Privacy Policy

What fewertools collects, where it goes, how long it stays, and what you can ask us to do.

Last reviewed:

Make is not open for reference processing. Upload, link ingestion, and model processing remain disabled while specialist legal review is pending. This notice describes the proposed controls so the release gate is visible, not to imply that approval has been obtained.

Who we are

FEWERTOOLS LTD is the operator and data controller for fewertools.com and Fewertools Editions. FEWERTOOLS LTD is registered in England and Wales under company number 17022891. Its registered office is 607 The Almere Flat 607 The Almere, Avebury Boulevard, Milton Keynes, England, MK9 2GG. For privacy questions or requests, email clinton@fewertools.com.

What we collect on the active site

Site analytics and consent

Vercel Analytics and Speed Insights receive normal web request, page, referrer, browser, device, performance, and country-level information so we can understand site reliability and aggregate usage. Google Analytics is loaded by our cookie-consent script only after you select Accept, or when your browser already stores an accepted choice. It can receive page activity, referrer, browser, device, approximate location, and campaign information and can set analytics cookies. We store your accepted or declined choice in browser local storage under ft_cookies. Declining prevents our consent script from loading Google Analytics.

Email subscriptions

Beehiiv is our email processor. If you subscribe to The Drop, we send Beehiiv your email address, a server-recorded consent timestamp, the Drop purpose and consent version, and the signup placement. The public subscription endpoint forces double opt-in, so you must use the confirmation link in Beehiiv's email before the subscription becomes active. Beehiiv also records subscription delivery, open and click activity. A Drop request is only for Fewertools tool news and editorial updates. It does not request Fewertools Editions emails.

Fewertools Editions has a separate collector-email purpose for occasional collection news. The two email purposes were verified against separate Beehiiv publications on 19 August 2026. If you join the collector list, its form sends your email address, the Editions purpose, its own consent version, the signup placement, and a server-recorded consent timestamp only to the reviewed Editions publication. You must use the confirmation link before that subscription becomes active. Joining it does not add you to The Drop. You can leave either audience through the unsubscribe link in any email.

Fewertools Editions

The Editions checkout is not active. The current Editions pages display artwork previews and do not load a payment script, send payment data, or offer a purchase. If verified digital sales open, this policy will identify the active checkout provider, the data it receives, the records returned to FEWERTOOLS LTD, and the applicable retention before checkout is enabled.

Contact and submission forms

If you send a contact, suggestion, or submission form, Fewertools receives the email address, subject, message, form source, and any additional fields you choose to provide. Our server sends that submission through Resend to the Fewertools contact inbox so we can respond and manage the request. Resend is an email-delivery processor for this flow.

Existing account and profile features

Existing directory account features use Supabase authentication and profile storage. Depending on how you sign in, Supabase can process your email address, authentication provider identifiers, session information, and account timestamps. The profile record can include a user ID, handle, display name, avatar URL, bio, role, company, building type, stage, onboarding time, and created and updated timestamps. Authentication sessions are persisted in your browser so you can remain signed in. Google receives data under its own terms if you choose Google sign-in.

Saved stacks

If you are signed out, the active site can save the tool names in your stack in browser local storage under ft-my-stack. If you are signed in, the stack can be synchronized to Supabase with its owner ID, tools, name, monthly cost, slug, visibility, and timestamps. The is_public field defaults to true, so a saved stack and its associated public profile can be publicly readable unless you set the stack to private. You may remove browser storage locally and may ask us to access, correct, make private, or delete account, profile, and saved-stack data.

Fonts, affiliate links, and cookies

Pages request Google Fonts, so the browser can send Google normal network-request information such as an IP address and user agent. Some outbound links are monetised through Skimlinks. Skimlinks and a merchant can receive link, device, referral, and transaction-attribution information and may set affiliate cookies when the affiliate script or link is used. Fewertools may earn a commission without increasing the price you pay. Google Analytics loads only after you select Accept. Skimlinks loads only after you select Accept. Declining prevents Google Analytics from loading. Declining prevents Skimlinks from loading. Third-party destinations still apply their own policies when you visit them.

Active directory AI features

The active directory already uses Anthropic for three features. Chat messages and up to 12 recent messages of chat history, including earlier generated responses, are sent to Anthropic with relevant catalog and system instructions. A stack audit sends the audit stack and context with relevant catalog, regret-pattern, and system context. The how-to feature sends the how-to goal with relevant catalog and system context. Anthropic generates the chat, audit, and how-to responses that Fewertools returns to your browser.

Anthropic states that commercial API data is not used to train its generative models by default, only while Fewertools has not opted in to any Development Partner, training, or model-improvement program. Its current standard commercial API retention is up to 30 days. Flagged inputs and outputs may be retained for up to 2 years, safety classification scores associated with flagged content for up to 7 years, and data associated with feedback submissions for 5 years. Feature-specific retention, safety-review, and legal-retention exceptions can also apply. Do not submit credentials, confidential source material, or personal data that is not needed for the answer.

