Privacy Policy
Implementation-aligned draft pending legal review. Last updated: 1 August 2026
1. Controller
Fluctara is operated by Miroslav Šotek, Marbach SG, Switzerland (ANULUM / Fortis Studio). Privacy contact: privacy@fluctara.com. General contact: protoscience@anulum.li.
2. Data We Collect
- Account data: email address, display name, hashed password.
- Account security data: email verification, password reset, MFA, passkey, login-alert, refresh-session, and abuse-prevention metadata.
- Mail preference data: required notice state, optional consent choices, unsubscribe suppressions, outbox metadata, and delivery or inbound review metadata.
- Billing data: subscription tier, checkout, invoice, entitlement, and payment-status metadata when paid plans are enabled.
- Profile data: birth date (optional), chronotype, experience level, health flags (epilepsy, pacemaker — used solely for safety screening).
- Session data: entrainment session records, EVS scores, protocol choices, duration.
- Biometric data: heart rate, HRV, and EEG-derived values when you explicitly connect a physical device and the required purpose decision is active.
- Clinical outcomes: self-reported questionnaire scores (PHQ-9, GAD-7, ISI) — entered voluntarily.
3. How We Use It
- Personalise your entrainment protocols and closed-loop feedback.
- Compute your EVS (Entrainment Verification Score) per session.
- Display analytics and longitudinal trends.
- Safety screening (contraindication flags).
- Send required account, security, billing, product, and legal notices.
- Send optional digest, research, or marketing messages only when consent is recorded.
We do not sell or rent your personal data. We do not serve advertisements.
4. Proposed Processing Basis
This draft does not provide a jurisdiction-specific legal conclusion. The implementation separates requested account/session delivery and security from optional purposes; the final basis for each market remains subject to legal review.
- Consent — for biometric data processing and optional clinical outcomes.
- Contract performance — for account creation, session delivery, required account notices, and paid-plan administration.
- Legitimate interest — for security logging and abuse prevention.
- Legal obligation — for notices, records, and responses required by applicable law.
5. Data Retention
Retention is controlled by the live purpose and retention registries. Several server-side periods still require an owner and legal decision; this draft does not invent automatic 12-month biometric anonymisation or a universal 90-day log schedule. Optional browser-purpose choices expire after no more than 365 days, become stale when the notice version changes, and can be withdrawn earlier. Rendered email bodies are cleared after accepted SMTP delivery when real delivery is enabled; failed messages require separate lifecycle handling. A rights-job receipt identifies completed, retained, delayed-backup, and failed components without putting personal values in the receipt.
6. Your Rights
Under GDPR and Swiss FADP, you have the right to access, rectify, erase, restrict processing, data portability, and object. You may also withdraw consent at any time. Contact us at privacy@fluctara.com or use the in-app privacy controls.
7. Security
The current web application keeps access and refresh credentials in Secure httpOnly cookies, uses a separate readable CSRF value for request integrity, and verifies the server session before treating the local account shell as current. Production transport is configured for HTTPS and HSTS. This draft does not claim that biometric database fields are encrypted or pseudonymised at rest.
8. Third-Party Services
The current public and application clients do not embed third-party analytics, tracking pixels, advertising networks, remote fonts, or session-replay scripts. Infrastructure and operator-enabled services may process data for hosting, email transport, security, backups, and payment administration. Physical-device and provider processing starts only after an explicit connection action and an active purpose decision. Provider activation, region, contract, and subprocessor status are deployment facts and are not inferred by this draft.
9. Email Preferences and Unsubscribe
Required account, security, billing, product, and legal notices are sent where needed to operate the Service and cannot be disabled through optional-mail preferences. Optional digest, research, and marketing messages require consent and can be withdrawn in the app or through an unsubscribe link. Public unsubscribe links use expiring single-use tokens and do not reveal the recipient address in the response.
10. Browser Storage and Privacy Controls
- Authentication: short-lived access and refresh credentials are Secure httpOnly cookies and cannot be read by application JavaScript. CSRF and short MFA state use separate cookies; a first-party
fluctara_csrflocal fallback supports request integrity. - Account shell:
fluctara_usercaches a non-secret display copy while the authoritative session remains the httpOnly cookie and is rechecked with the server. - Preferences:
fluctara-theme,fluctara_language, andfluctara_accessibilitystore first-party display and accessibility choices. - Offline shell: the versioned
fluctara-shell-v3service-worker cache stores first-party application resources. - Compatibility client: the older mounted
/staticclient uses afluctara_tokenlocal bearer credential. It is not the current application session model and should not be used on a shared browser.
The in-app Privacy & data screen can clear preferences, account-shell data, compatibility credentials, service workers, and caches. Signing out also clears local CSRF state. These strictly necessary and first-party functional technologies do not cause a tracking-consent banner to appear.
11. Global Privacy Control
When the browser exposes Global Privacy Control, the current application records deny decisions for optional product analytics and external telemetry under the current notice version. No analytics or telemetry browser vendor is loaded in either state. GPC does not silently withdraw a device connection, optional mail, research participation, or personalisation choice that has a separate user-facing purpose and withdrawal action.
12. Changes
We will notify registered users by email of material changes to this policy. The "last updated" date above reflects the most recent revision.
13. Contact
Miroslav Šotek
ANULUM / Fortis Studio
Marbach SG, Switzerland
privacy@fluctara.com
www.anulum.li