Effective August 15, 2026 · applies to all fidubond products
Every fidubond product runs entirely in your web browser. Data you enter is stored locally using:
Optional master-password encryption (AES-256-GCM via the Web Crypto API) encrypts your IndexedDB data at rest on your device. We do not hold the key.
End-to-end encrypted cloud sync (multi-device access) is on our roadmap. When launched, your data will be encrypted on your device with a key only you hold, then synced to our servers in encrypted form. We will not be able to read it.
We do not operate any backend server that receives your product data. Specifically, we do not collect:
The only data we may receive is:
The Service is currently free and no checkout exists. If paid plans are introduced and you purchase a license, Creem.com Market Limited (our Merchant of Record) will process your payment. In that case Creem will collect:
Creem's processing is governed by Creem's Privacy Policy. We do not receive your card details — Creem is PCI-DSS compliant and tokenizes all payment data.
The limited data we receive is used only to:
We do not use your data for marketing, advertising, or selling to third parties.
We do not sell, rent, or share your personal data with third parties for their promotional purposes. The only situations where we may disclose data:
We do not use tracking cookies. Each fidubond product uses localStorage and IndexedDB on your device to store your product data and preferences. This data:
If paid plans are introduced, Creem's checkout may set its own cookies on checkout.creem.io — see Creem's Cookie Policy.
Depending on your jurisdiction, you may have the following rights:
Same rights as GDPR, enforced by the Information Commissioner's Office (ICO).
To exercise any right, email [email protected]. We respond within 30 days.
Your product data is retained in your browser until you clear it. We have no control over this.
Email correspondence with our support team is retained for 2 years for support continuity, then deleted.
If paid plans are introduced, Creem retains transaction records per their own retention policy (typically 7 years for tax compliance).
Your product data is stored locally in your browser, which inherits your browser's security model. Optional master-password encryption uses AES-256 via the Web Crypto API.
Future license tokens will be RSA-2048 signed JWTs verified locally with an embedded public key. We do not operate any backend server that could be breached for product data.
If paid plans are introduced, payments will be processed by Creem, which is PCI-DSS Level 1 compliant.
The Service is not directed to children under 13 (COPPA) or under 16 (GDPR). Our products are designed for adults acting in fiduciary capacities (guardians, attorneys-in-fact, trustees, LPA attorneys). We do not knowingly collect data from children.
Because your product data stays in your browser, there are no international transfers of product data. If paid plans are introduced, Creem may transfer checkout data internationally per their Privacy Policy; such transfers use Standard Contractual Clauses (SCCs) approved by the European Commission.
We may update this Policy from time to time. We will notify users of material changes by posting a notice on the homepage at least 30 days before changes take effect. The "Last Updated" date above reflects the most recent revision.
For privacy questions or to exercise your rights: [email protected].
For Creem-specific privacy questions (once paid plans exist): [email protected].