FuryRoadMap

Privacy policy

Last updated

What FuryRoadMap collects, why, who processes it, and how to exercise your rights.

Who is responsible

FuryRoadMap is run by an individual entrepreneur (entrepreneur individuel) established in France. That person is the data controller for the personal data described here. Contact: hello@furyroadmap.fun.

What we collect

Only what the service needs to work:

  • Your account. Your email address. If you sign in with Google or GitHub, the name and profile details that service shares with us.
  • Your roadmap. Its name, slug, tagline, theme and items. A public roadmap is meant to be seen: anyone can read it on your site, on its hosted page and through the public API.
  • Sign-in records. Our authentication provider keeps a log of sign-ins with the IP address and browser, to secure accounts.
  • Product analytics. Only inside the app, when analytics are on: page views and three events (roadmap created, item created, install prompt copied), with the page address, referrer, browser, operating system and device type. They are not linked to your account, and your IP address is discarded. No cookies, no session recording, no advertising.
  • Server logs. Our host records requests and errors, which can include IP addresses and your account ID.

You need an email address to create an account; without it we cannot run one. Everything else you add is up to you.

Visitors of sites that embed a roadmap

When someone opens a page that embeds a FuryRoadMap roadmap, their browser loads the roadmap from our servers. We use the IP address of that request to deliver the response and to limit abuse, in memory; our network provider’s and host’s request logs may keep it (see How long we keep it). We never use it to identify or follow anyone.

The script embed then sends one anonymous event saying it was displayed: the roadmap’s slug, the host name of the page and the layout. The visitor’s IP address is not passed on to our analytics provider. The iframe and the hosted page send no event. None of them sets a cookie or stores anything on the visitor’s device.

Why, and on what legal basis

  • Creating your account, signing you in and running your roadmap: performance of our contract with you.
  • Delivering an embedded or hosted roadmap to the people who view it, and counting how often embeds are displayed: our legitimate interest, and our customers’, in showing the roadmap they chose to publish.
  • Securing accounts, preventing abuse and keeping the service running: our legitimate interest in a secure, available service.
  • Understanding, in aggregate, how the product is used: our legitimate interest in improving it.
  • Answering your messages: our legitimate interest, or the contract when it concerns your account.

Cookies and local storage

We set no advertising or tracking cookies, so there is no cookie banner. When you ask for a sign-in link or sign in, we set the cookies that keep you signed in (names starting with sb-). They are strictly necessary, last up to 400 days and are removed when you sign out.

Our network provider may set a short-lived security cookie when it checks for bots.

In the editor, your browser remembers whether the single-key shortcut is on (local storage, on your device only).

Sign-in emails contain no tracking pixel and no tracked links.

Who processes it for us

These providers process data on our behalf, only to run the service:

  • Cloudflare: DNS, HTTPS and network protection in front of the site.
  • Supabase: database and authentication.
  • Railway: hosting of the application and its logs.
  • Resend: delivery of sign-in emails.
  • PostHog (EU cloud): cookieless product analytics, when enabled.

If you choose to sign in with Google or GitHub, that service handles the sign-in under its own privacy policy. We never sell personal data or share it for advertising.

Analytics run on PostHog’s EU servers, and sign-in emails are sent from Resend’s EU region. Cloudflare, Supabase, Railway, Resend and PostHog are US companies, so data may be accessed from the United States. These transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses. Ask us for a copy at hello@furyroadmap.fun.

How long we keep it

  • Account and roadmap: as long as your account exists.
  • A roadmap you delete in Settings is deleted at once, with its items. Cached public copies can take up to a day to clear.
  • To close your account, write to hello@furyroadmap.fun. We delete it and its data within 30 days.
  • Sign-in records (IP address and browser): as long as our authentication provider keeps them.
  • Server logs: as long as our host keeps them.
  • Analytics events: as long as our analytics provider keeps them.
  • Backups: copies in our providers’ backups expire on their own schedule.

Your rights

You can ask to access, correct or delete your data, to limit its use, and to receive it in a portable format. You can also tell us what should happen to your data after your death. Write to hello@furyroadmap.fun from the email address of your account. We answer within one month.

Right to object. You can object at any time to any use of your data based on our legitimate interest, including analytics. Turn on Global Privacy Control or Do Not Track in your browser and the app records no analytics, or write to hello@furyroadmap.fun.

We make no decisions about you based only on automated processing, and we do no profiling.

You can also complain to the French data protection authority, the CNIL, or to the authority of the country where you live.

Security

Data travels over HTTPS. Only your account can change your roadmap: the server checks ownership on every change, and database rules enforce it. A private roadmap is shown to no one else. Sign-in is passwordless: a one-time link or your Google or GitHub account.

Children

FuryRoadMap is a tool for businesses. It is not meant for anyone under 15.

Changes

We update this page when the service changes, for example before paid plans, imports or custom fonts open, and change the date at the top. For significant changes, we tell account holders by email first.

See also the Terms of service. Questions: hello@furyroadmap.fun.