Legal
Privacy policy
This page explains which personal data we process when you use buildwithfaber.dev and Faber, why, on which legal basis, and what rights you have.
- Controller
Tobias Bayer
contact@buildwithfaber.dev- Hosting and server logs
The website and the application run on Vercel Inc. (USA); the servers are in Dublin (Ireland). Each request processes technically necessary data: IP address, date and time, the address requested, browser and operating system, and the referring page.
We do this to deliver the pages, keep them secure and analyse errors, based on our legitimate interest in a secure, working service (Art. 6(1)(f) GDPR). Server logs are deleted after 30 days at the latest.
- Cookieless analytics
We use Vercel Web Analytics to understand which pages are visited. It sets no cookies and stores nothing on your device. It records the page, the referring page, country, device type, operating system and browser. Visitors are told apart only by a hash that changes daily; no profile across days is built.
Vercel Speed Insights also measures how fast the pages load for you. It records load times, the page, country, device type, operating system, browser and connection type, again without cookies and without storing anything on your device.
The legal basis is our legitimate interest in improving our service (Art. 6(1)(f) GDPR).
- Statistics with PostHog (only with your consent)
If you tap “Accept” in the cookie notice, we use PostHog, a service of PostHog Inc. (USA), on the public pages of buildwithfaber.dev: the home page, the demo, the guides, the legal pages, sign-in and the waitlist. Until then, PostHog isn't even loaded. It shows us how the pages are used: the pages you open, clicks on buttons and links, how far you scroll, the referring page and campaign details in the link, device type, operating system, browser, screen size, language and approximate country. If you join the waitlist, we learn that it happened and how you got there, not your email address.
PostHog also records the course of your visit (session replay): how the page changes and where you click and scroll. That's how we see where visitors get stuck. Anything you type into a form field is not recorded. PostHog is not active in the signed-in game or in your projects; the recording ends when you leave the public pages.
So that several page views count as one visit, PostHog stores a random identifier and its settings in a cookie and in your browser's localStorage (the names start with “ph_”). We don't link this data to your name, your email address or your account. Your IP address is used only to transmit the data and is not stored. If “Do Not Track” is switched on in your browser, PostHog records nothing, even with your consent.
The data is kept by PostHog in Frankfurt am Main (EU); requests go through our own domain. PostHog processes it on our behalf (Art. 28 GDPR). PostHog Inc. is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). Recordings are deleted after 30 days, all other data after one year at the latest.
The legal basis is your consent (Art. 6(1)(a) GDPR; for storing and reading in your browser, § 25(1) TDDDG). It is voluntary: the website works exactly the same without it. You can withdraw it at any time with effect for the future, under “Cookie settings” at the bottom of every page. PostHog then stops recording anything, and we delete its cookies and entries in your browser.
- Waitlist
When you join the waitlist we store your email address, your language, where you came from if you used an Instagram link, when you joined and when you confirmed. You receive an email with a confirmation link (double opt-in); only then are you on the list. Once confirmed, we email you once when early access opens. There is no newsletter. These emails are sent through Resend (Resend, Inc., USA).
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time for the future, with the link to leave in our emails, on the page buildwithfaber.dev/en/waitlist/leave or by emailing us; your entry is then deleted. Unconfirmed entries are deleted after 30 days; confirmed ones when the waitlist ends or you withdraw.
- Account and sign-in
For an account we process your email address, your password (only as a secure hash) and your language. Accounts and sign-in run on Supabase (Supabase Inc., USA); the data is stored in an EU data centre (Ireland). Signing in sets session cookies that are technically required for the service (§ 25(2) no. 2 TDDDG).
If you sign in with Google, we receive your name, email address, profile picture and a Google identifier from Google Ireland Limited. We request only this basic data.
If you sign in with GitHub, we receive your name, username, email address, profile picture and a GitHub identifier from GitHub, Inc. (USA). Signing in gives us no access to your repositories; that only happens if you connect GitHub to a project separately.
Emails that confirm your address, change it or reset your password are sent through Resend (Resend, Inc., USA).
On your profile you can change your email address and password, download all your data as a file (Art. 15 and 20 GDPR) and delete your account (Art. 17 GDPR). Deleting it removes your account with all projects, uploaded files and your energy ledger. We keep the AI usage records (see “AI proposals”) without any link to you.
The legal basis is providing the service you use (Art. 6(1)(b) GDPR). We keep account data while your account exists.
- Your project content
What you create in Faber — ideas, definitions, decisions, designs and uploaded files — is stored in your project at Supabase in the EU so that Faber works for you, based on Art. 6(1)(b) GDPR. We keep it until you delete it or your account.
