Fylark

Privacy policy

Fylark waitlist · last updated: 23 September 2026

This page explains how we handle the data you provide when joining the Fylark waitlist or using the contact form. We collect only the bare minimum. We use no analytics, audience measurement or advertising.

Controller

The controller is Lucas Ezequiel Palma, an individual who operates the Fylark project from Andorra under Andorran data protection law. The GDPR may also apply if we intentionally target an offer at people in the EU; mere accessibility, a free service or pre-launch status does not decide that assessment. We have not appointed an EU representative: before targeting an EU launch or campaign we will complete the assessment and, if GDPR Article 27 requires it, publish the representative details. We have not appointed a DPO because the current scope has no automated decisions with legal effects, no large-scale processing of special-category data and no other identified high-risk mass processing; we will reassess before material changes. Contact us and exercise your rights at privacy@fylark.app or through the unsubscribe and contact page.

What we collect

Purpose and legal basis

For the waitlist, we use your data to manage your waitlist signup and notify you at launch. The legal basis is your consent, given expressly in the form and withdrawable anytime. Before adding you, we check that the address is yours: we send you a confirmation email, and your signup stays pending until you open its link and select the confirm button on our website. Opening the link is not enough, so a program that scans your email cannot sign you up. You can also enter that email’s 6-digit code on our website; it is valid for 24 hours. If you unsubscribe and sign up again, you will need to confirm again.

If you use the form for an ordinary enquiry, we process the email address and message to receive, manage and answer it. The legal basis is our legitimate interest in responding to the enquiry you initiated.

If you exercise a data protection right, we process the information needed to verify your identity proportionately, handle the request, document the decision and respond. The legal basis is compliance with our legal obligations.

We process technical security signals, pseudonymous attempt identifiers and audit events to prevent abuse, protect the service and demonstrate the operations performed. The legal basis is our legitimate interest in maintaining a secure and accountable service, with data minimisation and specific retention periods.

Retention

Waitlist data leaves ordinary use after 24 months, or earlier if you unsubscribe or the purpose ends. If you do not confirm your address, the signup leaves ordinary use 7 days after the last confirmation email. Contact messages, including privacy requests, and the associated email leave ordinary use after 12 months. They are then blocked and separated from the active database in an encrypted vault with EU data jurisdiction, invisible to the admin panel and available only to courts, prosecutors, competent administrations or the APDA for possible liabilities. Our ordinary operational candidate for destruction is 36 months after blocking; this is not a universal legal period, and a claim, formal action or proceeding can change it. Once every applicable period has expired and no legal hold exists, we remove the encrypted material from operational state. We do not treat destruction as complete while a technical recovery copy could reintroduce it: after a restore, the service stays closed, preserves the block and reapplies deletion. D1 Time Travel may allow technical recovery for up to 7 days. To reconcile retries and restores, the vault keeps for 30 days a pseudonymous HMAC receipt containing the operation reference, the destruction-operation date, policy and key version; it contains no email or message and cannot reconstruct them by itself. It then becomes eligible for purge. This receipt is pseudonymous, not anonymous. Minimized audit metadata follows its own 36-month maximum window. The generic Google alert contains neither your email nor message, and we do not promise that Gmail automatically deletes it. If the product does not launch, we will block the list and apply the same later destruction.

Recipients

Cloudflare processes hosting, execution and forms for us through Pages/Workers, D1 and Queues. Workers may run globally near the connection; the observed D1 location is WEUR, but this database has no EU-only jurisdiction. Free-plan Queue receives the contact UUID inside a constant technical envelope containing version and type, without visitor email, message or classification, and retains it for up to 24 hours. Cloudflare publishes its DPA and subprocessors. The optional alert uses Google Workspace and Google Apps Script only after the account-level CDPA is accepted and the contracting entity, subprocessors and international transfer safeguards are documented. When active, the payload sent to Google contains only the UUID (event_id), brand and type; the technical envelope adds the version, key identifier, timestamp, random nonce and HMAC signature, without the visitor’s email address or message; the email is generic, with no visitor email, message, UUID or date, and Apps Script schedules deletion of the UUID hash after 70 hours. During the 12-month period and until the next daily purge, with operational latency under 24 hours while the cron is healthy, its time and type may be indirectly correlated with D1. We do not rely solely on the EU-US framework to protect people in Andorra; ask our privacy channel for the applicable safeguards or a reference to them. Through Resend (Resend, Inc., USA) we send these emails from support@fylark.app, with an EU sending region (Ireland): the signup confirmation (also when you select “Resend the email”), the “You’re already on the list” notice when someone enters an already confirmed address again, the unsubscribe confirmation link and the contact form acknowledgement, which carries an opaque reference and no content from your message. Resend receives your address, the language and the signed links, keeps metadata and delivery logs for 30 days in the USA under its DPA with standard contractual clauses and its EU-US Data Privacy Framework participation, and publishes its subprocessors. We do not sell your data or share it for commercial purposes.

Direct email to the privacy channel

If you choose to write directly to privacy@fylark.app instead of using the form, your email service sends Google Workspace the sender address and everything you include: subject, body, signature and attachments. We use that content only to receive, handle, document and answer the request: the legal basis is compliance with our legal obligations when you exercise a right and our legitimate interest for an ordinary enquiry; it is not used for marketing. We delete each direct message, together with our reply, at the first monthly review after it is 365 days old. Only a documented legal or tax hold can postpone that deletion, and we review those exceptions at the same monthly review. Once deletion is no longer recoverable, the CDPA allows Google to complete deletion from its systems as soon as reasonably practicable and within 180 days at most, unless law requires retention. Do not include special-category data or attachments unless strictly necessary; the web form is the minimised alternative.

