Privacy Policy

Effective: September 16, 2026 · Last updated: October 9, 2026

Fabricate ("we," "us," or "our") provides AI-assisted software generation tooling. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and what rights you have. It applies to our website at fabricate.build and all related services (the "Service").

If you are located in the European Economic Area, United Kingdom, or Switzerland, the GDPR-specific section below applies to you. If you are a California resident, the CCPA section applies.

1. Information we collect

1.1 Information you provide

  • Account data: name, email address, profile photo (from your authentication provider)
  • Billing data: subscription tier, transaction history (payment card details are handled by Stripe and not stored by us)
  • Prompts and generated content: text prompts you submit and applications the Service generates
  • Communications: support emails and feedback you send us
  • Availability requests: your email address, region, and request date when you ask to be notified that Fabricate has opened in your region
  • Linked integrations: GitHub account information if you connect GitHub sync, the Google account details described in Section 1.5 if you connect Google Sheets or Google Calendar to an app, and the Stripe keys and account details described in Section 1.6 if you connect Stripe to an app

1.2 Information collected automatically

  • Usage data: features used, generation history, credit consumption, session duration
  • Log data: IP address, browser type, operating system, referring URLs, error logs
  • Device data: device type, screen resolution, timezone
  • Campaign data: when you arrive through a link with campaign tags, the tagged source, medium, campaign and ad content, and whether an ad click identifier was present (never the identifier itself); see Section 5
  • Cookies and similar technologies: see Section 5

1.3 Information from third parties

When you sign in via a third-party provider (e.g., Google, GitHub via Clerk), we receive basic profile information such as your name and email. We do not receive your passwords.

1.4 Connected AI assistants

If you connect an AI assistant such as ChatGPT, Fabricate asks you to approve the requested permissions before sharing data with that assistant's provider. The app-only permission shares your owned app titles, recorded generation status, public or private visibility, last update and workspace links. It does not share prompts, source code, credentials or billing information. Other account-read connections may also read your subscription tier, as shown on the consent screen.

App-building connections are separate and require fresh consent. Depending on the permissions you choose, an assistant can read build progress, the builder's questions and replies (which may repeat details from your requests), previews, earlier versions and your credit balance; create or change apps; and read or edit eligible app source files. Building uses your existing credits within a limit stated before each request. Publishing, taking an app offline, making it public, making a published app private and restoring an earlier version each require your approval of the exact action on a signed-in Fabricate page. These connections do not buy credits, change subscriptions, take payments or read account credentials.

We store the connection's permissions and authorization records, and record operational events such as tool name, completion status and duration to run and secure the integration. These events do not include tool inputs or app titles. The retention periods in Section 6 apply. You can remove a connection at Connected agents; it then loses access to further requests, and its requests still waiting for approval are withdrawn. Work already admitted may finish. Data already sent to the assistant remains subject to its provider's privacy and retention policies. Existing metadata-only connections retain their original read-only permissions.

1.5 Google account data: Sign in with Google, Google Drive (Sheets) and Google Calendar

Fabricate asks Google for the permissions below and for no others, each only when you use the feature that needs it:

  • Sign in with Google (openid, userinfo.email, userinfo.profile): your name, email address and profile photo, used to create your Fabricate account, sign you in and run your account, as "How we use it" below describes (Section 1.3).
  • Google Sheets in your Google Drive (drive.file): Fabricate creates one spreadsheet in your Google Drive, named after your app, and adds a row to it for each new form response. This permission reaches only files Fabricate creates; Fabricate cannot see, change or delete any other file in your Drive.
  • Google Calendar (calendar.events): Fabricate adds an event to the calendar you choose for each new form response, and reads that calendar's time zone when you connect it or choose another calendar. It does not read, change or delete your other events, and cannot change your calendar settings or sharing.

Google's names for these permissions are openid, https://www.googleapis.com/auth/userinfo.email, https://www.googleapis.com/auth/userinfo.profile, https://www.googleapis.com/auth/drive.file and https://www.googleapis.com/auth/calendar.events.

Google Sheets and Google Calendar are connectors: an app owner connects a Google account to one of their apps from the app's Connectors page, so that each new form response the published app collects is added as a row or an event. Connecting one also asks for openid and userinfo.email, so Fabricate can show which Google account the connection uses.

