Privacy
Last updated 29 August 2026
This explains what CraftingFables collects, why, and what you can do about it. It is written to be read rather than to be defensible, so where something is a judgement call it says so.
Who is responsible
CraftingFables is operated by George Papasotiriou, who is the data controller for the purposes of the UK and EU General Data Protection Regulation. For anything in this notice — including a request to see, correct, export or delete your data — write to the contact address published on the site.
What is collected
- Your account
- Name, email address and a hashed password. The password itself is never stored and cannot be recovered by anyone, including us.
- Two-factor details
- If you set up an authenticator, the shared secret and your backup codes, both encrypted.
- What you make
- Documents, presentations, spreadsheets, images and posters you create, and files you upload or convert.
- Activity needed to run the service
- Which jobs you ran and when, how many exports you have used against your daily limit, and sign-in sessions.
- Payment references
- If you subscribe, an identifier linking your account to a customer record at our payment processor. Card numbers never reach this application.
- Your own AI key
- If you connect one, encrypted. It is used to call the provider you chose, on your account, and is never sent anywhere else.
There is no analytics, no advertising and no third-party tracking on this site. Nothing here follows you to any other website.
Why, and on what legal basis
- To provide the service
- Performance of our contract with you. Without an account and somewhere to keep your files there is no product.
- To keep it working and prevent abuse
- Our legitimate interests: rate limits, usage counters and error logs exist so one account cannot degrade the service for everyone.
- To take payment
- Performance of our contract, and a legal obligation to keep accounting records.
- To protect your account
- Our legitimate interests, and yours: two-factor authentication exists so a forgotten password does not become a lost account.
Cookies and local storage
Only what the service needs to function. A signed cookie keeps you logged in; a small amount of browser storage remembers your light or dark preference. Both are strictly necessary or purely functional, neither is shared, and neither is used to build a profile — which is why you are told about them rather than asked to consent to them.
Artificial intelligence
Two disclosures, both of which EU law now expects to be made plainly.
AI was used to build this software. Parts of the CraftingFables codebase were written with the assistance of AI coding tools, reviewed by a human before release.
AI features are available inside it. When you use them you are interacting with a generative AI system, not with a person. Text and images it produces are machine-generated and may be wrong; anything written by AI is marked as such in the editor so you can always tell which words are yours. These features run only when you ask for them, and where you have connected your own provider they run on your key and your account. Your content is not used to train any model by us.
Who else sees your data
Only the processors it takes to run the service:
- Hosting and database
- Where the application and your records run.
- Object storage
- Where your files are kept.
- Stripe
- Payments, if you subscribe. They receive your email and payment details directly; we never see a card number.
- An AI provider
- Only for AI features you invoke, and only the content of that request. If you connected your own key, the provider is the one you chose.
Nothing is sold, and nothing is shared for advertising. If you connect CraftingFables to your own Claude over MCP, that connection runs on your Claude subscription and we never receive its credentials.
How long things are kept
- Converted and generated files
- 24 hours on the free plan, 7 days on the paid plan, then deleted automatically.
- Documents you are working on
- Until you delete them or close your account.
- Your account
- Until you close it.
- Payment records
- Kept by our payment processor for as long as accounting law requires, which is longer than your account.
Your rights
Under the GDPR you can ask for a copy of your data, have it corrected, have it deleted, object to processing based on our legitimate interests, or ask for it in a portable form. Most of it you can act on yourself immediately:
- See and export
- Everything you have made is in the app and can be downloaded at any time.
- Delete
- Settings has a Delete account control that removes your account, your files and everything you have made — not a flag, an actual deletion.
- Correct
- Your name and email are editable in Settings.
You also have the right to complain to a supervisory authority in the country where you live.
Security
Passwords are hashed and never stored in a readable form. Two-factor secrets and any AI key you connect are encrypted at rest. Conversions run in an isolated worker with no shell and no filesystem access, and uploads are checked before anything decodes them. No system is perfect, and this one is small — if you find a problem with it, please say so rather than exploiting it.
Changes
If this notice changes in a way that affects you, the date at the top changes and the change is announced in the app. Older versions are available on request.