Certificate verifier

The certificate verifier runs in your own browser. The document and certificate you drop are never uploaded or stored on any server: they are processed on your device. To check the seal’s date, only the Bitcoin block number (a public value) is sent to a chain explorer (blockstream.info or, as a fallback, mempool.space); never your document or its fingerprint. We keep no record of what you verify. Those explorers are independent third parties and may see your IP address when queried for the block, as on any website visit.

Website language

The landing page uses the first supported language configured in your browser. The choice is processed on your device, without geolocation. You can change it manually. We do not store the language on your device: each page’s address indicates it.

A draft in this tab

When you visit a legal page or change language, we temporarily save the email you typed only in this tab so it can be restored when you return. This draft is not sent to our servers, expires after 30 minutes and is removed when we try to restore it or once the signup is sent successfully. Consent is not saved: you must select it again. The 30-minute limit applies only to this stored copy: we do not clear the email from a form your browser keeps open. If the browser does not retain that form and no valid draft is available because it has expired or storage is blocked, you will need to enter your email again. After you sign up, the page keeps your address only in memory for the “Resend the email” and “Change the address” buttons; it does not save it on your device.

Technical tickets and retries

When a waitlist signup, contact or unsubscribe starts, this site obtains a signed ticket for that action and temporarily stores the ticket, its random UUID and a timestamp in this tab’s sessionStorage. The ticket identifies Fylark, the action and its technical validity window; it contains no email address, message or profile. It authorises a new operation for 10 minutes. If the result is uncertain, the same tab may retain it for up to 24 hours solely to reconcile that exact request; it is removed sooner when the result is confirmed, definitively rejected or the tab closes. The server keeps for 24 hours a receipt containing pseudonymous HMAC references to the request and its canonical content, together with the action, state and timestamps; the receipt does not store the ticket, clear UUID, email address or message. It then becomes eligible for the daily purge. These references are pseudonymous, not anonymous.

Technical waitlist-control cookie

After a waitlist attempt, we may set our own technical control cookie, which is strictly necessary to protect renewal and removal. When we issue a real capability, its name is dynamic: it starts with __Host-fylark-waitlist-control- and ends with that capability’s random UUID. When the response cannot authorise an existing registration, we may set a fixed-name cover cookie with a public shape indistinguishable from the real capability, so the response does not reveal whether the email is registered. Both cookie types are host-only to fylark.app, Secure, HttpOnly and SameSite=Strict, so JavaScript cannot read them. The token contains a random UUID and its authenticated issued-at (iat) and expiry (exp) timestamps, never the email address or a reversible derivative. The cookie and token last no more than 730 days, and the server validates the signature and expiry before accepting control. They are not used for analytics, advertising or cross-site tracking and are not disclosed beyond the processors that provide this site. Their strictly necessary nature and operation are disclosed here. You can delete them in your browser; deleting the real capability means automatic renewal or removal of that registration will no longer be available in this browser, but you can always use ‘Privacy request’ or email privacy@fylark.app.

Bot protection

To stop bots from submitting the signup, contact and unsubscribe forms, we use our own proof of work: your browser solves a small calculation tied to that submission and our server checks it. It uses no cookies, does not analyse your browser and sends no data to third parties. To limit abuse of the sign-up and contact forms, we keep a pseudonymous HMAC reference to the IP address in D1, never the IP address in clear text. For sign-up emails, the unsubscribe page and the contact-form acknowledgement we also keep, with the same mechanism, a pseudonymous HMAC reference to the email address, whether or not it is on the list, to send each address at most three sign-up confirmation emails (the first included) and one “You’re already on the list” email every 24 hours, three unsubscribe links every ten minutes and three acknowledgements every hour, and to allow at most five attempts a day at entering its confirmation code; never the address in clear text. Each reference becomes eligible for deletion after 24 hours and the daily purge completes physical deletion on the next run, with operational latency under 24 hours while the cron is healthy. The proof of work, rate limits and automated guards only decide whether a particular submission is technically accepted: they do not profile you, decide access to the future service or produce legal or similarly significant effects. If there is a false positive, retry or write to privacy@fylark.app.

Your rights

You can unsubscribe, exercise your rights (access, rectification, erasure, objection, restriction and portability), and withdraw consent by writing to privacy@fylark.app or through our unsubscribe and contact page. You can ask through the same channel for a copy of our record of processing activities. You may also lodge a complaint with the Andorran Data Protection Agency (APDA) and, where applicable, the authority for your habitual residence. The service is not directed at children under 16: they must not use the waitlist or ordinary contact form without authorisation from their legal representative. If we detect a child submission, we limit processing to proportionately verifying that authorisation or deleting it; the child and representative retain their rights.

You can unsubscribe from any device: the signup confirmation email and the “You’re already on the list” email include your signed unsubscribe link and, on the unsubscribe page, entering your email sends you a link to confirm it. Unsubscribe links keep working even after they expire (current ones last 730 days), and so does your email app’s unsubscribe button. If you open the page from one of these links, we show which address will leave the list, partly hidden. If this browser still holds the technical signup credential, the unsubscribe runs without a link. Both responses are generic: they do not reveal whether the address was registered, and only the link or the credential can execute the unsubscribe. For any other right, or if the link does not arrive, choose “Privacy request” on the same page: we will verify your identity proportionately and handle the request.

← Back to Fylark

Informational document for a waitlist. See also the terms of use. Not legal advice.