Privacy Policy

Effective date: 24 September 2026

Who we are

Infinity Loom Ltd, registered in England and Wales, company number 15581022, with registered office at 69 Torrington Road, Ashford, England, TN23 7TG ("we", "us", "our"), operates the Fateweaver application and website (the "Service"). Infinity Loom Ltd is the data controller for personal data processed through the Service, except where this policy says a provider acts as an independent controller (see Sharing and processors). This policy explains how we collect, use, and protect your information when you use the Service.

Information we collect

  • Account information: name, email address, authentication identifiers.
  • Usage data: pages viewed, where you came from, features used, browser, operating system, device type, screen size, language and the approximate location (country, region and city) your connection comes from (IP address is processed transiently for routing, security and that location lookup, and is not stored), and technical error reports if something goes wrong.
  • Content you provide: relationship maps, entities, collections, tags, and any files or metadata you upload or create within the app.
  • Support communications: messages sent via contact forms or email.

How we use information

  • Provide, maintain, and secure the Service.
  • Improve features, performance, and user experience.
  • Communicate updates, respond to support, and provide notices.
  • Comply with legal obligations and enforce terms.

Cookies

We use only essential cookies: cookies that keep you signed in, maintain your session, and protect the sign-in process against attacks. These are required for the Service to function. We do not use advertising cookies or third-party tracking cookies.

Analytics

We measure how the Service is used with analytics software we run ourselves on our own servers (Umami). It sets no cookies. It records the pages you visit, where you came from, your browser, operating system, device type, screen size, language and the approximate location (country, region and city) your connection comes from. Your IP address is used to derive that location and to tell one visit from another, and is not stored. We honour your browser's Do Not Track setting. If you sign in, we will ask once whether we may also record which features you use, linked to your account id only, never to your name, email address or content. You can change that answer at any time under Settings, Preferences. If you say no, we keep a small marker in your browser's local storage so the analytics script stays switched off there; it holds no identifier, and we remove it if you later say yes. We rely on legitimate interests for the anonymous measurement and on your consent for the account-linked part.

Content you share with others

Some features let you share content. Content in a map or collection you share with collaborators is visible to those collaborators. Content you choose to publish publicly (for example, a public pack or a map listed on our discovery pages) is visible to anyone who can access the Service, along with your display name. You can unpublish public content at any time, though copies others have already viewed or followed may persist in their accounts.

Legal bases for processing

Where required under UK GDPR and EU GDPR, we rely on one or more of the following:

  • Performance of a contract (to provide the Service).
  • Legitimate interests (e.g., product improvement, security).
  • Consent (where requested and obtained).
  • Compliance with legal obligations.

Data retention

We retain personal data only as long as necessary for the purposes described in this policy. As a guide:

  • Account information and content: kept while your account is active, and deleted when your account is deleted (residual copies in encrypted backups are removed as backups rotate).
  • Support communications: kept for up to two years after the request is resolved.
  • Records we must keep for legal, tax, or dispute-resolution reasons: kept for the period required by law.

You may request deletion of your account data at any time (see Your rights).

Sharing and processors

We do not sell your personal data. We share it only with the service providers below, under appropriate safeguards. Most act only on our instructions; where a provider also processes your data for its own purposes, we say so:

  • OVHcloud - cloud infrastructure that hosts our application, database, and business mailbox. Email you send to our contact address is stored there, along with any notices we send you about your subscription. Your data is hosted within OVH's infrastructure.
  • Resend - sends the email the Service itself generates, such as email verification, password resets and sign-in links.
  • Google - we read our business mailbox through Gmail, so copies of email you send us may be held in Google's systems as well.
  • Stripe - payment processing and merchant of record for subscription purchases. Through its Managed Payments service (shown to you as "Sold through Onelink" on receipts and statements), Stripe takes your payment, issues your receipt, and calculates and remits any applicable sales tax or VAT in the countries it supports. For these payments Stripe acts as an independent controller of your payment data, deciding its own purposes such as fraud prevention and tax compliance, rather than acting solely on our instructions. Stripe processes your payment and billing details under its own security and privacy standards, and we never see your full card details.
  • Sentry - error and performance monitoring. If the Service hits an error, a technical report (the error and its stack trace, the page or route where it happened, browser and device details, and a small sample of request timings) is sent to Sentry so we can fix it. We do not attach your name, email address, or account identifier, and session replay is off. Sentry stores this data in its EU region (Germany).

International transfers

If we transfer data internationally, we use appropriate safeguards such as Standard Contractual Clauses or similar mechanisms, as required by law.

Security

We implement administrative, technical, and physical safeguards designed to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal data, object to or restrict certain processing, or withdraw consent where applicable. To exercise these rights, contact us at scott@fate-weaver.com.

If you are in the UK, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EU, you can complain to your local data protection authority. We would appreciate the chance to address your concerns first.

Children's privacy

The Service is not intended for children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this policy from time to time. We will post the updated version and revise the "Effective date" above. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.