FACTREE information
Privacy policy
Last updated: 7 September 2026
You can explore FACTREE without an account. An optional account keeps your journey across devices. This notice explains the information used by those features, search, sharing and email delivery.
Who is responsible
FACTREE is operated by XXVIII Ltd, a private limited company registered in England and Wales, company number 08184502. XXVIII Ltd is the controller of the personal information described here. Registered office: 87a Cherry Orchard Road, Croydon, United Kingdom, CR0 6BE. This is a postal address for formal correspondence, not a public customer-service location.
For privacy questions or requests, email factree.admin@gmail.com.
Your device and saved journey
FACTREE uses browser storage to remember your saved facts, viewed and reviewed topics, journey, learning progress and preferences. Clearing site data can remove local information. An installed web app also uses device storage. Sign-out, account deletion and clearing device storage are different actions.
If you sign in, your device journey can be merged with your account and synchronised across devices. Account records include your confirmed display name, saved facts and paths, topic history, learning position, lesson progress, and daily activity summaries and milestones. Account identity and email references in the progress database are hashed; hashed information is not necessarily anonymous.
Sign-in and Google information
Auth0 provides sign-in. When you choose Google, Google provides identity information to Auth0, including an account identifier, email address, verification status and basic profile information such as name and profile picture. FACTREE uses sign-in information to authenticate you, associate your journey with your account, display your verified email and suggest a display name. You confirm the name used for FACTREE sharing.
The Google connection requests basic profile information, not access to your Gmail messages, Google Drive files or calendar. FACTREE does not receive your Google password or your passkey's private key. Authentication services may use cookies and related storage to operate sign-in.
Search, suggestions and service activity
Search requests are sent to the server to find relevant facts. Unsuccessful searches and explicit topic suggestions can be recorded with a hashed browser identifier to understand demand and limit repeated submissions. Administrators review suggestions and may use a suggested topic in the content-creation process. Please do not put personal or confidential information in suggestions.
FACTREE records engagement such as facts displayed, saved or shared and related connections opened or followed. Records can include topic identifiers, dates, event identifiers and a hashed browser or account reference. These support usage totals, duplicate prevention and service improvement. Guest journeys are local, but guest use is not entirely unrecorded on the server. Hosting and security logs may contain IP addresses, request paths, timestamps and technical information.
Email subscriptions and sharing
If you subscribe, FACTREE processes your email address, chosen subjects, frequency and delivery preferences. Journey-based email personalisation is optional; if you select it, saved journey and favourite information can influence which facts are sent. You can change preferences or stop subscribed facts using the links in an email. Subscription addresses and access-link material are encrypted in the subscription store.
When you share a fact by email, FACTREE sends the recipient address, your confirmed display name, selected fact and optional note to Resend for delivery. The recipient sees your name and note, not your sign-in email. A one-off share does not subscribe its recipient. Recent recipient addresses can be saved on your device; you can clear them through Account & privacy. Only send to someone who would reasonably welcome the message.
Delivery records include status, message identifiers, sent-fact history and suppression information used to avoid duplicates and unwanted delivery, including after bounces or complaints. FACTREE's subscription templates do not include tracking pixels.
Why information is processed
We use information necessary to provide the account and journey services you request. We rely on consent for optional subscribed emails and journey-based email personalisation; you can withdraw it through the email controls. We use legitimate interests in operating, securing and improving FACTREE for proportionate service records, demand measurement, abuse prevention, support and requested one-off sharing. Where consent is required for a particular storage or processing activity, that requirement is separate from these interests. Legal obligations may also require records or disclosures.
You do not have to create an account or subscribe to browse. Without the relevant information, we cannot provide cross-device account storage or deliver requested emails. Recommendations and milestones are learning features, not decisions about eligibility for employment, credit or other legal rights.
Providers and international processing
Authentication information is processed by Auth0 and, when selected, Google. Resend processes email delivery information. Hosting, infrastructure and mailbox providers process information needed to deliver, secure and support the service. A person you send a fact to receives that message. We may disclose information where required by law or to protect the service against abuse.
Providers can process information outside the UK. FACTREE uses an EU Auth0 tenant, but that does not mean every provider operation stays in Europe. Resend states that it stores message content and delivery records in the United States and provides contractual transfer safeguards, including standard contractual clauses and the UK Addendum, in its data processing terms. See also Auth0's data-processing information and Google's privacy policy. Contact us for information about arrangements relevant to your data or a copy of applicable safeguards.
Retention and deletion
Local data remains until cleared or replaced. The account store keeps the current journey and up to 20 previous progress revisions. Engagement cleanup uses a 35-day window for event receipts and a 400-day window for daily unique records; cleanup is performed during service operations rather than at a guaranteed deletion instant. Aggregate counts and saved-state records have different lifecycles.
Account & privacy offers a journey download and account deletion. Deletion removes account progress and profile records and attempts to remove the Auth0 sign-in identity. If that step fails, the interface offers a retry. A hashed deletion-block record prevents reuse of old tokens for up to 31 days, after which it is eligible for cleanup. This does not delete your Google account or recall messages already delivered.
Unsubscribing stops subscribed facts but does not automatically erase delivery or suppression records. Search-demand, support, sharing and provider records have separate retention needs. Application logs rotate by size, currently up to three 10 MB files, rather than after a fixed number of days. Runtime backups do not currently have a fixed automatic expiry, and account deletion does not immediately erase backup copies. Contact us about deletion beyond the in-product controls; we assess what can be removed and what must be retained for security, suppression or legal reasons. We do not promise that all copies disappear immediately.
Your rights and choices
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing. Where we rely on consent, withdrawal does not affect processing already lawfully carried out. Contact factree.admin@gmail.com; we may need to verify your identity to protect your information. You can complain to the UK Information Commissioner's Office or your relevant local authority without first contacting us.
Children and families
FACTREE is intended for children as well as adults. Younger users can ask a parent, carer or trusted adult to help understand account and privacy choices. Avoid including your address, school details or other private information in suggestions and personal notes. Parents and carers can contact us about a child's information. Where the law requires parental authorisation for consent-based processing, permission from a parent or guardian is required; Google sign-in alone is not proof of that permission. This notice does not claim that an automated parental-verification system is provided.
Changes
We will update the date on this page when the notice changes and provide an appropriate additional notice for material changes affecting how information is used.