Privacy Policy
Version 2.0 — Effective April 4, 2026
1. Introduction
FairEnough ("we," "us," or "our") is operated by Mid-Continental Dental Supply Company Ltd. and provides the website fairenough.life. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our interpersonal negotiation platform.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and a hashed password. If you sign in via Google or Facebook, we receive your name, email, and profile picture from those services. We never store your social login passwords.
Relationship Data
To provide the negotiation service, we store the items you list, the costs you assign, appreciation messages, proposals you make, agreements you reach, and adherence check-in notes. This data is visible only to you and your partner within your partnership, subject to phase-gating rules (your partner cannot see your data until the mutual reveal phase).
Usage Data
We collect standard server logs including IP address, browser type, pages visited, and timestamps. This data helps us maintain and improve the service.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
| Processing Activity | Legal Basis (GDPR Art. 6) |
|---|---|
| Account creation and operation | Performance of contract (Art. 6(1)(b)) |
| Negotiation data storage and sharing with partner | Performance of contract (Art. 6(1)(b)) |
| AI coaching suggestions | Consent (Art. 6(1)(a)) |
| Transactional emails (phase notifications, reminders) | Legitimate interest (Art. 6(1)(f)) |
| Service improvement via aggregated analytics | Legitimate interest (Art. 6(1)(f)) |
| Security and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
For processing based on consent, you may withdraw consent at any time (see Section 9). For processing based on legitimate interest, you may object by contacting us; we will cease processing unless we have compelling legitimate grounds.
4. How We Use Your Information
- Provide and operate the FairEnough negotiation service
- Send transactional emails (password resets, partner invitations, phase notifications, check-in reminders)
- Improve the application based on aggregated, anonymized usage patterns
- Enforce our Terms of Service and prevent abuse
5. AI Coach
FairEnough includes an AI-powered negotiation coach. When you use the coach, your negotiation data (items, costs, proposals) is sent to our AI provider (Anthropic, based in the United States) to generate suggestions. We do not use your data to train AI models. The AI provider's processing is governed by a data processing agreement with us. Your individual AI coaching conversations are private and are not shared with your partner.
6. Data Sharing
We do not sell or share your personal information for advertising purposes. We share information only in these circumstances:
- With your partner — Negotiation data (items, costs, proposals, agreements, check-in notes, appreciation messages) is shared with your linked partner as part of the core service, subject to phase-gating. Your partner cannot see your data until the mutual reveal phase. Individual AI coaching sessions remain private.
- Service providers — We use Amazon Web Services (hosting, database, email delivery; data processed in Canada and the United States) and Anthropic (AI coach; data processed in the United States). These providers process data on our behalf under data processing agreements.
- Legal requirements — We may disclose information if required by law, subpoena, or court order.
7. International Data Transfers
FairEnough is operated from Canada. Your data may be processed in Canada and the United States by our service providers (AWS and Anthropic). If you are located in the European Economic Area, United Kingdom, or Switzerland, your data is transferred to countries that may not provide the same level of data protection as your home country. We protect these transfers through:
- Standard Contractual Clauses (SCCs) approved by the European Commission with our sub-processors
- Data processing agreements with all service providers
- Technical safeguards including encryption in transit and at rest
For Canadian users: in accordance with PIPEDA, please be aware that your personal information may be processed in the United States and may be accessible to US law enforcement and national security authorities under US law.
8. Data Security
We protect your data with HTTPS encryption in transit, encrypted database connections, hashed passwords (bcrypt), and AWS security infrastructure including WAF, VPC isolation, and encrypted storage at rest.
9. Your Rights and Consent Withdrawal
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (see Section 10)
- Export your data in a portable format
- Object to processing based on legitimate interest
- Withdraw consent for non-essential processing
- Restrict processing of your data
- Lodge a complaint with a supervisory authority
Withdrawing consent: You may withdraw consent for non-essential processing (such as AI coaching) at any time by emailing privacy@fairenough.life or by adjusting your preferences in account settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Some features may become unavailable if consent is withdrawn.
For Canadian users (PIPEDA)
You have the right to access and correct your personal information, and to withdraw consent for non-essential processing. You may file a complaint with the Office of the Privacy Commissioner of Canada.
For California users (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to Know: You may request the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of your personal information (see Section 10).
- Right to Opt-Out: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is necessary.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
Categories of personal information collected: Identifiers (name, email), account credentials (hashed password), internet activity (usage logs), and user-generated content (negotiation data). These are collected for the purposes described in Section 4 and shared only as described in Section 6.
For EEA/UK users (GDPR)
You have the rights listed above plus the right to data portability and the right to lodge a complaint with your local data protection authority. Our legal bases for processing are described in Section 3.
10. Data Retention and Deletion
We retain your data according to the following schedule:
- Account and negotiation data: Retained while your account is active, plus 30 days after account deletion to allow recovery from accidental deletion.
- Server and usage logs: Retained for 90 days, then automatically purged.
- Database backups: Purged within 30 days of a deletion request being processed.
- Legal holds: Data may be retained longer if required by law or legal proceedings.
You can delete your account at any time from the Settings page. Account deletion permanently removes your profile, partnership data, and all associated negotiation history after the retention period above. This action is irreversible.
11. Cookies
We use essential cookies only for authentication (session token) and user preferences (theme, dismissed guides). We do not use advertising, analytics, or tracking cookies. By using FairEnough, you consent to the use of these essential cookies, which are strictly necessary for the service to function.
12. Children
FairEnough is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If we learn that we have collected data from a user under 18, we will delete it promptly.
13. EU Representative
If you are located in the European Economic Area and wish to contact us regarding data protection matters, you may reach us at privacy@fairenough.life. We will designate a formal EU representative under GDPR Article 27 if our processing of EU residents' data reaches applicable thresholds.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email at least 30 days before the changes take effect. Continued use of the service after changes constitutes acceptance of the updated policy.
15. Contact
For privacy-related questions or to exercise your data rights, contact us at privacy@fairenough.life.