Privacy Policy — FansaChat
Last updated: 9 August 2026
1. Who is responsible for your data
The data controller is Aminur Rahman Noor, an individual based in Narayanganj, Bangladesh, operating FansaChat at fansachat.com.
Contact: support@fansachat.com
There is no registered company and no data protection officer; a solo operator of this size is not required to appoint one.
EU / UK representative. We are established outside the EU and UK. Where a controller outside those regions offers services to people inside them, GDPR Article 27 (and its UK equivalent) requires a representative to be appointed there, unless the narrow exemption in Article 27(2) applies.
We will appoint a representative before the Service opens to users in the EU or UK, and name them here. We are not relying on the exemption to avoid it: the exemption turns on processing being occasional and small-scale, and a service with ongoing accounts and continuous workflow processing would not qualify — whether or not it is free. Until then, if you are in the EU or UK, email us and we will deal with your request directly.
2. What we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Email address, hashed password or Google sign-in identifier, account creation date | You, when you sign up |
| Waitlist data | Email address only | You, if you join the waitlist |
| Workflow data | The descriptions you write, the workflows built from them, and the data those workflows process | You, as you use the Service |
| Connection data | The authorisation for each third-party app you connect. Our own database stores only a reference to that connection — never the token itself; see section 8 | You, when you authorise a connection |
| Technical data | IP address, browser type, timestamps, error logs | Automatically, when you use the Service |
We do not use advertising cookies or third-party analytics trackers.
Stopping automated signups. When the signup form is submitted we keep a hashed record of the IP address it came from — the address is put through SHA-256 with a secret key, and the address itself is never written into that record. It exists for one reason: to rate-limit bots hammering the form. It is not linked to your email address, it is not used to identify anyone, and it is deleted automatically within a few days.
Cookies and browser storage
We use browser storage for one thing: keeping you signed in.
| What | Name | Purpose | Consent needed? |
|---|---|---|---|
| Local storage | fansachat-auth |
Holds your session so you stay signed in between visits | No — strictly necessary |
| Local storage | fansachat-last-email |
Pre-fills your email on the sign-in form, if you asked us to remember it | No — you opt into it |
Both are cleared when you sign out. Neither is shared with anyone, and neither tracks you across other websites.
Under the ePrivacy Directive, storage that is strictly necessary to deliver a service the user asked for does not require consent — which is why signing in does not trigger a consent banner. If we ever add analytics or any non-essential storage, it will be off by default and will only run if you actively turn it on. We will not use pre-ticked boxes, and refusing will be as easy as accepting.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and running your account | Contract — Art. 6(1)(b) |
| Building and running your workflows | Contract — Art. 6(1)(b) |
| Keeping the Service secure, preventing abuse, fixing faults | Legitimate interests — Art. 6(1)(f). The interest pursued is keeping the Service secure and available, protecting users and ourselves from fraud and abuse, and diagnosing faults. |
| Emailing you about the launch, if you joined the waitlist | Consent — Art. 6(1)(a) |
| Meeting legal obligations | Legal obligation — Art. 6(1)(c) |
Where we rely on consent, you can withdraw it at any time — and withdrawing it is as easy as giving it. Every launch email carries an unsubscribe link, and you can email us instead. Withdrawal does not undo processing already done.
We do not sell your personal data. We do not use your workflow data to train AI models.
Do you have to give us this data?
Your email address is required to create an account — it is how we identify you and sign you in. Without it we cannot create an account for you. Everything else is optional, and not providing it only means the related feature will not work.
When your workflows handle other people's data
If your workflows process personal data about other people — your customers, your contacts, your subscribers — then for that data you are the controller and we are your processor. It is your data, used on your instructions.
That means: you decide what is collected and why, you need a lawful basis for it, and it is your responsibility to tell those people how their data is used (GDPR Articles 13 and 14). We only process it to run the workflow you built and approved, we do not use it for anything else, and we delete it with your account.
