fog — Privacy Policy

Last updated: 18.6.2026

The short version

fog is a private home for your ideas. Your canvases and library are private by default — visible only to you and the people you explicitly invite. We don't sell your data, we don't show ads, and we don't use your content to train AI. This page explains, in plain terms, what we collect, why, who helps us run the service, and the choices you have. fog is currently in beta and under active development, so this policy may change as the product grows. We'll update the date above when it does.

Who we are

fog is operated by Onion Tmi, Agricolankatu 2 A 38, 00530 Helsinki, Finland. For any privacy question, or to exercise your rights, contact us at hello@fog.do. This policy covers the fog web app (app.fog.do), the fog Chrome extension, and the fog Figma plugin. A mobile app is planned for later and is not covered yet.

What we collect

Account information. When you create an account, we collect your email address and any profile details you choose to add, such as a display name. We use Supabase to manage authentication. Content you create and upload. Everything you put into fog: canvases, bubbles (notes, links, images, video, audio, documents), text annotations, drawings, tags, your personal library, and comments — including any files you upload. Content you save from the web (Chrome extension). When you trigger a capture, the extension reads the active tab's image URLs, page title, and source URL, plus the content you selected, and saves it to your fog account. The extension only accesses a page when you initiate a capture — it does not run in the background or monitor your browsing. Content you choose to save may itself contain other people's personal data (for example, a profile or contact you capture); you are responsible for ensuring you may save it, and we process it only to provide the service to you. Collaboration and sharing. When you share a canvas, we process the email addresses you invite and send them an invitation. When people work on a shared canvas together, their identity (name/email, an assigned colour, live cursor position, and current selection) is visible to others on that canvas in real time, and comments are visible to collaborators. Real-time presence is handled by Liveblocks. Connection tokens. The Chrome extension and Figma plugin store a personal access token locally on your device to authenticate to your fog account. Technical and usage data. Our infrastructure receives standard technical data needed to operate and secure the service — such as IP address, browser/device type, and request timestamps. Feedback. If you send feedback through the in-app widget (Userback), we receive what you submit along with basic context such as your browser and any screenshot you choose to include. Cookies and local storage. We use essential cookies and local storage to keep you signed in and remember basic preferences. We do not use advertising or cross-site tracking cookies.

How we use your data

• To provide and operate fog — your account, canvases, library, uploads, sharing, and collaboration.
• To send service communications you ask for, such as canvas invitations.
• To secure the service, prevent abuse, and debug problems.
• To respond to your support requests and feedback.
• To comply with legal obligations.
Where the GDPR applies, our legal bases are: performing our contract with you (running the service and your account), our legitimate interests (keeping fog secure and improving it), consent where we ask for it, and legal obligation where applicable.

What we don't do

• We do not sell or rent your personal data — ever.
• We do not use your content to train AI models.
• We do not show ads or use cross-site advertising trackers.
• The extension does not monitor your browsing, track clicks or keystrokes, or read pages in the background — it acts only when you trigger a capture.
fog's use of information received from the Chrome extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Who we share data with (service providers)

We don't sell your data, but we rely on a small set of vetted providers to run fog. They process data only on our instructions: • Supabase — database, authentication, and file storage
• Liveblocks — real-time collaboration (presence, cursors, comments)
• Vercel — application hosting and server logs
• Resend — sending transactional email such as invitations
• Userback — in-app feedback widget
If you use the fog Figma plugin, content you choose to export is sent to your own Figma account at your initiation. We may also disclose data if required by law, or to protect the rights, safety, and security of fog and its users.

Where your data is stored

Your account and content are stored in the European Union / Switzerland — Supabase on AWS Europe (Zurich, eu-central-2). Some of our other providers (such as Liveblocks, Vercel, Resend, and Userback) may process limited data in other regions, including the United States, under appropriate data-transfer safeguards.

How we protect your data

Your canvases and library are private by default — accessible only to you and the people you choose to share a canvas with. All traffic between your device and fog is encrypted in transit (HTTPS). No method of transmission or storage is ever completely secure, so we can't guarantee absolute security, but we work to protect your data and limit access to it.

How long we keep it, and deletion

We keep your data for as long as your account is active. You can delete individual content at any time from your library or canvases. You can also delete your entire account, which removes your canvases, library, and uploaded files; some data may persist briefly in backups before being overwritten. To delete your account or request deletion, use the in-app option or email hello@fog.do.

Your rights

Depending on where you live (including under the GDPR), you have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. To exercise any of these, contact hello@fog.do. You may also lodge a complaint with your local data-protection authority.

The fog Chrome extension — permissions

The extension requests only what it needs to save content to your account: • activeTab — temporary access to the current tab, only when you start a capture, to read the page URL, title, and selected content.
• scripting — injects the capture script on demand, only after you trigger a capture; nothing runs automatically or persists afterward.
• storage — stores your fog access token and settings locally in your browser.
• contextMenus — adds the "Add to fog" right-click option.
• Access to app.fog.do — the only always-on external host; used to send what you capture to your fog account.
• Optional access to other websites (off by default) — requested only if you enable it from the extension's "Connect" screen, and used solely to re-fetch images you capture so they're saved to your library even if the original page later removes them. Capturing works without granting this, and fog never uses it to read or monitor your browsing.

Children

fog is not directed to children under 16, and we don't knowingly collect their personal data. If you believe a child has provided us data, contact hello@fog.do and we'll delete it.

Changes to this policy

We may update this policy from time to time. We'll post changes here and update the "Last updated" date; significant changes may be communicated in-app or by email.

Contact

Questions about this policy or your data: hello@fog.do