1. Data controller
The data controller is:
- Data controller: Lorenco Shametaj (natural person; “Fluera” is the product/brand — a company is being incorporated and will assume this role)
- Address:
Via Boccaccio 44, 35128 Padova (PD), Italia - VAT / Tax ID: not yet assigned (to be added upon incorporation)
- Privacy email: lorenco@fluera.dev
- Support email: support@fluera.dev
A Data Protection Officer (DPO) has not been appointed since the conditions under Art. 37 GDPR do not apply. For any matter related to your data, contact the controller at the addresses above.
2. Personal data processed
Fluera processes the following categories of personal data, strictly as needed for the declared purposes and subject to granular consent where required.
2.1 Account data
- Email address if you create an account (Supabase Auth)
- User identifier (
user_id) generated by Supabase — also for anonymous sessions - Auth provider data if used (Google Sign-In, Sign in with Apple): email, name, unique provider ID
2.2 User-generated content
- Canvases, strokes, notes, PDF annotations, inserted images
- Audio recordings of study sessions (only if Time Travel is enabled)
- Content is stored in a local database scoped to your account. From version 1.5 that database is encrypted at rest with AES-256 (Art. 32 GDPR) using a 256-bit key generated on your device and held in your operating system’s keystore — iOS/macOS Keychain, Android Keystore, libsecret on Linux, DPAPI on Windows. The key never leaves the device and we never see it. Content leaves your device in three cases, each on your own action: when you enable Cloud Sync; when you publish a study card to the catalogue; when you keep a card in your private catalogue to share it by link. The last two work even with Cloud Sync off, and cover only the portion of notes you select — never the whole canvas. See §2.11
- What that means if you lose the device or reinstall: because the key lives only in your device’s keystore, uninstalling the app, clearing its data, or moving to a new device makes the local database unreadable — to you and to us alike. Cloud Sync is the recovery path, and it is opt-in: if you have not enabled it, your canvases exist only on that device.
- Beta note: databases created before version 1.5 are unencrypted and cannot be opened with a key. On the first launch of version 1.5 such a database is deleted and a new encrypted one is created. Canvases already synced to the cloud come back; canvases that only ever existed locally do not.
2.3 Usage data (telemetry)
Only if you have consented to the Product analytics category:
- Randomly generated anonymous
session_idper session - Your account identifier, so that you can access and delete your own telemetry (§6). The crash-reporting processor (§5) receives only a SHA-256 hash of it, never the plaintext identifier
- Platform, app version, subscription tier, device language
- Product events from a server-side whitelist (session start/end, Ghost Map, Socratic, SRS reviews, AI calls with duration and tokens)
- Not collected: note content, question text, identifying information.
2.4 AI feature data
Only if you have consented to the AI features category:
- Selected canvas content sent for Socratic Mode, Ghost Map, LaTeX OCR, Exam Session — text portions and rendered PNG images of individual handwriting-cluster regions (never the full notebook)
- AI inference runs on Google Vertex AI in the European Union (europe-west4 Netherlands, with europe-west1 Belgium failover); canvas content is not transferred outside the EU for AI inference
- Usage tokens for plan limit enforcement
- In production, calls go through a Supabase Edge Function proxy (API key server-side)
2.5 Cloud Sync data
Only if you have consented to the Cloud Sync category:
- Canvas copies stored on Supabase (EU region
eu-north-1), encrypted in transit (TLS) and at rest at the infrastructure level. Cloud Sync is not end-to-end encrypted: as the data controller, Fluera can technically access synced content to provide, secure and support the service (we never sell it or use it for advertising) - Sync metadata (hash, timestamp, size)
2.6 Diagnostic and crash data
Only if you have consented to the Crash reporting category:
- Stack trace, OS version, device model, app version
- No user content in reports (
sendDefaultPii: false) - IP addresses are not stored (server-side IP scrubbing enabled in Sentry)
- Processed via Sentry — privacy policy: https://sentry.io/privacy/
2.7 Subscription data
- Subscription status (free / essential / plus / pro), activation, renewal, expiration dates
- RevenueCat / Apple / Google identifiers for receipt matching
- No payment data (card numbers, IBAN) is ever stored by our systems: transactions are handled by Apple, Google, and RevenueCat
2.8 Third-party software components (on-device)
Fluera includes some embedded third-party SDKs that process data exclusively on your device, without sending anything back to their producers. For transparency:
- Google ML Kit (on-device Digital Ink & Text Recognition) — on-device handwriting and text/image recognition. Recognition runs locally on your device; ink and images are not sent to Google for these on-device APIs (recognition models are downloaded from Google). Google receives no canvas content from Fluera via ML Kit.