What we store: from Sign in with Google, the name, email address and profile photo on your Fabricate account (account data, Section 6). From Google Sheets and Google Calendar: the access Google grants (an OAuth refresh token, encrypted with AES-GCM before it is stored), the connected account's email address, and the connection's settings: the spreadsheet's ID, link and column names, or the calendar's ID, its time zone, which form fields hold the date and time, and how long each event lasts. Short-lived access tokens are kept only in memory while in use and never stored. For each response sent, we keep a delivery record with the response's content and Google's reply, so the owner can see what was sent and failed sends can be retried; these records are deleted after 30 days.

How we use it: we do not use Google user data for advertising, we do not sell it, and we do not use it to train AI models.

Sign-in data (the name, email address and profile photo on your Fabricate account) is used to run your account and the Service, and to understand and improve the Service. It goes to these providers and people, for these purposes:

  • Signing in: Clerk, our sign-in provider, receives it from Google when you sign in and keeps it with your login.
  • Storage: it is stored with your account at Cloudflare, our hosting provider, and can appear in our service logs (Section 6).
  • Billing: when you sign up, we create your customer record at Stripe, our payment processor, with your email address, so you can subscribe or buy credits; it appears on your invoices. If you set up payments in an app, Section 1.6 describes what else we send Stripe.
  • Emails: Resend, our email provider, delivers the emails we send to your address, addressed to your name: account, billing, credit and build notices, and lifecycle emails you can opt out of. It also delivers our internal notices about your account, such as a new subscription.
  • Error monitoring: the error reports we send to Sentry include your account ID, email address and name, so we can find and fix the problems you run into.
  • Product analytics: PostHog keeps a copy of our Stripe records, including your email address, which we use to measure revenue. If you allow analytics cookies, PostHog also links your use of Fabricate to your account, with your name, email address and profile photo.
  • Referral commissions: Tolt, which we use to pay commission to partners who refer customers to us, has access to our Stripe records, including your email address.
  • People who see your apps: a public app's page and the public app gallery show your name and profile photo as its creator. On an app you share, the people you invite see your name and profile photo; if you join someone else's app, its owner and the other people on it see your name, profile photo and email address.
  • Your apps' emails: if you turn on confirmation or reminder emails for an app's forms, your email address is the reply-to address on them, so the people who use your app can reply to you.
  • Support, billing and security: people at Fabricate, and the AI assistant they use for this work (Claude, from Anthropic), see your name and email address when they answer your support requests, handle billing and payments, or protect the Service against fraud and abuse.

Sheets and Calendar data is used only to add the rows and events you set up, to show the connection and its recent deliveries to you, and to keep the connection working and secure. It is stored with our hosting provider, Cloudflare. People at Fabricate do not read it unless you ask us to (for example in a support request), or as needed for security or to comply with the law. What Fabricate writes to your spreadsheet or calendar is then held by Google under your Google account.

We do not transfer Google user data to anyone else except as described above, as needed for security or to comply with the law, or, with your prior consent, as part of a merger or acquisition.

How to revoke access and delete the data:

  • In Fabricate, open the app's Connectors page, choose Google Sheets or Google Calendar, and click Remove on the connection. We delete its stored token, settings and delivery records straight away and ask Google to revoke Fabricate's access. If the same Google account still backs another Fabricate connection, we keep the access that connection needs, and revoke it when the last one is removed.
  • In your Google Account, at myaccount.google.com/connections, you can remove Fabricate's access at any time. Fabricate then turns its Sheets and Calendar connections off the next time it tries to use them, and Google asks for your consent again the next time you sign in with Google. Remove the connections in Fabricate as well to delete what we store.
  • Deleting the app, or your Fabricate account, deletes all of its connections and what they store. To end the access at Google too, remove the connections first, or remove Fabricate in your Google Account as above. Deleting your Fabricate account also deletes the name, email address and profile photo kept from Sign in with Google, from your account and from Clerk, within the period in Section 6. Billing records, which include your email address, are kept as Section 6 describes, at Stripe and in PostHog's copy of them. You can also ask us to delete the data at support@fabricate.build.
  • The spreadsheet and events Fabricate created stay in your Google account until you delete them in Google Drive or Google Calendar.

Limited Use: Fabricate's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

1.6 Stripe accounts connected for payments in apps

An app owner can let their app take card payments through Stripe, from the app's Payments page. Real payments go to the owner's own Stripe account, under the owner's own agreement with Stripe; Fabricate's own Stripe account (Section 4) does not handle them. We handle the information below on the owner's behalf, to run their app. There are two ways to connect, and both end with a Stripe key saved for the app.

