Your data
Privacy Policy
2026-08-15 · in effectLast updated: 15 August 2026
Who we are
Fairhanded is operated by Trajecta OÜ (registry code 17540551), registered at Niinesaare tee 17/2-3, Peetri alevik, 75312 Rae vald, Harju maakond, Estonia. We are the controller of the personal data described here.
Contact: privacy@fairhanded.com
If you think we have got something wrong, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority where you live.
What this policy is for
You came here because you are on a performance improvement plan. This policy is about what we do with your information — written to be read, not to be survived.
Three things first, because they are the ones you actually want to know:
Your employer cannot see any of this. There is no employer-facing part of Fairhanded. No manager accounts, no organisational accounts, no shared view of a live file, no way for anyone but you to read your record. This is not a setting; it does not exist in the product.
Your record is held in the European Union. Your record, your documents and your recordings are stored in Helsinki. Two things leave: your payment details, which go to Stripe, and the photographs and plan documents you upload, which are sent to be read. Both are named below.
You can take everything and leave, at any time. Export is free, permanently, in every state your case can be in. Deletion is immediate and irreversible.
What we collect, and why
Before you buy anything
The triage runs on your device. Your ten answers are scored in your browser and are not sent to us. If you ask us to email you the read, we receive your email address and the read itself so we can send it.
We use privacy-respecting analytics with no cookies and no cross-site tracking, and we record which questions you reached — never the answer you gave to the question about protected characteristics.
Basis: your request, for the email. Your consent, for analytics.
When you buy
Stripe collects your email address and payment details. We receive your email address, your country and confirmation that payment succeeded. We never see or hold your card details. You then set a name and a password.
We record that you asked for immediate access and understood the effect on your withdrawal right, along with the exact wording you were shown and when.
Basis: performing our contract with you. Legal obligation, for the consent record.
Your triage answers
When you buy, your answers move from your device to your case so the guide can use them. You are told this is happening.
Your answer to the question about protected characteristics never leaves your device. Not the answer, not anything we derived from it. It is used to produce your read in your browser and then it stays there. We do not want it, we do not hold it, and there is no setting that changes that.
Basis: performing our contract with you.
Your plan and your record
Your plan document, everything you write, the photographs and recordings you attach, and the timestamps on all of it.
Photographs you attach are sent to Anthropic, in the United States, to read the text in them. This is so a photograph of a notice or an email is searchable and quotable rather than being a picture you have to retype. The photograph and the text that comes back are yours, are part of your record, and are not used to train anybody's model. We remove the location and camera information from a photograph before it is stored, so none of that is sent either.
Basis: performing our contract with you.
Uploading your plan document to fill in the form
Typing your plan into the form is the ordinary way to start a case. You can also upload the document itself — a PDF, a Word file, or photographs of the pages — and we will fill in what we can read.
That document is sent to Anthropic, in the United States, to read the dates, the role and the goals out of it. What comes back goes into the form beside what it was read from, for you to check and correct. Nothing is saved until you confirm it, and the model is never asked for anything the form does not have a field for.
By default the document is kept with your file, alongside your other attachments, where you can open it, export it, or delete it on its own at any time. That changed on 15 August 2026; before then it was discarded by default and kept only if you asked.
The reason is what the document is. It is the plan you are being measured against, and a file that holds every note you made about that plan but not the plan itself is a file with the first exhibit missing — which is the one a reader would ask for.
There is a box beside the upload, ticked, and unticking it before you upload means the document is not kept: it then exists for as long as that one request takes and is discarded — not written to disk, not written to a log, not stored anywhere.
Basis: performing our contract with you.
Other people in your record
Your plan names your manager and usually someone from HR. What you write may describe conversations with colleagues. We hold that information because you wrote it, and we do not contact those people about it — telling your manager that you are keeping a record would expose you to exactly the harm this service exists to help you avoid.
We never ask you for anyone's name and we never need one.
Basis: our legitimate interest in providing the service you asked for, and yours in keeping the record.
Timestamps
Every entry you seal is stamped twice: when the thing happened, which you set, and when it was logged, which we set and neither of us can change.
Who we share it with
| Who | What for | Where |
|---|---|---|
| UpCloud | Hosting and storage | Finland |
| Brevo | Email we send you | France |
| Mistral | Turning your voice notes into text | France |
| Anthropic | Reading the text in photographs you attach, and reading your plan document when you upload it | United States |
| Stripe | Taking payment | Ireland, with onward transfers to the United States |
| PostHog | Cookieless analytics | European Union |
| Cloudflare | Serving the site and blocking abuse | United States |
| Sentry | Telling us when something breaks | European Union |
We do not sell your data, we do not share it for advertising, and there are no advertising trackers on this site. None of the companies above may use your information to train a model.
Stripe, Cloudflare and Anthropic involve transfers outside the EU, protected by the European Commission's standard contractual clauses. Nothing you write, attach or record is sent to Stripe or Cloudflare. What goes to Anthropic is the photographs you attach, and the plan document you upload if you choose to upload one. Nothing else does — not the entries you write, not your recordings, and not your triage answers.
How long we keep it
Your record stays until you delete it. Nothing expires on its own — a file that vanished on a schedule would be worse than useless to you.
When you delete a case or your account, we remove it from our systems immediately and from backups within 30 days. Voice recordings live as long as the case they belong to, because the recording is the evidence and the transcript is only a copy of it. A plan document you asked us to keep lives as long as its case, and you can delete it on its own at any time; one you did not ask us to keep was never stored in the first place. If you asked us to email you a read but never bought anything, we keep your address for 24 months.
Your rights
You can ask us for a copy of your data, correct it, delete it, restrict what we do with it, object to processing based on legitimate interest, take your data elsewhere in a portable form, and withdraw any consent you gave.
Most of these are buttons rather than requests: export is always available and always free, deletion is immediate. For anything else, write to us and we will respond within a month.
One thing works differently, and it is deliberate. A sealed entry cannot be edited or removed individually. That is what makes the record worth having — a file that could be quietly revised afterwards would prove nothing. Corrections are attached underneath, dated, with the original left intact. You can always delete the whole case or the whole account.
Security, honestly stated
Your data is encrypted in transit and at rest, held on EU servers, and access is limited to what is necessary to run the service.
We can technically read your data. We are not going to claim otherwise. End-to-end encryption would mean we could not produce your guidance, could not build your export, and could not help you if you lost your key — and losing your key would mean losing your evidence permanently. We judged that a worse trade for you. What protects the record from being altered is the seal chain and the logged timestamp, not encryption.
The most likely way your record gets exposed is not us being breached. It is someone else reading your email. Because you can reset your password by email, anyone with access to your inbox can reach your account. Use a personal address nobody else can open, and turn on the device lock when we offer it.
Automated processing
Your triage read is produced by a scoring function running on your device. Your guidance is produced from your plan and your file, and every suggestion tells you where it came from. The text in a photograph you attach is read by a model, and what it produces sits beside the photograph rather than replacing it — the photograph is the evidence and the text is a copy of what it says.
If you upload your plan document, a model reads the dates, the role and the goals out of it and puts them in the form for you. You see everything it read, next to the sentence it read it from, and you correct anything wrong before any of it is saved. It is a way of not retyping a document you are already holding, and nothing more.
None of it is a decision about you and none of it has legal effect. It is not legal advice, and no automated process here determines anything about your employment. Whatever it says, the decisions remain yours.
Children
Fairhanded is not for anyone under 18 and we do not knowingly hold data about children.
Changes
If we change how any of this works, we update this page and tell you before it takes effect. We do not make privacy claims here that the product cannot support — if the architecture changes, this document changes with it.