Privacy
FunGen does its work on your computer. Your videos, your scripts, your edits and every AI tracker run stay there. This page is the full list of what does leave, so you do not have to take that on trust.
What we do not collect
We never receive any of the following, whatever your settings say:
- Your videos, or any frame of them.
- Your funscripts, projects, chapters and edits.
- File names, folder names and paths.
- Titles, or anything identifying what you opened or watched.
One exception, and you choose it. The Handy over the internet, and the Autoblow, play a script by uploading it to their makers' servers, so picking one of those modes sends that script's timings and positions to the device maker. It does not come to us. No file name, folder or title goes with it. Bluetooth and local modes send nothing.
All AI generation runs locally, on your own machine. Nothing is uploaded for processing, and there is no cloud step in the pipeline.
The licence check
When FunGen starts, and from time to time while it is open, it checks for a newer version and confirms your licence. It runs in the background and does not interrupt what you are doing.
What follows describes the version you can download today (2.5.3-beta, published 5 August 2026). It is not what the application does any more, and the difference is set out below it. We would rather describe the build in your hands than the one in our source.
That request carries:
- Two one-way codes, one for your machine and one for the user account on it. Neither can be reversed on its own into a name, an address or a serial number. They are not anonymous, though, and we would rather say so: we hold the email you bought with, and these codes are what tie a licence check to that purchase. They tell one machine from another, and they are how a pass is matched to its owner.
- Your licence status, and, when a pass is present but not working, a code saying why.
- Basic details of the install: app version, operating system, processor type and app language.
- Three running totals: how many funscripts this install has generated using the Pro models, and how many full-video tracker sweeps it has run with them, counted separately for 2D and VR. Totals only. Not when, not on what, not for how long.
None of that is sent any more, and none of it is kept. On 24 August 2026 the machinery that built and sent it was deleted from the application rather than switched off: the codes, the counters, the install details and the sealing that carried them. What is left is a plain request for the version list and the entitlement data that goes with it, with no body, no identifier and nothing attached to it. You can watch it with any proxy.
The three running totals are gone from your machine as well. The files that held them are deleted the next time you open the app, including the ones kept outside the FunGen folder.
But the published build still sends. 2.5.3-beta is still the current download, so every install running it, and every new one, continues to send the list above about once an hour until a newer release reaches it. Our end no longer reads it, stores it, or acts on it: the request arrives, nothing looks at it, and it is discarded when the request ends. We would rather say that plainly than let "we stopped collecting" stand for something that is only true of our source code.
Like any request over the internet, ours arrives with the address it came from. We no longer keep it, or a hash of it, or the country. Cloudflare answer the request on our behalf and see the connection as any host would, and they retain their own record of it: which address was asked for, what the answer was, and roughly where it came from. That is part of using them and we cannot switch it off on the plan this site runs on.
Licence-check records are cut off at 365 days. The cutoff is applied when our database is opened, rather than running on a timer. The service that used to receive these records was retired on 22 August 2026 and its store was removed, so there is no second copy left to age out. That service's code had described a 30 day deletion which was not in fact running, and earlier wording on this page repeated it.
The usage counters we removed
Until August 2026 the app also kept coarse usage counts: how long it had been open, how many sessions you had run, how many videos you had opened, how many tracker runs you had done, and whether your graphics card had worked. Counts, not content: never a file, a folder or a title.
What they were for. Three things, and none of them was advertising or resale. Which parts of the app people actually reached, so the work went where it mattered instead of where we guessed. Where the licensing was being defeated, because one pass running on many machines is what an unpaid copy looks like from the outside. And what the app was worth to the people using it, which is what the price was set from. The basis was our own legitimate interest in building and defending something we sell, not consent: there was no setting for them, in any released version.
Then we measured them. We tested those counters against the checks that actually decide whether a pass is refused, and the outcome never changed when a counter was taken away. They were not doing the job they were kept for. So they came out rather than being trimmed, and on 24 August 2026 the collected counts were deleted from our records along with the rows that carried them. A small number of records are held back where the law requires it, and copies survive in the backup snapshots described further down, which are pruned on a schedule.
Collection stopped on 22 August 2026, at 11:33 UTC. It stopped in two steps, and only the second one bit. The counters were taken out of the application source on 18 August, but that change is not in a published release: 2.5.3-beta, published on 5 August, is still the current download and it still sends them. On 22 August the service that received them was replaced, and it no longer accepts or stores anything at all.
The second step is what makes that date a fact rather than a promise about a future version. A copy of the app you have not updated yet may still try to send; nothing is recorded when it does.
Nothing else is measured
That is the whole list. Beyond the counter above, FunGen does not measure how long you use it, which features you open, what you watch or edit, how long anything took, or anything about your hardware other than the two words already listed. None of it is collected, so none of it can be sent.