- sqlite3mc — the local database engine, which provides the AES-256 encryption described in §2.2. The key is supplied by the app from your device’s keystore; sqlite3mc itself sends nothing anywhere. All processing is on-device.
- Sentry SDK (Functional Software Inc.) — only the embedded library; see §4 for the data controller and §3 for the legal basis of crash report transfer (consent, opt-in).
These components are not data processors under Art. 28 GDPR because they do not receive personal data. They are third-party software components like any other library used to build the app.
2.9 Cognitive memory (on-device indexing)
On by default (opt-out) and processed exclusively on your device: Fluera builds a cognitive index of your notes that powers the study features — automatic cluster titles, the concept map (“Ghost Map”), spaced repetition (FSRS), and the learning-state checkpoints (“Sé”).
- No transfer: this index never leaves your device. It is distinct from AI features (§2.4, which send content to the cloud) and Cloud Sync (§2.5), which remain separate opt-in consents.
- Locally derived and processed data: cluster and concept identifiers, on-device-generated titles, the concept-graph structure, the concept event log, repetition scheduling. Stored locally under the same protection described in §2.2.
- Control (opt-out): you can disable it at any time from Settings → Privacy → Cognitive memory. On disable, indexing stops and the cognitive data already created on the device is erased immediately; your notes stay intact. Re-enabling rebuilds the index.
2.10 Handwriting recognition dataset (opt-in, off by default)
Fluera is building its own handwriting recogniser trained on real handwriting from Fluera users. Every collection mode is off by default, each is a separate decision, and each is revocable at any time from Settings → Privacy → AI Training Data.
- What is collected: raw strokes (coordinates, timing, pressure, stylus tilt where supported), a small PNG image of each handwriting cluster, and basic device information (platform, pointer type). Never your name, your email, or the content of PDFs you read.
- How it is protected: encrypted on your device with AES-256-GCM before upload. Only a pseudonymous identifier travels with it — never your name or email — so we cannot link a contribution back to your account from the data itself.
- Where it goes: Supabase, EU region
eu-north-1(Stockholm), the same as §2.5. When our Vertex AI agreement is finalised, Google Gemini will analyse the images to generate training labels; until then nothing is sent to Google. - Legal basis: explicit and revocable consent (Art. 6.1.a GDPR), separate from the AI features consent of §2.4.
- Retention: up to 5 years after account deletion, or until you withdraw it — whichever comes first, always pseudonymised. This is the one category that deliberately outlives your account: because contributions are pseudonymised before upload, deleting your account does not reach them.
- How to withdraw, and the limit you should know about (Art. 11 GDPR): the pseudonym attached to your contributions is computed on your device, from a key that never leaves it. That is what makes the dataset genuinely unlinkable to your account — and it has a consequence we would rather state than hide. Settings → Privacy → AI Training Data erases the contributions made from that device, as long as the app’s data is still there. If you uninstall the app, clear its data, or move to a new device, that key is gone, and neither you nor we can any longer tell which contributions were yours. In that case we are not in a position to identify you within this dataset (Art. 11 GDPR), and what bounds the data is the 5-year retention above. If you plan to withdraw, do it before uninstalling. Contributions made from a different device must be withdrawn from that device.
2.11 Catalogue: published cards and private cards
Fluera lets you turn a portion of your notes into a study card and share it. It is always your explicit action: without it, nothing you write leaves the device by this route. There are two destinations, and the difference between them is the whole point.
