Fictura Privacy Policy

Last updated: August 13, 2026Effective: August 13, 2026

Fictura, Inc. ("Fictura," "we," "us") provides infrastructure that mobile application developers install in their own applications. This Privacy Policy explains what personal information we handle, why, and what rights you have.

1. Two roles, and which one applies to you

We handle personal information in two distinct capacities, and your rights differ depending on which applies.

As a controller. When you visit fictura.co, read our documentation, contact us, or create and administer a Fictura account, we determine why and how your information is processed. We are the controller (or, under United States state privacy laws, the "business"). Sections 2 through 15 apply to you.

As a processor. When a developer installs our SDK in their application, that developer decides what to collect and why. We process that information only on their instructions and on their behalf. We are the processor (or "service provider"), and the developer is the controller. If you are the user of an app that uses Fictura, see Section 13.

2. Information we collect as a controller

Account information. Name, email address, company or product name, and the credentials associated with your Fictura account.

Communications. The content of messages you send us through the contact form, by email to support@fictura.co, or through support channels, together with your contact details and any attachments.

Application and configuration data. The names and identifiers of the applications you register, your dashboard configuration, API key metadata, and records of connections you establish to third-party services.

Usage and device information. Log data generated when you use fictura.co or the dashboard, including IP address, browser type and version, operating system, referring page, pages viewed, timestamps and actions taken.

Cookies. As described in Section 11.

Billing information. We do not currently charge for the Service and do not currently collect payment card information. If that changes, payment details will be collected and processed by a PCI-compliant payment processor, and we will not store full card numbers.

3. Information we process as a processor

When a developer integrates our SDK, we receive and process the following on that developer's behalf. The developer chooses what is enabled, and every category below can be switched off from their dashboard.

Device and installation identifiers. A vendor-scoped device identifier and a locally generated installation identifier stored in the device's secure storage. We do not collect the Apple Advertising Identifier (IDFA) and the SDK does not request App Tracking Transparency permission on the developer's behalf.

Account identifiers. An identifier supplied by the developer for their own signed-in user, and, where the developer has connected a subscription provider, that provider's user identifier. These are used to resolve one person's activity into a single record rather than several.

Product events. Application lifecycle and interaction events, for example first open, application open, screen viewed and element tapped, together with any custom events the developer chooses to log and any properties they attach to them.

Purchase and entitlement events. Trial starts, purchases, renewals, cancellations, refunds and entitlement state, received from the developer's store or payment provider by webhook.

Diagnostic data. Error and crash reports, including stack traces, device model, operating system version, application version, and any context the developer attaches.

Attribution signals. Campaign and link parameters, referrer strings supplied by an application marketplace, and, where the developer has enabled passive matching, a truncated cryptographic hash of the IP address observed at the time of a click and at the time of an install. We do not store the raw IP address for this purpose. The hash is computed identically at both points and compared. Passive matching is capped at twenty-four hours and is not applied to users more than forty-eight hours old.

Approximate location. Country and platform, derived from network metadata, used to determine eligibility for features that are restricted by jurisdiction and to segment reporting. We do not collect precise or GPS location.

We instruct developers not to send us special categories of personal data, health data, government identifiers, payment card numbers, biometric identifiers, precise location, or the personal data of children under sixteen. Section 5.03 of our Terms of Service makes this a contractual obligation.

4. How we use information, and our legal bases

PurposeCategories usedLegal basis (UK and EU GDPR)
Provide, operate and secure the ServiceAccount, usage, application dataPerformance of a contract
Respond to enquiries and provide supportCommunications, accountPerformance of a contract; legitimate interests
Detect, prevent and investigate abuse, fraud and security incidentsUsage, device, logLegitimate interests; legal obligation
Improve and develop the Service using aggregated and de-identified dataUsage, aggregatedLegitimate interests
Send service and administrative noticesAccount, communicationsPerformance of a contract; legal obligation
Send product marketing to business contactsAccount, communicationsConsent, or legitimate interests where permitted, with opt-out in every message
Comply with law and enforce our agreementsAll categories, as necessaryLegal obligation; legitimate interests
Process End User Data on a developer's behalfSection 3 categoriesThe developer's legal basis, established by the developer

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights, and you may object as described in Section 9.

5. How we share information

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have not done so in the preceding twelve months.

We disclose personal information only as follows.

Service providers and subprocessors. We engage a small number of vendors to host and operate the Service. Each is bound by a written contract that limits them to processing on our instructions, imposes confidentiality, and requires appropriate security measures. Our current list of subprocessors is available on request at support@fictura.co, and we will give notice of a material change before a new subprocessor begins processing customer data.