Pasting a key: the owner pastes a Stripe secret or restricted key, for test mode, live mode or both. Before saving it, Fabricate sends Stripe one request with the key to check that it is valid and can create Checkout Sessions. That request creates nothing and charges nothing.

One-click setup, where offered: the owner can instead have Fabricate set up a Stripe test account (a Stripe sandbox) for the app. Fabricate asks Stripe to create it, sending the email address of the owner's Fabricate account, the app's name, and the country the owner appears to be connecting from (or the United States, where Stripe cannot create one in that country). Stripe returns the test account's keys once, and Fabricate saves its secret test key for the app just as it saves a pasted one. Stripe uses the email address to fill in its claim page, and to remind the owner seven days before it deletes a test account nobody has claimed. From the Payments page, the owner can claim the test account into a new or existing Stripe account; Fabricate asks Stripe for that claim link each time and does not store it. Once claimed, the account is the owner's; to take real payments, the owner adds a live key from their Stripe account as above. Stripe deletes a test account that is not claimed within 60 days; Fabricate then removes its key from the app.

What we store: each key, encrypted with AES-GCM, as one of the app's secrets; the Payments page shows only its last four characters. For a one-click test account we also keep a record of it: its Stripe IDs and status, when it expires or was claimed, which Fabricate user set it up, a one-way fingerprint of its key (so we can tell when the owner replaces the key) and, once the owner installs Fabricate's Stripe app in their live Stripe account, that account's ID. The record holds no keys and no claim link. Stripe tells Fabricate when the test account is claimed, changes or expires, and Fabricate asks Stripe for its status then and when the owner opens the Payments page.

What is read from the owner's Stripe account: Fabricate gives the keys to the app's own server: a test key to the app's preview, so test payments work there, and the saved keys to the published app when it is next published. The payment code Fabricate builds into apps uses the key to create a Stripe Checkout Session when a customer pays (with what is being bought, its price, the app's order number and, if the customer gave one, their email address), and then to ask Stripe whether it was paid: the payment status, amount and currency, the email address the customer entered and, for a subscription, its ID and status. Each order is recorded in the app's own database, which Fabricate hosts for the owner, so the owner can see who paid; an owner can change what their app records. Fabricate's own servers do not read the owner's customers, payments or subscriptions. In the payments Fabricate builds, customers enter their card on Stripe Checkout, Stripe's own payment page, so card numbers never reach Fabricate or the app.

Fabricate's Stripe app: one-click setup works through Fabricate's app for Stripe. Stripe installs it in each test account it creates for Fabricate, and asks the owner to install it in their own Stripe account when they take a claimed test account live. Wherever it is installed, it has one permission, event_read, which lets Fabricate read the account's Stripe events. Fabricate would use it only to follow the test account it created for the app: whether it has been claimed, whether the account application has been sent, and when it will expire. Today Fabricate's servers do not use it at all: Stripe sends those updates to Fabricate's own Stripe account, and the app's server uses the account's key, as described above. Fabricate does not read the owner's customers, payments or subscriptions through the app. Uninstalling Fabricate's app in the Stripe Dashboard removes this permission. It does not remove the key saved in the app.

How to disconnect and delete the data:

  • On the app's Payments page, Remove takes a key out of the app's saved secrets at once (the key is also listed with the app's other secrets, and can be removed there). It leaves the preview at once (in apps from our older builder, when the preview next restarts), and the published app when the app is next published or taken offline.
  • To stop a key working everywhere at once, roll or delete it in the Stripe Dashboard.
  • Deleting the app deletes its saved keys, including the preview's copy, our record of its one-click test account, and the published app with its database. Deleting your Fabricate account deletes its apps in the same way, within the period in Section 6. You can also ask us to delete the data at support@fabricate.build.
  • What is in the owner's Stripe account, including a claimed test account and its payments, stays there under the owner's agreement with Stripe. A test account nobody claimed is deleted by Stripe 60 days after it was created, even if the app is deleted first.

2. How we use your information

We use the information we collect to:

  • Create and manage your account and authenticate you
  • Provide, operate, and improve the Service
  • Process payments and manage subscriptions
  • Run the integrations you connect to your apps, such as Google Sheets, Google Calendar and Stripe payments (Sections 1.5 and 1.6)
  • Track credit usage and enforce plan limits
  • Send transactional emails (account creation, billing receipts, password reset)
  • Send lifecycle emails to help you get value from the Service (you may opt out)
  • Send the one-time regional availability notice you requested (you may opt out)
  • Detect, investigate, and prevent fraud, security incidents, and abuse
  • Comply with legal obligations
  • Analyze aggregate usage trends to improve the product

We do not use your prompts or generated content to train AI models or sell your data to third parties for advertising.

