Your context. Your control.
Efixedit is a preview project by Enoch in Italy. The controller’s complete identity, address, and privacy contact must be finalized before paid processing or Google sign-in is enabled.
What happens in the preview
Fictional examples run in your browser. Text typed or extracted from a PDF is not uploaded by the preview engine. The original PDF is never uploaded by the app. Normal hosting requests still reach Vercel and may produce technical logs. There are no advertising trackers or analytics scripts installed by Efixedit.
Data and purposes when enabled
To fulfil a requested run, we process your background, brief, selected tool, relevant prior drafts if you choose to use them, and generated text. This processing is necessary to perform the requested contract (GDPR Article 6(1)(b)). Optional Google sign-in provides a user identifier and email to maintain your account; we do not request access to Gmail, Drive, or contacts.
Payment references, amounts, consent records, and refund states support purchases, accounting obligations, and dispute handling. Applicable legal obligations provide the basis for required accounting records (Article 6(1)(c)); proportionate security and fraud prevention use legitimate interests (Article 6(1)(f)). We hash network identifiers for short-lived rate limits. No automated hiring or credit decisions are made about you.
Providers and international processing
Vercel hosts the service; Supabase stores application content in Frankfurt; OpenAI processes text for generation; Stripe handles payment details directly. Google supplies identity information only if you select its sign-in option. Do not upload passwords, financial account data, health data, or confidential employer material.
OpenAI requests use store:false, which disables storage of response objects; this is not a promise of zero provider retention. Provider security and legal retention may still apply. Some providers may process data outside the EEA. Before paid launch the operator must complete processor agreements, document applicable transfer safeguards such as an adequacy decision or standard contractual clauses, and provide information on obtaining them.
Retention and deletion
Workspaces, background text, and generated drafts expire 30 days after workspace creation and are removed by scheduled cleanup. Completed workspace content can be deleted earlier. Unresolved purchases need to be resolved before deletion. Payment records are separated from creative content so deleting a draft does not silently erase payment evidence. The operator’s accounting retention schedule must be finalized and published before paid launch; Stripe retains its own records under its policies. Short-lived rate-limit records are cleaned after approximately one day.
Saved tools on this device
If you bookmark a tool, its numeric tool identifier is stored locally in this browser so your choices can be restored. This list contains no resume, draft, payment information, or authentication tokens. Remove individual bookmarks with the same control or clear this site’s browser data.
Necessary cookies
The efixedit_session cookie identifies a guest workspace for up to 30 days. Optional server-managed Supabase authentication cookies maintain Google sign-in. The efixedit_remember cookie records your device preference. With “keep me signed in” selected, authentication cookies are persistent for up to 30 days and may refresh while you use the service; otherwise they are browser-session cookies. Browser session-restore settings can preserve session cookies. Use Sign out on a shared device.
These cookies support requested account and security functions. No profiling-cookie consent is requested because no profiling cookies are installed. Adding advertising or nonessential tracking would require a separate review and appropriate controls.
Sharing and your rights
Share links are optional and can be revoked. Anyone with a valid link can read the saved output snapshot. The original background and payment references are not included. Shared pages request no indexing, but this cannot prevent a recipient from copying content.
Subject to applicable conditions, you may request access, correction, erasure, restriction, portability, and object to legitimate-interest processing. You may complain to the Italian supervisory authority, Garante per la protezione dei dati personali, or the competent authority where you live or work. We may need proportionate verification before releasing data. Download controls export drafts; contact support for other rights or full account requests.
A working privacy contact must be published before account and paid processing activation.
Sources
GDPR · Garante cookie guidance. This notice describes the implemented preview and the planned activation conditions; it does not replace the operator’s legal obligations.
Back to workspace