Fractal
Privacy policy · last updated 5 September 2026

What Fractal does with your data.

Fractal is an AI product. To answer you it sends your words — and context about your work — to AI companies that are not us. This page says exactly which ones, exactly what they get, and what is still undecided. Where we don't know something yet, it says that too.

00

The short version

  • We do not sell your data, and we do not share it for advertising.
  • We do share it with AI providers — that is how the product works. Your messages, your voice, your ticket titles, your calendar event titles and times, and your name and email address reach at least one third-party model provider in ordinary use.
  • Live microphone audio can leave your device without passing through us. In voice and dictation modes your browser streams audio directly to ElevenLabs.
  • Retention is not yet defined. See section 05. We would rather say so than invent a number.
01

What Fractal collects

Account identity. When you sign in, Fractal stores your user id, your email address, and the display name your identity provider gives us.

Google Calendar. If you sign in with Google, Fractal requests openid, email, userinfo.email and full read & write access to your Google Calendar. It reads your events — titles, times, calendars — and can create, change and delete events you ask it to.

Your work content. Tickets, cards, notes, decisions, plans, sessions, comments, uploaded and pasted images, and the full text of your conversations with Fractal's assistants.

Voice. When you use voice or dictation, your microphone audio and its transcript.

Behavioural signal. Fractal derives a tendency profile — a short synthesised description of how you tend to work — from your activity, and uses it as context for planning.

Operational records. Sign-in cookies, an audit log of changes and tool calls, and, on mobile, a device token if you enable push notifications.

02

Where it goes — the AI path

This is the section that matters, so it is specific. Two things happen that are easy to miss:

  • Your name and email are attached to every chat turn. Fractal prepends a signed-in-user block — user id, email, display name, workspace — to each turn so the assistant addresses you correctly. That block goes to the model provider along with your message.
  • The assistant is given a snapshot of your work, not just your question. Each planning request carries up to 60 of your sessions (including events read from your Google Calendar, with their titles and times), up to 60 unassigned inbox tickets, and your tendency profile, embedded in the prompt sent to the model provider.
  • Live microphone audio goes straight from your device to ElevenLabs. Fractal mints a single-use token and your browser opens the connection itself; no Fractal server sits in that audio path. Separately, recorded audio clips and text destined to be spoken aloud are relayed to ElevenLabs by our server.
  • Which model provider gets a chat turn depends on the tier you pick, on fallbacks, and on the assistant runtime. The application's source configures Fast and Deep towards Z.ai with OpenRouter as a fallback, and Best towards OpenAI with Anthropic as a fallback; the runtime that actually relays the turn has its own default and may serve a turn on Anthropic. So every provider in section 03 is one that may process a turn, and none is promised for a specific turn. Every turn passes through Fractal's self-hosted assistant runtime on the way.
  • The assistant can read more than the message. When you ask it something, it may read your cards, tasks, notes, calendar and — where you have connected them — messages from Telegram or WhatsApp threads and items from Linear, Notion or GitHub, and that material becomes part of what the model provider receives for that turn.
  • Small background tasks also use models. Naming a conversation, classifying a note, tidying a comment, turning a spoken sentence into a card, summarising a finished conversation, and routing a request are each done by sending the relevant text to a model provider (Anthropic, through Fractal's relay).
03

Who receives your data

The list below is exhaustive as of the last-updated date. Each recipient is bound by the same commitment, stated once here and applying equally to all of them: data is disclosed only so that they can perform the specific function described, they are not permitted to sell it or to disclose it onward for their own purposes, and we do not disclose more than the function needs. No recipient is given a weaker or a stronger commitment than any other.

The recipients below are rendered from the same list the in-app consent step shows you (disclosure ai-processing-v1, September 2026). When that list changes materially, the identifier changes and you are asked again. Each AI processor is described as one that may process your content: which one serves a given turn depends on the tier you select, on fallbacks, and on the assistant runtime's own configuration (section 06).

