Privacy
last updated · 26 August 2026
Fumbleproof is a texting practice app. This page explains what it stores, what it deliberately does not, and how to get any of it back or deleted. It is written to be read, not to be survived.
Your practice conversations are never sent to our servers or stored. The app keeps the score, not the words. If you make an account we store your email and your session results; you can export or delete all of it yourself, from inside the app, at any time.
Who is responsible
Fumbleproof is a service of EFO Commerce, a sole trader (eenmanszaak) registered in the Netherlands, which is the data controller for everything described here.
| EFO Commerce Ruysdaelhof 11 2251 JJ Voorschoten The Netherlands |
Chamber of Commerce (KvK): 89053338 VAT (BTW): NL004690417B41 Contact: [email protected] A real person reads that address. |
What the app stores
If you just practise (no account)
Nothing leaves your phone except anonymous counts. Your session history, your training week, your drill results and your settings live in your browser's local storage on that device only. Clearing the site's data erases them permanently — there is no copy anywhere else.
If you create an account
| What | Why |
|---|---|
| Your email address | It is the entire login — we use a one-time link instead of passwords, so there is no password to store or leak. |
| Session results: which practice partner, the outcome, the grade, the number of messages, and the interest curve the engine calculated | So your log and progress follow you to another device. |
| A list of one-way fingerprints of lines she has already used on you | So she does not repeat herself in your next session. These cannot be turned back into text. |
| Your purchase record, if you buy anything | To know what you paid for. The card itself never touches us — see Stripe below. |
The messages you type in a practice session, and the replies she gives, are never transmitted to us and never written to any database. They exist in your browser for the length of the session and are gone when it ends. The coach analyses them on your device. What reaches our servers is the outcome and the numbers — never the conversation.
This is a property of how the app is built, not a promise about how carefully we behave.
If you buy founding access
Payment runs entirely through Stripe. They collect your name, email, billing address and card details; we never see or hold the card. We receive and store only a record that a payment happened, its Stripe reference, and the amount — enough to give you what you paid for and to refund you.
Analytics, and what we do about your privacy in it
We measure whether the app works: how many people open it, start a session, finish one, or hit an error. Those events carry the event name and a few properties — never the content of any message.
- Without your consent, these are stored as pure counts with no identifier attached at all — we can see "twelve sessions started today" and nothing about who.
- With your consent, a random identifier generated in your browser is attached, so we can tell whether the same person came back. It is not linked to your name or email, and it disappears when you clear the site's data.
- Microsoft Clarity records anonymised session replays so we can see where the interface confuses people. Every surface that can contain your words — the chat thread, the coach's quotes, your email address — is masked before recording, so they are not captured.
- The Meta and TikTok pixels run on the marketing page only, never inside the app, and tell us whether an ad led to a signup.
Cookies and consent
If you are in the EU or EEA we ask before loading any of the tools above, and nothing is set until you say yes. Decline and the site works exactly the same — you simply become an anonymous number in a counter. Outside the EU they load by default, and you can opt out by clearing this site's data. Everything strictly needed to run the app (your login session, your settings) is not optional and is not used for tracking.
Who else touches your data
| Who | What for | Where |
|---|---|---|
| Supabase | Database and login | EU (Ireland) |
| Cloudflare | Website hosting and email forwarding | Global edge network |
| Stripe | Payments | US / EU |
| Postmark | Sends your login email (via Supabase) | US |
| Formspree | The waitlist form on the marketing page | US |
| Microsoft Clarity | Anonymised interface analytics | US |
| Meta, TikTok | Advertising measurement (marketing page only) | US |
Transfers outside the EU rest on the European Commission's standard contractual clauses, which these providers offer as part of their terms. We sell your data to nobody, ever, and we do not share it beyond what is listed here.
About the AI
The practice partners are currently powered entirely by a scoring engine and pre-written lines running on your device. No AI provider receives anything from the app today. When the live-AI mode we are building is switched on, the messages in that mode would be sent to Anthropic to write her replies — we will update this page and tell paying members before that happens, not after.
How long we keep it
- Your account and session results: until you delete them. Deleting your account removes them immediately.
- Payment records: our own record of what you bought is deleted with your account. The invoice itself is held by Stripe for seven years because Dutch tax law requires it — that copy is not ours to erase, and a deletion request cannot reach it.
- Analytics events: purged after twelve months.
- Waitlist emails: until you unsubscribe or ask us to remove you.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, delete it, restrict how we use it, or object to it. Two of those are one tap, no email required:
- Export — the You tab in the app hands you everything we hold, as a file.
- Delete — the You tab erases your account and everything attached to it. It is immediate and it is not reversible.
For anything else, email [email protected] and you will get an answer within thirty days, usually the same day. If we get it wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Why we are allowed to hold it
- Your account and session results — to provide the service you asked for (contract).
- Purchases — contract, plus the legal obligation to keep tax records.
- Analytics and advertising tools — your consent in the EU/EEA; our legitimate interest in knowing whether the product works elsewhere.
- Anonymous counts — not personal data, so no basis is needed.
Adults only
Fumbleproof is for people aged 18 and over, and the app asks before you start. It is not directed at children and we do not knowingly hold data from anyone under 18. If you believe we do, email us and it will be deleted.
Changes
If this policy changes in a way that affects what we do with your data, we will change the date at the top and tell anyone with an account by email before it takes effect.