4. Who we share it with
We use the following processors. Each acts on our instructions only.
| Processor | What it does, and what it touches | Where |
|---|---|---|
| Netlify | Hosts the website and serves its pages. Its server logs see your IP address, your browser type and which pages you asked for. It does not hold your account, your workflows or your connected-app credentials. | United States |
| Supabase | Database and sign-in — this is where your account lives. It holds your email address, your hashed password or Google sign-in identifier, your profile, and the references that link your account to the apps you have connected. | Singapore (ap-southeast-1) |
| Railway | Hosts the servers our workflow engine runs on. Your workflows, the credentials for the apps you connect, and the data a workflow handles while it runs all live and execute there. | United States |
| Resend | Sends our email — the waitlist confirmation and account messages. It receives the recipient's email address and the contents of the message we send. | United States |
| Zoho Mail | Hosts the support@fansachat.com mailbox, so it holds anything you send us by email — including a request to exercise the rights in section 7 below, and whatever you put in it. |
Global |
| Cloudflare | Domain registration and DNS for fansachat.com. It answers the lookups that point your browser at the site. It does not sit in front of the site, so it does not see your account or workflow data. | Global |
| Only if you choose "Sign in with Google" — it confirms who you are and returns your email address to us. | Global | |
| Have I Been Pwned (a third-party service, not a processor acting on our instructions) | When you set a password we send the first 5 characters of its SHA-1 hash to check it against known breaches. Your password is never sent, and the check cannot identify you (this is the published k-anonymity model). | Global |
Activepieces is deliberately not in that table. The workflow engine we run is Activepieces (see section 11 of the Terms). It is open-source software we host ourselves on Railway — software we run, not a supplier we hand your data to. Its authors never receive your data. Railway is the processor here, and it is listed above.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
If we add or change a processor, we will update this table and the "last updated" date before the change takes effect. Where the change is significant — a new category of processor, or one in a new country — we will tell account holders by email first.
5. International transfers
FansaChat is operated from Bangladesh, and the processors above are mostly in the United States. If you are in the EU, UK or EEA, this means your data leaves your region.
Transfers rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. We will not use a processor for personal data unless that safeguard is in place — this is a commitment, not a best-efforts statement. You can ask us for a copy of the safeguards by emailing support@fansachat.com and we will send them or tell you where to find them.
Bangladesh has not received an EU adequacy decision. You are entitled to know that, and to decide whether you are comfortable with it.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account exists, then deleted within 30 days of account deletion |
| Workflow data | While your account exists, then deleted within 30 days |
| Waitlist emails | Until launch, or until you unsubscribe, or 24 months, whichever comes first |
| Connection tokens | Until you disconnect the app, or your account is deleted |
| Technical and security logs | 90 days |
Backups are kept for up to 60 days and are then overwritten on a rolling cycle. This is why deletion can take slightly longer than the table above.
7. Your rights
If the GDPR or UK GDPR applies to you, you have the right to:
- access a copy of your data
- rectify data that is wrong
- erase your data ("right to be forgotten")
- restrict how we process it
- port your data to another service in a machine-readable form
- object to processing based on legitimate interests
- withdraw consent at any time
- not be subject to a solely automated decision with legal or similarly significant effects — we do not make any such decisions
Email support@fansachat.com to exercise any of these. We will respond within one month. We do not charge for this.
You also have the right to complain to a supervisory authority — in the EU, the data protection authority of the country where you live; in the UK, the Information Commissioner's Office (ico.org.uk). You do not have to contact us first, though we would rather you did.
8. Security
We use HTTPS everywhere, a Content Security Policy, and row-level security on the database — so a signed-in user can reach their own rows and nobody else's. Passwords are checked against known breaches before being accepted.
Where your connected-app credentials actually live
Our database does not hold the access tokens for the apps you connect. When you authorise an app, the credential is created and held by the workflow engine we self-host — the Activepieces instance described in section 4, running on Railway. What our own database stores is an opaque reference: an identifier for that connection, which app it is for, a display label and whether it is still active. There is no token, password or secret in it.
We are stating this rather than promising to encrypt those tokens, because it is the stronger fact: a credential we never receive is a credential we cannot leak from our database.
Supabase, where your account lives, encrypts the data it stores at rest using AES-256, and traffic to it travels over TLS. That is a documented property of the platform itself, which you can check against Supabase's own published material — it is not a claim about bespoke encryption in code we wrote, and we would rather point you at something verifiable than at something you have to take on trust.
No system is completely secure, and we will not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and tell you directly where the risk is high.
9. Children
FansaChat is not intended for children. You must be at least 16 to hold an account. If we learn we hold data from a child under that age, we delete it.
10. Changes
We will post any changes here and update the date at the top. If a change materially affects how we use your data, we will tell you before it takes effect.
11. Contact
support@fansachat.com