Privacy Policy
Version 2.0 · Effective 13 September 2026 · supersedes the 2 February 2026 notice
TL;DR
Our software runs on your own machine and sends us nothing. This website counts visits with cookieless aggregate analytics. The only personal data we ever hold is what you hand us yourself — through the contact or bug-report form, or by subscribing to the newsletter. Both are covered below.
Our Commitment
At Fiavaion, we believe privacy is a fundamental right, not a premium feature. The commitment is simple: our software collects nothing about you, and this website asks for nothing you have not chosen to give. That is an architectural decision, not just a policy — and where we do hold something, this page says so plainly rather than rounding it down to zero.
What We Don't Do
On this website and in our software, we do not:
- Use cookies for tracking purposes
- Sell or share any user data
- Track your usage patterns or build a profile of you
- Fingerprint your browser or device
- Use advertising networks or third-party marketing trackers
- Collect anything from our software products — no telemetry, no crash reporting
We do count page views with cookieless, aggregate analytics, described under Website hosting and analytics below.
Our Software Products
All Fiavaion software products are designed with privacy as a core architectural principle:
MultiMon (Video Wall Software)
- Runs entirely on your local machine
- No account or login required
- No internet connection required after download
- No telemetry, analytics, or "phone home" features
- Projects are saved as plain
.mmprojJSON files, where you choose to save them - Does not access any files beyond what you explicitly open
AssisT (Chrome Extension)
- No account, no sign-in, no telemetry, no usage or reading history collected
- Text-to-speech uses the browser's own speech APIs; OCR runs on-device
- Settings are stored in
chrome.storage.localon the device you set them on. Nothing syncs across devices - Annotations, sticky notes, citations, mind maps and Authorship Shield writing history are stored on your device in IndexedDB
- Nothing leaves your device unless you switch on a cloud AI provider (Google Gemini, Anthropic, OpenAI or Perplexity, with your own API key) or a cloud translation provider (DeepL or Azure Translator, with your own key), or use the default MyMemory translation or the dictionary lookup. In those cases only the text you selected is sent, and it goes to that provider directly — never to Fiavaion
- Local AI (Ollama) and Browser AI (WebLLM) keep everything on the machine. Ollama access is a separate optional permission, asked for the first time you turn Local AI on, never at install
- FERPA: designed with FERPA principles in mind — no student data is collected
- GDPR: Fiavaion processes no personal data. Any cloud provider a user enables is that user's own sub-processor
- We make no HIPAA claim. AssisT is not a healthcare application and has not been assessed against HIPAA
Full detail, including the sub-processor list and the Chrome permissions, is in the AssisT privacy policy and the sub-processor list.
Future Products
All future Fiavaion products will follow the same principles: local-first processing, no accounts required, no telemetry, and no data collection.
Website Hosting and Analytics
This website is hosted on Cloudflare Pages, which injects Cloudflare Web Analytics into the pages it serves. We do not add a tracking snippet or a token of our own; the measurement comes with the hosting. It is cookieless and collects only aggregate data — page views, referrers, country, device type and load performance. It sets no cookies, does not fingerprint or identify you, stores no personal data, and does not follow you to other websites. We run no advertising or third-party marketing trackers.
Cloudflare, as our hosting provider, may collect standard web server logs (IP addresses, request timestamps, etc.) as part of their infrastructure. This is standard for all web hosting. We do not access, analyze, or store this data. For details, see Cloudflare's Privacy Policy.
Contact and Bug-Report Forms
If you send us a message through the contact form or the bug-report form, this is what happens to it:
- What we receive: the name, email address and message you typed, plus the product you selected on the bug-report form. Nothing is taken from you that you did not type in.
- Where it goes: straight into a private GitHub issue
tracker (
Fiavaion/feedback), which is how we read it and reply. The issue is not public. GitHub is the processor for that tracker; see GitHub's privacy statement. - Spam check: the form is protected by Cloudflare Turnstile, which checks the request before it is accepted and sees your IP address in the process. Your IP is used for that check and is not stored by us. See Cloudflare's privacy policy.
- How long we keep it: until the enquiry or bug is resolved. After that, we delete it on request — email info@fiavaion.com and say which message.
- Lawful basis: legitimate interest in answering enquiries and fixing reported bugs. We do not use the address for anything else, and we never sell or share it.
Email Newsletter
If you choose to subscribe to our launch notifications or newsletter, we store your email address in our own database hosted on Cloudflare D1.
- Controller: Fiavaion, Dublin, Ireland. Fiavaion is not a registered company; the controller is the individual developer who publishes under that name, identifiable on written request to info@fiavaion.com
- What we collect: your email address, and nothing else
- Lawful basis: your consent, given when you subscribe
- Where it is stored: a Cloudflare D1 database under our own account. No third-party email service has access to it
- Retention: until you unsubscribe, after which the address is deleted
- How to unsubscribe: email info@fiavaion.com and we will remove you. There is no unsubscribe link or self-service page yet — we would rather say so than promise one that does not exist
- What we send: launch updates and important announcements only. No spam, and we never sell or share your address
- Age: the newsletter is not offered to anyone under 16. Please do not subscribe if you are younger than that
Support Platforms
If you choose to support Fiavaion through Patreon or Buy Me a Coffee, those platforms have their own privacy policies:
We only receive the information necessary to acknowledge your support (such as your display name for our contributors page, if you opt in).
