Back to home

FableNode privacy notice

How FableNode handles account, creative, AI task and payment data, private access, and service providers.

Last updated: 2026-09-29

Scope

FableNode is operated by Pivotfrag LLC. This notice describes data handled by the available account, private workspace, creative editing, character and world records, AI authoring, and billing features. Features and payment availability are shown in the service. Real-time co-editing and public publication are not part of the current ordinary Studio. Planned features do not describe data processing that is already available. Contact us at hi@fablenode.com.

Data handled by the service

  • Account details: your sign-in email and any name or avatar you provide. Supabase manages login credentials, verification, and sessions.
  • Workspace and project details: account associations, membership and role records, project names, descriptions, and status, used to save projects and control access.
  • Saved creative source: the document content, identifiers, version markers and entry scene you explicitly save. Private object storage retains committed source revisions; the database records revision numbers, sizes, integrity hashes and the saving account. Historical revisions currently remain stored and count toward workspace storage.
  • Character and world records: the character details, relationships, knowledge entries and revisions you explicitly save for reference or select for AI tasks.
  • AI authoring tasks: when you explicitly create a task, the materials shown for that task are sent through Cloudflare AI Gateway to the configured model provider. Depending on the task, these may include your idea, selected saved text or scenes, characters, relationships, knowledge and instructions. The service stores task status, pinned material and source references, instructions, usage, point settlement and private candidate results, including retained failed candidate text where available, to execute tasks and let you retrieve results. Ordinary editing, saving or playtesting does not automatically send your project to a model for analysis.
  • Billing details: when you purchase or manage a subscription, Stripe receives the workspace association and product or order information needed for the transaction. Checkout may request a billing email, name or address; payment credentials are entered through Stripe's hosted payment interface. FableNode stores customer, subscription, price, order, invoice, payment status, refund, dispute, payment event and point records. Test and live records are kept separate.
  • Support requests: content you choose to send by email or through the in-app support ticket form.
  • Request and operational information: website requests pass through Cloudflare. Infrastructure services may process IP addresses, browser request information, and operational logs to serve the website, diagnose failures, and maintain access security.

Billing records are used to process purchases and renewals, provide entitlements and invoices, handle payment or refund support, prevent duplicate processing, and maintain billing security. Information requested at checkout depends on the payment method and flow. Stripe handles data under its privacy policy.

Clearly marked test checkout does not charge real money. Where live purchase is available, checkout shows the amount before payment confirmation. AI tasks make real model calls and consume product points as described in the interface; these points are not the provider's dollar invoice.

Optional Google sign-in

When enabled, you can use the Google sign-in button or a Google One Tap prompt to create or access an account. After you choose to continue, Google provides basic identity information such as an account identifier, email address and verification status, name and profile image. Supabase verifies the Google credential and manages the resulting application session; FableNode uses the verified Supabase identity to associate your existing account or create a new one. Matching email text alone does not authorize FableNode to merge separate accounts or transfer their projects, permissions or billing data.

This sign-in integration requests only basic identity, email and profile information, not access to Gmail messages, Drive files or contacts. It does not send your creative projects to Google as part of signing in. Google sign-in and One Tap involve requests to Google, which may receive browser and network information needed to deliver the sign-in interface. Whether a prompt appears also depends on your Google and browser settings. You can dismiss it and use the available sign-in buttons instead. Google and Supabase process authentication information under their applicable policies.

Creative content is private by default

Workspaces and projects are private account areas that require sign-in and permission checks. They are not automatically included in public blog posts, the sitemap, or summaries for search engines. Private access does not mean end-to-end encryption: authorized maintenance access and infrastructure processing may still occur. The current ordinary Studio does not offer public publication of creative work.

Infrastructure providers

  • Supabase provides identity authentication and the business database.
  • Cloudflare provides domain access, website hosting, private R2 storage, background AI workflows and AI Gateway.
  • The configured model provider processes inputs for AI authoring tasks you explicitly request and generates candidates. The current assistant uses Sonnet 5.
  • Stripe provides hosted checkout, payment method management, subscriptions, the customer portal and payment events.
  • Resend supports account emails such as registration verification and password recovery.

These services process data required by the deployment. Model providers may process inputs and outputs under their applicable terms; this service does not promise zero provider retention or exclusion from training. Disabling gateway content logs does not establish the same retention rules for every downstream service.

Cookies and browser storage

Session cookies support sign-in. The interface may store language and theme preferences, and visits with source parameters may set an attribution cookie. Clearing these values can sign you out or restore default preferences.

Studio uses browser IndexedDB for local recovery copies, which may contain drafts not submitted to the cloud. Authoring forms and candidate edits may also be stored in your browser. A form prepared before sign-in is stored in the tab's session storage and can be resumed after signing in within 24 hours; expiry prevents resuming and does not itself erase the stored text. Closing the tab or clearing browser storage can remove it. The return URL contains a random reference, not the creative text. Restoring a recovery copy requires an explicit action. Browser cleanup, private-browsing restrictions, disk failure or switching devices can make these copies unavailable. Take care on shared devices; a local copy is not a cloud backup.

Data controls and contact

Account settings let you update your name, avatar, and password. Studio can preview, name and restore saved revisions, and export supported saved revisions as JSON, CSV, source, Yarn or Ink packages under the applicable compatibility checks. Full account export, account deletion and historical revision deletion do not yet have self-service controls. A uniform retention schedule has not been published.

Send privacy and data requests to hi@fablenode.com. Signed-in users can also use support tickets. Do not send passwords, full card numbers, security codes or access keys. See Contact for request details.

Keep an independent copy of your work. This page's date and description will be updated as the processing scope changes.