Privacy Policy
Last updated: 2026-07-18
This policy explains what Feasibly does — and does not — do with your data. If you create an account, your projects, subscription and usage are stored server-side in our database so you can access them across sessions and devices. If you use guest mode (no account), your studies stay local to your browser and never reach our servers.
1) Accounts, server storage & backups
If you sign in and create an account, we store the following on our server, tied to your account: your projects, inputs and generated studies; your subscription/plan status and activation history; and usage/quota counters (e.g. exports and AI-assisted generations this period). This lets you resume work across devices and lets us enforce plan limits. If you never create an account (guest mode), none of this applies — your projects, inputs and generated studies stay in your browser's localStorage on your device, we do not run a per-guest server record of them, and clearing your browser storage deletes them irrecoverably.
All server-stored data is backed up nightly to ensure data integrity and recovery capability. Backups are retained for 14 days and stored securely in a separate location from our primary database. This redundancy protects your data against unexpected system failures.
You can delete your account and its server-stored data at any time by contacting privacy@feasibly.space; we will remove your projects, source documents and account record, subject to the billing-records retention described below.
2) Billing data
Manual activation codes are never stored in plaintext — only a one-way sha256 hash of the code is persisted, so the plaintext code cannot be recovered from our database even by us. We record which hashed code redeemed which account and when, for support and fraud prevention. We do not store your card or bank details: the manual (activation-code/bank-transfer) path involves no card data at all, and if/when an online payment processor (e.g. Stripe) is enabled, card details are handled entirely by that processor under its own privacy policy — we only receive a subscription/payment status, never the card number.
3) Stored sources
If you upload documents or URLs to your personal source library (signed-in accounts only), they are stored per-account in our database, isolated by a compound account+document check on every read, write and delete — another account's request for your document simply no-ops, it is never returned or overwritten. You can delete any source document at any time; deletion is a HARD delete (the row and its content are removed, not flagged), not a soft-delete you can later undo. Your source documents are never shared across accounts and are never sent to the AI provider except when you explicitly use them within your own studies — the same “figures never change, only prose may be assisted” boundary described in the AI section below applies to source-derived text as well.
4) AI & generated prose
All figures are computed by a deterministic engine. When an AI language provider is configured, it may be used ONLY to draft or refine narrative prose on top of those figures — it never changes the numbers. If a provider is configured, the relevant text and figures needed to write the prose are sent to that provider under its own terms. By default the Service runs the deterministic engine only, with no third-party AI provider.
5) Hosting & data locality
The Service is hosted on a virtual private server in Europe, and both requests and our database are served from that region. Guest-mode studies never leave your device in the first place, so this section only concerns signed-in, server-stored data.
6) Cookies & session
Signed-in accounts use a single httpOnly, essential session cookie to keep you logged in — it is strictly necessary for the account feature to function, is never used for advertising or cross-site tracking, and so does not require a cookie-consent banner. We do not use advertising cookies or third-party trackers. A small amount of local storage holds your preferences (language, theme, brand kit) and, in guest mode, your saved studies.
7) Your rights & contact
You can view, export or delete your content at any time. In guest mode, that is done entirely from your browser (local storage/settings). For a signed-in account, you can delete individual projects and source documents from within the app, or request full account deletion by contacting privacy@feasibly.space. For any privacy question, contact privacy@feasibly.space.