Skip to content
Fabla

Top / Privacy Policy

Privacy Policy

Effective August 1, 2026 Version 1.0

Introduction

Fabla, LLC, a limited liability company formed under the laws of the State of Delaware (“we”, “us” or “Fabla”), handles the personal information and user data we collect in providing Fable and our website (together, the “Service”) in accordance with this Privacy Policy. This policy is written against U.S. federal and state law (including the California Consumer Privacy Act as amended by the CPRA), the EU General Data Protection Regulation, and the Google API Services User Data Policy.

Limited Use declaration for Google user data

Fable’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. Specifically, we (1) use Google user data only to provide features that are visible to the user, (2) never use it for advertising of any kind, including personalised advertising, (3) never sell or transfer it to third parties, and (4) allow human review only with the user’s express consent, where necessary for security investigation or abuse prevention, to comply with applicable law, or where the data is aggregated and anonymised internal operational data.

Article 1

Controller and contact

1.
The data controller is Fabla, LLC, a limited liability company formed under the laws of the State of Delaware, at 2810 N Church St STE 89647, Wilmington, DE 19802, United States. The Service is provided by that company.
2.
For any matter concerning personal information, write to info@fabla-us.com.
Article 2

Information we collect

We collect the following information to the extent necessary — through what you enter, through automatic transmission as you use the Service, and from Connected Services you have authorised.

(1)
Registration details: name, company, department, job title, email address, telephone number.
(2)
Authentication data: passkey public keys, authenticator device information, session identifiers, and access and refresh tokens for Connected Services (stored encrypted).
(3)
Data from Connected Services: message subjects, bodies, senders, recipients and attachments; chat messages; calendar events; contacts; file metadata.
(4)
Usage data: IP address, browser and operating system, referring URL, activity logs, error logs, access timestamps.
(5)
Billing details: billing name, address and payment method information. We do not hold card numbers ourselves.
Article 3

Purposes of use

We use the information we collect only for the purposes below. If we need to go beyond them, we will obtain your consent first.

(1)
Providing, displaying, synchronising and authenticating the Service.
(2)
Answering enquiries and corresponding about the work.
(3)
Investigating incidents and detecting and preventing abuse.
(4)
Improving quality, developing features and analysing usage.
(5)
Billing, payment administration and meeting legal obligations.
Article 4

Legal bases

1.
For users in the EU and the UK, we rely on performance of a contract (GDPR Article 6(1)(b)), our legitimate interests (Article 6(1)(f)), legal obligation (Article 6(1)(c)), or consent (Article 6(1)(a)).
2.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before it.
Article 5

Handling of Google user data

1.
We obtain information through Google APIs only within the scopes you authorise. The scopes requested and their purpose are shown on the consent screen.
2.
We use Google user data only to display and search the unified inbox, synchronise your calendar, reference files, and run AI features you have expressly invoked.
3.
We do not use Google user data for advertising, and we do not sell or transfer it to third parties.
4.
Human review occurs only with your express consent, where necessary for security investigation or abuse prevention, to comply with applicable law, or where the data is aggregated and anonymised internal operational data.
5.
You can revoke our application’s access at any time from your Google account permissions at myaccount.google.com/permissions.
Article 6

Disclosure to third parties and processors

1.
We do not disclose personal information to third parties except with your consent, where required by law, or where we engage a processor to handle it on our behalf.
2.
Processors are bound by contract to safeguards equivalent to this policy and applicable law, and we supervise their performance.
3.
Our principal subprocessors are listed below. A current list is available on request to info@fabla-us.com.
(1)
Cloudflare, Inc. — application runtime, D1 database, R2 storage, authentication gateway.
(2)
Google LLC — Gmail, Calendar and Drive integration where you have authorised it.
(3)
Providers of the messaging services you have authorised.
Article 7

International transfers

1.
We are a Delaware company, and personal data may be processed outside your country, including in the United States and at Cloudflare edge locations.
2.
For transfers from the EU and the UK we rely on Standard Contractual Clauses or another lawful transfer mechanism.
Article 8

Retention and deletion

1.
We retain personal data only for as long as needed to fulfil the purpose of use and for any period required by law.
2.
On receiving a deletion request we verify your identity within 30 days and delete the data, or render it unrecoverable, within 90 days. Residual data on backup media is deleted when the retention period for that media expires.
3.
If you revoke an integration’s authorisation, we destroy the associated tokens immediately and delete synchronised data as described above.
Article 9

Security measures

1.
We encrypt data in transit (TLS 1.2 or above), encrypt stored data and refresh tokens, apply least-privilege access, authenticate with passkeys, record audit logs, and scan dependencies and secrets automatically.
2.
The Service runs behind a Cloudflare Access boundary; unauthenticated requests never reach the application or the API.
3.
If we become aware of a personal data breach, we notify the relevant supervisory authority and affected users within the period required by applicable law, or otherwise without undue delay.
Article 10

