Legal

Privacy Policy

Your privacy is not just a feature — it's the foundation of everything we build.

Layered Encryption & Privacy

FortressDrive employs AES-256-GCM encryption for critical assets, multi-layer authentication, per-module security gates, and comprehensive audit logging. Your most sensitive data — files, credentials, and wallet keys — is encrypted at rest.

1. Introduction

FortressDrive ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Personal Operating System platform (the "Platform").

FortressDrive uses strong encryption and access controls. Some features, including the AI Assistant, necessarily process readable content that you choose to submit or explicitly authorize. The sections below identify those exceptions and the service providers involved.

This Privacy Policy should be read together with our Terms & Conditions. Optional AI data sharing requires a separate, explicit in-app permission and is not enabled merely by accepting our general terms.

2. Encryption and Content Access

FortressDrive limits access according to the feature being used. We do not describe content as zero-knowledge when a feature requires our server or an authorized processor to read it.

Data protected by encryption:

• Your files stored in My Drive — AES-256 encrypted before upload to Cloudflare R2.

• Your passwords and credentials in the Password Vault — AES-256-GCM encrypted at rest.

• Your crypto wallet private keys — AES-256 encrypted and never exposed in plaintext.

Data protected by server-side security:

• Your notes, documents, and journal entries — stored behind multi-layer authentication and module security gates.

• Your goals, projects, and personal database content — access-gated with per-module PIN protection.

• Your financial data in the Finance Tracker — protected behind authentication and security gates.

• Your business reports and analytics — gated behind multi-layer authentication.

AI Assistant conversations:

• After you explicitly allow AI data sharing, AI messages and authorized context are processed by our servers and OpenAI's API to provide the requested feature.

Our security architecture combines encryption for critical assets with authentication, per-module security gates, scoped access, and audit logging.

3. Information We Collect

We collect and process information necessary to operate the Platform and information you choose to provide:

Account Information:

• Email address — Used for account creation, authentication, and critical security notifications.

• Hashed password — Your password is hashed using industry-standard algorithms. We never store your plaintext password.

• TOTP authenticator data — We store your 2FA enrollment status and TOTP configuration data required for authentication verification.

Security & Authentication Data:

• Login timestamps — When you log in, we record the time for audit trail purposes.

• IP addresses — Logged during authentication events for security monitoring and brute-force protection.

• Device identifiers — Used for device verification as part of three-factor authentication.

• Failed login attempts — Tracked to enforce brute-force protection and account lockout policies.

• Security event logs — Password changes, 2FA toggles, and module gate changes are logged for your audit trail.

Subscription & Payment Data:

• Subscription tier and status.

• Cryptocurrency wallet addresses used for payment (public blockchain data).

• Payment confirmation timestamps and transaction hashes.

Workspace Content:

• Files, notes, goals, journal entries, saved AI memories, AI conversations, financial records, and other content you create or upload. The exact content processed depends on the feature you use.

• Images, document text, and audio are collected when you deliberately attach or record them for an AI request. Documents are parsed on FortressDrive servers; authorized extracted text may then be sent to OpenAI.

• When optional Workspace Context is enabled, relevant excerpts from notes, goals, journal entries, and saved AI memories may be included in AI requests.

• When optional AI Financial Analysis is enabled, only the financial categories selected in its privacy controls are summarized and sent for analysis.

We do not collect browsing history or use advertising cookies or tracking pixels. Device contacts and media are accessed only when you invoke backup or organization features and grant operating-system permission.

4. How We Use Your Information

The minimal information we collect is used exclusively for:

• Account authentication — Verifying your identity through our 3FA system.

• Security protection — Detecting and preventing brute-force attacks, unauthorized access, and suspicious activity.

• Audit trail — Providing you with a transparent log of all security events on your account.

• Service operation — Managing your subscription, processing payments, and enforcing storage limits.

• Critical notifications — Sending security alerts for login attempts from new devices or suspicious activity.

• User-requested AI services — Generating responses, titles and images; analyzing user-selected images or document text; transcribing user-recorded audio; and generating separately authorized financial observations.

• Platform improvement — Aggregated, anonymized usage statistics (such as total user count) to improve service reliability. No individual user data is analyzed.

