Data Controller and Contact
Swiftaw SAS is the data controller for everything processed on Fortized. In plain terms, we're the company that decides what gets collected and why, and we're the ones you hold to it.
Got a data question, want a copy of what we hold, or need to make a complaint? Reach Fortized Support and mark your message Data Protection Request. We'll get back to you within 30 days, or up to 90 for the complicated ones, which is what the GDPR allows.
What Data We Collect
When you sign up and use Fortized, you hand us:
- Email address: for account creation, recovery, and login
- Password: hashed and encrypted; we never see it in readable form
- Username and display name: public profile identifiers
- Date of birth: used to determine age tier (child, teen, adult) and enforce age-gating
- Profile picture: optional image you upload
- Bio and profile information: text you choose to display
- Custom status: emoji and text you set
- Pronouns: optional information you provide
- Social links: optional links to external profiles
Some things we pick up on our own as you use Fortized:
- Messages and content: every message, image, video, emoji, file you post (for display and moderation)
- Activity metadata: timestamps, bastion memberships, friends list, channel access, game detection
- Voice and video metadata: participant lists, join/leave timestamps, duration (not recordings themselves)
- Account activity: login times, device information, IP address, browser type, operating system
- Onyx balance and transaction history: how much you earned, spent, and when
- Fortshop purchases: what you bought, when, and at what price
- Settings and preferences: notification settings, theme choices, language, accessibility preferences
- Logging data: we log actions for security and debugging (login attempts, content moderation actions, account changes)
If you connect Spotify to Fortized, we receive:
- Your currently playing track and album art (refreshed every 10-15 seconds)
- Your Spotify display name and profile picture
- A Spotify refresh token (stored server-side, never shared with anyone)
We never see your Spotify password. Anything that comes from Spotify is covered by Spotify's own Privacy Policy.
Why We Collect Data
We only collect and use your data for reasons the law recognises. Ours are:
- Service provision: to deliver Fortized (messages, voice, storage, profiles, etc.)
- Contractual performance: to manage your account, purchases, subscriptions, and Onyx transactions
- Legal compliance: to obey laws, respond to legal requests, enforce these Terms
- Safety and security: to prevent abuse, fraud, harassment, and illegal activity
- Moderation: to detect and remove content that violates these Terms (via automated systems and human review)
- Legitimate interest: to improve Fortized, analyze usage patterns, debug bugs, and optimize performance
- Your consent: if you opt in to marketing emails or beta features
How We Store and Protect Data
Your data lives on encrypted servers at Swiftaw's datacenter in Orleans, France and Supabase's datacenter in Paris, France. It's encrypted on the way there (TLS/HTTPS) and while it sits at rest (AES-256 or equivalent). Passwords are hashed with a standard algorithm (bcrypt or similar), so we never store them in a form anyone can read.
Only Swiftaw staff and contractors who actually need your data to run the service can get to it, and they're bound by confidentiality agreements. No one here can wander into your private messages or raw data on a whim. It takes a proper, authorised reason, like answering a valid law-enforcement request.
We keep encrypted backups in secure facilities so nothing gets lost. If something goes badly wrong, we can bring your account and your data back from them.
Data Retention
While your account is open: we keep your data for as long as you're with us, plus however long the law or an open dispute needs us to.
When you delete your account: we clear your data from our live systems within 30 days, and from backups within 90. A few things may stick around longer if the law says so, or if your content is caught up in a legal dispute like a lawsuit.
Law-enforcement holds: if law enforcement asks us to preserve your data, we may hold onto it for as long as that request stands, even after you've deleted your account.
International Data Transfers
We're a French company, and we keep and process all of your data inside the European Union, full stop. It sits at Swiftaw's datacenter in Orleans and Supabase's in Paris. Under normal operations, none of it leaves the EU.
If we ever do need to move data outside the EU to keep Fortized running, we'll lean on Standard Contractual Clauses and other tools the European Commission has approved, so your data stays protected to the same standard the GDPR expects. We'll update this page if that day comes.
Your GDPR Rights
If you're in the EU, or somewhere with similar data-protection laws, these are yours:
- Access: Request a copy of all your personal data we hold. We will provide it in a machine-readable format.
- Rectification: Correct or update inaccurate data (e.g., change your display name).
- Erasure: Request deletion of your data ("right to be forgotten"), subject to legal and operational limits.
- Restriction: Ask us to limit how we process your data (e.g., suspend automated moderation while you appeal).
- Portability: Get your data in a structured, portable format and transfer it to another service.
- Object: Refuse processing of your data for certain purposes (e.g., opt out of analytics).
- Withdraw consent: If we rely on your consent, you can withdraw it at any time (though this won't affect prior processing).
To use any of these, message Fortized Support and tell us plainly what you want. We'll reply within 30 days, or up to 90 for the tricky ones.
Cookies and Tracking
We don't use cookies to track you or to advertise. The only ones we set are the essentials, for things like:
- Session management (keeping you logged in)
- Security (preventing CSRF attacks)
- Remembering user preferences (theme, language)
You can switch cookies off in your browser, though a few things on Fortized might stop working right if you do. We don't use third-party analytics that follow you around other sites.
Data Breaches
If a breach ever puts your personal data at risk, here's what we'll do:
- Notify you and affected users without undue delay (as required by GDPR, within 72 hours of discovery)
- Describe the nature and scope of the breach
- Provide advice on how to protect yourself
- Notify relevant authorities as required by law
We carry cyber insurance and keep incident-response procedures ready so we can move fast and keep the damage small.
Changes to This Policy
We'll update this policy now and then. When something meaningful changes, we'll tell you in the app or by email at least 30 days before it kicks in. Keep using Fortized after that window and you're accepting the new version.