This Privacy Policy explains how Slow Delivery ("Fernsage", "we", "us") collects, uses, and protects your information when you use Fernsage at fernsage.com and the application (together, the "Service").
We built Fernsage to be a calm, private home for your thinking. The short version: we don't sell your data, we don't use your notes to train AI, and your book is private until you choose to publish it. The details follow.
1. Information we collect
Information you provide:
- Account. Your email address, used for passwordless, one-time-code sign-in. We don't store passwords.
- Your content. The pages, notes, titles, links, and structure you create: your book. This is yours.
- Profile & site settings. Your chosen username/handle, optional site title and intro, and (if you set one) your custom domain.
- Payment information. When you start a subscription, payment is handled by Stripe. We receive your subscription status and limited billing metadata (e.g. plan, renewal date). We never receive or store your full card number.
- Communications. Anything you send us (e.g. support or abuse reports).
Information collected automatically:
- Basic technical/log data needed to operate and secure the Service (e.g. IP address, browser/user-agent, timestamps, error logs), collected by our hosting/CDN provider, Cloudflare, as part of serving every request. Used for security, abuse-prevention, and reliability.
- Local device storage. Some preferences and draft autosaves are kept in your browser's local storage on your device.
We do not run advertising trackers.
2. How we use your information
- To provide the Service: store, display, search, link, and resurface your book, and publish the parts you choose to make public.
- To authenticate you (send one-time sign-in codes by email).
- To process subscriptions and the free trial (via Stripe).
- To secure the Service: detect and prevent spam, fraud, and abuse.
- To communicate with you about the Service (transactional messages; any non-essential email is opt-out).
We do not:
- Sell or rent your personal information.
- Use your private notes or content to train machine-learning / AI models.
- Share your content with third parties except the service providers below, or as required by law.
3. What's public vs. private
- Your book is private by default. Nothing is public until you turn on publishing for your site.
- Once you publish, the pages you've filed and not hidden become publicly readable at your Fernsage address (and your custom domain, if set). Your Unfiled items are never published.
- Anything you publish is, by nature, accessible to anyone with the link and may be cached or indexed by third parties (e.g. search engines, link unfurlers). New sites carry a
noindexsignal until your subscription starts.
4. Service providers (subprocessors)
We use a small number of trusted providers to run Fernsage. They process data only to provide their service to us:
- Supabase: Database, authentication, backend functions
- Cloudflare: Hosting, CDN, and request routing for the app and every published site (Pages, Workers, R2 for image storage and encrypted database backups)
- Stripe: Subscription payments (card data handled by Stripe)
- Postmark: Sending sign-in codes and other transactional email
5. Your rights and choices
- Export. You can export your entire book as Markdown files at any time, from within the app.
- Delete your account. In-app self-service account deletion is not yet available. Until it ships, you can request deletion by contacting us at hello@fernsage.com; we will permanently delete your account from our active systems. Note that this is irreversible.
- Access & correction. You can view and edit your content and profile at any time in the app.
- Unpublish. You can unpublish your site or hide individual pages at any time.
6. Data retention
We keep your information for as long as your account is active. After deletion, content is removed from active systems; residual copies may persist in encrypted backups for up to 30 days before being overwritten. We may retain limited records where required for legal, tax, or fraud-prevention purposes.
7. Security
We protect your data with measures including row-level access controls so each account can only reach its own data, encryption in transit (HTTPS), and restricted access to production systems. No method of transmission or storage is 100% secure, but we work to protect your information and to respond promptly to any incident.
8. Children
Fernsage is not directed to children and is not intended for anyone under 16. We don't knowingly collect personal information from children. If you believe a child has provided us information, contact us and we'll delete it.
9. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date and, where appropriate, notify you in the app or by email.
10. Contact
For questions about this policy or your data or to report abuse of a published Fernsage site: hello@fernsage.com