Skip to content

Legal

Privacy Policy

Last updated: March 2026.

Who we are

Frond, Inc. is a Delaware, United States corporation with offices at 115 Sansome Street, Suite 800, San Francisco, CA 94104. We build and operate Frond, an AI knowledge assistant for teams. References to Frond, we, our, or us in this policy mean Frond, Inc..

This policy describes what information we collect, why we collect it, how we use it, and the choices you have. Questions about this policy can be sent to privacy@getfrondai.com.

What we collect

We collect information in three categories:

  • Account information. Your work email address, display name, and a hashed credential when you register. If you sign in through a third-party identity provider such as Google, we receive the profile details that provider shares with us.
  • Content from your connected sources. When you connect a source, such as Notion, Confluence, Google Drive, Zendesk, Slack, or Linear, Frond reads that source over a read-only, permission-aware connection to build your workspace index. The content belongs to you and to your organization. We process it on your behalf and use it only to answer your team's questions. Nothing is moved or copied out of your systems for any other purpose.
  • Usage and service data. Which features you use, how many questions you ask, timestamps, session identifiers, browser type, and IP address. We use this to operate, improve, and secure the service.

We do not buy personal data from data brokers and we do not build advertising profiles.

How we use your data

We use your information to:

  • Index your connected sources and answer your team's plain-language questions with verbatim citations from your own documents, tickets, and messages.
  • Operate, maintain, and improve the service, including monitoring reliability, diagnosing bugs, and planning capacity.
  • Send you transactional messages about your account and billing, and, where you have opted in, product updates.
  • Detect and prevent fraud, abuse, and security incidents.

Your connected-source content is used only to answer your team's questions. It is never used to train a shared model, improve a public model, or disclosed to other customers or organizations.

Subprocessors

To deliver the service, we share data with a small set of subprocessors, each bound by a data processing agreement:

  • Model providers. When Frond answers a question, the relevant passages from your indexed sources are sent to a model provider to compose the answer. The specific provider depends on the routing table for that question. Current providers include OpenAI; Anthropic, Google, and open models may be added as the router registry grows. Each provider is contractually prohibited from training on your data or using it for any purpose other than returning the response.
  • Hosting and infrastructure. Frond is deployed on Vercel's infrastructure. Your indexed content and account data are stored in a managed database service. Both operate under data processing agreements.
  • Payment processing. Stripe handles card transactions for Team and Business plan subscriptions. We share only the billing information required to complete a purchase. Stripe operates under its own privacy policy.
  • Monitoring. We use operational monitoring tooling that receives aggregated service-health data, not your source content or personal information.

Business plan customers can restrict which model providers the Frond router is permitted to use, including routing exclusively to open models hosted within their own infrastructure so that source content never leaves their perimeter.

Data retention and deletion

Your workspace index is retained for as long as your account is active. You can remove a connected source at any time from your workspace settings, which removes that source's content from your index immediately. You can request that we delete your account and all associated data at any time by emailing privacy@getfrondai.com. We will complete the deletion within 30 days and confirm when it is done.

Some data may be retained for a short additional period for legal or fraud-prevention purposes, after which it is permanently deleted.

Security

All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Connections from Frond to your sources are read-only by default. Access to production data is restricted to engineers with a demonstrated need, is logged, and is reviewed periodically. We conduct regular security assessments.

For a full breakdown of our security controls, see the Security page. To report a vulnerability, contact security@getfrondai.com.

Your rights

If you are located in the European Union, European Economic Area, or United Kingdom, you have rights under the GDPR or UK GDPR, including the right to access, correct, delete, or export your personal data, and to restrict or object to certain processing.

If you are a California resident, you have rights under the CCPA, including the right to know what personal data we hold, to delete it, and to opt out of any sale. We do not sell personal data.

To exercise any of these rights, email privacy@getfrondai.com. We will respond within 30 calendar days, with extensions where permitted by applicable law. We will not discriminate against you for exercising your rights.

International transfers

Frond is operated from the United States. If you access the service from outside the United States, your data may be transferred to and processed in the United States. For transfers from the EEA or UK, we rely on the European Commission Standard Contractual Clauses or the UK International Data Transfer Agreement, as applicable. You can request a copy of our transfer safeguards by contacting privacy@getfrondai.com.

Children

Frond is a professional tool for teams and organizations. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected data from a child, contact privacy@getfrondai.com and we will delete it promptly.

Changes to this policy

We may update this policy as the service evolves. If we make material changes, we will email the address on your account at least 14 days before they take effect. The date at the top of this page always reflects when the policy was last updated.

Contact

Privacy questions and data rights requests: privacy@getfrondai.com

Security concerns: security@getfrondai.com

Frond, Inc.
115 Sansome Street, Suite 800
San Francisco, CA 94104
United States