- Public catalogue — the card becomes visible to anyone, indexable by search engines and reachable from a public share page.
- Private catalogue — the card stays yours and reaches only the people you send a link to. It appears in no search, has no public page, and the link’s social preview shows no content: someone who receives it in a group chat sees only “somebody shared a card with you”.
What is uploaded. The card’s bytes (the portion of notes you selected, plus the list of concepts we derive from it), a PNG thumbnail — an image of the handwritten page —, the title you write, the concept count, the size, a SHA-256 digest of the content, the version of the Terms you accept, and your account identifier. Your learner model (what you remember, when you review) is not uploaded: it stays on the device.
Why the thumbnail is mandatory. It is what the person receiving the link looks at before deciding whether to install, and the only thing a moderator can see if the card is reported. Without it, a removal would be decided blind.
Who can see it.
- You, always.
- The people who open your link. They become recipients of the data the card contains: it is a disclosure to third parties, and you decide it.
- An automated check on upload, which analyses the thumbnail and the images inside the card to catch unlawful content. It runs at Google Cloud (Vertex AI) inside the European Union — see §4 and §5.
- A human moderator, and only if the card has been reported. In that case they see the thumbnail, never the card’s bytes. There is no way to open a private card nobody has reported.
The link. It has an expiry (72 hours by default, never beyond 7 days) and a cap on people (25 by default). You can revoke it at any time, and you can remove one person’s access without touching the others. We keep only a cryptographic fingerprint of the link, never its text: that is why we cannot show it to you again, and “create a new link” is the only route.
What revocation does NOT reach, plainly. Anyone who already installed the card holds a copy on their own device, and that copy stays. A delivered copy cannot be recalled — not by you, not by us. Revoking prevents new access; it does not erase what has already been delivered.
Who sent you a card, and who received it. The author sees how many people opened the link and when, never who they are: we do not return their identifier. The recipient, in turn, does not receive the author’s identifier.
Retention. A card stays until you remove it or moderation removes it. Expired links and revoked authorisations stay recorded so it remains possible to show who had access and when. On account deletion, the bytes of cards you authored are deleted from our servers along with everything else; cards you merely received are untouched, because they belong to whoever wrote them.
Your rights over this feature. At any time you can revoke a link, remove a person’s access, leave a card you received, remove a card of your own, and report a card you received. Cards you authored are included in your data export (§7).
2.12 Study digest for your connected AI assistant (opt-in, off by default)
If you enable “Connected AI assistant”, Fluera publishes a compact study digest to our server so that an AI assistant YOU connect can read your study state through the Model Context Protocol.
- What it contains, and nothing else: only course names, exam dates and outcomes, readiness as counts, the titles of concepts currently due for review with their date, stage, durability in days according to the model and how many times they have already lapsed, the titles of concepts you have never studied, the CONCEPT on which you have a correction still to recheck together with its recheck date, and — where available — weak topics as coarse bands, how many topics have passed the check that precedes a closed-book test and how many have not, and for those that have not the title and the REASON that is missing: too few demanding questions, a single session, sessions too close together, no successful recall after a pause, too many recent errors, a memory gone cold, competence still below threshold, or an answer that felt right and was not, still to be reviewed. That reason is a technical label chosen by Fluera from eight possible ones — never a sentence of yours.
- What it never contains: your notes, handwriting, OCR text, images, and the content of your error journal — the sentence you wrote, the correction and the critique — are not included: all that leaves the journal is the concept it belongs to and the recheck date. A “counts only” switch (Settings → Cognitive features) removes concept titles as well.
- Where it is stored: on Supabase in the EU region
eu-north-1, one row per course, overwritten in place. It is included in your data export (§7). - How long: only as long as you keep the feature on. Revoking this consent deletes the stored digest; deleting a course or a canvas deletes its row; deleting your account deletes everything.
- Who can read it: only an assistant holding a personal connector token that you create in the app and can revoke at any time. Revoking this consent also stops every token from resolving.
- Legal basis: consent, Art. 6(1)(a), withdrawable at any time from Settings → Privacy.