We do NOT use your information for: advertising, profiling, selling to third parties, training AI models, marketing campaigns, or any purpose beyond operating and securing the Platform.

5. Data Sharing & Third Parties

FortressDrive does not sell or rent personal information. We share data with service providers only to deliver requested features, operate the service, process payments, communicate with you, or comply with law.

Limited third-party services we use:

• Cloudflare R2 — For encrypted file storage (My Drive). Cloudflare stores only encrypted, unreadable data. They cannot decrypt your files.

• Replit AI Integrations — Provides the managed API gateway through which authorized AI requests are transmitted to OpenAI. The request content categories are the same as those listed for OpenAI below.

• OpenAI API — Only after explicit in-app permission. Depending on the feature and your settings, we may send your name, AI messages and conversation history, user-selected images, extracted document text, user-recorded audio, saved AI memories, authorized workspace excerpts, and separately authorized financial summaries. OpenAI processes this information to generate responses, analyze content, create images, or transcribe audio. OpenAI states that API data is not used to train its models by default. Unless a stricter retention control applies to our account, OpenAI may retain abuse-monitoring logs containing customer content for up to 30 days, subject to limited legal or safety exceptions.

• Blockchain Networks — Crypto wallet transactions are broadcast to public blockchain networks (Ethereum, Solana, Tron, Bitcoin). Blockchain transactions are public and immutable by nature.

• SMTP Email Service — For sending security notifications and password reset emails. Only your email address and the notification content are transmitted.

We require service providers that receive user data to protect it under contractual and security obligations providing the same or equivalent protection described in this policy. We may disclose information when legally required by a valid request; what we can provide depends on the data and feature involved.

6. Data Encryption & Security Measures

We implement comprehensive security measures to protect your data:

Encryption:

• AES-256-GCM encryption is used for critical assets including Drive files, credentials, and wallet keys.

• Other workspace content is protected at rest and by authenticated, user-scoped access controls; it may be processed in readable form when needed for a feature you request.

• Data is encrypted in transit using TLS.

Authentication:

• Three-factor authentication (3FA): password + TOTP authenticator + device verification.

• Per-module security gates with separate PIN codes.

• Password strength enforcement: minimum 12 characters with complexity requirements.

• Automatic account lockout after repeated failed login attempts.

Infrastructure Security:

• HSTS (HTTP Strict Transport Security) enforced.

• X-Frame-Options DENY to prevent clickjacking.

• Strict referrer policies and permissions controls.

• Content Security Policy headers to prevent XSS attacks.

• Inactivity auto-lock after 5 minutes.

• Full audit trail with timestamps and IP addresses for all security events.

Brute-Force Protection:

• Intelligent rate limiting on all authentication endpoints.

• Progressive delays after failed attempts.

• Automatic account lockout with email notification.

7. Data Retention & Deletion

Active accounts: Your encrypted data is stored for as long as your account is active. We do not impose data expiration on active accounts.

Account deletion: When you delete your account, all your data is permanently and irreversibly removed from our servers within 30 days. This includes:

• All encrypted notes, files, and documents.

• All wallet data and encrypted keys.

• All vault credentials.

• All journal entries, goals, and reports.

• All financial tracking data.

• AI conversations, saved memories, and AI privacy preferences.

• Your account information and audit logs.

This deletion is irreversible after applicable backup and operational retention periods expire.

AI permission: You can revoke permission in Profile & Settings → AI data sharing. Revocation blocks new transmissions to OpenAI but does not itself delete conversation history stored in FortressDrive; delete individual conversations or your account to remove that history.

Third-party processing: Data already sent to OpenAI is handled under OpenAI's applicable retention rules. Standard API abuse-monitoring logs may be retained for up to 30 days unless a stricter control applies, and limited content may be retained longer when legally required or flagged for safety review.

Security logs: Authentication and security event logs are retained for 90 days after account deletion for fraud prevention and security purposes, then permanently deleted.

Inactive accounts: Accounts that have been inactive for 24 consecutive months may be flagged for deletion. We will send email notifications before taking any action.

8. Cookies & Tracking

FortressDrive uses only essential cookies required for the Platform to function:

• Session cookie — Maintains your authenticated session. Expires when you close your browser or after inactivity timeout (5 minutes).