AI processors — the ones your consent covers.

Z.ai (Zhipu AI)May process your chat turns depending on the model tier selected and provider availability.

Receives: Your messages and conversation history; your name and email; the cards, tasks, notes and files the assistant reads to answer; calendar events when Google Calendar is connected; messages from Telegram or WhatsApp threads the assistant reads when those are connected; and results returned by connected tools (Linear, Notion, GitHub).

OpenAIMay process your chat turns depending on the model tier selected and provider availability, and may run real-time voice sessions.

Receives: Your messages and conversation history; your name and email; the cards, tasks, notes and files the assistant reads to answer; calendar events when Google Calendar is connected; messages from Telegram or WhatsApp threads the assistant reads when those are connected; and results returned by connected tools (Linear, Notion, GitHub). In voice mode, your live microphone audio and its transcript.

AnthropicMay process your chat turns depending on the model tier selected, provider availability and the runtime's default; also runs automatic naming, tidying, classification and conversation summaries.

Receives: Your messages and conversation history; your name and email; the cards, tasks, notes and files the assistant reads to answer; calendar events when Google Calendar is connected; messages from Telegram or WhatsApp threads the assistant reads when those are connected; and results returned by connected tools (Linear, Notion, GitHub). For the automatic features: the message text, transcript or card content being named, tidied, classified or summarised.

OpenRouterRouting service that may forward a chat turn to Z.ai, Alibaba (Qwen), DeepSeek, Moonshot or xAI models depending on the tier selected and availability.

Receives: Your messages and conversation history; your name and email; the cards, tasks, notes and files the assistant reads to answer; calendar events when Google Calendar is connected; messages from Telegram or WhatsApp threads the assistant reads when those are connected; and results returned by connected tools (Linear, Notion, GitHub).

Google (Gemini)May run real-time voice sessions on the voice gateway depending on the engine selected and availability.

Receives: Your live microphone audio and its transcript for that voice session.

ElevenLabsSpeech-to-text for dictation, Listen mode and the Watch; text-to-speech for spoken replies; real-time voice sessions on the voice gateway.

Receives: Your microphone audio (streamed directly from your device or uploaded as clips), its transcript, and text Fractal speaks aloud.

Fractal's model relay (cliproxy.moti.bio)Request relay operated for Fractal that forwards the automatic features' requests (naming, tidying, classification, summaries, the legacy planning assistant) to Anthropic.

Receives: The text of those requests in transit to Anthropic.

Fractal's assistant runtime (Hetzner, EU)The self-hosted server that runs your agent and relays each chat turn to a model provider above according to the tier selected and its own configuration.

Receives: Every chat turn and the context assembled for it, in transit to the model providers above.

Infrastructure — not optional, and not switched off by declining AI processing. This consent covers sending your content to the AI processors listed (kind: ai). It does not cover, and declining or withdrawing it does not undo, the sign-in and storage infrastructure your account already uses (kind: infrastructure) — deleting your account is the control for that. Withdrawing stops further AI transmissions from that moment; it does not retrieve what providers already received.

SupabaseDatabase, file storage and sign-in. Not optional: your account already lives here; declining AI processing does not change this — deleting your account does.

Receives: Everything Fractal stores for your account.

VercelApplication hosting. Not optional: every request to the app passes through it regardless of this consent.

Receives: Requests to the app and the operational logs of serving them.

GoogleSign-in, and calendar where you connect it

Receives: Sign-in: the identity assertion for your Google account. Calendar: read and write access to your events, used to show your schedule and to make the changes you ask for. If you did not sign in with Google, Fractal holds no Google data for you.

AppleSign-in and push notifications, on iOS

Receives: If you sign in with Apple, the identity assertion — name and email, or Apple's private relay address if you hide your email. If you enable push notifications, the notification payload passes through Apple's push service.

Optional connections. If you connect a messaging channel such as Telegram for notifications, the summaries and notifications you have asked for are delivered through that channel and are visible to its operator. Nothing is sent there unless you connect it.

