Privacy Policy
fallibi is a personal, non-commercial project run by one individual (“Doni”, “we”). It powers the personal homepage doni.page and its back end at fallibi.com, including a Model Context Protocol (MCP) server that AI assistants can connect to. The service has not formally launched. This policy explains what information is handled when you use either site, and how. Questions: donim@andrew.cmu.edu.
Information we receive
- Google sign-in. You can read both sites without signing in. If you sign in, we ask Google only for the
openidandemailscopes, so Google shares your Google account identifier and email address. We do not request your name or profile picture. The account identifier and email address are stored by our authentication provider (Supabase Auth). We do not receive your Google password and we request no access to Gmail, Drive, Calendar, contacts or any other Google data. - Your nickname. Each account gets a random public nickname such as
anon-4298a2, which you can change. Our own tables store an internal account ID and this nickname; they do not copy your email address. - What you submit. Questions you ask (and any translation you add), your upvotes, and the date and time of each.
- Notifications. A record that a question you asked or upvoted has been answered, and whether you have read it.
- AI assistant connections. When you connect an assistant to the MCP server, we store the assistant's registration (its name and redirect addresses), cryptographic hashes of the access and refresh tokens issued to it, and a daily count of its tool calls. Search queries your assistant sends are used to answer the request and are not stored in our database.
- Technical data. Our hosting and network providers process IP addresses and request metadata to deliver the sites and may keep short-lived logs under their own policies.
What is public
Questions you submit are shown publicly on doni.page together with your nickname, and may be returned to AI assistants connected through the MCP server and indexed by search engines. Upvote totals are public; who upvoted is not. Your email address is never shown publicly.
How we use information
- To sign you in, keep you signed in, and show you your own questions and notifications.
- To publish your questions and Doni's answers, and to count upvotes once per account.
- To enforce limits (for example, 20 questions per day on the website and 100 tool calls per day through the MCP server) and to prevent abuse.
We do not use your information for advertising, profiling or marketing, and we do not sell, rent or trade it. We do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models.
Google user data
fallibi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use the Google account information described above only to provide sign-in and the account features on this site.
Service providers
We rely on the following providers, which process data on our behalf under their own terms and may store it in the United States or other countries: Supabase (database and authentication), Vercel (website hosting), Cloudflare (domain name service) and Google (sign-in). We share information with them only as needed to run the sites, and we may disclose information if required by law.
Cookies and browser storage
- Sign-in session cookies set by our authentication provider, needed to keep you signed in.
- A
langcookie that remembers your language choice. - Your theme choice (light, dark or automatic), stored in your browser's local storage.
We use no analytics, advertising or cross-site tracking cookies.
Retention and your choices
- You can change your nickname and delete your own questions before they are answered, from “My questions” on doni.page.
- You can disconnect an AI assistant at any time in that assistant; its tokens expire or can be revoked.
- To access or delete your account and personal data, email donim@andrew.cmu.edu. We will respond within 30 days. When an account is deleted, questions that Doni has already answered may remain public without any link to the account.
- We keep account data while the account exists, and delete it on request or if the service shuts down.
Security
Connections use HTTPS. Access tokens are stored only as hashes, and database access is restricted by row-level security so that each account can read only its own private data. No system is perfectly secure, so please do not submit sensitive personal information in questions.
Children
The sites are not directed to children under 13, and we do not knowingly collect their personal information.
Changes
If this policy changes, the new version will be posted on this page with a new effective date. Significant changes will also be noted on doni.page.