← Back to fidubond.com
LEGAL · LAST UPDATED 2026-08-15

Privacy Policy

Effective August 15, 2026 · applies to all fidubond products

On this page

  1. Summary (TL;DR)
  2. Local-first architecture
  3. What we collect
  4. What Creem collects (future paid plans)
  5. How we use your data
  6. Sharing & disclosure
  7. Cookies & local storage
  8. Your rights (GDPR, CCPA, UK DPA)
  9. Data retention
  10. Security
  11. Children's privacy
  12. International transfers
  13. Changes to this policy
  14. Contact

1. Summary (TL;DR)

The short version: Your product data (transactions, decisions, contacts, generated records) never leaves your browser. We do not have a server that receives or stores it. During the current free beta we collect no payment data at all; if paid plans are introduced later, checkout data will be processed by Creem, our payment provider, not by us.

2. Local-first architecture

Every fidubond product runs entirely in your web browser. Data you enter is stored locally using:

  • IndexedDB — structured data (transactions, profiles, decisions)
  • OPFS (Origin Private File System) — binary data (PDFs, attachments)
  • localStorage — license tokens and small preferences

Optional master-password encryption (AES-256-GCM via the Web Crypto API) encrypts your IndexedDB data at rest on your device. We do not hold the key.

End-to-end encrypted cloud sync (multi-device access) is on our roadmap. When launched, your data will be encrypted on your device with a key only you hold, then synced to our servers in encrypted form. We will not be able to read it.

3. What we collect

We do not operate any backend server that receives your product data. Specifically, we do not collect:

  • Your transactions, decisions, contacts, or generated documents
  • Your name, address, or email (unless you email us directly)
  • Analytics or tracking data (no Google Analytics, no Mixpanel, no Facebook Pixel)
  • Cookies that identify you across sessions
  • Any payment or billing information (the Service is currently free)

The only data we may receive is:

  • Emails you send to support@fidubond.com (for support purposes)
  • Aggregate, anonymized error logs if you explicitly enable error reporting (off by default)

4. What Creem collects (future paid plans)

The Service is currently free and no checkout exists. If paid plans are introduced and you purchase a license, Creem.com Market Limited (our Merchant of Record) will process your payment. In that case Creem will collect:

  • Your name and email address (for receipts and license delivery)
  • Your payment method details (card number, PayPal account, etc.)
  • Your billing country (for sales tax/VAT calculation)
  • Transaction records (amount, currency, timestamp)

Creem's processing is governed by Creem's Privacy Policy. We do not receive your card details — Creem is PCI-DSS compliant and tokenizes all payment data.

5. How we use your data

The limited data we receive is used only to:

  • Respond to your support requests
  • Issue refunds (via Creem) if you request them on a future paid plan
  • Notify you of material changes to Terms or this Policy (if we have your email from a support interaction)

We do not use your data for marketing, advertising, or selling to third parties.

6. Sharing & disclosure

We do not sell, rent, or share your personal data with third parties for their promotional purposes. The only situations where we may disclose data:

  • To Creem (for payment processing and refunds, once paid plans exist) — limited to transaction data
  • To our hosting provider (Cloudflare, for serving the static website) — only aggregate request logs
  • To law enforcement if compelled by valid legal process

7. Cookies & local storage

We do not use tracking cookies. Each fidubond product uses localStorage and IndexedDB on your device to store your product data and preferences. This data:

  • Stays on your device
  • Is not transmitted to any server
  • Can be cleared at any time by clearing your browser's site data

If paid plans are introduced, Creem's checkout may set its own cookies on checkout.creem.io — see Creem's Cookie Policy.

8. Your rights (GDPR, CCPA, UK DPA)

Depending on your jurisdiction, you may have the following rights:

GDPR (EU/EEA residents)

  • Access — request a copy of personal data we hold (we hold none of your product data; for future checkout data, contact Creem)
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data (clear your browser's site data; for future checkout data, contact Creem)
  • Portability — receive your data in a machine-readable format (use the in-app Export feature)
  • Objection — object to processing (we don't process product data, so this is moot)
  • Lodging a complaint — with your local Data Protection Authority

CCPA (California residents)

  • Know — what personal data we collect (answer: none of your product data)
  • Delete — request deletion (clear browser site data)
  • Opt-out — of sale of personal data (we don't sell any data, so this is automatically satisfied)
  • Non-discrimination — equal service regardless of exercising rights

UK DPA 2018 (UK residents)

Same rights as GDPR, enforced by the Information Commissioner's Office (ICO).

To exercise any right, email privacy@fidubond.com. We respond within 30 days.

9. Data retention

Your product data is retained in your browser until you clear it. We have no control over this.

Email correspondence with our support team is retained for 2 years for support continuity, then deleted.

If paid plans are introduced, Creem retains transaction records per their own retention policy (typically 7 years for tax compliance).

10. Security

Your product data is stored locally in your browser, which inherits your browser's security model. Optional master-password encryption uses AES-256 via the Web Crypto API.

Future license tokens will be RSA-2048 signed JWTs verified locally with an embedded public key. We do not operate any backend server that could be breached for product data.

If paid plans are introduced, payments will be processed by Creem, which is PCI-DSS Level 1 compliant.

11. Children's privacy

The Service is not directed to children under 13 (COPPA) or under 16 (GDPR). Our products are designed for adults acting in fiduciary capacities (guardians, attorneys-in-fact, trustees, LPA attorneys). We do not knowingly collect data from children.

12. International transfers

Because your product data stays in your browser, there are no international transfers of product data. If paid plans are introduced, Creem may transfer checkout data internationally per their Privacy Policy; such transfers use Standard Contractual Clauses (SCCs) approved by the European Commission.

13. Changes to this policy

We may update this Policy from time to time. We will notify users of material changes by posting a notice on the homepage at least 30 days before changes take effect. The "Last Updated" date above reflects the most recent revision.

14. Contact

For privacy questions or to exercise your rights: privacy@fidubond.com.

For Creem-specific privacy questions (once paid plans exist): privacy@creem.io.

© 2026 fidubond · Terms of Service · Refund Policy · Back to homepage