
Privacy statement
What we hold about you, why we hold it, where it lives, and what you can do about it.
Last updated 24 August 2026
1. Who is responsible
There are two answers, and the difference matters.
- Your account. For the data that exists because you have an account with us — your identity, sign-in, and the record of your consents — Solidarity Lab B.V., Rotterdam, The Netherlands, is the controller.
- The records an organisation keeps about you. When an organisation uses The Fibre to run its courses, meetings or programmes, that organisation decides what it records about you and why. It is the controller; we are its processor. Ask them first about anything they have entered; ask us and we will help.
2. What we hold
The governing rule is that a field only exists because a specific app needs it. There is no general notes box quietly filling up. In practice we hold:
- Identity
- Name, email address, and optionally language, country, postal address and links to organisations you belong to.
- Per-app records
- Whatever the app you are using needs — a booking, an enrolment, a task in a flow, a budget line. Each app keeps its own, and each shows up as its own tab on your profile.
- Activity
- A thin log: that something happened, its type, a one-line title and a date. “Attended the Athens session” — never what was said, written or attached. It cannot be edited afterwards; a mistake is corrected by adding a line, not rewriting one.
- Purchases
- Where you have paid for something: amount, currency, what it was for, and the invoice. Card details never reach us — see sub-processors below.
- Consents
- What you agreed to, when, and against which version of which document. Withdrawals are recorded the same way.
- Technical
- Server logs needed to keep the service running and secure. No advertising identifiers, no profiling, no third-party trackers.
3. What does not move between apps
Each app on the platform keeps its own content in its own place, and there are no connecting doors. Exactly three kinds of thing cross between them: the thin activity log described above, purchase records, and the links that say two apps are talking about the same person. The contents of a message, a note, a reflection or a document never cross. The thinness is deliberate: it makes leaking between apps impossible rather than merely discouraged.
4. Why we are allowed to hold it
- Contract — to give you the service you or your organisation signed up for: your account, your bookings, your enrolments, the emails that make them work.
- Consent — for anything optional: newsletters, appearing in a cohort directory, learning analytics. You can withdraw these at any time on your Privacy page, and withdrawal is as easy as giving it.
- Legitimate interest — keeping the platform secure and working, and defending legal claims.
- Legal obligation — invoices and accounting records we are required to keep.
5. Where it lives
In the European Union, and it stays there. The database and sign-in run in Ireland; the API runs in Frankfurt. The web front end holds no personal data at all — it asks the EU API for everything, every time.
6. Who else touches it
These are our sub-processors. There is nobody else.
- Supabase
- Database and authentication. Hosted in Ireland (EU).
- Fly.io
- The API. Hosted in Frankfurt (EU).
- Vercel
- Serving the web interface, from Frankfurt (EU). It is stateless — no personal data is stored there.
- Resend
- Sending transactional email — sign-in links, invitations, receipts.
- Stripe
- Card payments, where an organiser takes them. Card numbers go to Stripe directly and never reach us; we see the amount, the outcome and the invoice.
- Only if you choose it: signing in with a Google account, or connecting your calendar so Fibre Meet can read your availability. Disconnecting revokes it.
7. How long we keep it
For as long as your account exists, or as long as the organisation that entered a record has a reason to keep it. When something is deleted we mark it deleted rather than scrubbing the row immediately, so that a mistaken deletion can be undone and so the audit trail stays honest — but a marked record is out of use and out of sight. On an erasure request we zero the personal content across every app within 30 days. Invoices are kept for as long as tax law requires, and the activity log keeps the fact that something happened even after its personal content is gone.
8. Your rights
You have the full set under the GDPR: to see what we hold, to correct it, to have it erased, to restrict or object to how it is used, and to take it elsewhere. Two of them are buttons rather than requests:
- Export (Article 15) — download everything held about you as JSON, from the Privacy page when signed in.
- Erasure (Article 17) — request it from the same page; we act on it within 30 days.
For anything else, write to support@thefibre.app with “privacy” in the subject. We answer within one month. If you are unhappy with how we handle it you can complain to your national data protection authority — in the Netherlands, the Autoriteit Persoonsgegevens.
9. Cookies
Three kinds, all strictly necessary or functional, which is why you are not being asked to dismiss a banner: the cookie that keeps you signed in, and two that remember your theme and sidebar preference across the Fibre apps. There are no advertising or analytics cookies, and no third party sets a cookie through us.
10. Changes
We will update this page when what we do changes, and move the date at the top. Where you have accepted this statement as part of enrolling in something, the version you accepted is recorded against that enrolment.
11. Contact
Solidarity Lab B.V., Rotterdam, The Netherlands. support@thefibre.app. The rules of use are in the terms.