Privacy Policy — Modaal
Effective date: 2 January 2026
This Privacy Policy explains how we collect, use, and protect personal data when you visit our websites, use Modaal (the "Service"), or contact us.
1) Who we are (data controller)
Controller: FabFun (The Netherlands), trading as Modaal
KvK: 92807224
Contact: hi@modaal.dev
If you use Modaal through a company account, your employer may also be a controller of certain data (e.g., your work email and usage under its policies).
2) Scope
This Policy applies to:
- Visitors of our websites and documentation
- Users of Modaal (web app, desktop clients, APIs, integrations)
- People who contact support, sales, or participate in beta programs
3) What data we collect
A. Account and profile data
- Name, email address, account identifiers
- Authentication data (e.g., hashed passwords, SSO identifiers)
- Workspace / team details (if you collaborate)
B. Billing and transaction data
- Subscription tier, invoices, payment status
- Payment card details are processed by our payment provider (we do not store full card numbers)
C. Customer Content you submit to the Service
This is content you (or your team) provide for the Service to operate, such as:
- Product specs, prompts, requirements, tickets, user stories
- Generated outputs (e.g., code, project files, build logs)
- Uploaded files (e.g., screenshots, assets, documents)
- Integration data you connect (e.g., repositories, issue trackers) when you authorize access
Important: Do not upload sensitive personal data (e.g., health data, government IDs) or secrets (e.g., private keys, confidential tokens) unless a feature explicitly requires it and you have a secure method for doing so.
D. Usage, device, and log data
When you use the Service, we collect operational telemetry to keep it secure and reliable, such as:
- IP address, device/browser type, timestamps
- Pages/features used, session IDs, error codes, performance diagnostics
E. Communications and support
- Emails and messages you send us
- Support tickets, recordings or screenshots you choose to share
- Feedback, survey answers, and beta testing notes
F. Cookies and similar technologies
We use cookies and similar tools to run the Service, remember preferences, and understand usage. We ask for consent where required by law.
4) Why we use your data (purposes)
We process personal data to:
- Provide and operate Modaal (accounts, access, collaboration)
- Generate outputs you request (e.g., code, screens, plans) using AI models
- Maintain security, prevent abuse/fraud, and debug incidents
- Improve product performance and user experience (analytics in aggregate)
- Provide support and respond to requests
- Send essential service messages (e.g., security, billing, updates)
- Comply with legal obligations (e.g., accounting, dispute handling)
5) Legal bases (GDPR)
We rely on these legal bases where applicable:
- Performance of a contract (to provide the Service you request)
- Legitimate interests (security, fraud prevention, service improvement)
- Consent (non-essential cookies, optional marketing)
- Legal obligation (tax/accounting, lawful requests)
6) How AI processing works in Modaal
Modaal is an AI-assisted build system. When you submit prompts/specs or connect tools:
- Your inputs may be processed by AI model providers and infrastructure providers acting as our processors/sub-processors, strictly to deliver the Service.
- We may store prompts/outputs and related logs to operate the Service, troubleshoot errors, prevent abuse, and improve reliability.
Model training
We do not use your Customer Content to train public, general-purpose AI models.
If we ever introduce optional training (e.g., to improve Modaal-specific quality), we will provide clear controls (opt-in/opt-out) and update this Policy.
Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects on individuals within the meaning of GDPR Article 22.
7) Sharing your data (processors and third parties)
We may share data with:
- Infrastructure providers (hosting, storage, databases, email delivery)
- Analytics providers (to understand usage and improve product)
- Payment processors (to manage subscriptions and invoices)
- AI providers (to generate outputs you request)
- Integrations you choose (e.g., Git providers, issue trackers) when you connect them
We only share what is necessary and under contractual safeguards.
8) International transfers
Some providers may process data outside the EEA. Where required, we use appropriate transfer safeguards such as EU Standard Contractual Clauses (SCCs) and/or other lawful mechanisms depending on the transfer context.
9) Retention
We keep personal data only as long as needed for the purposes above:
- Operational logs/telemetry: typically up to 90 days, unless needed longer for security or legal reasons
- Account data: for the life of the account
- Customer Content: kept while your account is active; upon deletion/termination we delete or de-identify within a reasonable period (backups may persist for a limited time, typically up to 90 days)
10) Security
We use reasonable technical and organizational measures such as:
- Encryption in transit and (where appropriate) at rest
- Access controls and least-privilege policies
- Monitoring and abuse prevention
You are responsible for keeping credentials secure and using strong authentication (e.g., MFA) where available.
11) Your rights (EEA / Netherlands)
Depending on your situation, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Delete data (with legal exceptions)
- Restrict or object to processing
- Data portability
- Withdraw consent at any time (for consent-based processing)
Complaints
You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.
12) Cookies
We use cookies for:
- Strictly necessary functionality (login, security, session)
- Analytics/performance (to improve the Service)
- Preferences (language/theme)
- Marketing (only where used and where consent is required)
You can manage cookie preferences via our cookie banner/settings (where available) and browser controls.
13) Children
Modaal is not intended for children. We do not knowingly collect personal data from children.
14) Changes to this Policy
We may update this Policy to reflect changes in law or our practices. If changes are material, we will provide notice in-product or via email, and update the effective date.
15) Contact
For privacy questions or requests, contact: hi@modaal.dev