- AI proposals
When you ask for a proposal, we send the parts of your project it needs to Anthropic PBC (USA) to generate it. We send only what the task requires. We also record how much the request used (for example token counts) to monitor cost and abuse.
The legal basis is Art. 6(1)(b) GDPR, and for the usage records also our legitimate interest in economical operation free of abuse (Art. 6(1)(f) GDPR).
- Purchases and payment
Energy packs and the Builder subscription are sold through Link, a Stripe service, with Stripe acting as the merchant of record. You enter your payment and billing details directly with Stripe at checkout, not with us. Stripe processes them as a controller in its own right — to make the sale to you, take the payment, meet its tax and accounting duties and prevent fraud — under Stripe’s privacy policy (stripe.com/privacy).
We never see or store your card details. We keep only what we need to give you what you bought: the Stripe customer ID linked to your account, the IDs of your checkouts and your subscription, your plan and its status, and the entries in your energy ledger (what was added, spent and given back). Stripe sends us these through signed notifications.
The legal basis is performing our contract with you (Art. 6(1)(b) GDPR). Where the law requires us to keep business records, we keep them for the statutory period (Art. 6(1)(c) GDPR). Otherwise we keep this data while your account exists.
- Affiliate links
Some tool recommendations in Faber may contain an affiliate link, which we label right next to the recommendation. If you follow one, we send no personal data about you to the tool’s provider. The tool’s website may set its own cookies or other tracking, for example to credit a sign-up to Faber; the tool’s provider is responsible for that under its own privacy policy.
- GitHub connection (optional)
If you connect a repository, Faber reads the repository data needed to check your work through the GitHub App of GitHub, Inc. (USA). Faber writes to your repository only when you tap to merge: it then merges the checked state of a skill's branch into your main branch. The legal basis is Art. 6(1)(b) GDPR. You can disconnect at any time in Faber or on GitHub.
- Test runs of your app
When you start a test run, Faber loads the checked state of your repository into an isolated environment at Vercel (Vercel Sandbox), builds it there with fixed commands and runs its tests — without your keys. This produces screenshots of your app, which we store in your project at Supabase. The environment is discarded afterwards. The legal basis is Art. 6(1)(b) GDPR.
- Cookies and storage in your browser
We set cookies for signing in (see “Account and sign-in”) and, only with your consent, for statistics with PostHog (see above). There are no advertising cookies.
We remember your choice in the cookie notice in your browser's localStorage (“faber.consent”: your choice and when you made it), so that we don't ask again on every visit and can honour your choice. None of it is sent to us, and it is required for this (§ 25(2) no. 2 TDDDG).
The game keeps only what it has already shown you in your browser's storage (localStorage and sessionStorage): which level it last announced, whether you've opened your starter deck and which parts of your path you've already seen. None of it is sent to us, and it is required to show the game (§ 25(2) no. 2 TDDDG). The demo on the home page stores nothing. You can clear this storage at any time in your browser settings.
- Cancellations
If you cancel through “Cancel contracts here”, we store what you enter (name, email address, type of cancellation and, where given, its reason), when it arrived and what came of it, and email you a confirmation. This lets us prove that and when you cancelled (Art. 6(1)(c) GDPR together with § 312k BGB). We delete this after three years.
- Emails to us
Emails to addresses at buildwithfaber.dev are forwarded to our inbox by the ImprovMX service. We process your message to answer it (Art. 6(1)(b) GDPR, otherwise (f)) and delete it once it is dealt with and no retention duty applies.
- Recipients and transfers to third countries
We use the providers named above as processors under Art. 28 GDPR: Vercel (hosting, Web Analytics, Speed Insights, Sandbox), Supabase, Resend, Anthropic, ImprovMX, PostHog (statistics, only with your consent) and — if you use it — GitHub. Google and GitHub act as independent controllers for sign-in, and Stripe for purchases, as the merchant of record.
Some of these providers are based in the USA. Transfers there rely on the EU-US Data Privacy Framework where the provider is certified under it (Art. 45 GDPR), and otherwise on EU standard contractual clauses (Art. 46(2)(c) GDPR).
- Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time (Art. 7(3)). Just email us.
You can also lodge a complaint with a data protection supervisory authority, in particular in the member state where you live or work (Art. 77 GDPR).
- Required data, no automated decisions
An account and the waitlist need your email address; without it you cannot use them. A purchase needs the payment details Stripe asks for at checkout. Everything else is voluntary. We make no automated decisions within the meaning of Art. 22 GDPR; AI proposals are proposals you decide on.
Last updated: 29 September 2026