What Fractal does with your data.
Fractal is an AI product. To answer you it sends your words — and context about your work — to AI companies that are not us. This page says exactly which ones, exactly what they get, and what is still undecided. Where we don't know something yet, it says that too.
The short version
- We do not sell your data, and we do not share it for advertising.
- We do share it with AI providers — that is how the product works. Your messages, your voice, your ticket titles, your calendar event titles and times, and your name and email address reach at least one third-party model provider in ordinary use.
- Live microphone audio can leave your device without passing through us. In voice and dictation modes your browser streams audio directly to ElevenLabs.
- Retention is not yet defined. See section 05. We would rather say so than invent a number.
What Fractal collects
Account identity. When you sign in, Fractal stores your user id, your email address, and the display name your identity provider gives us.
Google Calendar. If you sign in with Google, Fractal requests openid, email, userinfo.email and full read & write access to your Google Calendar. It reads your events — titles, times, calendars — and can create, change and delete events you ask it to.
Your work content. Tickets, cards, notes, decisions, plans, sessions, comments, uploaded and pasted images, and the full text of your conversations with Fractal's assistants.
Voice. When you use voice or dictation, your microphone audio and its transcript.
Behavioural signal. Fractal derives a tendency profile — a short synthesised description of how you tend to work — from your activity, and uses it as context for planning.
Operational records. Sign-in cookies, an audit log of changes and tool calls, and, on mobile, a device token if you enable push notifications.
Where it goes — the AI path
This is the section that matters, so it is specific. Two things happen that are easy to miss:
- Your name and email are attached to every chat turn. Fractal prepends a signed-in-user block — user id, email, display name, workspace — to each turn so the assistant addresses you correctly. That block goes to the model provider along with your message.
- The assistant is given a snapshot of your work, not just your question. Each planning request carries up to 60 of your sessions (including events read from your Google Calendar, with their titles and times), up to 60 unassigned inbox tickets, and your tendency profile, embedded in the prompt sent to the model provider.
- Live microphone audio goes straight from your device to ElevenLabs. Fractal mints a single-use token and your browser opens the connection itself; no Fractal server sits in that audio path. Separately, recorded audio clips and text destined to be spoken aloud are relayed to ElevenLabs by our server.
- Small background tasks also use models. Naming a conversation, classifying a note, turning a spoken sentence into a card, and routing a request are each done by sending the relevant text to a model provider.
Who receives your data
The list below is exhaustive as of the last-updated date. Each recipient is bound by the same commitment, stated once here and applying equally to all of them: data is disclosed only so that they can perform the specific function described, they are not permitted to sell it or to disclose it onward for their own purposes, and we do not disclose more than the function needs. No recipient is given a weaker or a stronger commitment than any other.
Receives: Your message text; the work snapshot described in section 02, including Google Calendar event titles and times, ticket titles and your tendency profile; your name and email as part of the signed-in-user block; voice transcripts passed to background tasks.
Receives: Everything sent to Anthropic passes through this relay first. It is a request relay operated for Fractal, not a public service, and it forwards prompts to the model provider.
Receives: Depending on which model a conversation is configured to use, your message text and inline images may be routed to OpenAI instead of, or in addition to, Anthropic.
Named here because the chat backend can route to it. See section 06 — the backend's current provider configuration lives outside the app and is not something this page can verify for you.
Receives: Your microphone audio — streamed live from your device in voice and dictation modes, or uploaded as clips by our server — its transcript, and text that Fractal speaks aloud to you.
Receives: Sign-in: the identity assertion for your Google account. Calendar: read and write access to your events, used to show your schedule and to make the changes you ask for. If you did not sign in with Google, Fractal holds no Google data for you.
Receives: Everything Fractal stores, because Fractal stores it there: your account, your tickets, cards, plans, conversations and audit log, held in a Postgres database with per-user row-level security.
Receives: Requests to the app, and the operational logs that come with serving them.
Receives: If you sign in with Apple, the identity assertion — name and email, or Apple's private relay address if you hide your email. If you enable push notifications, the notification payload passes through Apple's push service.
Optional connections. If you connect a messaging channel such as Telegram for notifications, the summaries and notifications you have asked for are delivered through that channel and are visible to its operator. Nothing is sent there unless you connect it.
What we do not do
- We do not sell your personal data.
- We do not share it with advertisers or data brokers, and Fractal carries no advertising or third-party analytics SDKs.
- We do not read your content to build a profile for anyone but you. The tendency profile exists to plan your days and is not shared outside the flows described above.
How long it is kept
Fractal keeps your content in its database for as long as your account exists, and keeps an audit log of changes and tool calls for the same period. Deleting a card, ticket or conversation in the app removes it from your view; the audit log entry that records the change remains.
What this page cannot yet verify
Two honest limits, stated rather than hidden:
Your rights and your controls
- Disconnect Google. You can revoke Fractal's calendar access at any time from
/settings, or from your Google account's third-party access page. Fractal stops reading your calendar immediately. - Access and export. Ask us for a copy of what Fractal holds about you and we will send it.
- Correction. Most of your content is editable in the app. For anything that is not, ask.
- Deletion. You can ask for your account and its contents to be deleted, and we will delete them. Email privacy@fractal.pakhchau.com from the address you signed in with. Deletion covers what Fractal stores; it does not by itself reach copies held by the providers in section 03, whose retention we have not verified (section 05).
- Withdrawing AI processing. There is no switch for this yet — see section 06. If you want your data to stop being sent to AI providers, the honest answer today is to stop using Fractal and ask us to delete your account.
Security
Your data sits behind per-user row-level security in Postgres, so a signed-in account can read only its own rows. Traffic to Fractal and to every provider named above is encrypted in transit. Fractal is a small product and does not hold a formal security certification; treat it accordingly with genuinely sensitive material.
Children
Fractal is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it.
Changes, and how to reach us
When what Fractal does with your data changes, this page changes in the same release, and the last-updated date at the top moves. If the change is material we will tell you in the app before it takes effect.
Questions, requests, or a correction to anything stated here: privacy@fractal.pakhchau.com.
Last updated 4 August 2026