The assistant you connect is chosen and authorised by you; its provider processes what it reads under its own terms (see §4, “Assistants you connect”). Fluera does not send your digest to any AI provider on its own initiative.
2.13 Visitors to the website and the web catalogue
This section is about anyone who visits fluera.dev or share.fluera.dev in a browser, even without a Fluera account.
- Technical logs of the hosting providers. fluera.dev is served by GitHub (GitHub Pages), share.fluera.dev by Deno (Deno Deploy). Like any web server, they record for each request the IP address, the time, the page requested and the browser’s identifier, to run and protect the service. The providers keep them under their own rules (§4); Fluera does not use them to identify or profile you.
- No cookies of our own, no analytics. The pages set no cookies of our own and load no analytics or tracking tools. fluera.dev remembers in your browser only your light or dark theme and whether you closed the language notice: this stays on your device and is not sent to us.
- Catalogue images. Card previews are served by Supabase through
Cloudflare’s network, which may set the technical cookie
__cf_bm(bot protection, 30 minutes). It is a technical cookie of the provider, needed by the service and not used to profile you. - Invite links. When someone opens an author’s invite link (share.fluera.dev/i/…), we count the click for that code, with the platform (for example “Android”) and the time: no data about who clicked.
- Report form (share.fluera.dev/report). If you report content we process what you write in the form — the content reported, the reason, the description, the good-faith statement and, if you give them, name and email (required for copyright reports, optional for the others) — to handle the report and reply to you, as Article 16 of Regulation (EU) 2022/2065 (“DSA”) requires. To stop automated submissions, the number of recent submissions per IP address is kept only in the server’s memory, for 10 minutes.
- Legal bases: legitimate interest in running and securing the service for logs, clicks and abuse protection (Art. 6(1)(f) GDPR); legal obligation for reports (Art. 6(1)(c) GDPR, DSA).
- Retention: logs stay with the providers for the period set by their rules; reports as moderation decisions (§6).
3. Purposes and legal bases
- Service provision (account, local canvases): contract performance (Art. 6.1.b GDPR)
- AI features: explicit and revocable consent (Art. 6.1.a GDPR)
- Cloud Sync: explicit and revocable consent (Art. 6.1.a GDPR)
- Product analytics: explicit and revocable consent (Art. 6.1.a GDPR)
- Crash reporting: explicit and revocable consent (Art. 6.1.a GDPR)
- Handwriting recognition dataset (§2.10): explicit and revocable consent (Art. 6.1.a GDPR), separate from AI features
- Catalogue and card sharing (§2.11): contract performance (Art. 6.1.b GDPR), on your explicit request — no card is uploaded unless you ask for it
- Moderation of shared content, handling of reports and abuse prevention (§2.11): legal obligation (Art. 6.1.c GDPR, EU Regulation 2022/2065 “DSA”) and legitimate interest (Art. 6.1.f GDPR) in preventing the service from carrying unlawful content. This also covers recording the version of the Terms you accept and your declaration about the rights in the content, which is what makes the conditions of your sharing demonstrable
- Subscription management: contract performance (Art. 6.1.b GDPR)
- Security and abuse prevention (AI quota enforcement): legitimate interest (Art. 6.1.f GDPR)
- On-device cognitive memory (local indexing for titles, Ghost Map, repetition): legitimate interest (Art. 6.1.f GDPR) in providing the study features, processed exclusively locally (no transfer), with a right to object (Art. 21 GDPR) exercisable at any time via the opt-out in Settings → Privacy
4. Recipients of data
All recipients are processors bound by contract under Art. 28 GDPR:
- Supabase Inc. — database, auth, storage, telemetry, Edge Functions (EU region
eu-north-1, Stockholm) — https://supabase.com/privacy - Google Cloud (Google Ireland Ltd.) — Vertex AI (Gemini), processed in the EU (Netherlands / Belgium) — https://cloud.google.com/terms/data-processing-addendum
- Google LLC — Sign in with Google (authentication only) — https://policies.google.com/privacy
- Apple Inc. — Sign in with Apple, App Store — https://www.apple.com/legal/privacy/
- RevenueCat Inc. — subscriptions — https://www.revenuecat.com/privacy
- Functional Software Inc. (Sentry) — crash reporting — https://sentry.io/privacy/
- Deno Land Inc. — hosting of share.fluera.dev (web catalogue, card pages, report form, assistant connector): IP address and request data of visitors (§2.13) — https://docs.deno.com/deploy/privacy_policy/
Providers acting as independent controllers. fluera.dev is hosted on GitHub Pages: GitHub Inc. records the technical data of visits (IP address, time, page requested) to secure its own service, as an independent controller and under its own privacy statement — https://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement. The same applies to the typefaces that share.fluera.dev loads from fluera.dev (§2.13).
