Privacy policy

Privacy policy

Effective May 2026 (draft)

Draft pending legal review. This document is a working draft and will be reviewed by qualified counsel before public launch. The exact language may change; the principles will not.

Introduction

Fairly (“Fairly,” “we,” “us”) operates a consent-first consumer data marketplace at https://joinfairly.com. This privacy policy explains what personal information we collect, why we collect it, how we protect it, and your rights to access, download, and delete it. We have written this policy in plain language. If anything is unclear, email [email protected].

What we collect

The categories below are the maximum we can collect — what we actually hold for you depends on which consent toggles you have turned on.

  • Account data. Email, password hash, display name, country, region, timezone, account-creation date.
  • Phone number. If you verify a phone number — required before you can cash out or join a paid research session — we keep a one-way hash of it and the last 4 digits, and we do not keep the number itself. It is used only to send you a verification code by text message: we never sell it, never share it with anyone, and never use it for marketing or any other messaging.
  • Profile data — standard categories. Demographic, financial, lifestyle, browsing of supported retailers, purchase activity through Fairly coupons, and general location (city / state level — never precise GPS). Each category has its own toggle and its own consent record.
  • Profile data — sensitive categories. Race / ethnicity, religion, political affiliation, sexual orientation, gender identity, health conditions, detailed financial. Stored separately, with stricter access controls and a per-access audit log.
  • Wallet activity. Credits, debits, cash-out requests, and the processor reference (never the full destination account number).
  • Browser-extension telemetry. Minimal — only retailer-domain matches, coupon-application reports, and crash diagnostics. The extension does not record your browsing outside of supported retailers.
  • Email-derived purchase data. If you connect Gmail or Outlook, the structured details of order confirmation emails — store, order number, date, amounts, items. The emails themselves are never stored. See Connecting your email.

Connecting your email

Fairly can read order confirmation emails from your inbox so your purchases count toward your profile and earnings without you photographing a receipt. This is entirely optional. Fairly works without it, and you can disconnect at any time.

What you are agreeing to

When you connect Gmail, Google asks you to approve read-only access to your mail. When you connect Outlook, Microsoft asks the same. Fairly requests the narrowest access that lets it read a message:

  • Gmail. gmail.readonly — read your email messages and settings.
  • Outlook. Mail.Read — read your mail.

Fairly cannot send, delete, or change any email, and never asks for permission to do so.

What this means: the permission Google and Microsoft grant covers your whole mailbox, because neither company offers a permission limited to “just receipts.” What limits Fairly is not the permission — it is what Fairly actually asks for, described next.

What Fairly actually reads

Fairly does not scan your mailbox. It runs a specific search and only opens the messages that search returns:

  • Messages received in the last 6 months when you first connect, and in the last 7 days on each sync after that.
  • Messages whose subject line looks like an order — for example “order confirmation,” “your order,” “shipping confirmation,” “thank you for your order.”
  • Messages your mail provider has not classified as promotional or social.

Everything else in your mailbox is never requested and never opened. Personal correspondence, work email, and anything that does not match that search stay untouched.

What Fairly keeps

Fairly opens a matching message, reads it, and keeps only the structured facts about the purchase: the store name and sender address, the subject line, the order number, the purchase date, the amounts (subtotal, tax, shipping, total), the items on the order where the email lists them, and a score for how confidently the email was read.

Fairly does not keep the email itself. The message body is held in memory only long enough to read those fields, then discarded. It is never written to disk, never stored in a database, and cannot be retrieved later — not by you, not by Fairly staff, not in response to a support request. Attachments are never downloaded.

Reading the email

Most order emails are read by pattern matching that runs entirely on Fairly's own servers.

When Fairly does not recognize a store's email format, the text of that message is sent to Anthropic, which provides the AI model Fairly uses, so the purchase details can be extracted. Only the message text is sent — up to roughly the first 10,000 characters — along with the subject and sender. Anthropic processes it to return the purchase fields and does not use it to train its models. Fairly keeps only the extracted fields; Anthropic is not given your name, your Fairly account, or any other profile data.

What Fairly never does with your email

  • We never show your emails, or anything from them, to advertisers.
  • We never sell email data, and never transfer it to a data broker, information reseller, or advertising network.
  • We never use email content to build advertising profiles outside the consent categories you have turned on.
  • We never use email content to train AI models, and do not permit our providers to.
  • No human at Fairly reads your email — access is limited to what the automated parsing requires.