3. Legal bases for processing (EEA/UK)

If you are in the EEA or UK, we process your personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service, manage your account, process payments, and deliver generated applications.
  • Legitimate interests: Fraud prevention, security, improving our services, sending lifecycle emails to active users (you may opt out), and analytics for product development.
  • Legal obligation: Processing required by applicable law (e.g., financial record-keeping, responding to lawful requests).
  • Consent: Analytics cookies, marketing pixels, and session-recording tools are only activated after you provide consent via our cookie banner. You may withdraw consent at any time.

4. Who we share data with

We share personal data only with vendors and partners necessary to operate the Service ("sub-processors") and as required by law. We do not sell your personal data.

VendorPurposeLocation
StripePayment processing and subscription management for Fabricate plans, and creating the Stripe test accounts of one-click payments setup. Real payments inside an app go to the app owner's own Stripe account instead (Section 1.6).USA
ClerkAuthentication and user identity managementUSA
CloudflareInfrastructure, CDN, serverless compute, database, and storageGlobal
AnthropicAI model inference for code generation, and the AI assistant our team uses to run the Service (Section 1.5)USA
ResendTransactional and lifecycle email deliveryUSA
PostHogProduct analytics and feature flags (consent-gated), the server page counts and sign-up source described in Section 5, and a copy of our Stripe billing records used to measure revenue (Section 1.5)USA / EU
SentryError monitoring and performance trackingUSA
OpenAI AdsConsent-gated purchase measurement: payment amount, currency, opaque event ID and advertising click reference. Automatic advanced matching is not loaded.USA
Meta (Facebook)Conversion tracking via Meta Pixel (consent-gated)USA
TikTokConversion tracking via TikTok Pixel (consent-gated)Global
CrispCustomer support chat widget (consent-gated)EU
GoogleGoogle Analytics (consent-gated) and Google Tag ManagerUSA
RedditAdvertising conversion pixel, delivered via Google Tag ManagerUSA
ToltAffiliate referral attribution: its script loads only with your consent, and it has access to our Stripe records to pay referral commissions (Section 1.5)USA
GitHub (optional)Source control sync when you enable GitHub integrationUSA
Google Sheets and Calendar (optional)Receive the form responses an app owner chooses to add to their own spreadsheet or calendar (Section 1.5)USA

We may also disclose data: (a) to comply with legal obligations or respond to lawful requests from public authorities; (b) to protect our rights, property, or safety or that of our users; or (c) in connection with a merger, acquisition, or sale of all or a portion of our assets, in which case we will notify you before your data is transferred to a new entity.

5. Cookies and tracking

We use the following categories of cookies and similar technologies:

  • Necessary: Essential for authentication, security, and core functionality. Cannot be disabled.
  • Analytics: PostHog and Google Analytics collect aggregated usage statistics to help us improve the product. Activated only with your consent.
  • Functional: The Crisp support chat widget uses cookies to maintain conversation state. Activated only with your consent.
  • Advertising: The Meta Pixel and the TikTok Pixel track conversion events (e.g., signups) for advertising measurement, and Tolt attributes referrals to the affiliate who sent you. Activated only with your consent.

Separately from these categories, our servers count page visits. Each count uses an identifier derived from your IP address that changes daily and is never linked to your account. On the page you land on, it also records campaign tags from the link (source, medium, campaign and ad content) and whether an ad click identifier was present, but never the identifier itself or any other part of the address. We use this only to measure, in aggregate, which campaigns bring visitors.

When you first arrive from another website or through a tagged link, we keep the same campaign tags, the referral code of the link if it has one (which names the partner, site or Fabricate member that sent you, not you), which advertising platform's click identifier was present (never the identifier), the name of the referring website (never the page) and the page you landed on in one first-party cookie, fab_src, for up to 90 days. It contains no identifier, it is not readable by scripts or by other websites, and it is never sent to an advertising platform. If you create an account, we copy it to your account so we know which channel brought you, and attach it to your subscription record at our payment processor. If the code is a Fabricate member's invite code, we also record that member as having referred you, so we can give you your sign-up bonus and credit them when you pay; they see how many friends joined and paid, never who. After you sign up we may also ask, optionally, where you heard about us; your answer is stored with your account.

You can manage cookie preferences through our cookie banner or your browser settings. Withdrawing consent for non-essential cookies does not affect the lawfulness of prior processing. For more details, see our Cookie Policy.

