Fabius ("Fabius", "we") at fabius.online is a personal dashboard that brings your tasks, updates, and metrics from other apps into one place. This policy explains what we collect, why, and the choices you have.
What we collect
- Account details. Your name and email address. If you sign up with a password, we store only a salted hash of it (PBKDF2-SHA256), never the password itself. If you use "Continue with Google", we receive your name, email address, profile photo, and Google account ID from Google. We never see your Google password.
- Your workspace. Dashboards, tasks, notes, goals, links, and metrics you add, plus the decisions you make in your attention queue (for example, marking an item done or delegated).
- Connected apps. When you connect an app, you either sign in to it and approve read-only access (Fabius receives an access grant), or give Fabius an access token, API key, or address. These are encrypted (AES-GCM) before they are stored and are never sent back to your browser. Fabius uses them only to read data: for example issue and pull request titles, mentions, calendar events, posts, and metric values. For Stripe, Fabius asks for a read-only restricted key and reads only amounts, currencies, dates, and failure or dispute reasons, never card details or customers' names and emails. For Discord, it reads only the server and channel you choose, through a bot you add. We keep the most recent copy of that data so your dashboard loads quickly, and a daily history of each metric for up to 90 days. For Jira connected by signing in, we tell Atlassian weekly which Atlassian account we hold data for; if that account is closed, we delete the connection and everything we stored from it.
- Security records. An activity log of connections, credential changes, sync failures, and deletions (the last 200 events), and short-lived counters of failed sign-in attempts per email and IP address (cleared after 15 minutes).
- Cookies and browser storage. One essential cookie keeps you signed in, and a short-lived cookie protects Google sign-in. Your appearance preferences (theme and accent) are stored in your own browser. We use no advertising or analytics cookies.
- Usage counts. To learn whether Fabius saves people time, we count, per day, how many times you open your dashboard, clear items from your attention queue, ask Fabius a question, and open one of your apps from a link in Fabius. These are counts only, never what the items, questions, or links were. About once a week we may also ask whether Fabius saved you time that day; answering is optional. You can switch the counts off in Settings → Usage counts.
- Visit statistics. We use Vercel Web Analytics to count page views and see which pages are used, by country, browser, and device type. It sets no cookies and doesn't identify you or follow you across other sites; visits can't be linked back to your account.
How we use it
Only to run Fabius for you: to sign you in, show and save your workspace, sync your connected apps, keep your account secure, and respond to you. If you ask to reset your password, we email you a link to choose a new one, sent through Resend. We do not sell your data, use it for advertising, or share it with other users.
Teams (Fabius Max)
If you run a team, the teammates you invite can see your connected apps that are filed under a client, and only the clients you choose for each of them. Apps you haven't filed under a client stay private to you. Teammates never see your app passwords or tokens, can't connect or change apps, and don't see your billing. The team shares its queue decisions (done, snoozed, assigned), and when someone assigns an item to a teammate, Fabius emails that teammate. You can change what a teammate sees or remove them at any time; removing them ends their access at once. If you join someone else's team, your own workspace, apps and plan stay yours.
Emails, the assistant, and client reports
- Morning brief and urgent alerts. If you choose them in the welcome setup or in Settings, we email you a summary of what's waiting in your workspace. Emails are sent through Resend, which processes your email address and the email's content to deliver it. Every email has a one-click unsubscribe link.
- The Fabius assistant. Quick questions and commands are answered by Fabius itself. For other questions, your question, your recent messages to the assistant, and a summary of your synced items (titles, app names, and numbers) are sent to Groq to write the answer, under Groq's terms. Data from YouTube, Google Calendar, and Google Analytics is never sent to any AI service. Any change the assistant suggests (like adding a task) happens only after you confirm it. AI answers are on by default; you can switch them off in Settings, and then nothing you ask leaves Fabius.
- Client reports. If you create a report link for a client, anyone with that link can see that client's metrics and published posts, videos, and releases, but never comments, tasks, or your inbox. We store only a fingerprint (hash) of each link, and you can turn any link off.
Google user data
With Google sign-in, Fabius requests only your basic profile and email address, and uses them only to create and sign in to your account. If you choose to connect a Google app, Fabius asks for read-only access to just that app and shows the results only to you: YouTube (your channel's statistics, latest uploads, and recent comments you haven't replied to yet), Google Calendar (events on your primary calendar for the next 7 days), and Google Analytics (users, sessions, page views, and top pages for one GA4 property). Fabius never changes anything in your Google account. Fabius's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Fabius uses YouTube API Services when you connect YouTube; see the YouTube Terms of Service and Google Privacy Policy. You can remove Fabius's access at any time from your Google account permissions.
Who processes your data
Fabius is hosted on Vercel and stores data in a Turso database; emails you opt into are sent through Resend. If you buy a paid plan, Dodo Payments processes the payment as merchant of record: it collects your card and billing details directly, and Fabius only receives your plan, subscription status and renewal date, never your card number. These providers process data on our behalf to run the service, and your data may be processed in countries other than your own. We share data with anyone else only if the law requires it.
How long we keep it
Your account and workspace are kept until you delete them. Metric history is kept for 90 days, usage counts for about 13 months, attention-queue decisions for 60 days, and the activity log keeps its most recent 200 events. When you disconnect an app, its credentials and synced data are deleted immediately. When you delete your account, everything above is deleted immediately from our live database; our providers' backups may retain copies for a limited time before they expire.
Your choices
- Export your workspace, or disconnect any app, from Settings in your dashboard.
- Switch off usage counts in Settings → Usage counts.
- Delete your whole account from Settings → Sign out & delete → Delete account.
- For access, correction, or any other request, use the contact details on fabius.online.
Security
We use HTTPS everywhere with strict security headers, encrypted credentials, hashed passwords and session tokens, sessions that end after a week without use, rate-limited sign-in, and read-only access to connected apps. You can sign out of every device at once from Settings. No system is perfectly secure, so please use a strong, unique password.
Children
Fabius is not directed at children under 13, and we do not knowingly collect their data.
Changes
If we change this policy, we will update the date above and, for significant changes, tell you in the app.
Contact
Questions about privacy? Please use the contact details on fabius.online.