Privacy policy
What Facet stores, why, who can technically reach it, and how to take it back or destroy it.
Last changed September 2, 2026
These details are not published yet: the company is still being formed. Until then, send any request through the app.
Who is responsible for your data
The controller is named below. Any request about your rights goes to the same address.
What we store
About the account:
- your email address and a hash of your password — held by the authentication service; we never see the password itself;
- the name you gave and the language you read the app in;
- a profile picture, but only if you signed in with Google and it supplied one.
About the personas you create:
- a name, a date of birth, and how that person is related to you.
About documents:
- the file itself;
- its original filename, type, size and checksum;
- the text recognised from it;
- the document type and the fields pulled out of it — a number, an expiry date;
- the tags you added, a small copy for the list, and a numeric vector used for search by meaning.
About use:
- your questions to the assistant, its answers, and the documents it cited;
- notifications and, if you allowed them, the subscription that delivers them;
- counters of AI calls per day, so the daily allowances can be kept.
We collect no analytics, run no visitor counters and hand nothing to advertising networks. The app loads no third-party script at all.
Purposes of processing
The data is used to provide the service: storing documents, recognising them, searching them, giving notice before something expires, and answering questions about your own documents.
Your documents are used for nothing else. We do not mine them for our own purposes, do not build profiles, and do not sell access.
The legal basis
Processing is necessary to perform our contract with you (Art. 6(1)(b) GDPR): you create a document vault and we maintain it. Without this data the service cannot operate.
Device notifications are sent only on your explicit consent, which you can withdraw at any time in settings or in the browser.
Medical documents are a case apart. The GDPR treats health data as a special category (Art. 9), and an agreement with us does not on its own cover it. So we ask for that consent separately — a switch under “Privacy and security”, off unless you turn it on. Facet works exactly the same without it; simply keep no medical documents in it. Withdrawing is the same switch, one click, whenever you like.
Processing by artificial intelligence
The files you upload are read by Google's Gemini model — that is where the recognised text, the document type and the extracted fields come from. It is a core part of the service, not an optional extra.
A separate page sets it out in detail: what is submitted for processing, what is excluded, the terms the processor works under, and the limits that apply.
Processors
The service runs on third-party infrastructure, so your files physically pass through those systems. The full list:
- Supabase — database, authentication and file storage; servers in Frankfurt;
- Vercel — application hosting; served from Frankfurt;
- Google — the Gemini model that reads documents;
- Resend — delivery of our email (address confirmation, password resets);
- Cloudflare — the domain name and DNS.
Each acts on our instructions and may not use your data for its own ends.
Transfers outside the EU
Files are stored in Frankfurt. Recognition is performed by Google's model, and that processing leaves the EU: the Gemini interface the service uses offers no choice of processing region. Vercel and Cloudflare are United States companies as well.
Such transfers rest on the EU–US Data Privacy Framework and the European Commission's standard contractual clauses.
Retention periods
A deleted document goes to the bin and stays there for 30 days, so that deleting the wrong thing can be undone. After that the file and everything derived from it are destroyed.
Deleting an account destroys all associated data at once: documents, files, personas, tags, conversations, notifications. No backup copies of deleted data are retained.
Your rights
Under the GDPR you may know what we hold about you, receive a copy of it, correct it, have it erased, restrict our processing of it and object to that processing.
Two of these are a button in the app: “Export data” hands back everything that is yours in one file, and “Delete account” destroys all of it. For the rest, write to the address above.
You may also complain to the data protection authority where you live.
Cookies
We set three, and all of them are functional: your session, the language you chose, and the persona you are looking at.
There are no analytics or advertising cookies, and therefore no consent banner — functional cookies do not need one (§25 TDDDG).
Security measures
Every table holding your data is closed by row-level policies: a query made as somebody else returns none of your rows. File storage is private — a file is handed over only through a temporary signed link that lasts an hour.
End-to-end encryption is not used: it is incompatible with recognising and searching documents, which the service is built on. This is a design decision, not an omission. Files are encrypted at rest by the provider, and access to them is governed by the rules above.
Changes
If this policy changes materially we will say so in the app. The date of the last change is at the top of this page.