Turning it off, and what happens then

You can disconnect at any time in Settings → Email. When you disconnect, Fairly's access tokens are erased immediately and every receipt imported from that mailbox is deleted. Credits you already earned stay in your wallet.

You can also revoke Fairly's access directly from your Google Account or your Microsoft account. Revoking there stops all future access; use Settings → Email as well if you also want the already-imported receipts deleted.

Deleting your Fairly account removes this data on the same 7-day schedule as the rest of your account, described under “Data retention and deletion” below.

Google Limited Use

Fairly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use it

  • To build anonymized audience segments that advertisers can target.
  • To match coupons and offers to your consented categories.
  • To compute earnings and cash-outs, and to work out how the annual charity pool is divided across the causes users pick.
  • To detect abuse and protect the integrity of the wallet and consent system.
  • To send transactional emails (verification, security alerts, payout confirmations).

Marketing emails are sent only with explicit opt-in (see the Notifications section of Settings) and can be revoked at any time.

What we never do

  • We do not sell raw user data to anyone. Period.
  • We do not provide your name, email, or individual record to advertisers.
  • We do not collect data from anyone under 18 (Fairly is 18+ only).
  • We do not auto-fill retailer checkout fields or interact with payment forms.

How we protect it

  • Encryption in transit and at rest. All traffic is TLS; the database is encrypted at rest by the underlying managed Postgres provider.
  • Row-level security. Every personal-data table enforces row-level security so only the owning user (and audited service operations) can read it.
  • Sensitive-data isolation. The sensitive profile table has a stricter policy than other tables, and every read or write writes a separate access-log row recording who touched it, when, and why.
  • Append-only audit logs. Consent records and wallet transactions are append-only — a revoke is a new row, not an update. This means we (and a future auditor) can reconstruct exactly what you authorized at any moment in time.

Your rights

  • Access & download. Visit Settings → Download my data to export a JSON of everything Fairly knows about you.
  • Withdraw consent. Toggle a category off in Settings or My profile. Withdrawal is effective immediately; the underlying profile data for that category is cleared, and you are removed from any related audience segments within 24 hours.
  • Delete your account. Settings → Delete account schedules a hard deletion in 7 days. During the grace window you can cancel. After deletion, your profile and selection data are removed; we retain the audit log (anonymized) for legal defense.
  • California residents (CPRA). You have additional rights including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing of personal information. We do not sell personal information; the opt-out of sharing is available via the consent toggles described above. To be explicit about what those toggles cover: they govern the profile data used to build audience segments. Your phone number is not part of that. It is never sold and never shared, there is no toggle that exposes it, and the only thing it is ever used for is sending you a verification code.

Third parties

Fairly relies on a small set of vetted service providers: Supabase (managed Postgres + authentication), SendGrid (transactional email), PayPal (payouts), Stripe (advertiser billing in Phase 2), Anthropic (the AI model that reads receipt, invoice, and order-email text — see Connecting your email), Sentry (error monitoring), and PostHog (privacy-respecting product analytics — no PII). Each only receives the minimum necessary data for its role. None receives raw profile data, and none is permitted to use what it receives to train its own models.

Cookies

The dashboard uses HTTP-only cookies to keep you signed in. The marketing site does not set tracking cookies. PostHog product analytics on the dashboard is anonymous and can be opted out of in Settings.

Data retention and deletion

Profile data is retained while you have an active account. Revoking a category clears the underlying values immediately. Account deletion has a 7-day soft-delete window, after which the profile data is hard-deleted. Wallet and historical charity records are retained for the period required by law and for our annual charity reporting; identifiers are anonymized after hard-delete.

Receipts imported from a connected inbox are deleted as soon as you disconnect that inbox — you do not have to delete your account to remove them. Order emails themselves are never stored at all. See Connecting your email.

Children's privacy

Fairly is for adults — accounts are gated by an 18+ verification step during onboarding, and we do not knowingly collect data from anyone under 18. If you believe a minor has created a Fairly account, please contact us so we can investigate and delete.

Changes to this policy

We will email all account holders before any material change to this policy. Minor wording changes are versioned in our changelog at /press.

Contact

Privacy questions, and requests to access, download, correct, or delete your data: [email protected]. For anything else, [email protected]. We respond within five business days.

You can also use our contact form, which reaches the same inboxes. The addresses above always work on their own.