Privacy

What Fenlio collects, who else sees it, and how to take it back.

What we collect

Your account. Your name, email address and profile picture, as provided by Google when you sign in. We never see or store your Google password.

Your content. The notes and files you upload (Markdown, plain text, PDF, Word, Pages, RTF, CSV, JSON or HTML), text you paste, files from public GitHub repositories you choose to import, the answers you give in the onboarding interview, and the drafts Creator Studio generates from them. This is the substance of the product and it is stored until you delete it.

Your subscription. Whether it is active, and identifiers that let us match your account to your record at our payment provider. Card numbers are handled entirely by Stripe and never reach our servers.

Operational logs. Errors and request failures, kept so faults can be diagnosed. These can include your account identifier.

Voice answers never leave your device as audio

The interview lets you speak instead of typing. Transcription is done by your own browser’s built-in speech recognition, which hands back text. No audio recording is ever created, sent to us, or stored — there is nothing to delete because nothing is captured. Only the resulting text is saved, exactly as if you had typed it.

Who else processes it

Anthropic — the text of your notes is sent to Anthropic’s API so agents can file them, spot duplicates and contradictions, draft your interview answers when you ask for that, and draft in Studio. Only the notes involved in a given task are sent, and never your account details.

GitHub — only if you import a repository. We fetch the repository’s files from GitHub’s servers; GitHub sees that request, and none of your other content.

Stripe — payment processing. Stripe receives your billing details directly; we receive back only your subscription status and an identifier.

Our hosting and database provider — stores the data described above so the product can run.

That is the complete list of processors we choose. Fenlio contains no analytics, advertising or tracking services of any kind, and we do not sell or share your content with anyone else.

Destinations you connect yourself

Two features send data where you point them, and only if you set them up. API keys let an external tool you authorize read (or, if you grant it, write to) your workspace; anyone holding a key can use its permissions, so treat keys like passwords — you can revoke one at any time from your account page. Webhooks send the events you subscribe to — such as check-in summaries or draft notifications — to a URL you configure. Whatever service runs that URL receives that data; choose it as carefully as you would any recipient of your notes.

Cookies

One cookie: the sign-in session that keeps you logged in. There are no advertising cookies and no third-party trackers.

Getting your data out, or removing it

Your account page has both, and neither requires contacting us or having an active subscription. Download my data gives you a single file containing your notes in full, the folders they were filed into, the connections found between them and every Studio draft.

Deleting your account removes your account, all your notes, connections, conflicts and drafts immediately and permanently, and cancels any subscription first. We cannot restore it afterwards.

Depending on where you live you may also have rights to correct your data, object to processing, or complain to a regulator. Write to us and we will act on it.

How long we keep it

Your content is kept until you delete it or your account. Operational logs are retained for a short period for diagnosis. Records we must keep for tax or accounting reasons are retained for as long as the law requires, even after an account is deleted.

Contact

Last updated 14 August 2026.