04

What we do not do

  • We do not sell your personal data.
  • We do not share it with advertisers or data brokers, and Fractal carries no advertising or third-party analytics SDKs.
  • We do not read your content to build a profile for anyone but you. The tendency profile exists to plan your days and is not shared outside the flows described above.
05

How long it is kept

Fractal keeps your content in its database for as long as your account exists, and keeps an audit log of changes and tool calls for the same period. Deleting a card, ticket or conversation in the app removes it from your view; the audit log entry that records the change remains.

Not yet settled
Fractal does not yet publish a defined retention window — for its own database, its logs, or its audit trail — and the retention terms that apply at each AI provider named in section 03 have not been verified and are not asserted here. Do not read this page as a promise that your prompts are deleted at any provider, or that any provider does or does not use them to improve its models. This will be settled and stated plainly here.
06

What this page cannot yet verify

Two honest limits, stated rather than hidden:

Not yet settled
The chat backend's terminal provider. Fractal's conversational assistant runs on a self-hosted runtime whose provider configuration lives outside this application. The tier-to-provider mapping in section 02 is what the application's source configures; the runtime is checked against it separately, and every provider the source can route to is named in section 03 so that your text reaching it is disclosed even when a specific model is not guaranteed.
Not yet settled
Consent — where it stands. Fractal records an explicit consent to third-party AI processing per account (the consent step in the app, and DELETE /api/me/consent to withdraw it), and the server can refuse to transmit for an account without one. That refusal is switched on per release. In a release where it is off, no message is blocked for lack of consent: this page is the disclosure, the consent step still records your answer, and signing in and sending is what proceeds. When a release has it on, nothing you write, say or attach reaches a provider named above until you have accepted the current disclosure, and withdrawing it stops further transmissions from that moment.
Not yet settled
Guests dictating on a shared card. A visitor who is not signed in has no account to record a consent against. When enforcement is on, voice dictation on public cards is disabled for guests rather than sent without consent.
07

Your rights and your controls

  • Disconnect Google. You can revoke Fractal's calendar access at any time from /settings, or from your Google account's third-party access page. Fractal stops reading your calendar immediately.
  • Access and export. Ask us for a copy of what Fractal holds about you and we will send it.
  • Correction. Most of your content is editable in the app. For anything that is not, ask.
  • Deletion. Delete your account yourself from the app (Account → Delete account, which calls POST /api/account/delete): it removes your account and everything Fractal stores for it, and signs you out. If you cannot reach the app, email privacy@fractal.day from the address you signed in with and we will delete it for you. Deletion covers what Fractal stores; it does not by itself reach copies held by the providers in section 03, whose retention we have not verified (section 05).
  • Withdrawing AI processing. Withdraw the consent you gave in the app's consent step (the server endpoint is DELETE /api/me/consent); Fractal records the withdrawal with a timestamp and pauses any of your scheduled routines that run on the assistant runtime. What withdrawal changes depends on the release, as section 06 states: in a release where the refusal is switched on, nothing further you write, say or attach reaches an AI provider from that moment; in a release where it is off, your withdrawal is recorded but sending still proceeds, and the only way to be certain nothing is transmitted is to stop using Fractal or delete your account. Withdrawal never retrieves what a provider already received.
08

Security

Your data sits behind per-user row-level security in Postgres, so a signed-in account can read only its own rows. Traffic to Fractal and to every provider named above is encrypted in transit. Fractal is a small product and does not hold a formal security certification; treat it accordingly with genuinely sensitive material.

09

Children

Fractal is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it.

10

Changes, and how to reach us

When what Fractal does with your data changes, this page changes in the same release, and the last-updated date at the top moves. If the change is material we will tell you in the app before it takes effect.

Questions, requests, or a correction to anything stated here: privacy@fractal.day.

Last updated 5 September 2026

← Back to sign in