FetchBeta

Privacy Policy

Version 2026-10-11, updated 2026-10-11.

What we collect

  • Your account: name, email address (stored lower-case, without any "+tag"), the sign-in methods you add (passkey public keys, a hashed password, the id a sign-in provider gives you), the organizations you belong to and your role, and when you accepted the terms.
  • Activity: an audit log of sign-ins and changes in your organizations, with IP address and browser, and usage counts used for billing.
  • Billing: a Stripe customer id. Card details go straight to Stripe and never reach us.
  • What you put in Fetch.

What you put in Fetch: collections, requests, environments, collection runs, monitors, mocks and published docs, kept in a Cloudflare Durable Object for your organization. Secret variables are encrypted. Uploaded files go to your own bucket when you set one, otherwise to Cloudflare R2. History of requests sent from your browser or the Fetch Agent stays on your device. Results of requests Fetch sends from Cloudflare (cloud sends, collection runs and monitors) are kept 30 days: a summary in that Durable Object, and the request and response (up to 256 KB of the body) in Cloudflare R2, or in your own bucket when you set one (its own rules then decide how long they stay). AI features call your provider straight from your browser, with your key.

How we use it

To run Fetch, keep it secure, bill for it and send the email it needs (sign-in links, invites and the notices you set up). We do not sell data, show ads, or train AI on your data. AI features run only on your own provider keys.

Where it lives

On Cloudflare (Workers, Durable Objects, D1 and R2), which chooses data-center locations, and in your own storage bucket if you connect one. The subprocessors page lists everyone who handles data for us.

How long we keep it

Your account: until you delete it. Deleting your account is immediate and cannot be undone. Organization data: until the organization deletes it or is deleted. Audit log: searchable for 28 days, then archived: to the organization's own storage bucket if it connected one, otherwise kept by us for 400 days in total and then deleted. Cloudflare keeps point-in-time recovery copies for up to 30 days, after which deleted data is gone for good.

Data an organization holds about you

When an organization invites you, it decides what it keeps about your work there (your membership, the audit log of your actions, what you created in its workspace). We process that data for the organization, on its instructions. To have it changed or removed, ask that organization's admins.

Cookies

One session cookie that keeps you signed in. No tracking or advertising cookies.

Contact

admin@nightroll.app. Fetch is operated by JML Software Solutions LLC.