When Vercel KV rate limiting is configured for chat, Fewertools uses the request's raw IP address to create a chat rate-limit counter in Vercel KV. The counter has a one-hour TTL. The audit and how-to endpoints do not use that KV counter. These active directory AI flows are separate from the proposed Make flows described below.

What we do not collect

  • We do not sell your personal data.
  • We do not currently collect card details or sell products directly through the directory.
  • We do not intentionally collect precise location through the directory.
  • We do not use directory contact messages, accounts, or profiles to train our own models.
  • We do not ask for sensitive identity documents through ordinary contact forms.

Third-party links and services

The active site uses Vercel for hosting and analytics, Google Analytics after consent, Beehiiv for newsletters, Resend for contact email delivery, Supabase for existing authentication and profiles, Google Fonts for typography, and Skimlinks for affiliate attribution. Each service processes data under its own terms and privacy notice. External tool and merchant links take you to services Fewertools does not control, so review their terms and privacy practices before creating an account or making a transaction.

See the Affiliate Disclosure for more information about compensated links.

Your rights

You may ask for access to, correction of, or deletion of personal data Fewertools controls, including account, profile, saved-stack, contact, and support records, and you may object to or restrict processing where applicable. You can unsubscribe from Beehiiv emails through any newsletter, remove local stack data and consent choices from browser storage, and ask us to delete Supabase account, profile, or saved-stack data. Email clinton@fewertools.com to make a request. We may need enough information to verify the request and locate the relevant record.

Proposed Make coach pilot measurement

Make coach pilot collection is not active. The proposed coach-only scope contains exactly six categorical events: breakdown_viewed, outcome_selected, recipe_created, first_asset_checked, project_resumed, and project_completed. Supabase would store the categorical_pilot_event fields id, event_id_hash, anonymous_id_hash, session_id_hash, event_name, pack_id, pack_version, breakdown_id, placement_id, media_family, entry_point, source_channel, internal_traffic, bot_disposition, occurred_at, created_at, and retention_until. It would also store the anonymous_attribution_record fields anonymous_id_hash, breakdown_id, placement_id, source_channel, attribution_policy_version, attributed_at, expires_at, and retention_until. Event, anonymous, and session identifiers would use separately named versioned HMAC fields. A valid approved placement token could create a server-derived first touch, and the server could copy that attribution onto later categorical events until the approved window expires. The production attribution window and signed pilot start are pending. Projects, prompts, answers, reference URLs, files, and creative content stay in the browser and are never analytics fields. Event deletion is unavailable because the HMAC records cannot be linked back from a deletion request; this limitation and the exact expiry periods require legal review. HMAC rate-limit counters and payload-free rejection counters would have separate deadlines. Enablement requires the exact country, controller, purpose, lawful-basis version and meaning, deletion statement, event and attribution retention, verified cleanup schedule, approved automated abuse control, internal-traffic allowlist and current HMAC key, pack and breakdown registry versions, placement-token version, attribution-policy version, approved Supabase coach data types and region, signed pilot start, and exact public-copy hashes. Every approval remains pending. Anthropic, Render, uploads, source-platform operations, reference processing, accounts, payments, and all creative content are outside this coach scope.

Make provider data flows

No public Make reference is currently sent to these services. If launch approval is later recorded, the proposed minimum data flows are:

  • Supabase: the proposed coach pilot adds only categorical pilot events and anonymous attribution records, both still pending approval. Future reference processing separately proposes private source uploads, sampled frames, extracted audio, transcript files, OCR text, and analysis proxies, plus project identifiers and tokens, rights confirmation records, structured project data, and user-approved artifacts. Source uploads and temporary derived objects use the 24-hour deletion rule. Approved artifacts use their separate persistence rule. An authenticated technical check verified the linked live project in West EU (Ireland), AWS eu-west-1, on 18 August 2026, but legal region, residency, transfer, DPA, and subprocessor approval remains pending.
  • Render worker: authorized source media, sampled frames, extracted audio, transcript files, OCR text, analysis proxies, and temporary copies of user-approved artifact media or text needed to run analysis and artifact-stage checks. The self-hosted faster-whisper model receives extracted audio inside that worker. Render working copies are deleted within 24 hours after the applicable analysis or check completes, or within 24 hours after the last retry or abandonment. No Render persistent disk or Render-managed datastore may receive a source-derived or artifact-derived working copy. Persistent approved-artifact storage is prohibited on Render and remains only in private Supabase storage under the user-approved artifact rule until project deletion or the separately communicated inactivity policy applies.
  • Anthropic API: selected sampled frames, transcript excerpts, OCR text, permitted source metadata, user instructions, structured analysis, and a user-approved artifact image or text when required for a check. Fewertools does not propose sending complete source video files, complete audio files, private credentials, signed source URLs, or payment card data.
  • Vercel: normal web request and operational data for the Make interface. Source bodies, private links, transcripts, prompts containing private content, and artifact content must be excluded from analytics and content logs.
  • Stripe, if payments launch: Stripe receives checkout and payment details. Fewertools receives transaction identifiers, status, amount, currency, refund state, and limited customer details needed for support and records.

