Privacy policy
Last updated:
This policy explains which data is processed when you use the FaamOffice app, this website and the Faam AI Cloud service, and what your rights are. “We” means the operator of this website ([OPERATOR NAME]).
1. The desktop app and your files
FaamOffice opens, edits and saves files on your own computer. We do not receive, store or have access to your documents.
When you use Faam AI with your own API key, requests go directly from your computer to that AI provider and are governed by its policies. With local AI, data never leaves your computer or local network.
2. Account data
When you create a FaamOffice account we store:
- Your name and email address, and whether the email is verified.
- Your password as a one-way hash (scrypt) — we never know your password.
- The devices signed in to your account (device name, sign-in time and last use).
- Your credit balance and credit history.
- Browser sessions, with the browser (user agent) and IP address at sign-in, to protect your account.
3. Faam AI Cloud
When you use Faam AI Cloud, the content of your request (including any document content sent with it) passes through our servers to the AI model provider behind the service so that a reply can be generated. We do not store request or response content.
For each request we store the time, model name, input/output token counts and the credits charged, for billing and to show you your history.
The model provider behind the service processes data under its own policy: [LIST PROVIDERS AND POLICY LINKS].
4. Cookies
This website only uses necessary cookies:
- A session cookie (httpOnly) that keeps you signed in for 30 days.
- A language cookie that remembers whether you chose Vietnamese or English.
We do not use advertising cookies or third-party trackers.
5. Email
We only send transactional email: email verification and password reset. We do not send marketing email without your consent.
6. Retention
Account data is kept until you delete your account. Sessions expire after 30 days; email verification links expire after 24 hours and password reset links after 1 hour. Server logs may be kept for a short time for operations and security.
7. Your rights
You can view and edit your name, change your password, sign devices out and permanently delete your account from the Account page. Deleting your account removes your profile, credits, usage history and all signed-in devices. For any other request about your personal data, contact us.
8. Security
Passwords are hashed with scrypt; device tokens, sessions and email links are only stored as SHA-256 hashes. Connections to the website are encrypted with HTTPS.
9. Children
The service is not intended for children under 13 (or the minimum age required where you live).
10. Changes to this policy
When this policy changes we update the date at the top of the page and announce significant changes on the website.
11. Contact
[OPERATOR NAME], [ADDRESS], email: [CONTACT EMAIL].