There is no setting that changes any of this, and nothing here to switch off. What the app sends is the licence check itself, so it lasts as long as the licence does. If that is not a trade you want to make, the list above is exactly what you would be declining, which is why it is written out in full rather than summarised.
No account
There is no sign-up, no sign-in and no account. A Pro Pass is a file you load; it is verified on your machine, and it stays there.
Who else handles your data
We use three companies, and only for the jobs named here. None of them is an advertiser or a data broker, and none receives anything about what you do in the app.
- Cloudflare serves this website and answers the app's version and entitlement check.
- GitHub hosts the downloads and the data the app fetches alongside them.
- Resend sends licence email. If you buy a pass, your email address and the message we send you pass through Resend on the way to you. Our own mailbox is Proton.
This website
fungen.app uses Umami for visitor statistics. It sets no cookies, does not track you across other sites, and does not build a profile of you. It counts page views and which links get clicked, so we know which pages are worth writing.
Counting on your own machine
The free tier allows a limited number of generations, so the app has to keep a count. It is kept in a few small files on your own computer, in more than one place, so that clearing one of them does not silently reset the allowance. They hold counts and nothing else: no titles, no file names, no history of what you did.
Two things about them are worth saying plainly rather than leaving you to find out. They are not all inside the FunGen data folder, and they are not removed when you uninstall the app. If you want them gone, ask us and we will tell you exactly where they are on your system. Nothing in them is ever transmitted: they exist so the app can enforce its own limit offline, not so we can learn anything.
Who is responsible, and on what basis
FunGen is made and run by one person, not a company, reachable at [email protected]. That address reaches the person who decides what happens to your data, and it is the right address for any request on this page.
The reasons we are allowed to handle the little we handle:
- To give you what you bought. Your email address and the record of your pass exist so a licence can be issued to you and reissued if you lose it. Without them there is no way to give you the thing you paid for.
- To keep licences honest. The one-way codes for a pass and a machine let a shared or refunded pass be withdrawn. This is our own legitimate interest in not having the product taken without payment, balanced against the fact that the codes identify a licence rather than a person, and that a purchased licence is never withdrawn over anything anyone says. The pass policy is the written limit on that.
- Because the law requires it. The accounting record of a payment (amount, date, reference) has to be kept, and is kept even after an erasure. The address attached to it is not.
How long. Licence records last as long as the licence, and the accounting records for as long as we are required to keep them.
Backups, honestly. We keep encrypted backups of our own records, and older copies are removed as newer ones are made rather than on a fixed calendar. An erasure is written to a separate log and re-applied if a backup is ever restored, so a restore cannot bring somebody back who asked to be removed; that log currently has nothing in it, because nobody has asked yet. If you ask for an erasure we will tell you when the last backup that could still contain you is expected to go.
Where it goes. The companies named above are based in the United States and handle this data on our behalf under their own data processing terms. We do not sell anything to anyone, and none of them receives anything about what you do in the app.
Decisions made by machine. Two things happen without a person, and both are lookups rather than judgements. A pass stops working once its end date has passed: the date either has passed or it has not. And a pass that does not appear in our records at all stops working when it is presented from a machine that is already blocked: it is on the list or it is not.
Nothing else about your pass acts on its own. The rule we hold ourselves to is that a lookup may act and an inference may not.
Blocking a machine is a person's decision. It is a conclusion about someone rather than a fact we can look up, so no automatic process makes it and none is permitted to. That has been the rule since 23 August 2026. Before that date an automatic check could restrict a machine on an inference drawn from these records, and that capability has been deleted rather than adjusted.
A block is not final: say so and a person will look at it again, and if we got it wrong we fix it the same day and you keep the pass. We have got it wrong before, and would rather reissue a pass wrongly than take one wrongly.
If you are not satisfied. You can complain to your national data protection authority. In France that is the CNIL; every EU country has an equivalent, and you can go to the one where you live.
Ask what we hold, or have it removed
Write to [email protected] and ask what we hold about you, or ask for it to be deleted. Neither needs a reason. You get a copy of the data itself, every field we hold with a plain-English dictionary of what each one means, and a deletion removes the records tied to your pass and your machines. Two things are kept: the accounting record of a payment, which we are required to retain, and the one-way code of a withdrawn pass, so the withdrawal is not undone. By then neither is attached to your name.
The same address covers every right you have: a copy of what we hold, a correction of anything wrong, deletion, a pause on our using it, and a copy in a portable form. They are normally free and none needs a reason. We answer within one month, and if a request is complex enough to need longer we tell you inside that month, as the law allows.
Objecting to our using your data at all
Separately from the rights above, you can object to our using your data where we rely on our own legitimate interest, which is the basis described under "Who is responsible, and on what basis". Write to the same address and say you object. You do not have to give a reason, though telling us about your situation helps us weigh it.
We then stop, unless we can show compelling grounds that override your interests, or we need the data to establish or defend a legal claim. If we think one of those applies we say which, in writing, so you can take it further if you disagree.