What Fractal does with your data.
Fractal is an AI product. To answer you it sends your words — and context about your work — to AI companies that are not us. This page says exactly which ones, exactly what they get, and what is still undecided. Where we don't know something yet, it says that too.
The short version
- We do not sell your data, and we do not share it for advertising.
- We do share it with AI providers — that is how the product works. Your messages, your voice, your ticket titles, your calendar event titles and times, and your name and email address reach at least one third-party model provider in ordinary use.
- Live microphone audio can leave your device without passing through us. In voice and dictation modes your browser streams audio directly to ElevenLabs.
- Retention is not yet defined. See section 05. We would rather say so than invent a number.
What Fractal collects
Account identity. When you sign in, Fractal stores your user id, your email address, and the display name your identity provider gives us.
Google Calendar. If you sign in with Google, Fractal requests openid, email, userinfo.email and full read & write access to your Google Calendar. It reads your events — titles, times, calendars — and can create, change and delete events you ask it to.
Your work content. Tickets, cards, notes, decisions, plans, sessions, comments, uploaded and pasted images, and the full text of your conversations with Fractal's assistants.
Voice. When you use voice or dictation, your microphone audio and its transcript.
Behavioural signal. Fractal derives a tendency profile — a short synthesised description of how you tend to work — from your activity, and uses it as context for planning.
Operational records. Sign-in cookies, an audit log of changes and tool calls, and, on mobile, a device token if you enable push notifications.
Where it goes — the AI path
This is the section that matters, so it is specific. Two things happen that are easy to miss:
- Your name and email are attached to every chat turn. Fractal prepends a signed-in-user block — user id, email, display name, workspace — to each turn so the assistant addresses you correctly. That block goes to the model provider along with your message.
- The assistant is given a snapshot of your work, not just your question. Each planning request carries up to 60 of your sessions (including events read from your Google Calendar, with their titles and times), up to 60 unassigned inbox tickets, and your tendency profile, embedded in the prompt sent to the model provider.
- Live microphone audio goes straight from your device to ElevenLabs. Fractal mints a single-use token and your browser opens the connection itself; no Fractal server sits in that audio path. Separately, recorded audio clips and text destined to be spoken aloud are relayed to ElevenLabs by our server.
- Which model provider gets a chat turn depends on the tier you pick, on fallbacks, and on the assistant runtime. The application's source configures Fast and Deep towards Z.ai with OpenRouter as a fallback, and Best towards OpenAI with Anthropic as a fallback; the runtime that actually relays the turn has its own default and may serve a turn on Anthropic. So every provider in section 03 is one that may process a turn, and none is promised for a specific turn. Every turn passes through Fractal's self-hosted assistant runtime on the way.
- The assistant can read more than the message. When you ask it something, it may read your cards, tasks, notes, calendar and — where you have connected them — messages from Telegram or WhatsApp threads and items from Linear, Notion or GitHub, and that material becomes part of what the model provider receives for that turn.
- Small background tasks also use models. Naming a conversation, classifying a note, tidying a comment, turning a spoken sentence into a card, summarising a finished conversation, and routing a request are each done by sending the relevant text to a model provider (Anthropic, through Fractal's relay).
Who receives your data
The list below is exhaustive as of the last-updated date. Each recipient is bound by the same commitment, stated once here and applying equally to all of them: data is disclosed only so that they can perform the specific function described, they are not permitted to sell it or to disclose it onward for their own purposes, and we do not disclose more than the function needs. No recipient is given a weaker or a stronger commitment than any other.
The recipients below are rendered from the same list the in-app consent step shows you (disclosure ai-processing-v1, September 2026). When that list changes materially, the identifier changes and you are asked again. Each AI processor is described as one that may process your content: which one serves a given turn depends on the tier you select, on fallbacks, and on the assistant runtime's own configuration (section 06).
AI processors — the ones your consent covers.
Receives: Your messages and conversation history; your name and email; the cards, tasks, notes and files the assistant reads to answer; calendar events when Google Calendar is connected; messages from Telegram or WhatsApp threads the assistant reads when those are connected; and results returned by connected tools (Linear, Notion, GitHub).
Receives: Your messages and conversation history; your name and email; the cards, tasks, notes and files the assistant reads to answer; calendar events when Google Calendar is connected; messages from Telegram or WhatsApp threads the assistant reads when those are connected; and results returned by connected tools (Linear, Notion, GitHub). In voice mode, your live microphone audio and its transcript.
