Privacy
Policy

Last updated: October 4, 2026

1. Data Controller & Scope

This Privacy Policy applies to the software platform, web application, and related services operated under the name Falbor ("Falbor", "we", "us", or "our"), accessible via https://falbor.xyz and its subdomains.

For users subject to data protection laws, Falbor acts as the data controller determining the purposes and means of processing personal data relating to user account creation, billing, and platform interactions.

Contact & Requests:

contact@falbor.xyz

2. Information We Collect

We process information depending on how you interact with Falbor:

A. Information You Provide Directly

When setting up or editing your profile in account settings, we collect your email address, username, display name, bio, avatar image, location, social profile links, timezone, and user profile preferences.

B. Information Received from Third-Party Services (OAuth & Integrations)

If you authenticate or integrate third-party services (such as Google, Discord, Slack, Miro, or GitHub), we receive basic authentication details made available by that service, which may include your email address, account ID, profile avatar, and authentication tokens required to connect your account.

C. Technical & System Log Information

IP address, browser type, operating system, access timestamps, and error logs necessary to deliver, debug, and secure the service.

3. Connected Accounts & Repositories (GitHub Integration)

When you connect a GitHub account or repository to Falbor:

  • OAuth Tokens: Authentication tokens are stored securely to authorize repository operations. When you disconnect GitHub, active connection tokens are removed.
  • Repository Scope: Access is limited to the repository permissions granted during authorization.
  • Code & Schema Processing: We access repository files and project structure to render previews and process AI generation requests initiated by you.

4. AI Data Processing & Model Providers

Falbor integrates with commercial AI model providers, specifically OpenAI and Anthropic.

When you submit a prompt, request code generation, or process workspace files with AI assistance:

  • The text of your prompt, selected code snippets, repository files, database schema context, and uploaded files needed to fulfill your request are transmitted over HTTPS to OpenAI or Anthropic API endpoints.
  • Data transmitted to third-party AI model providers via developer API integrations is governed by the respective API agreements of OpenAI and Anthropic.

5. How We Use Information & Training Policy

We process user information for distinct operational purposes:

  • Service Delivery: Managing authentication, account preferences, billing, workspace loading, and live previews.
  • Debugging & Security: Monitoring errors, system telemetry, and latency to fix bugs and secure infrastructure.
  • AI Request Execution: Sending user prompts to AI API endpoints to generate software code.
  • No Public Model Training by Falbor: Falbor does not train public AI foundation models on your private workspace prompts, repository code, or user project content.

6. Ownership, License & Content Access

Ownership & License: Subject to our Terms of Service, you retain ownership of the original prompts, code, and project files you create. You grant Falbor a technical, non-exclusive license to host, store, execute, transmit, and display your project content solely to operate the platform.

Personnel Access: Access to user workspaces by Falbor personnel is restricted to authorized support requests, technical debugging, or security investigations.

7. Third-Party Service Providers

We share relevant data with service providers necessary to operate the service:

ProviderCategoryPurposeData Shared
OpenAIAI ModelsCode generation & processingPrompts, selected code, project context
AnthropicAI ModelsCode generation & processingPrompts, selected code, project context
NeonCloud Database ProviderData storage hostingUser profile, workspace & project records
StripePayment ProcessorBilling & subscriptionsPayment metadata & billing details

8. Cookies & Custom Domains

Cookies: We use essential session cookies and local storage to maintain login state, user preferences, and workspace context.

Custom Domains & Deployments: When custom domains or previews are configured, we process domain names, DNS records, and SSL data necessary to route web traffic.

9. Data Retention, Deletion & Verification

Data Retention: Profile details and project workspace files are retained for as long as your account remains active or as needed to provide the service.

Account Deletion & Request Verification: To request account deletion or data access, email contact@falbor.xyz from the email address registered with your Falbor account. To protect your privacy and security, we verify your identity by confirming matching email credentials before processing account deletion or data access requests. Upon verified deletion, active database records are removed, and residual data in encrypted server backups is overwritten in accordance with standard backup rotation cycles.

10. Regional Privacy Rights (GDPR & California)

European (EEA/UK) Users: Where applicable under GDPR, users have rights regarding access, rectification, erasure, restriction, objection, data portability, and withdrawing consent. You also have the right to lodge a complaint with your local data protection supervisory authority. Legal bases include performance of contract, legitimate interests, and legal obligations.

California Residents: Where applicable under California privacy laws (CCPA/CPRA), residents may have rights to request access, deletion, correction, and limiting the use of sensitive personal information. Falbor does not sell personal information or discriminate against users exercising privacy rights.

11. International Transfers & Children's Privacy

International Data Transfers: Cloud hosting, database, and AI providers process data in facilities located in various regions (including the United States). Transfers are conducted in accordance with applicable legal transfer mechanisms provided by our vendors.

Children's Privacy (13+ Policy): Falbor is intended for users who are at least 13 years of age. We do not knowingly collect personal data from children under 13.

12. Security & Policy Updates

Security: We implement encrypted HTTPS data transmission and access security measures. In the event of a security breach affecting user personal data, we will notify impacted users as required by applicable law.

Updates: Material updates to this policy will be posted on this page with an updated date.

Privacy Contact & Identity Verification:

Email: contact@falbor.xyz