Privacy Policy

Last updated: January 2025

Overview

Facta ("we", "our", "us") operates the facta.tech website and MCP server API. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service.

Information We Collect

Account Information

When you create an account, we collect your email address and name through our authentication provider (Clerk). We use this information to identify your account and communicate with you about the service.

Usage Data

We collect information about how you use our API, including:

  • API requests (tool name, timestamp, jurisdiction if provided)
  • Request counts for rate limiting and billing
  • Error logs for debugging

We do not store the content of your search queries or the legal documents you research. Query content is processed transiently and not logged.

Payment Information

Payment processing is handled by Stripe. We do not store credit card numbers or bank account details. We retain only the information necessary to manage your subscription (plan type, billing period, Stripe customer ID).

How We Use Your Information

  • To provide and maintain the Service
  • To manage your account and subscription
  • To enforce rate limits and usage quotas
  • To communicate important updates about the Service
  • To respond to support requests
  • To detect and prevent abuse or fraud

Data Sharing

We do not sell your personal information. We may share data with:

  • Service providers: Clerk (authentication), Stripe (payments), Vercel (hosting), Neon (database)
  • Legal requirements: When required by law or to protect our rights

Data Retention

We retain your account information for as long as your account is active. Usage logs are retained for 90 days for debugging and analytics purposes. You can request deletion of your account and associated data by contacting us.

Security

We implement industry-standard security measures including:

  • Encryption in transit (HTTPS/TLS)
  • Encrypted database connections
  • Hashed API keys (we store only the prefix for identification)
  • Access controls and authentication

Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate information
  • Delete your account and associated data
  • Export your data

To exercise these rights, contact us at privacy@facta.tech.

Cookies

We use essential cookies for authentication and session management. We do not use tracking or advertising cookies.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

Contact Us

If you have questions about this Privacy Policy, contact us at privacy@facta.tech.