Receives: Your messages and conversation history; your name and email; the cards, tasks, notes and files the assistant reads to answer; calendar events when Google Calendar is connected; messages from Telegram or WhatsApp threads the assistant reads when those are connected; and results returned by connected tools (Linear, Notion, GitHub). For the automatic features: the message text, transcript or card content being named, tidied, classified or summarised.
Receives: Your messages and conversation history; your name and email; the cards, tasks, notes and files the assistant reads to answer; calendar events when Google Calendar is connected; messages from Telegram or WhatsApp threads the assistant reads when those are connected; and results returned by connected tools (Linear, Notion, GitHub).
Receives: Your live microphone audio and its transcript for that voice session.
Receives: Your microphone audio (streamed directly from your device or uploaded as clips), its transcript, and text Fractal speaks aloud.
Receives: The text of those requests in transit to Anthropic.
Receives: Every chat turn and the context assembled for it, in transit to the model providers above.
Infrastructure — not optional, and not switched off by declining AI processing. This consent covers sending your content to the AI processors listed (kind: ai). It does not cover, and declining or withdrawing it does not undo, the sign-in and storage infrastructure your account already uses (kind: infrastructure) — deleting your account is the control for that. Withdrawing stops further AI transmissions from that moment; it does not retrieve what providers already received.
Receives: Everything Fractal stores for your account.
Receives: Requests to the app and the operational logs of serving them.
Receives: Sign-in: the identity assertion for your Google account. Calendar: read and write access to your events, used to show your schedule and to make the changes you ask for. If you did not sign in with Google, Fractal holds no Google data for you.
Receives: If you sign in with Apple, the identity assertion — name and email, or Apple's private relay address if you hide your email. If you enable push notifications, the notification payload passes through Apple's push service.
Optional connections. If you connect a messaging channel such as Telegram for notifications, the summaries and notifications you have asked for are delivered through that channel and are visible to its operator. Nothing is sent there unless you connect it.
What we do not do
- We do not sell your personal data.
- We do not share it with advertisers or data brokers, and Fractal carries no advertising or third-party analytics SDKs.
- We do not read your content to build a profile for anyone but you. The tendency profile exists to plan your days and is not shared outside the flows described above.
How long it is kept
Fractal keeps your content in its database for as long as your account exists, and keeps an audit log of changes and tool calls for the same period. Deleting a card, ticket or conversation in the app removes it from your view; the audit log entry that records the change remains.
What this page cannot yet verify
Two honest limits, stated rather than hidden:
DELETE /api/me/consent to withdraw it), and the server can refuse to transmit for an account without one. That refusal is switched on per release. In a release where it is off, no message is blocked for lack of consent: this page is the disclosure, the consent step still records your answer, and signing in and sending is what proceeds. When a release has it on, nothing you write, say or attach reaches a provider named above until you have accepted the current disclosure, and withdrawing it stops further transmissions from that moment.Your rights and your controls
- Disconnect Google. You can revoke Fractal's calendar access at any time from
/settings, or from your Google account's third-party access page. Fractal stops reading your calendar immediately. - Access and export. Ask us for a copy of what Fractal holds about you and we will send it.
- Correction. Most of your content is editable in the app. For anything that is not, ask.
- Deletion. Delete your account yourself from the app (Account → Delete account, which calls
POST /api/account/delete): it removes your account and everything Fractal stores for it, and signs you out. If you cannot reach the app, email privacy@fractal.day from the address you signed in with and we will delete it for you. Deletion covers what Fractal stores; it does not by itself reach copies held by the providers in section 03, whose retention we have not verified (section 05). - Withdrawing AI processing. Withdraw the consent you gave in the app's consent step (the server endpoint is
DELETE /api/me/consent); Fractal records the withdrawal with a timestamp and pauses any of your scheduled routines that run on the assistant runtime. What withdrawal changes depends on the release, as section 06 states: in a release where the refusal is switched on, nothing further you write, say or attach reaches an AI provider from that moment; in a release where it is off, your withdrawal is recorded but sending still proceeds, and the only way to be certain nothing is transmitted is to stop using Fractal or delete your account. Withdrawal never retrieves what a provider already received.
Security
Your data sits behind per-user row-level security in Postgres, so a signed-in account can read only its own rows. Traffic to Fractal and to every provider named above is encrypted in transit. Fractal is a small product and does not hold a formal security certification; treat it accordingly with genuinely sensitive material.
Children
Fractal is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it.
Changes, and how to reach us
When what Fractal does with your data changes, this page changes in the same release, and the last-updated date at the top moves. If the change is material we will tell you in the app before it takes effect.
Questions, requests, or a correction to anything stated here: privacy@fractal.day.
Last updated 5 September 2026