GitHub
Our source code and issue tracking is hosted on GitHub. If you interact with our repositories, GitHub's privacy policy applies. See GitHub's Privacy Statement.
Children's Privacy
AssisT is designed to be used by students of all ages, including children under 13. It is built with the principles of COPPA (the Children's Online Privacy Protection Act) in mind: no data is collected from any user, including children. Fiavaion is not certified under COPPA and makes no compliance claim — what we can state is that the software collects nothing, so there is no children's data to protect.
The newsletter is a separate matter and is not offered to under-16s. The contact and bug-report forms are meant for adults; if a child has sent us a message and a parent or guardian wants it deleted, email info@fiavaion.com and we will remove it.
GDPR & International Users
For users in the European Union and other jurisdictions with data protection laws:
- Controller: Fiavaion, Dublin, Ireland. Fiavaion is not a registered company; the controller is the individual developer who publishes under that name, identifiable on written request to info@fiavaion.com
- Data we collect: only what you send us through the forms or newsletter above. Our software products collect nothing at all, and this website's analytics are aggregate and cookieless
- Lawful basis: consent for the newsletter; legitimate interest in answering enquiries for the contact and bug-report forms
- Data transfers: our software makes none. Form submissions reach GitHub and newsletter addresses sit in Cloudflare D1; both providers operate internationally under their own transfer mechanisms
- Your rights: access, rectification, erasure, restriction, portability and objection. Email info@fiavaion.com and we will act on it. For data held on your own device by our software, you already have full control — it never leaves the machine
- Right to complain: if you are unhappy with how we have handled your data you can complain to the Irish supervisory authority, the Data Protection Commission, or to the authority in your own EU member state.
California Privacy Rights (CCPA)
California residents have specific rights under the CCPA. We do not sell or share personal information, and our software collects none:
- Right to know: our software collects nothing. What we hold is what you sent us through a form or the newsletter, and we will tell you exactly what that is on request
- Right to delete: email info@fiavaion.com and we will delete it
- Right to opt-out: we do not sell or share personal information, so there is nothing to opt out of
- Right to non-discrimination: everyone gets the same free software either way
Educational Privacy Laws
Our software is designed with educational privacy regulations in mind. Fiavaion is not certified under any of them and makes no compliance claim on an institution's behalf — here is what the software actually does:
- FERPA: designed with FERPA principles in mind — no student data is collected, so we hold no education records
- COPPA: designed with COPPA principles in mind — no data is collected from any user, including children
- US state student privacy laws: designed on the same basis — we receive no student data, so there is nothing for us to disclose, sell or re-purpose. Whether that satisfies a particular state's statute is a judgement for your own counsel, not a claim we make
Because there is no data flow from our software to us, there is nothing for a data processing agreement with Fiavaion to cover. If your procurement process needs that stated in writing, email info@fiavaion.com and ask. An agreement you hold with a cloud AI or translation provider a student chooses to enable is a separate matter, and is yours.
Changes to This Policy
If we ever change our privacy practices (which would be unlikely given our core values), we will update this page and note the changes. Our commitment to not collecting your data is fundamental to who we are.
Contact
If you have any questions about our privacy practices, please reach out:
- GitHub: github.com/fiavaion
- Email: info@fiavaion.com
Summary
We built Fiavaion because we believe powerful software should be free and private. Our software collects nothing about you, because we don't need it, don't want it, and don't believe anyone else should have it either. The only things we hold are the message you sent us and the address you asked us to write to — and you can have either deleted by asking. Your tools. Your data. Your privacy.
Change Log
- 13 September 2026 (version 2.0) — Removed the claim that we use no analytics: Cloudflare Pages injects cookieless aggregate Web Analytics into every page it serves, and the policy now says so once, in one place. Added a section for the contact and bug-report forms, which send your name, email and message to a private GitHub issue tracker and are checked by Cloudflare Turnstile. Rewrote the newsletter section with the controller, lawful basis, storage, retention and the fact that unsubscribing is by email because no unsubscribe route exists yet. Replaced "Data we collect: None" in the GDPR block, which was untrue once a form existed, and added the right to complain to the Data Protection Commission. Hedged the COPPA and state student privacy law wording to match the FERPA pattern.
- 13 September 2026 — Rewrote the AssisT section for version 1.0.0: corrected settings storage to
chrome.storage.local(nothing syncs across devices), listed the IndexedDB items, named the optional cloud AI and translation providers, replaced the HIPAA compliance claim with a statement that no HIPAA claim is made, and restated FERPA and GDPR accurately. Corrected the MultiMon configuration-storage line. Added links to the AssisT sub-processor list. - 2 February 2026 — Previous version.