forgetless
Privacy Policy
Paid subscriptions are not yet offered during the current free launch. Free accounts continue to be available.
Who controls your data
Radu-Dumitru Stochitoiu, a Swiss sole proprietor trading as Stochitoiu Digital Products, is the data controller. Address: General-Wille-Strasse 19, CH-8002 Zürich, Switzerland. Contact: radu.stochitoiu@gmail.com.
What we process
We process account and authentication data, the text, links and screenshots you submit, facts and review history created from those submissions, support messages, capture-token metadata, rate-limit records, and short technical error reports. If you buy a subscription, we also process billing status, transaction identifiers and records needed to document the contract, cancellation, withdrawal or refund. We do not sell personal data and we do not use advertising trackers.
Why we process it
Account, capture and review data are necessary to provide the service and perform the contract. Billing and accounting data are processed to perform the contract and comply with legal obligations. Security limits, failure diagnostics and fraud prevention are used for our legitimate interest in operating a reliable service. Where consent is legally required, you may withdraw it without affecting earlier lawful processing.
Sensitive information
Forgetless is not designed for passwords, payment-card details, government identification, health records, intimate images, criminal-case information or other highly sensitive information. Please do not submit such information, or personal information about another person, unless you have a lawful basis and authority to do so.
Service providers and international transfers
- Supabase hosts authentication, the database and private screenshot storage in the configured European region.
- Vercel serves the web application and processes request and deployment logs.
- Google Gemini receives the submitted content needed to extract and verify facts. Google states that prompts and responses from Paid Services are not used to improve its products. Google may keep limited data for abuse monitoring, and Google Search grounding retains prompts, context and generated output for 30 days.
- Stripe processes payment, tax, billing and fraud-prevention data. Forgetless does not receive full card numbers. For Managed Payments transactions, Link acts as merchant of record, sends transaction messages and provides payment support. Stripe and Link may act as independent controllers for some purposes.
- Resend delivers authentication and operational email. Transactional messages do not include capture contents or screenshots.
The controller is established in Switzerland. Providers and their subprocessors may process data in Switzerland, the European Economic Area, the United Kingdom, the United States and other countries where they operate. Where required, transfers use an applicable adequacy decision or contractual safeguards such as standard contractual clauses.
Paid EU availability remains disabled until the required representative is appointed and published here.
Paid UK availability remains disabled until the required representative is appointed and published here.
A merchant of record does not replace the operator's privacy responsibilities.
Retention
- Captures, facts and review history remain until you delete them or delete the account.
- Original screenshots use the period selected in Settings: 30, 90 or 365 days, or until account deletion.
- Client error reports are removed after 30 days and rate-limit records after two days.
- Revoked capture tokens and Stripe webhook deduplication records are removed after 90 days.
- Delivered operational alert records are removed after 90 days; pending alerts remain until delivery.
- Support messages are removed after two years.
- Contract, payment, refund and accounting evidence may remain after account deletion for the period required by tax, accounting and legal-claims rules, generally 10 years.
- A Managed Payments customer may ask Link to delete payment data. Link can remove associated Stripe objects and cancel the related subscription; Forgetless separately applies this policy to data it controls.
- An Android share made offline stays in that device's private browser storage until it can be delivered or you clear the app's local data. It is bound to the account active when it was shared and is never delivered to a different account.
- Provider backups age out on the provider schedule. Account deletion removes live product data immediately, while encrypted backups expire through that cycle. It does not erase the contract and accounting evidence described above.
Your choices and rights
Settings lets you export your account as machine-readable newline-delimited JSON (NDJSON), choose screenshot retention, rotate capture tokens and delete the account. Depending on applicable law, you may also request access, correction, deletion, restriction, objection or portability, and withdraw consent where processing is based on consent. Send a request to radu.stochitoiu@gmail.com. We may verify identity before fulfilling it. You may report a significant data-protection concern to the Swiss Federal Data Protection and Information Commissioner. If the GDPR applies, you may also complain to a supervisory authority in the EU Member State of your habitual residence, place of work or the alleged infringement.
Security and changes
We use private storage, row-level account isolation, encrypted transport, scoped secrets, rate limits and tested deletion paths. No system is risk-free. We will post material policy changes here and provide additional notice where law requires it.
Automated processing
Forgetless uses automated models to extract, check and organise facts. It does not make solely automated decisions that produce legal or similarly significant effects about you. You can review, correct and delete resulting information.