Internal alerts. For service alerts — costs and reports concerning child safety — we use Discord. The messages contain no personal data: no account identifiers, no content, not who reported or who was reported; only the type of alert, the subscription tier, the amounts and the internal number of the alert or report.
Other users. When you publish a card to the catalogue, or share a private one by link (§2.11), the data that card contains reaches the people you chose to give it to — anyone, in the public catalogue’s case; only those who open your link, in the private one. They are not processors acting on our behalf: they are recipients you decide on, and the disclosure happens only through your action.
Assistants you connect. If you enable the study digest (§2.12), the AI assistant you connect reads it through your personal connector token. Its provider (for example Anthropic or OpenAI) is a recipient you choose and authorise, not a processor acting on our behalf; what it does with the data it reads is governed by its own terms, and the disclosure happens only through your action of connecting it.
Apart from this, we do not sell, transfer, or communicate personal data to parties other than those listed. No advertising profiling is performed.
Each processor’s Art. 28 data processing terms apply to us, either through a separately executed DPA or through the DPA incorporated by reference into their terms of service. Counter-signed copies are kept on file where the processor issues one; the current status for each processor is available on written request to lorenco@fluera.dev. The up-to-date sub-processor list for each processor is published at the privacy policy links above.
5. Transfers outside the EU
Some processors — Sign in with Google (Google LLC), Apple, Sentry, RevenueCat, Deno — are based in the United States. Transfers to them are based on the Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR) and, where applicable, the processor’s adherence to the EU-US Data Privacy Framework.
AI inference does not leave the EU. Canvas content submitted to AI features is processed by Google Vertex AI in the European Union only (europe-west4 Netherlands, with europe-west1 Belgium failover) and is not transferred to the United States.
Supabase allows region selection: we use the region eu-north-1 (Stockholm) within the EEA.
6. Retention periods
- Account and user content: for the duration of the contractual relationship and until deletion request
- Telemetry events: 180 days
- Crash-report events: 30 days in Sentry. Encrypted backup copies are deleted within 90 days of their creation
- AI usage logs (
ai_usage_events): 24 months - Subscription data: 10 years for tax purposes (Italian Civil Code Art. 2220). At RevenueCat (§4) subscriber and purchase data are not deleted when a subscription expires — they are removed when we delete the customer, and from their downstream systems within 30 days. Note that deleting the customer does not cancel the subscription with Apple or Google: only you can do that, from your store account, and until you do, restoring your purchases can recreate the record
- Catalogue cards (§2.11): until you remove them or moderation removes them. Expired or revoked links and revoked authorisations stay recorded (without the link’s text, of which we keep only a fingerprint) so it remains possible to show who had access and when. On account deletion, cards you authored are deleted together with their files; copies already installed by other people stay on their devices and are reachable neither by you nor by us
- Moderation decisions and reports: kept for as long as needed to handle a complaint or appeal, and in any case to meet DSA obligations
- Consent audit trail: until revocation + 3 years (Art. 7.1 GDPR)
- Handwriting recognition dataset (§2.10): up to 5 years after account deletion, or until you withdraw it in Settings → Privacy → AI Training Data — whichever comes first, always pseudonymised. Withdrawal only reaches contributions made from a device whose app data is still present; after an uninstall the 5-year window is what bounds them (see §2.10, Art. 11 GDPR)
- Cognitive memory index (on-device): kept locally while the feature is enabled; erased immediately on disable (opt-out) or on a data-deletion request
- Anonymous sessions: when you use Fluera without a permanent account, data is associated with a temporary device identifier. If you do not convert the session into a permanent account within 24 hours of inactivity after opening a new session on another device, the anonymous account and all associated data are automatically deleted by a scheduled job on our servers.
