Privacy policy

This explains what personal data Fóir holds, why, and what you can ask us to do with it. It covers two different groups of people, and the distinction matters throughout.

Two groups of people

The first group is you: the person with a Fóir account, who signs in to the admin, is named on a workspace, and pays for a plan. We are the data controller for that.

The second group is your end users: the people who sign in to an application you have built on Fóir. For them you are the controller and we are a processor acting on your instructions. We hold their data because you asked us to, and we do not decide what it is used for.

What we hold about account holders

Your name and email address, which come from how you signed up. Authentication records, meaning credentials or the identifier your chosen provider returns, plus session and refresh tokens.

Records of what you did in the platform: the workspace and project you acted in, the action, and when. This is how the audit trail works and how we investigate a problem you report.

Billing details. Card numbers are handled by our payment processor and never reach our systems; we hold the subscription, the plan and the usage counted against it.

What we hold on your behalf

Whatever your models describe. Fóir does not decide the shape of your content, so if a model has a field for a date of birth then that is what is stored.

If you use hosted sign-in, we hold your end users' credentials or provider identifiers, their sessions, and any profile fields you have modelled. If you use notifications, we hold the addresses or device tokens needed to deliver them.

We do not use your content to train models. If you use the assistant or another AI feature, the content you send to it is processed by the AI provider that serves it, which is OpenAI or Anthropic. If you turn on semantic search for a project, the text of its records and notes is sent to OpenAI to be turned into embeddings. That happens in the background whenever content changes, so it applies even in a project where nobody uses an AI feature directly.

Apps you connect

When you connect an app to a project, such as Shopify, it writes into your project only what its setup allows, and the access the other service granted it is kept encrypted in your project's vault. What it writes is your content, and we hold it as your processor like anything else in the project.

Some services send their privacy requests to the app rather than to you, so Fóir answers them for you and records each one where you can read it:

  • A customer asks for their data (Shopify's customer data request). Fóir answers from that customer's profile in your project.
  • A customer asks to be erased (Shopify's customer redaction). Fóir deletes that customer's profile and the link to their store account. The customer is deleted too, unless something else in your project still belongs to them, such as another way of signing in or records of their own; the record of the request says what kept them.
  • A store is erased after removing the app (Shopify's shop redaction). Fóir ends the connection. The store's products, collections and customers already in your project stay, because they are your own data in your own system and you are their controller; delete them as you would any other content. The connection's stored access, which no longer works, is removed when you remove the app from your project.

Why we are allowed to hold it

For account holders: to perform the contract you entered when you created an account, and our legitimate interest in keeping the service secure and working.

For end-user data: your instructions, under the terms you agreed when you created a project. Your own lawful basis for collecting it is yours to establish and to tell your users about.

Who else processes it

We use a small number of sub-processors, each for a specific job. This is the full list, with what each one can reach.

  • Hetzner hosts the application and its databases, in Nuremberg, Germany, and terminates TLS for custom sign-in domains. It can reach all customer data.
  • Cloudflare stores and delivers the files you upload, holds our database backups, runs our DNS and hosts our web applications. It can reach those files and backups, and the traffic that passes through it.
  • Railway hosted the application and its databases before the move to Hetzner. It holds a copy of the databases until that service is retired.
  • Stripe handles payments and billing, and holds account and billing details.
  • Resend delivers transactional email, so it sees the recipient's address and the content of the message.
  • Sentry tracks errors. Its diagnostic data can include the context of the request that failed.
  • PostHog, on its EU instance, records product analytics, session replay with all text and input values masked, and the bug reports you send us from the admin.
  • OpenAI serves AI features and semantic search when you use them. It receives the content you send to an AI feature, and the text of records and notes in a project with semantic search turned on.
  • Anthropic serves AI features when you use them, and receives the content you send to them.
  • Google, Apple, Microsoft and GitLab are sign-in providers, used only where you enable one. They receive authentication identifiers.
  • Apple and Google deliver push notifications when you use them, and receive device tokens and the content of the notification.
  • Infisical manages secrets for our own infrastructure and reaches no customer data.

We do not sell personal data and we do not share it for advertising. If we add or change a sub-processor we will update this page.

Data Processing Agreement

When we hold your end users' data we do it as your processor, and a Data Processing Agreement governs that relationship.

We provide one on request: write to info@foir.io. How we protect what we hold is described on the security page.

Where it is held

Content and database records are held in the EU, in Germany. Files you upload are stored in Cloudflare's Western Europe region. Some sub-processors operate globally distributed networks, so a request may be served from an edge location near the person making it.

Where data moves outside the UK or EEA, it is covered by the standard contractual clauses or an equivalent safeguard in our agreement with that provider.

How long we keep it

Content lives as long as your project does. Deleting a record removes it and its versions; deleting a project removes what it held.

Audit and event records are kept for a bounded window and then expire. Backups roll on their own schedule, so something you deleted may persist in a backup for a short period before it ages out.

If you close your account we remove your workspace data after a grace period, which exists so an accidental closure can be undone.

What you can ask for

You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Write to hello@foir.dev and we will respond.

You do not need to ask us for an export. Every plan can produce a Postgres database containing your project, at any time, without involving us.

If your end user asks you for their data, you can serve that yourself: it is in your project and you control it. If you need our help, ask.

Complaints

If you think we have handled your data badly, tell us first and we will try to put it right. You also have the right to complain to your data protection regulator.