Privacy notice for Fred
The German version of this notice is the legally binding original. This English text is a translation for convenience. If the two differ, the German text prevails.
This notice explains how SFJ Capital UG processes personal data when you use Fred at fredgoals.com and app.fredgoals.com. It does not cover hejsfj.com, our social media profiles, or Sunny Days Ahead. Each of those has its own notice.
1. Controller
The controller is SFJ Capital UG (haftungsbeschränkt), Dhauner Straße 42, 67067 Ludwigshafen am Rhein, Germany, represented by the managing director Sebastian Frederik Jacobsen, commercial register HRB 67315, Amtsgericht Ludwigshafen am Rhein, email hello@hejsfj.com. Privacy requests can be sent to that address. If a data-protection officer is appointed, the officer’s contact details will be added here.
2. Data we process
Depending on how you use Fred, we process:
- Account data you submit, such as your email address and authentication identifiers. We do not store your password in plain text.
- Content you store: goals, milestones, descriptions, dates, steps, and vision-board material.
- If you use an AI suggestion, the text you submit for that request and the suggestion returned.
- If you buy a paid plan, subscription status and billing metadata. Full card numbers are collected by the payment provider, not stored by us.
- Technical data such as IP address, device and browser type, timestamps, and security logs.
- Support messages you send us.
3. Special categories
Fred does not ask for special-category data under Art. 9 GDPR. Do not put health data, religious beliefs, political opinions, or similar information into a goal. If you choose to store such information anyway, we process it only as part of the content you asked us to host, so that we can provide the service, and you can delete it.
4. Purposes and legal bases
- Creating your account and providing the goal service you asked for: Art. 6(1)(b) GDPR.
- Generating an AI suggestion you requested: Art. 6(1)(b) GDPR.
- Taking payment for a plan you ordered, and keeping invoices: Art. 6(1)(b) and Art. 6(1)(c) GDPR.
- Security logs, abuse prevention, and keeping the service available: Art. 6(1)(f) GDPR. You may object under Art. 21 GDPR. Strictly necessary storage on your device also relies on § 25(2) No. 2 TDDDG.
- Non-essential analytics or marketing storage on your device: only with consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR. Consent is separate from these terms and can be withdrawn.
- Service messages about your account or a contract: Art. 6(1)(b) GDPR. Promotional email only where § 7 of the German Unfair Competition Act allows it, or with consent.
5. AI suggestions
Fred’s optional suggestions are produced by an AI system. Art. 50 of Regulation (EU) 2024/1689 (the AI Act) has applied since 2 August 2026. When you use the feature:
- You are told that you are interacting with an AI system. The suggestion is labelled as machine-generated.
- The suggestion can be wrong, incomplete, or unsuitable. It is not medical, legal, financial, psychological, or employment advice, and it is not a decision about you.
- You decide whether to keep or follow it. We do not make a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22 GDPR).
- We do not use the feature for practices prohibited by Art. 5 of the AI Act, including social scoring, emotion recognition, or biometric categorisation. We do not use your private goals to train general-purpose models.
6. Recipients
- Hosting and infrastructure providers that run Fred for us, as processors under Art. 28 GDPR.
- An AI model provider, when you request a suggestion, as a processor where a processing contract is in place. If a provider determines purposes of its own, it is an independent controller for those purposes and we say so before that processing starts.
- Stripe Payments Europe, Limited (and, where relevant, its affiliates), when you pay. Stripe is a processor for the billing steps we instruct and an independent controller for processing it must do under payment and anti-fraud law.
- Professional advisers who are bound to confidentiality, where we need them to operate or to defend the service.
- Public authorities, where the law requires disclosure.
We do not sell personal data and we do not share it for another person’s advertising. This notice names a category of recipient rather than a product-analytics brand. If we later add a non-essential analytics tool, we will ask for consent before it stores or reads information on your device and we will name it in an updated version of this notice.
7. Transfers outside the EEA
Some providers are in the United States or another country outside the EEA. Where the recipient is certified under the EU–U.S. Data Privacy Framework, the European Commission’s adequacy decision can apply. Otherwise we use the EU Standard Contractual Clauses and supplementary measures required by Chapter V GDPR. You can ask hello@hejsfj.com for a copy or a summary of the safeguards.
8. Retention
We keep account and goal content for as long as your account is open. After you close the account, or after we close it, we delete or anonymise that content within 30 days, except where a statutory retention period applies. Invoices and related tax records are kept for the periods in the German Commercial Code (HGB) and Fiscal Code (AO), typically up to 10 years. An AI prompt is kept only as long as needed to return the suggestion and to secure the service, unless you save the result into a goal. Backups are overwritten on a rolling cycle. Security logs are kept for a short operational period and then deleted or anonymised.
9. Export and switching
You can ask us, at hello@hejsfj.com, for an export of the goals and account data you provided, in a structured, commonly used, machine-readable format such as JSON or CSV. That covers portability under Art. 20 GDPR and, where Fred is a data processing service under Regulation (EU) 2023/2854 (the Data Act, applicable since 12 September 2025), your right to port data when you switch. We do not charge a fee for that export. We do not charge switching fees that the Data Act prohibits, including after switching charges end on 12 January 2027.
10. Data required for the contract
An email address and authentication data are required to open an account. You do not have to fill a goal with any particular private fact. If you do not provide the account data, we cannot open the account. Payment data is required only if you choose a paid plan, and you provide it to the payment provider.
11. Your rights
Subject to the statutory conditions, you have the right to:
- Access your personal data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interests, and object at any time to direct marketing (Art. 21 GDPR)
- Withdraw consent at any time with effect for the future, where processing is based on consent (Art. 7(3) GDPR)
- Not be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects (Art. 22 GDPR)
To exercise these rights, email hello@hejsfj.com. We may ask you to confirm your identity before we disclose data. We reply within one month, extended only in the cases Art. 12(3) GDPR allows.
You may lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement (Art. 77 GDPR). The authority competent for SFJ Capital UG is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34
55116 Mainz
Germany
Website: https://www.datenschutz.rlp.de
12. Security
We use HTTPS/TLS in transit, access controls, and contracts with processors (Art. 28 GDPR and Art. 32 GDPR). No method of transmission is perfectly secure. If a personal-data breach that we must report occurs, we notify the supervisory authority and, where Art. 34 GDPR requires it, you. We will not ask you for your password or your full card number by email.
13. Children
Fred is not directed at children under 16. We do not knowingly create accounts for children under 16. A paid contract requires the legal capacity to contract, which in Germany means being 18 or having a parent or guardian contract for you.
14. Changes
We update this notice when the service or the law changes. The date on the page is the date of the current version. If a change materially affects a paid account and the law requires notice, we tell you before it applies.