7. User rights
You may exercise the following rights under Art. 15-22 GDPR:
- Access (Art. 15): confirmation of processing and a copy of your data
- Rectification (Art. 16): correct inaccurate data
- Erasure (Art. 17, “right to be forgotten”)
- Restriction (Art. 18)
- Portability (Art. 20): JSON export (in-app function)
- Objection (Art. 21)
- Withdraw consent (Art. 7.3): immediate via Settings → Privacy
8. How to exercise your rights
- Toggles in Settings → Privacy
- Export my data in-app (Art. 20 GDPR)
- For a copy that includes your canvas contents (Art. 15): use Export on each canvas — the
.flueraformat preserves everything. The in-app data export covers server-side data and canvas metadata; stroke bodies are a proprietary binary format and are listed underexcludedin itsmanifest.json, with this same instruction. - Email lorenco@fluera.dev for account deletion or manual rectification
The controller responds within 30 days of receipt (Art. 12.3 GDPR), barring justified extension.
9. Complaints to the supervisory authority
If you believe processing violates the GDPR, you can lodge a complaint:
- Italian Data Protection Authority (Garante)
- Piazza Venezia 11, 00187 Roma
- https://www.garanteprivacy.it
9.1 Data breach notification
In the event of a personal-data breach, Fluera will notify the competent supervisory authority (the Italian Garante per la protezione dei dati personali, or your local authority) without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Art. 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also inform the affected users without undue delay, in clear language, as required by Art. 34 GDPR. We maintain an internal record of breaches per Art. 33(5).
10. Minors
Fluera is not intended for users under 14 years old. By using the Service you represent that you are at least 14 years old.
For ages 14-18, processing is permitted under Italian Legislative Decree 196/2003 Art. 2-quinquies, potentially subject to parental consent where required by the applicable national law. For users under 14, account creation is not permitted.
If we become aware of data collected from a user under 14, we will suspend the account and delete associated data within 30 days. Report non-compliant use to support@fluera.dev or lorenco@fluera.dev.
11. Changes to this policy
This policy may be updated to reflect service evolution or regulatory changes. For substantial changes you will be notified in-app and, if registered, via email. Users will need to re-confirm consent for affected categories.
12. Rights for specific jurisdictions (non-EU)
For users residing outside the European Union, in addition to the GDPR-equivalent rights described in sections 7-8, the following local protections apply. To exercise them, write to lorenco@fluera.dev indicating your country of residence — response within 30 days.
12.1 United States — California (CCPA/CPRA) and other states
California residents benefit from rights under the California Consumer Privacy Act (CCPA, as amended by CPRA 2023):
- Right to Know: obtain confirmation of processing and a copy of the data collected over the past 12 months.
- Right to Delete: request deletion of your personal information.
- Right to Correct: request correction of inaccurate data.
- Right to Limit Use of Sensitive Personal Information: Fluera does not collect SPI (no precise geolocation, no biometrics, no health data) — right not practically applicable.
- Right to Non-Discrimination: exercising your rights does not degrade your service.
- Right to Opt-Out of Sale/Share: see below.
Do Not Sell or Share Notice: Fluera does not sell, share, or trade your personal information for cross-context behavioral advertising or any other commercial purpose. We honor Global Privacy Control (GPC) signals where technically applicable.
Categories of information collected (Cal. Civ. Code §1798.130): identifiers (pseudonymous user_id), commercial information (subscription tier), internet activity (product telemetry if consented), inferred information (usage preferences). No sensitive data under CCPA.
Equivalent rights apply in Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA) and the new 2024-2025 laws (Texas, Oregon, Delaware, Iowa, New Hampshire, Montana). Use the same channel lorenco@fluera.dev to exercise them.
