Privacy

Privacy Policy

What Fragmenta collects, which companies it passes through, how long it's kept, and how to get it back or get rid of it.

Last updated 16 August 2026

Who we are

Fragmenta is a toolbox for the snippets, prompts, commands and notes you reuse. We are the data controller for everything described on this page, and you can reach us at contact@fragmenta.site.

What we collect

  • Account details — your email address, an optional display name, and a hashed password. If you sign in with GitHub, we also receive your GitHub username and avatar.
  • Your fragments — the titles, content, descriptions, tags, links and uploaded files you save.
  • Technical data — server request logs, error reports when something breaks, and short-lived counters derived from your IP address that stop abuse of sign-in and other endpoints.
  • Anything you send us — feedback submitted in the app, or email you write to us.

We do not run analytics, advertising, or third-party tracking, and we do not sell data to anyone.

Why we use it, and on what basis

  • To run the service — creating your account, storing and showing your fragments, sending verification and password-reset email. Legal basis: performance of our contract with you.
  • To keep it working and secure — rate limiting, abuse prevention, and error reporting so failures reach us instead of silently breaking your account. Legal basis: our legitimate interest in a secure, functioning service.
  • To improve it — understanding which features are used and where they fail. Legal basis: our legitimate interest in improving the product.

We don't currently rely on consent for anything, because we don't do anything that requires it. If that changes, we'll ask you first rather than bury it here.

Who else processes your data

Running Fragmenta means using other companies for hosting, storage and email. Each receives only what it needs to do its job:

  • Vercel — hosting and request logs. Our servers run in Frankfurt.
  • Neon — the database holding your account and fragments, hosted in the EU.
  • Cloudflare R2 — files and images you upload.
  • Resend — sends verification and password-reset email; receives your email address.
  • GitHub — only if you choose to sign in with GitHub.
  • Upstash — short-lived rate limit counters.
  • Sentry — error reports, which can include your user ID, your IP address, and details of the request that failed.
  • Venice AI — see the next section.

Some of these are based outside the EU. Where that's the case, transfers rely on the European Commission's standard contractual clauses or an equivalent safeguard.

If we ever start taking payments, card processing will be handled by Stripe and we'll update this page before that goes live. We don't take payments today.

AI features send fragment content to a third party

When you use an AI feature — auto-tagging, generated descriptions, explaining code, optimising a prompt, or asking a question about your library — the relevant fragment content is sent to Venice AI to produce the result. Your fragment text leaves our servers when you use those features.

AI features are optional. If you never use them, your fragments are never sent anywhere for processing.

The vault is exempt from all of this

Fragments you save to the vault are encrypted in your browser with a passphrase only you know, before they reach us. We store ciphertext we cannot read.

That means vault content is never sent to any AI provider, never readable by us or by anyone who obtained our database, and — the part that cuts both ways — not recoverable by us if you lose your passphrase. We cannot reset it for you, because we don't have it.

How long we keep things

  • Your account and fragments — until you delete them or delete your account. Deleting your account removes your data, including uploaded files, rather than hiding it.
  • Error reports — kept by Sentry under its own retention window, then discarded.
  • Rate-limit counters — expire automatically within hours.
  • Email you send us — kept while it is useful for support, then deleted.

What you can do

Under the GDPR you have rights over your data. Two of them are already self-serve, which we think is how it should be:

  • Get a copy — Settings → Export downloads everything you have as a ZIP, any time, without asking us.
  • Delete everything — Settings → Delete Account removes your account and its data.
  • Correct it — your display name and every fragment are editable in the app. To change your email address, write to us.
  • Object or restrict— email us and we'll handle it by hand; there's no button for this one.

If you think we've handled your data badly, you can complain to your local data protection authority. We'd appreciate the chance to fix it first — contact@fragmenta.site.

Cookies

We set one kind of cookie: the session cookie that keeps you signed in. There are no analytics, advertising or tracking cookies, which is why you haven't been asked to dismiss a consent banner.

Changes to this policy

If we change how we handle your data, we'll update this page and the date at the top. Significant changes will be announced in the app rather than made quietly. See also our terms of service.