# Privacy Policy

> How we handle personal data across the Frontminder platform.

Source: https://frontminder.com/privacy · Frontminder — the AI agent platform for business (frontminder.com) · Updated: 2026-09-11



**Last updated: September 11, 2026**

Frontminder ("**Frontminder**," "**we**," "**us**," or "**our**"), operated by an independent individual (a sole operator, not an incorporated business), provides a platform for creating AI-powered chat agents that answer questions on a business's website and messaging channels and capture leads (the "**Service**"). This Privacy Policy explains what personal data we process, why, how we share it, and the choices and rights you have.

This policy covers two audiences. **Customers** are the businesses that create an account and operate agents. **End users** are the people who chat with an agent on a customer's website or channel. Where we act as a **processor** on a customer's behalf, that customer is the **controller** of the end-user data and its own privacy notice governs; see our [Data Processing Addendum](/dpa).

## Information we collect

- **Account data.** When a customer signs up we collect a name, email address, password (stored only as a hash), and optional profile and billing details.
- **Content you provide.** Agent instructions, knowledge-base documents, product data, and configuration you upload to power your agents.
- **Conversation data.** Messages exchanged between end users and agents, including any information an end user chooses to share (for example a name, email, or phone number submitted as a lead).
- **Usage and device data.** Log data such as IP address, browser type, timestamps, pages viewed, and diagnostic events, used to operate, secure, and improve the Service.
- **Payment data.** Subscription and payment status. Card details are handled by our payment processor and are not stored on our servers.

## How we use information

We are an independent, individually operated service, not an incorporated business. We keep our data practices deliberately simple: we process personal data only to run the Service, we do **not** sell it, and we make no promises beyond acting in good faith and in line with the applicable norms we are subject to. Personal data is processed on infrastructure and services located in the **United States and/or the European Union**.

We use personal data to provide and maintain the Service; to generate agent replies; to authenticate users and secure accounts; to process payments and manage subscriptions; to send transactional and lifecycle email (such as verification, password reset, and usage notices); to provide support; to detect and prevent fraud and abuse; and to comply with legal obligations. We do **not** sell personal data, and we do **not** use end-user conversation content to train our own foundation models.

## AI processing and sub-processors

Agent replies are generated by third-party large-language-model providers acting as our sub-processors. Before content is sent to a model it may be optionally masked to remove certain personal data (an add-on feature). We use a limited set of infrastructure and service sub-processors — model providers, email delivery, payments, messaging, and hosting. The current list, with each provider's role, is maintained at [Sub-processors](/subprocessors). Some sub-processors may process data outside your country; where required we rely on appropriate safeguards for such transfers.

## How we share information

We share personal data only with: (a) sub-processors that perform services on our behalf under contract; (b) a customer, for conversations and leads captured by that customer's agents; (c) authorities when required by law or to protect rights and safety; and (d) a successor in the event of a merger, acquisition, or asset sale, subject to this policy.

## Data retention

We retain account and content data for as long as an account is active and as needed to provide the Service, then delete or de-identify it within a commercially reasonable period, unless a longer period is required by law. Customers can delete conversations, leads, and knowledge-base content from within the Service, and can **close their account** from Settings → Account, which removes their personal information (contact details are scrubbed and captured-lead contact data is redacted; records required for financial and legal purposes are retained).

## Security

We use technical and organizational measures designed to protect personal data, including encryption in transit, hashed credentials, access controls, and audit logging. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

## Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. Residents of California and other U.S. states may have rights under applicable state privacy laws, including the right not to be discriminated against for exercising them. End users should direct requests to the customer that operates the agent they interacted with; we will assist that customer as its processor. To exercise rights in data for which we are the controller, contact us at **support@frontminder.com**.

## Children

The Service is not directed to children under 13 (or the age defined by local law), and we do not knowingly collect their personal data.

## Changes to this policy

We may update this policy from time to time. Material changes will be signaled by updating the date above and, where appropriate, by additional notice.

## Contact

Questions about this policy or our data practices can be sent to **support@frontminder.com**.