6. Data retention

We retain personal data for as long as necessary to provide the Service and comply with legal obligations:

  • Account data: Retained for the lifetime of your account plus 30 days after deletion to enable account recovery.
  • Billing records: Retained for 7 years to comply with financial and tax regulations, including a one-way hash of the email of a deleted account that had a paid plan, kept to prevent repeat introductory offers.
  • Prompt and generation data: Retained while your account is active. You may delete individual projects at any time.
  • Log data: Retained for up to 90 days for security and debugging purposes.
  • Analytics data: Retained in aggregated or anonymized form for up to 2 years.
  • Email logs: Retained for up to 1 year for deliverability and compliance verification.
  • Availability requests: Retained until we send the requested notice, you opt out, or you ask us to delete it. We may retain a minimal delivery or suppression record afterward to honor your preference, prevent repeat messages, and demonstrate compliance.
  • Google Sheets and Calendar connections: The stored Google access and settings are kept while the connection exists, and deleted when you remove the connection, the app or your account. Delivery records are deleted after 30 days (Section 1.5).
  • Stripe keys for payments in apps: Kept, encrypted, until the app owner removes them or the app is deleted. The record of a one-click Stripe test account is deleted with the app (Section 1.6).

After account deletion, we will delete or anonymize your personal data within 30 days except where longer retention is required by law.

7. International data transfers

We are based in the United States. If you access the Service from the EEA, UK, or Switzerland, your personal data will be transferred to and processed in the USA and other countries that may not have equivalent data protection laws.

We rely on the following transfer mechanisms to ensure adequate protection:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to the USA
  • UK International Data Transfer Agreements (IDTAs) for transfers from the UK
  • The EU-U.S. Data Privacy Framework for vendors certified thereunder

You may request a copy of the applicable transfer safeguards by contacting us at support@fabricate.build.

8. Security

We implement administrative, technical, and organizational safeguards appropriate to the risk, including encryption in transit (TLS), access controls, and security monitoring. No security system is perfect; we cannot guarantee absolute security. If we become aware of a security breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.

9. Children's privacy (COPPA)

The Service is not directed to children under 13 years of age, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us at support@fabricate.build and we will promptly delete it. Users between 13 and 17 years old may use the Service with parental or legal guardian consent, as described in our Terms of Service.

10. Your privacy rights

10.1 General rights (all users)

Regardless of your location, you may:

  • Access and download your account data
  • Correct inaccurate information in your account
  • Delete your account and associated data
  • Opt out of lifecycle emails using the unsubscribe link in any email
  • Manage cookie preferences via our cookie banner

10.2 EEA, UK, and Switzerland (GDPR)

If you are located in the EEA, UK, or Switzerland, you have additional rights under the GDPR and equivalent laws:

  • Access: Obtain a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Request that we limit processing of your data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Withdraw consent at any time for consent-based processing
  • Lodge a complaint: File a complaint with your local supervisory authority. For EU residents, this is the Data Protection Authority in your member state. For UK residents, this is the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise these rights, contact us at support@fabricate.build. We will respond within 30 days (extendable by an additional 60 days for complex requests). We may ask you to verify your identity before fulfilling certain requests.

10.3 California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you additional rights:

  • Know: Request disclosure of the categories and specific pieces of personal information we have collected about you
  • Delete: Request deletion of personal information we have collected
  • Correct: Request correction of inaccurate personal information
  • Opt-out of sale or sharing: We do not sell or share your personal information for cross-context behavioral advertising
  • Limit sensitive personal information use: We use sensitive information only as necessary to provide the Service
  • Non-discrimination: We will not discriminate against you for exercising these rights

To submit a CCPA request, contact us at support@fabricate.build or use the unsubscribe link in any email we send. We will respond within 45 days (extendable to 90 days with notice).

Categories of personal information collected in the past 12 months: Identifiers (name, email, IP address); commercial information (subscription and billing history); internet activity (usage logs, session data); professional information (generated applications and prompts); and inferences drawn from the above. We collected this information for the business purposes described in Section 2.

11. Do Not Track

We currently do not respond to "Do Not Track" browser signals because no industry standard for such signals has been established. You can control analytics tracking via our cookie banner.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service at least 30 days before the changes take effect. We encourage you to review this policy periodically. Continued use of the Service after the effective date of the updated policy constitutes acceptance.

13. Contact us

For privacy questions, requests, or complaints, contact us at support@fabricate.build.

EEA/UK residents may also contact our representative or lodge a complaint with your local data protection authority.