you join the waitlist
Workflow data The descriptions you write, the workflows built from them, and the data those workflows process You, as you use the Service
Connection data The authorisation for each third-party app you connect. Our own database stores only a reference to that connection — never the token itself; see section 8 You, when you authorise a connection
Technical data IP address, browser type, timestamps, error logs Automatically, when you use the Service

We do not use advertising cookies or third-party analytics trackers.

Stopping automated signups. When the signup form is submitted we keep a hashed record of the IP address it came from — the address is put through SHA-256 with a secret key, and the address itself is never written into that record. It exists for one reason: to rate-limit bots hammering the form. It is not linked to your email address, it is not used to identify anyone, and it is deleted automatically within a few days.

Cookies and browser storage

We use browser storage for one thing: keeping you signed in.

What Name Purpose Consent needed?
Local storage fansachat-auth Holds your session so you stay signed in between visits No — strictly necessary
Local storage fansachat-last-email Pre-fills your email on the sign-in form, if you asked us to remember it No — you opt into it

Both are cleared when you sign out. Neither is shared with anyone, and neither tracks you across other websites.

Under the ePrivacy Directive, storage that is strictly necessary to deliver a service the user asked for does not require consent — which is why signing in does not trigger a consent banner. If we ever add analytics or any non-essential storage, it will be off by default and will only run if you actively turn it on. We will not use pre-ticked boxes, and refusing will be as easy as accepting.

3. Why we use it, and our legal basis

Purpose Legal basis (GDPR Art. 6)
Creating and running your account Contract — Art. 6(1)(b)
Building and running your workflows Contract — Art. 6(1)(b)
Keeping the Service secure, preventing abuse, fixing faults Legitimate interests — Art. 6(1)(f). The interest pursued is keeping the Service secure and available, protecting users and ourselves from fraud and abuse, and diagnosing faults.
Emailing you about the launch, if you joined the waitlist Consent — Art. 6(1)(a)
Meeting legal obligations Legal obligation — Art. 6(1)(c)

Where we rely on consent, you can withdraw it at any time — and withdrawing it is as easy as giving it. Every launch email carries an unsubscribe link, and you can email us instead. Withdrawal does not undo processing already done.

We do not sell your personal data. We do not use your workflow data to train AI models.

Do you have to give us this data?

Your email address is required to create an account — it is how we identify you and sign you in. Without it we cannot create an account for you. Everything else is optional, and not providing it only means the related feature will not work.

When your workflows handle other people's data

If your workflows process personal data about other people — your customers, your contacts, your subscribers — then for that data you are the controller and we are your processor. It is your data, used on your instructions.

That means: you decide what is collected and why, you need a lawful basis for it, and it is your responsibility to tell those people how their data is used (GDPR Articles 13 and 14). We only process it to run the workflow you built and approved, we do not use it for anything else, and we delete it with your account.

4. Who we share it with

We use the following processors. Each acts on our instructions only.

Processor What it does, and what it touches Where
Netlify Hosts the website and serves its pages. Its server logs see your IP address, your browser type and which pages you asked for. It does not hold your account, your workflows or your connected-app credentials. United States
Supabase Database and sign-in — this is where your account lives. It holds your email address, your hashed password or Google sign-in identifier, your profile, and the references that link your account to the apps you have connected. Singapore (ap-southeast-1)
Railway Hosts the servers our workflow engine runs on. Your workflows, the credentials for the apps you connect, and the data a workflow handles while it runs all live and execute there. United States
Resend Sends our email — the waitlist confirmation and account messages. It receives the recipient's email address and the contents of the message we send. United States
Zoho Mail Hosts the support@fansachat.com mailbox, so it holds anything you send us by email — including a request to exercise the rights in section 7 below, and whatever you put in it. Global
Cloudflare Domain registration and DNS for fansachat.com. It answers the lookups that point your browser at the site. It does not sit in front of the site, so it does not see your account or workflow data. Global
Google Only if you choose "Sign in with Google" — it confirms who you are and returns your email address to us. Global
Have I Been Pwned (a third-party service, not a processor acting on our instructions) When you set a password we send the first 5 characters of its SHA-1 hash to check it against known breaches. Your password is never sent, and the check cannot identify you (this is the published k-anonymity model). Global

Activepieces is deliberately not in that table. The workflow engine we run is Activepieces (see section 11 of the Terms). It is open-source software we host ourselves on Railway — software we run, not a supplier we hand your data to. Its authors never receive your data. Railway is the processor here, and it is listed above.

We may also disclose data where the law requires it, or to establish or defend a legal claim.

If we add or change a processor, we will update this table and the "last updated" date before the change takes effect. Where the change is significant — a new category of processor, or one in a new country — we will tell account holders by email first.

5. International transfers

FansaChat is operated from Bangladesh, and the processors above are mostly in the United States. If you are in the EU, UK or EEA, this means your data leaves your region.

Transfers rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. We will not use a processor for personal data unless that safeguard is in place — this is a commitment, not a best-efforts statement. You can ask us for a copy of the safeguards by emailing support@fansachat.com and we will send them or tell you where to find them.

Bangladesh has not received an EU adequacy decision. You are entitled to know that, and to decide whether you are comfortable with it.

6. How long we keep it

Data Retention
Account data While your account exists, then deleted within 30 days of account deletion
Workflow data While your account exists, then deleted within 30 days
Waitlist emails Until launch, or until you unsubscribe, or 24 months, whichever comes first
Connection tokens Until you disconnect the app, or your account is deleted
Technical and security logs 90 days

Backups are kept for up to 60 days and are then overwritten on a rolling cycle. This is why deletion can take slightly longer than the table above.

7. Your rights

If the GDPR or UK GDPR applies to you, you have the right to:

  • access a copy of your data
  • rectify data that is wrong
  • erase your data ("right to be forgotten")
  • restrict how we process it
  • port your data to another service in a machine-readable form
  • object to processing based on legitimate interests
  • withdraw consent at any time
  • not be subject to a solely automated decision with legal or similarly significant effects — we do not make any such decisions

Email support@fansachat.com to exercise any of these. We will respond within one month. We do not charge for this.

You also have the right to complain to a supervisory authority — in the EU, the data protection authority of the country where you live; in the UK, the Information Commissioner's Office (ico.org.uk). You do not have to contact us first, though we would rather you did.

8. Security

We use HTTPS everywhere, a Content Security Policy, and row-level security on the database — so a signed-in user can reach their own rows and nobody else's. Passwords are checked against known breaches before being accepted.

Where your connected-app credentials actually live

Our database does not hold the access tokens for the apps you connect. When you authorise an app, the credential is created and held by the workflow engine we self-host — the Activepieces instance described in section 4, running on Railway. What our own database stores is an opaque reference: an identifier for that connection, which app it is for, a display label and whether it is still active. There is no token, password or secret in it.

We are stating this rather than promising to encrypt those tokens, because it is the stronger fact: a credential we never receive is a credential we cannot leak from our database.

Supabase, where your account lives, encrypts the data it stores at rest using AES-256, and traffic to it travels over TLS. That is a documented property of the platform itself, which you can check against Supabase's own published material — it is not a claim about bespoke encryption in code we wrote, and we would rather point you at something verifiable than at something you have to take on trust.

No system is completely secure, and we will not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and tell you directly where the risk is high.

9. Children

FansaChat is not intended for children. You must be at least 16 to hold an account. If we learn we hold data from a child under that age, we delete it.

10. Changes

We will post any changes here and update the date at the top. If a change materially affects how we use your data, we will tell you before it takes effect.

11. Contact

support@fansachat.com