Privacy notice
Version 2026-09-27 · Effective 27 September 2026
Fabrikk is currently in private preview. Public signup and purchases open only when announced in the application. These terms describe the service when available; this page is not an offer of immediate access.
Who is responsible
Contact Hafstad Skogen, organisation number 937475926, Haxthausens gate 1b, 0263 Oslo, Norway. Account holders can also use Settings → Your account & help. Current contact options are listed on our help page.
Hafstad Skogen is the controller of personal data used to run Fabrikk. This notice covers our website, application and support. The public preview has no advertising pixels, behavioural analytics or signup form.
What we process and why
- Account email, name, identity reference and workspace membership: to create, secure and provide your account under our contract with you.
- Your prompts, scripts, uploads, generated media and assistant messages: to provide the editing and AI actions you request under that contract. You choose what to submit and which actions to run.
- Usage quantities, request IDs, reservations, credit entries and payment references: to meter the service, reconcile charges and handle refunds under the contract, and to meet accounting obligations.
- Support messages and requested exports or deletions: to provide support and comply with your legal rights.
- Operational and security records, such as request timing, status, account identifiers and network information needed by our infrastructure: for our legitimate interests in security, abuse prevention and reliable operation. We limit access and retention.
Stripe hosts payment entry. Fabrikk does not store full card numbers or card security codes. We do not sell your personal information or use your projects to train our own AI models. We do not make decisions with legal or similarly significant effects solely through automated profiling. You can request human review of an account or billing restriction.
Providers and international processing
AWS provides hosting, private media storage, delivery, email, logs and backups. Our primary AWS storage and Supabase database are in Ireland; CloudFront delivers the public site through a global network. Supabase provides authentication and database services. Stripe processes payments and associated fraud, regulatory and tax information. fal and the selected model suppliers process generation inputs and outputs; OpenAI processes assistant and text requests. Only the providers needed for your selected action receive that action’s content.
Some providers and their subprocessors process data outside the EEA, including in the United States. Their data-processing terms use applicable adequacy decisions or standard contractual clauses for relevant transfers. We do not promise EU-only AI processing or zero retention. Provider safety, abuse and legal retention may apply. Contact us for the applicable safeguards and help with a deletion request.
Provider details: AWS, Supabase, Stripe, fal, and OpenAI. We may also disclose limited information where required by law or necessary to establish or defend legal claims.
Retention and deletion
- Active projects and media remain available while your account is open, until you delete them or request account closure.
- Trash is scheduled for removal after 30 days. Assets still referenced by a project are retained until those references are resolved. Failed storage deletions are retried.
- After a closure request, account access is stopped. Personal content is deleted after active work, shared ownership and billing have been resolved. We explain any delay and respond to rights requests within the legal deadline.
- Routine application and website access logs are retained for 30 days. Infrastructure audit records are retained for 365 days to investigate security incidents.
- Accounting and transaction evidence is restricted and retained for five years after the relevant financial year ends, or longer where a specific legal requirement or active dispute requires it. Personal project content is not retained merely because a payment record must be kept.
- Support content is retained while the matter is open and normally for up to 12 months after resolution; accounting or dispute evidence may follow the separate legal period. Account closure removes ordinary in-app support message content.
- Recovery copies expire separately from active data. Media and database backup generations use a 35-day window; versioned storage can take up to a further 35 days to expire. Deletion is reapplied if a backup is restored. Recovery copies are not used for ordinary account access.
We retain a limited revoked-account identifier while needed to prevent old credentials from reopening a closed account. We review retained records and remove or anonymise data when the relevant purpose ends.
Your choices and rights
You may ask for access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Where consent is used, you can withdraw it. We may verify your identity and explain any lawful limit, such as keeping required accounting records or protecting another person’s data. Requests are normally free, and we respond within one month; we explain any permitted extension.
Settings offers an account JSON export and a closure request. Media files are downloaded separately from Library. Download them before closing your account. Shared-workspace exports are restricted to authorised owners.
You can complain to the Norwegian Data Protection Authority (Datatilsynet) or the supervisory authority where you live or work.
Browser storage and changes
The application uses necessary browser storage for login sessions, preferences, the optional tutorial and unsent editing drafts. Clear local drafts and sign out on shared devices. We will explain and obtain any required choice before introducing optional tracking or marketing tools. We date changes to this notice and provide additional notice for material changes.