12.2 Brazil (LGPD)
Brazilian residents are protected by the Lei Geral de Proteção de Dados (Law 13.709/2018). Titular rights under Art. 18 LGPD:
- Confirmation of the existence of processing
- Access to data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of unnecessary or excessive data
- Data portability to another service provider
- Deletion of data processed with consent
- Information about public and private entities with which data has been shared
- Information about the possibility of refusing consent and its consequences
- Revocation of consent
Supervisory authority: ANPD — Autoridade Nacional de Proteção de Dados (https://www.gov.br/anpd). International data transfers occur to countries with adequate protection levels or based on standard contractual clauses.
12.3 Japan (APPI)
Japanese residents are protected by the Act on the Protection of Personal Information (APPI, as amended 2022).
Cross-border transfer consent: when you enable AI features or Crash reports, your data is transferred respectively to Google LLC (United States) and Functional Software Inc./Sentry (United States). By confirming consents in the consent screen you explicitly authorize such transfers under Art. 28 APPI. You can revoke consent at any time from Settings → Privacy.
Rights: disclosure of retained data, correction, addition, deletion, cessation of use, cessation of third-party transfer. Contact: lorenco@fluera.dev.
12.4 South Korea (PIPA)
South Korean residents are protected by the Personal Information Protection Act (PIPA).
Personal Information Processing Notice: Fluera processes your personal data for the purposes described in section 3, retaining it for the periods indicated in section 6. US sub-processors (Sign in with Google, Sentry, RevenueCat) receive data only after your explicit consent via the consent screen. AI features are processed by Vertex AI in the EU and are not transferred to the US.
Rights: access, correction, deletion, suspension of processing. To exercise them: lorenco@fluera.dev. For complaints, the competent authority is the Personal Information Protection Commission (PIPC) — https://www.pipc.go.kr.
Chief Privacy Officer (CPO): Lorenco Shametaj (founder, Fluera). Operational contact: lorenco@fluera.dev. Designated pursuant to Art. 31 PIPA, which requires the appointment of a CPO for every personal information controller, regardless of the volume of users processed. For complaints not resolved via the CPO channel, Korean users can directly contact the Personal Information Protection Commission (PIPC) at the link above.
12.5 India (DPDP Act 2023)
Indian residents are protected by the Digital Personal Data Protection Act 2023.
Data Principal rights:
- Confirmation + summary of data processed (Sec. 11)
- Correction and erasure (Sec. 12-13)
- Grievance redressal within 30 days (Sec. 14)
- Nomination of a Consent Manager (Sec. 6)
Minors: the DPDP Act requires parental consent for users under 18, a stricter threshold than GDPR (14 in Italy). Fluera applies the minimum age declared in ToS §4.3 (≥14) and, for Indian residents, requires users aged 14-18 to obtain parental consent before use. Non-compliance reports are handled via support@fluera.dev with deletion within 30 days per global policy.
Data Protection Officer / Grievance Officer contact: lorenco@fluera.dev.
12.6 Saudi Arabia (PDPL)
Saudi Arabian residents are protected by the Personal Data Protection Law (in force since September 14, 2024), regulated by the Saudi Data and AI Authority (SDAIA).
Cross-border transfer: data collected from KSA users is transferred to EEA servers (Supabase Stockholm; AI inference on Vertex AI in the EU) and to US sub-processors (Sign in with Google, Sentry, RevenueCat). Such transfer occurs only after your explicit consent via the consent screen, under Art. 29 PDPL.
Rights: to be informed about processing, access, correction, deletion, objection to processing. To exercise them: lorenco@fluera.dev. Formal complaints can be addressed to SDAIA — https://sdaia.gov.sa.
12.7 Canada (PIPEDA + Quebec Law 25)
Canadian residents are protected by the Personal Information Protection and Electronic Documents Act (PIPEDA, federal) and, for Quebec residents, also by the Act respecting the protection of personal information in the private sector as amended by Law 25 (in force since 2023, notably stricter than PIPEDA).
