Privacy

The application sends us nothing.

The website and email still involve ordinary infrastructure. This page keeps those separate.

Controller

IT-Tervis OÜ, registry code 14693099, Estonia, is the controller for this website and for correspondence sent to us. Contact: security@fictor.dev.

The Fictor application

The application has no telemetry, analytics, crash reporting, account, automatic update check, remote activation, or licence server. It sends no usage data to us or to a telemetry service.

By default, model requests go to a local Ollama process. If you configure OpenAI or Anthropic, Fictor asks before every cloud operation and sends the disclosed brief, relevant app source, diagnostic context, and system instructions to that provider. Read the complete product privacy notice included with the release before using it.

This website

This static website is delivered through Cloudflare Pages. When you visit, Cloudflare necessarily processes request information such as IP address, request time, requested URL, browser information, and security signals to deliver and protect the site. IT-Tervis OÜ relies on its legitimate interests in operating a reliable and secure website.

We do not add analytics, advertising, tracking pixels, user accounts, contact forms, or marketing cookies. Cloudflare may process data outside the EEA under its Data Processing Addendum and applicable Standard Contractual Clauses. See Cloudflare’s privacy policy.

Email

If you email us, we process your email address, name if provided, delivery metadata, message, and attachments. Security reports are used to assess and correct vulnerabilities; other correspondence is used to answer you and improve Fictor. The lawful basis is our legitimate interest under GDPR Article 6(1)(f).

ContextRetention
Security reportUntil resolved and disclosed, then up to 24 months as an advisory record.
Support or feedbackUp to 24 months.

Incoming mail is routed by Cloudflare Email Routing to a mailbox hosted by Hostinger. They process the message and delivery metadata needed to route, filter, store, and deliver it. Their data-processing terms include safeguards for international transfers, including EU Standard Contractual Clauses where applicable. Processing may occur outside the EEA. See Cloudflare’s privacy policy and Hostinger’s privacy policy.

Privacy requests

Depending on the law that applies, you may have rights over your personal data, including access, correction, deletion, restriction, objection, or portability. Contact security@fictor.dev. Where the GDPR applies, you may also lodge a complaint with the data protection authority where you live or work, or where you believe an infringement occurred.

Version: 1.0, 30 July 2026.