Draft policy for publisher review · not yet published or effective
Fizzy

Privacy Policy

Prepared 11 October 2026. Fizzy is provided by Anunda Boonserm, trading as Asymmetry-lab. Contact: support@asymmetry-lab.com.

What Fizzy processes

Fizzy accounts are separate from KhaiHub. Account records include an identifier, your chosen display name, public passkey credential keys, authentication counters, credential metadata and a creation date. Fizzy does not receive fingerprints or account passwords. Connected-computer records include an identifier, the name you give the computer, its account association, a hashed device credential, status and creation date. Authorization records include client details and tokens needed to connect your account to ChatGPT.

To carry out a request, Fizzy can process selected source files or other file content, commands and their output, application or webpage text, UI state, and screenshots. This content can pass from your paired computer through the Fizzy service to ChatGPT. The file tools use workspace folders selected on your computer. Computer Use can interact with applications, webpages and accounts available on that computer within your system permissions.

Where information is kept

The gateway implementation keeps pending operation payloads in memory and removes them when completed, disconnected or timed out. It does not write those payloads or screenshots to a gateway history database. Cloudflare Workers hosts the Public gateway. Account and device records are stored in Cloudflare SQLite Durable Objects; OAuth authorization records use a dedicated Cloudflare KV namespace. Application request logging is disabled. Cloudflare still processes traffic and network metadata under its own service practices. This is TLS transport, not encryption that hides tool payloads from the service provider. The browser sign-in session lasts up to 12 hours; challenges and one-time computer pairing codes expire after ten minutes. OAuth access tokens last one hour and refresh grants last up to 30 days. Dynamic client registrations expire after 90 days. Request limits use a secret-salted hash of the connecting address instead of storing the raw IP in account records. No single-country storage restriction is configured.

Your computer keeps its own device credential, workspace configuration, file-version observations, command tasks, logs, and edit journals so it can report results and check later changes. Journals or logs can contain file content or command output. These remain on that computer unless returned for your request or shared with Support. File-version observations are logically valid for 24 hours; other local state has no automatic deletion schedule in this release.

Purpose and service providers

Fizzy uses the information to authenticate accounts, connect the correct computer, execute the requested operation, return its result and investigate support requests. OpenAI processes information returned to ChatGPT under its own applicable terms and privacy practices. The Support address uses Cloudflare Email Routing to deliver messages to the provider's Gmail inbox; Cloudflare and Google process those messages as part of delivery and email storage. Do not include credentials or unrelated private content in a Support message. Cloudflare hosts the gateway, account state and small website assets. GitHub hosts versioned app downloads. Provider recovery copies can have separate retention; this policy does not promise immediate erasure from provider backups or a specific-country storage guarantee.

Support-message retention

We keep Support correspondence and its attachments while a case is open and for 90 days after the case is closed. At the end of that period, we permanently delete that correspondence from our Support mailbox and delete any working copies under our control. This period is measured from case closure, not from the date a message was received. Provider recovery copies can have separate retention.

Disconnecting and deletion

You can disconnect a computer, revoke an OAuth connection, sign out or delete your account from the account page. A delivered operation is not automatically replayed after a connection failure. Revocation prevents new authorized device requests; it does not undo an action already executed or remove files and logs from your computer.

Account deletion disables computer and authorization access and removes active account, device and passkey records. Provider recovery copies can have separate retention. Contact Support for other requests concerning your personal information. Deleting local files and state is a separate action on your computer. Keep a synced or second passkey: this release has no Support reset flow for a lost passkey.

Security and sensitive content

Public connections use HTTPS. Passkey private keys remain with your authenticator. Server-side device credentials are hashed. Keep your computer connection, system permissions and credentials under your control. Fizzy can return private content when you request a tool action that reads it; choose appropriate files and applications and review sensitive actions.

Changes

Material changes to these practices will be reflected in the published policy and its effective date. The publisher confirmed the Support retention period on 11 October 2026. This draft still requires final publisher approval before it takes effect.