• Authentication token — Securely identifies your logged-in session. Encrypted and httpOnly.

We do NOT use:

• Advertising cookies or tracking pixels.

• Analytics cookies (Google Analytics, Mixpanel, etc.).

• Social media tracking scripts.

• Cross-site tracking of any kind.

• Fingerprinting technologies.

No third-party scripts are loaded on the Platform that could track your activity.

9. Your Rights

You have the following rights regarding your data:

• Right to Access — You can view your data through the Platform and request information about our processing.

• Right to Export — You can export your data at any time. No vendor lock-in.

• Right to Delete — You can delete your account and all associated data at any time.

• Right to Correct — You can modify your account information at any time.

• Right to Restrict Processing — You can disable optional AI sharing and request applicable processing restrictions.

• Right to Data Portability — Your data can be exported in standard formats.

• Right to Object — You can object to any processing of your non-encrypted account data by contacting us.

For users in the European Economic Area (EEA), these rights are provided in accordance with the General Data Protection Regulation (GDPR). For California residents, these rights align with the California Consumer Privacy Act (CCPA).

To exercise any of these rights, you can use the Platform's built-in tools or contact us through our support channels.

10. Children's Privacy

FortressDrive is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18.

If we become aware that a child under 18 has created an account, we will take steps to terminate the account and delete associated data promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

11. International Data Transfers

FortressDrive and its service providers, including OpenAI, may process information in jurisdictions outside your country of residence.

We use encryption in transit, access controls, contractual safeguards, and other appropriate measures for international transfers. AI content is readable by the systems processing the request and is not represented as end-to-end encrypted during that processing.

Where required, international transfers are handled using recognized legal safeguards and applicable data-protection requirements.

12. Cryptocurrency & Blockchain Privacy

When using the Crypto Wallet module, please be aware:

• Blockchain transactions are public — All cryptocurrency transactions are recorded on public blockchains. Transaction amounts, wallet addresses, and timestamps are publicly visible.

• Wallet addresses are pseudonymous — While blockchain addresses don't directly reveal your identity, they can potentially be linked to real identities through transaction analysis.

• Private keys are encrypted — Your wallet private keys are AES-256 encrypted and stored in your encrypted vault. We cannot access them.

• Transaction data — We do not store blockchain transaction data on our servers. Wallet balances and transaction history are fetched directly from blockchain networks in real-time.

FortressDrive has no control over blockchain networks and cannot reverse, modify, or censor blockchain transactions.

13. AI Assistant Privacy

FortressDrive uses OpenAI as its third-party AI provider and Replit AI Integrations as the managed gateway used to reach OpenAI. No AI chat, AI transcription, or AI financial-analysis data is sent to either service until you grant the current version of the in-app AI data-sharing permission.

• Core AI data may include your name, current and previous messages in the conversation, and content you deliberately attach or record.

• Optional Workspace Context is off by default. If enabled, relevant excerpts from notes, goals, journal entries, and saved AI memories may be included with requests.

• Optional AI Financial Analysis requires a separate opt-in and category selection. Only the selected aggregate categories are sent.

• You can decline AI permission and continue using non-AI FortressDrive features. You can revoke or change permission at Profile & Settings → AI data sharing.

• FortressDrive stores AI conversations in your account so you can access history. You may delete conversations, and account deletion removes AI history under our deletion process.

• OpenAI's API data policy applies. API content is not used to train OpenAI models by default; standard abuse-monitoring logs may be retained for up to 30 days unless a stricter retention control applies.

For maximum privacy, avoid sharing highly sensitive personal information (SSN, financial account numbers, etc.) in AI Assistant conversations.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

• We will update the "Last Updated" date at the bottom of this page.

• For significant changes, we will notify you via email or through the Platform.

• Your continued use of the Platform after changes constitutes acceptance of the updated policy.

We encourage you to review this Privacy Policy periodically.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us through the Platform's support channels.

For data protection inquiries from EEA residents, you may also contact your local data protection authority.

This Privacy Policy was last updated on September 22, 2026.

By using FortressDrive, you acknowledge that you have read and understood this Privacy Policy.

View our Terms & Conditions