Fictura's analytics, attribution, error tracking, experimentation and event pipelines are built and operated in-house rather than by routing your data through third-party analytics vendors. Where you connect a third-party service to Fictura yourself, for example a payment processor, a subscription provider, a messaging tool or an analytics destination, that connection is made at your direction using your own account, and that provider is not our subprocessor. Their handling of the data is governed by your agreement with them.

Affiliates. Fictura, Inc. is a subsidiary of Addicting Elements LLC. We may share information within our corporate group for the purposes described in this policy, under equivalent protections.

Legal disclosures. We may disclose information where we believe in good faith it is necessary to comply with a law, regulation, legal process or enforceable governmental request; to enforce our agreements; or to protect the rights, property or safety of Fictura, our customers or the public. Where we are legally permitted, we will notify the affected customer before disclosing their data.

Corporate transactions. In connection with a merger, acquisition, financing, reorganisation or sale of assets, information may be transferred, subject to this policy continuing to apply or the recipient providing equivalent protection.

With your direction. Where you instruct us to.

6. International transfers

We operate from the United States and process information there. Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where a transfer risk assessment indicates they are needed. A copy of the relevant mechanism is available on request at support@fictura.co.

7. Retention

We retain personal information only as long as necessary for the purposes described in this policy.

DataRetention
Account informationFor the life of the account, then up to 12 months
Contact form and support correspondence24 months from the last message
Website and dashboard logs12 months
Security and audit logs24 months
End User Data processed for a developerPer the developer's configuration and instructions; deleted or returned within 30 days of the end of their agreement, subject to backup cycles
Aggregated and de-identified dataIndefinitely, as it no longer identifies anyone

We may retain information longer where required to comply with a legal obligation, resolve a dispute, or enforce our agreements.

8. Security

We maintain administrative, technical and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls on a least-privilege basis, credential rotation, logging, and review of changes to systems that process personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Report a suspected vulnerability or incident to support@fictura.co.

9. Your rights

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to request access to your personal information; to have inaccurate information corrected; to have information erased; to restrict processing; to data portability; to object to processing carried out on the basis of legitimate interests, including profiling; and to withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with your supervisory authority, or with the Information Commissioner's Office in the United Kingdom. We ask that you contact us first so we can try to resolve the matter.

If you are a resident of California, you have the right to know the categories and specific pieces of personal information we have collected, the sources, the purposes and the categories of third parties to whom we disclose it; to delete personal information; to correct inaccurate personal information; to opt out of the sale or sharing of personal information (we do neither); to limit the use of sensitive personal information (we do not collect it for purposes requiring this right); and not to receive discriminatory treatment for exercising any right. You may use an authorised agent, and we will require proof of authorisation.

If you are a resident of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, or another state with a comprehensive privacy law, you have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and certain profiling. Where the law provides an appeal, you may appeal a refusal by replying to our decision, and we will respond within the statutory period.

How to exercise a right. Email support@fictura.co with the subject line "Privacy Request." We will verify your identity by reference to information already associated with your account or your prior correspondence with us, and will respond within the period required by applicable law, generally thirty (30) days, extendable where the law permits and we tell you why. Exercising a right is free unless a request is manifestly unfounded or excessive.

If your request concerns an app that uses Fictura, see Section 13.

10. Global Privacy Control

We treat a Global Privacy Control signal, or a comparable browser-based opt-out preference signal, as a valid request to opt out of sale and sharing for the browser that sends it, to the extent required by applicable law. Because we do not sell or share personal information, this has no practical effect on our processing.

11. Cookies and similar technologies

fictura.co and the Fictura dashboard use cookies and similar technologies that are strictly necessary to operate the site and keep you signed in, together with a limited set of first-party measurements to understand how the site is used. We do not use third-party advertising cookies and we do not run advertising pixels on fictura.co. Where required by law, we will present a consent banner before setting any non-essential cookie, and your choice is respected until you change it. You can also control cookies through your browser settings, though blocking strictly necessary cookies will prevent you from signing in.

12. Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under sixteen (16), and our Terms of Service prohibit developers from transmitting the personal information of anyone under sixteen through the Service. If we learn that we have received such information, we will delete it. Developers whose applications are directed to children are responsible for their own compliance with the Children's Online Privacy Protection Act and equivalent laws, and should not enable behavioural or attribution features for those users.

13. If you use an app that uses Fictura

If you are the user of a mobile application built by one of our customers, that developer, not Fictura, decides what information is collected about you and why. Your relationship is with them, and their privacy policy governs. Direct requests to access, correct or delete your information to that developer. If you contact us instead, we will refer you to them, and we will assist them in fulfilling your request as their processor. We do not use End User Data for our own purposes, do not combine it across our customers to build profiles, and do not sell it.

14. Changes to this policy

We may update this policy. When we do, we will revise the "Last updated" date above. Where a change is material, we will give notice by email or in-product notice before it takes effect. Prior versions are available on request.

15. Contact

Fictura, Inc.

Email: support@fictura.co