Cookies and similar technologies

1.
Our website uses cookies to maintain sessions, remember display preferences and measure traffic. We do not use third-party advertising or tracking cookies.
2.
You can disable cookies in your browser, though features requiring authentication will then not work.
Article 11

Your rights

1.
You may exercise the following rights in respect of your personal data. Requests are accepted at info@fabla-us.com.
2.
We verify your identity and respond within the period set by law — within 45 days under the CCPA, and normally within one month under the GDPR.
(1)
Access, notification of purpose, and a copy of your data, including portability.
(2)
Correction, addition or deletion.
(3)
Suspension of use, erasure, or suspension of disclosure to third parties.
(4)
Restriction of, and objection to, processing.
(5)
Withdrawal of consent.
(6)
Complaint to a supervisory authority — the California Privacy Protection Agency in the United States, or your national data protection authority in the EU.
Article 12

California residents

1.
We do not sell or share personal information for monetary consideration.
2.
California residents may request disclosure of the categories of personal information collected and the purposes of use, deletion, correction, and freedom from discriminatory treatment for exercising these rights.
Article 13

Children

The Service is intended for business use and is not intended for individuals under 16. If we learn that we have inadvertently collected personal data of someone under 16, we delete it promptly.

Article 14

Automated decision-making

1.
We do not carry out solely automated decision-making or profiling that has legal or similarly significant effects on you.
2.
AI summaries and drafts run only on your express instruction, and whether to use the result is always your decision.
Article 15

Changes to this policy

1.
We update this policy in response to changes in law, regulatory guidance, or changes to the Service.
2.
For a material change we publish it on our website, or notify you by email, at least 30 days before it takes effect.
Article 16

Contact

1.
For questions about this policy, to exercise your rights, or to request deletion of personal data, write to info@fabla-us.com.
2.
Postal address: Fabla, LLC, 2810 N Church St STE 89647, Wilmington, DE 19802, United States.
Article 17

Definitions

1.
“Personal information” means information that identifies a particular individual or can reasonably be linked to one, and includes personal information as defined in the CCPA.
2.
“Personal data” means personal information forming part of a structured set, and includes personal data as defined in the GDPR.
3.
“Processing” means any operation on personal data, including collection, recording, organisation, storage, alteration, access, use, disclosure and erasure.
Article 18

Lawful collection

1.
We do not obtain personal information by deception or other improper means.
2.
Collection occurs only through your direct input, automatic collection as you use the Service, and Connected Services you have expressly authorised.
3.
Where we receive personal data from a third party, we confirm that it was lawfully obtained and keep the records the law requires.
Article 19

Records of disclosure

1.
Where we disclose personal data to, or receive it from, a third party, we record the purpose, scope and date and retain that record for the required period.
2.
On a transfer of business, we pass obligations equivalent to this policy to the transferee.
3.
We do not currently operate any joint use of personal data. If we begin to, we will amend this policy in advance and publish the scope of joint use and the party responsible.
Article 20

Anonymised and statistical data

1.
We use statistical data processed so that no individual can be identified to improve quality and develop features.
2.
Where we create anonymised information, we safeguard the information about the anonymisation method and do not attempt to re-identify individuals from it.
3.
Statistical data never includes the content of an individual user’s messages or attachments.
Article 21

Log retention

1.
Access and error logs are retained for up to 12 months for incident investigation and detection of unauthorised access, then deleted.
2.
Audit logs — authentication, permission changes and deletions — are retained for up to 24 months for legal and dispute-handling purposes.
3.
Billing and accounting records are retained in line with U.S. tax record-keeping requirements, normally seven years.
Article 22

Data handling in AI features

1.
AI summaries, drafting and search assistance run only when you expressly invoke them.
2.
We do not provide the content of your messages or attachments to any external generative AI provider as training data.
3.
Where content is sent to an external AI service for inference, we limit it to the minimum needed to run that feature and state the destination and purpose in the feature description.
Article 23

Complaints and requests

1.
Requests for access, correction, suspension of use or deletion are accepted at info@fabla-us.com. We will ask for the information we specify in order to verify your identity.
2.
We acknowledge a request within three business days and respond within the period set by law. There is no charge.
3.
If you are not satisfied with our response, you may complain to a supervisory authority — the Federal Trade Commission or the California Privacy Protection Agency in the United States, your national data protection authority in the EU, or the ICO in the United Kingdom.
Article 24

Applicable law and governance

1.
We comply with Section 5 of the Federal Trade Commission Act, the CCPA and CPRA, the GDPR, the UK GDPR, and the Google API Services User Data Policy.
2.
We appoint a privacy officer and maintain internal handling rules, staff training and periodic review.
3.
This policy is published in English, and the English text governs.

Fabla, LLC (Delaware Limited Liability Company)

2810 N Church St STE 89647, Wilmington, DE 19802, United States

Privacy officer / Data deletion requests: info@fabla-us.com

For the conditions on which the Service is provided, see our Terms of Service .