1. Who is responsible
Fathin Dosunmu is the controller for personal data processed through fathin.ee. The site is operated from Tallinn, Estonia.
Privacy requests can be sent to hello@codesdevs.io.
2. What the site processes
- Ordinary visits. Hosting and security systems may process your IP address, browser and device details, requested page, referral information, timestamps, and request status.
- Site analytics. PostHog Cloud EU receives page views and deliberately selected interaction events, along with browser, device, referrer, campaign, and approximate location information. Autocapture is off. Typed questions, transcripts, recordings, account details, and reply text are not sent to PostHog.
- Google sign-in. Google and Clerk process the account and session information needed to authenticate you. Clerk may receive your name, email address, profile image, and Google account identifier. The fathin.ee API uses a Clerk user identifier to authorise and rate-limit requests; it does not copy your email address into a separate application database.
- Talk to Fathin. The service processes the message you type or the audio you deliberately record, its transcript, the short conversation context in your current tab, generated replies, and any public links or research query you provide.
- Generated speech. The selected voice service receives the generated reply text. It does not receive your microphone recording. The private voice-reference recording remains in the protected voice service and is not delivered to site visitors.
The application does not persist your conversation and does not persist your recording. Conversation context is kept in the current browser tab so the next answer can make sense.
3. Why it is processed
Data is processed to deliver and secure the website, authenticate access to the full Talk experience, transcribe an intentional recording, generate and speak a response, perform public-web research when requested, prevent abuse, diagnose failures, and understand which parts of the site are useful.
The legal bases are providing the service you request under these Terms, Fathin’s legitimate interests in operating, securing, and improving the site, and compliance with legal obligations where one applies. Microphone access only begins after your browser asks for permission and you start a recording.
The service does not make decisions about you that produce legal or similarly significant effects.
4. Service providers and transfers
- Cloudflare hosts the site, runs the API, protects it from abuse, and may process request and security metadata. Cloudflare privacy policy.
- Clerk and Google provide Google authentication and the necessary account and session cookies. Clerk privacy policy and Google privacy policy.
- OpenAI generates answers, transcribes managed voice input, and performs cited public-web research. Responses requests set
store: false. OpenAI states that API data is not used to train its models by default, although default abuse-monitoring logs may retain content for up to 30 days. OpenAI API data controls. - Modal hosts the selected voice and transcription inference endpoints. Modal states that inference endpoint request and response payloads are not stored. Modal security and privacy.
- PostHog Cloud EU, hosted in Frankfurt, provides limited site analytics. PostHog privacy policy.
- Google Fonts serves the display font used on the homepage, so your browser may send connection metadata such as an IP address and user agent to Google.
Some providers are based outside the European Economic Area or operate globally. Where personal data is transferred internationally, the relevant provider terms and legally recognised transfer safeguards apply.
5. How long data remains
- Current-tab conversation context ends when that tab’s session storage is cleared or the tab is closed.
- The fathin.ee application has no persistent conversation or recording database.
- OpenAI’s default API abuse-monitoring logs may be retained for up to 30 days, unless law or safety needs require longer.
- Modal says inference payloads are not stored; operational logs follow the account’s plan and provider policy.
- Cloudflare and Clerk keep operational, security, account, and session data under their applicable settings and retention policies.
- Analytics events are kept only while useful for understanding site performance and are then deleted or aggregated. You can request deletion using the contact below.
6. Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, or portability of your personal data, and you may object to processing based on legitimate interests. A request may require reasonable identity verification.
You may also complain to the Andmekaitse Inspektsioon, the Estonian Data Protection Inspectorate, or to the supervisory authority where you live.
7. Questions or requests
Email hello@codesdevs.io with “Privacy” in the subject. Requests will be answered without undue delay and normally within one month.
This notice may change when the service or its providers change. Material changes will be reflected here with a new update date.