Legal
Privacy policy
Last updated 11 September 2026.
This policy describes how TensorFleet (“we”, “us”) handles information when you use Fabplane — fabplane.com, the studio at app.fabplane.com, related APIs, and desktop software such as Fabdesk.
Information we collect
Depending on how you use the Service, we may process:
- Account data. When you sign in with GitHub or Google we receive the identifier, handle or name, and email the provider shares for sign-in. Email-and-password accounts store the email you submit and a password hash.
- Project and workspace data. Designs, files, comments, and settings you create or upload so we can run the studio, store artifacts, and publish pages you make public.
- Device-authorization data. Desktop clients may start a device-login flow. We store a short-lived user code and the resulting session or token until it expires or is revoked.
- Job applications. If you email jobs@fabplane.com, we process the message and any resume or portfolio you attach.
- Technical logs. Request paths, timestamps, and similar operational data needed to keep the Service available and secure.
- Measurement. Ahrefs Web Analytics measures public-site traffic without cookies. If you allow optional measurement, Google Analytics and Google Ads may also process page-use and advertising data as described below.
We do not require a profile beyond what is needed to sign in and operate your workspace. The public marketing site does not ask the API who you are; it only reads a small client-visible cookie to show signed-in links in the header.
Cookies and local storage
- fp_session — HttpOnly session cookie set after sign-in. It authenticates private API requests and is not readable by JavaScript on the public site.
- fp_user — a non-HttpOnly cookie with your handle and display name (which may be the name from your GitHub or Google account) so the public header can show that you are signed in.
- Short-lived cookies used during OAuth (state / PKCE) and then cleared.
- fabplane-theme in local storage, so the site can remember light or dark theme. This is not sent to our servers.
- Your cookie-choice preference in the browser for 180 days, so we know whether optional measurement is allowed.
Sign-in cookies, theme preference, and your cookie choice are needed for the site to work as you left it. Optional Google measurement tools load only after you allow them. We do not sell personal information.
Your cookie choice
On the public website, Google measurement tags load only after you choose to allow them. You can reject optional tracking, allow Analytics only, or allow Analytics and advertising measurement. Use Cookie settings at the bottom of the page to make or change your choice. Rejecting optional measurement does not prevent the site from remembering your theme, cookie choice, or sign-in state. Clearing stored data in your browser forgets that choice until you use Cookie settings again.
This optional integration does not run on the sign-in page or inside the authenticated editor.
Google Analytics
If you allow Analytics, Google processes information about the pages you visit and how you use them, including page views, scrolling, outbound links, downloads, supported embedded-video interactions, and clicks to open the Fabplane app. Google may use cookies and browser or device information to measure visits and engagement. We use these reports to understand traffic and improve the site.
Our public-site integration does not send account email addresses, form values, passwords, or private designs to Analytics. Automatic form and site-search measurement are disabled.
Google Ads
If you choose Accept all, the Google Ads tag also loads so advertising interactions can be measured. Advertising storage and advertising user-data consent remain denied for Analytics only. Ad personalization and Google signals are disabled in this integration.
Google's handling of this information is explained in How Google uses information from sites or apps that use its services and the Google Privacy Policy. You can also learn about Google's Analytics opt-out browser add-on.
Ahrefs Web Analytics
Ahrefs Web Analytics measures visits and engagement on public pages. Ahrefs describes the service as cookieless and says it does not collect or store personal data. We use its aggregate reports to understand search traffic and improve the site.
Ahrefs explains its handling of this information in the Ahrefs Privacy Policy.
How we use information
We use the information above to:
- Provide, secure, and improve the Service.
- Authenticate you and keep you signed in across our properties.
- Publish public projects and catalog pages you choose to make public.
- Respond to job applications and support requests.
- Diagnose outages and abuse.
- Measure public-site usage and advertising when you have allowed those tags.
Third-party services
- GitHub and Google — sign-in, and optional Analytics or Ads measurement if you allow it. Their privacy policies apply to the data they hold.
- Ahrefs — cookieless public-site traffic measurement. Its privacy policy applies to its service.
- Cloudflare — hosting, CDN, and object storage for the public site, images, and downloads.
- Sentry — optional error reporting. When a DSN is configured, the browser or server may send crash details. We disable default PII collection and do not attach cookies, authorization headers, or request bodies as context.
Public catalog photographs are hosted copies of freely licensed images; see Photo credits.
Sharing
We share personal information only with the processors listed above, when required by law, or if we transfer the Service to a successor that agrees to handle it consistently with this policy. We do not sell personal information. Content you publish as public is visible to anyone.
Retention
We keep account and project data while your account is active and for a reasonable period afterward if needed for backups, security, or legal claims. Session cookies stop working when they expire. The matching server record is removed when you sign out or revoke the token; expired rows may remain until they are cleaned up. Device codes are short-lived.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export personal information, or to object to or restrict certain processing. To make a request, email hi@fabplane.com. You can also disconnect GitHub or Google access from that provider’s account settings and sign out of Fabplane.
International transfers
We operate from Bangkok, Thailand, and use infrastructure that may process data in other countries (including Cloudflare, Google, and, when enabled, Sentry). If we transfer personal information internationally, we do so to operate the Service you requested.
Children
The Service is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.
Changes
We may update this policy as the Service or the law changes. The date at the top will change when we do. Material changes will be reflected on this page.
Contact
Privacy questions: hi@fabplane.com. See also our Terms and conditions.