Rights guaranteed:
- Access to personal data and information about its processing
- Correction of inaccurate or incomplete data
- Withdrawal of consent to processing
- Portability (Quebec Law 25, Art. 27)
- Deletion / “right to be forgotten” (Quebec Law 25, Art. 28.1)
Cross-border transfer: Quebec Law 25 Art. 17 requires a privacy impact assessment before transferring personal information outside Quebec. Fluera data transits to EEA servers (Supabase Stockholm; AI inference on Vertex AI in the EU) and US sub-processors (Sign in with Google, Sentry, RevenueCat) — coverage provided by the SCCs in the processors’ DPAs and by explicit consent through the consent screen.
Designated Privacy Officer: Lorenco Shametaj (founder, Fluera). Operational contact: lorenco@fluera.dev. Designated pursuant to Art. 8 Quebec Law 25.
Supervisory authorities:
- Federal: Office of the Privacy Commissioner of Canada (OPC) — https://www.priv.gc.ca
- Quebec: Commission d’accès à l’information du Québec — https://www.cai.gouv.qc.ca
12.8 Australia (Privacy Act 1988 + Australian Privacy Principles)
Australian residents are protected by the Privacy Act 1988 (including the 2024 reforms), which defines 13 binding Australian Privacy Principles (APPs).
Rights guaranteed:
- Notification at the time of collection (APP 5) — provided via the consent screen + Privacy Policy
- Access to stored data (APP 12) and correction (APP 13)
- Opt-out from use/disclosure for purposes other than the primary one (APP 6)
- Cross-border disclosure accountability (APP 8): Fluera remains responsible for processing by US sub-processors, to which the user explicitly consents through the consent screen
Sensitive Personal Information: Fluera does not collect sensitive information as defined under APP (no health, no biometric, no political/religious data).
Notifiable Data Breach scheme (Part IIIC): in case of an “eligible data breach” that may cause “serious harm”, Fluera notifies the Office of the Australian Information Commissioner (OAIC) and affected users “as soon as practicable”, in line with the same GDPR 72-hour breach notification policy.
Supervisory authority: Office of the Australian Information Commissioner (OAIC) — https://www.oaic.gov.au. Formal complaints: https://www.oaic.gov.au/privacy/privacy-complaints.
12.9 Other jurisdictions
For residents of any other jurisdiction not specifically listed above, we respect your rights under your applicable national data protection law. The following list is illustrative and non-exhaustive:
- 🇳🇿 New Zealand — Privacy Act 2020
- 🇸🇬 Singapore — PDPA 2012
- 🇭🇰 Hong Kong — PDPO
- 🇿🇦 South Africa — POPIA 2013
- 🇵🇭 Philippines — Data Privacy Act 2012
- 🇲🇽 Mexico — LFPDPPP
- 🇦🇷 Argentina — Ley 25.326
- 🇮🇱 Israel — Privacy Protection Law 1981
- 🇻🇳 Vietnam — PDPD 2024
- 🇮🇩 Indonesia — UU PDP 2022
- 🇹🇭 Thailand — PDPA 2022
- 🇹🇷 Turkey — KVKK 2016
- 🇳🇬 Nigeria — NDPA 2023
- 🇰🇪 Kenya — DPA 2019
- 🇰🇿 Kazakhstan — Data localization law
- other jurisdictions with equivalent privacy laws
If the local law of your country of residence requires more specific protections than those described here, those local protections will prevail to the extent applicable.
How to exercise them: write to lorenco@fluera.dev indicating your country of residence — response within 30 days (compatible with the maximum response times of the laws cited above).
Self-service: the most common operations (data export under “right to portability” equivalent, cloud data deletion under “right to erasure” equivalent, consent revocation) are already available in Settings → Privacy and work identically regardless of jurisdiction.
General note for all jurisdictions: the practical operations (data export, cloud deletion, consent revocation) are already implemented in the app: go to Settings → Privacy to exercise them independently, without having to write to lorenco@fluera.dev. The email channel is available for requests not covered by self-service tiles or for clarifications.