LEGAL / SERVICE DETAILS

Service Details

Draft — not yet in force. This page is published for review during the beta. Bracketed items like [DATE] are still being filled in and a lawyer has not yet reviewed the text. It will say "in force" here when that changes.

This page is part of the Terms of Service and holds the current lists the Privacy Policy refers to. It holds everything that changes with the product.

Keep it in sync with the code; the Terms and Privacy Policy should not need editing when it changes.

Notice rules for changes to this page

Last updated: [DATE]

1. Pricing

2. Account parameters

3. Technical requirements

4. Cookies

We use only cookies that are strictly necessary to keep you signed in and to protect your session: __Host-fn_session (keeps you signed in), fn_csrf (protects your actions against cross-site request forgery), and fn_relogin (a short-lived, 10-minute cookie used only on the sign-in page). When you sign in, our identity provider (Ory Hydra, on the authentication subdomain) sets its own short-lived flow cookies for the login and consent screens; these are also strictly necessary and are never shared with fair.ninja's own pages. None of these require consent. Our marketing websites set no cookies.

5. Processors

ProviderRoleLocation
Hetzner Online GmbHHosting: servers, database, exportsEU ([Germany / Finland])
[Google Ireland Ltd / Google LLC — Firebase Authentication]Sign-in[EU, USA]
Sold through Link, LLC (Stripe Managed Payments); payment processing: Stripe Payments Company / Stripe Technology Europe, LimitedReseller and merchant of record for chips; payments (independent controller)[Ireland, USA]
[Grafana Labs — Grafana Cloud]Logs and monitoring[EU or USA — confirm]
[Cloudflare, Inc.]DNS only[Global]
BunnyWay d.o.o. (bunny.net)Encrypted off-site backupsEU

6. Retention periods

DataPeriod
Sync change history90 days (a separate, shorter internal de-duplication window of 24 hours applies to commands that arrive outside a device's own stream — for example through an assistant connection or a webhook; it does not shorten what you see in your own sync history)
Data copy ZIP files7 days after the link is sent
Ended session records (incl. IP, user agent)90 days
Technical logs[30 days]
Backups14 days, encrypted
Payment and ledger records[5 years from end of tax year]
Correspondence[3 years after last message]
Abuse-prevention hash of deleted accounts24 months

Changelog

DateChange
[DATE]First version.

Generated from the repository's docs/legal/service-details.md. Questions: see section 1.