// legal

Privacy Policy

last updated: September 9, 2026

What we collect

We collect account details you give us (name, work email, company), billing metadata from our payment processor, and the security events your connected systems send us, such as login records, network metadata and scan results.

We do not collect contents of your files, message bodies or application payloads. Agents can be configured with additional exclusions.

How we use it

Security events are processed to detect threats, correlate indicators and produce alerts and reports for your account. Account details are used to operate the service, bill correctly and send you operational messages such as incident notifications.

We do not sell your data. We do not share event data with third parties except the subprocessors listed in your Data Processing Agreement, and we do not use your data to train machine learning models.

Where data lives

Team plan customers choose EU or US data residency at signup. Enterprise customers may request custom residency. Data does not leave the selected region except for aggregated, non-identifying operational metrics.

Retention

Event data is retained for the period of your plan (7 days on Free, 90 days on Team, custom on Enterprise) and then deleted. Account records are kept until you close your account, and for 30 days after, so we can honor a grace period.

Security

All traffic is encrypted in transit with TLS 1.2 or newer and data is encrypted at rest. Access to production systems requires SSO with hardware key MFA and is logged. We run an internal vulnerability management program on our own platform.

Your rights

You can export or delete your data at any time from Settings, or by writing to us. Depending on your jurisdiction you may have rights to access, correct, port or erase your personal data, and to object to certain processing. We respond to verified requests within 30 days.

Changes

If we change this policy in a material way, we notify account owners at least 14 days before the change takes effect.

Contact

Privacy questions go to support@frailwarden.com. Data protection requests can also be sent to security@frailwarden.com.