Model training and provider retention

Fewertools does not use uploaded references or project artifacts to train its own models. Anthropic states that commercial API data is not used to train generative models by default, only while Fewertools has not opted in to any Development Partner, training, or model-improvement program. Its published standard commercial API retention can keep inputs and outputs for up to 30 days. Flagged inputs and outputs may be retained for up to 2 years, safety classification scores associated with flagged content for up to 7 years, and data associated with feedback submissions for 5 years. Zero data retention is a separate provider arrangement and is not enabled for Fewertools. ZDR does not override Anthropic's permitted safety-review and legal-retention exceptions. We will not describe the production path as zero retention unless the exact organisation, model, and enabled features are verified.

The self-hosted faster-whisper model performs inference inside the Render worker and has no separate hosted prompt store. The zero-day value applies to the self-hosted model prompt store only. It does not describe Render filesystem, persistent disk, datastore, snapshot, dashboard log, or external log stream retention. No Render persistent disk or Render-managed datastore may receive a source-derived or artifact-derived working copy. Before launch, Fewertools must record the workspace plan and resulting dashboard log-retention period, inventory every external log stream, verify that logs exclude source-derived and artifact-derived content, and prove application cleanup meets the 24-hour working-copy rule. An ephemeral filesystem is not a time-to-live control.

What Make stores

  • The private source upload while it is needed for the approved job.
  • Temporary source-derived files such as sampled frames, extracted audio, transcript files, OCR dumps, and proxies.
  • Structured analysis text, evidence labels, timestamps, non-reversible measurements, rights answers, route state, and service records.
  • Only those frames, excerpts, files, or other derivatives that you explicitly approve as project artifacts.

Public examples must never expose a private upload or private project without separate informed permission.

24-hour source and transient deletion

Fewertools source media and transient derivatives are deleted within 24 hours after analysis completes. If analysis fails, they are deleted within 24 hours after the last retry or abandonment. Abandonment means you cancel, or the job has no user action or processing heartbeat for 24 hours.

This 24-hour rule applies to Fewertools source and transient storage only. It does not shorten a model provider's separately disclosed retention. Structured project data and artifacts you explicitly approve can remain private until you delete the project or a separately communicated inactivity policy applies. The project must show when its original evidence media has been deleted.

Reviewer access

Authorized Fewertools reviewers may access a private project only when needed for user-requested support, rights or safety escalation, abuse investigation, incident response, or deletion failure. Access must be role-limited, time-limited, and logged. Reviewers must not reuse private content for examples or model training.

Provider personnel may have controlled access where their published policy permits safety review, abuse enforcement, legal compliance, or support. Exact provider access conditions must be approved before launch.

Your deletion and data rights

You may request access, correction, or deletion by emailing clinton@fewertools.com. When Make launches, each private project must also provide a deletion control. Project deletion removes private creative media, approved artifacts, and project access from active Fewertools systems, subject to security recovery, legal holds, and records we must keep by law.

Payment and legal-record exceptions

Make does not currently accept payment. If payments launch, deleting a project will not promise deletion of payment, tax, refund, chargeback, fraud-prevention, consent, takedown, incident, or support records that Fewertools or its payment provider must keep by law or reasonably needs to establish, exercise, or defend legal claims. We will keep only the required fields for the applicable period and publish the specific retention schedule before paid use opens.

Supported jurisdictions and children

Make public acquisition is currently supported in no jurisdiction because specialist review is incomplete. Before opening it, we will publish supported countries, contracting terms, age rules, lawful bases, transfer safeguards, and contact routes. The existing directory is not directed at children under 13, and Make will not process a minor's reference until its age and guardian rules are approved. See the public supported countries and local terms.

Security

We use HTTPS, restricted service credentials, and provider security controls. No online service can promise absolute security. Before Make opens, private storage, role-based access, deletion alerts, incident escalation, and provider-spend controls must be tested.

Children's privacy

The active directory is not directed at children under 13, and we do not knowingly collect their personal data. Make will not process a minor's reference until its age, guardian, and supported-jurisdiction rules are approved.

Changes to this policy

We may update this policy when the site, providers, or legal requirements change. Material changes will be shown here with a new review date.

Contact

Questions or privacy requests can be sent to clinton@fewertools.com or through the contact page.