Privacy Policy
How Fenlo collects, uses, and protects your information.
1. Overview
Fenlo is a cloud-based enterprise search and knowledge management platform for teams. This Privacy Policy explains what information we collect through our website and service (collectively, the “Service”), how we use it, and what rights you have.
Fenlo is a SaaS-only product. All infrastructure is hosted and managed by Fenlo. This policy applies to the Fenlo hosted service only and does not apply to third-party services you connect to Fenlo.
2. Information We Collect
2.1 Account Information
- Authentication data: Email address, name, and profile picture provided through Google OAuth, email/password, or enterprise SSO (SAML/OIDC).
- Organization data: Organization name, member roles, and team structure.
- Preferences: Display name, role, theme preference, default app mode, and assistant configuration.
2.2 Connected Source Data
Fenlo connects to your existing tools to provide search and assistant features. We index content and metadata from these sources based on your authorization:
- Documents and knowledge bases: Titles, content, metadata, and folder hierarchy from Confluence, Notion, Google Drive, Dropbox, SharePoint, GitBook, Outline, and similar services.
- Communication: Message content and metadata from Slack, Discord, Microsoft Teams, and email (Gmail, IMAP).
- Code repositories: File paths, commit metadata, code file content, and AI-generated summaries from GitHub, GitLab, and Bitbucket.
- Project management: Task titles, descriptions, status, assignments, and due dates from Jira, Linear, Asana, ClickUp, and similar tools.
- Support and sales: Ticket content and customer data from Zendesk, Freshdesk, Salesforce, HubSpot, and similar platforms.
- Meeting transcripts: Transcripts and metadata from third-party meeting tools (e.g., Fireflies) that you connect to Fenlo. Fenlo does not record or store meeting audio.
- User-uploaded files: Documents and files you manually upload to Fenlo for indexing.
2.3 Usage and Technical Data
- IP address, browser type, device information, and operating system.
- Pages visited, features used, and interaction patterns.
- Search queries and results you interact with.
- Error logs and performance metrics.
- Session data including login timestamps, client IP, and user agent.
2.4 Payment Data
- Billing address, subscription status, and invoice history.
- Payment processing is handled by Polar.sh. We do not store credit card numbers or bank account details on our servers.
2.5 Security and Audit Data
- Audit logs: Event type, actor, timestamp, IP address, and outcome for actions like logins, data access, and administrative changes.
- API key metadata: Key prefixes, scopes, usage counts, and last-used timestamps. API keys are stored as SHA-256 hashes and never in plaintext.
- MFA enrollment: Encrypted TOTP secrets and verification status (for accounts with multi-factor authentication enabled).
3. How We Use Your Information
- Provide the Service: Index your connected sources, process search queries, generate AI responses with citations, and manage your organization's knowledge base.
- Improve the Service: Analyze anonymized usage patterns to fix bugs, improve search relevance, and develop new features.
- Security: Detect fraud, prevent abuse, maintain audit trails, and enforce access controls.
- Communications: Send service updates, billing notifications, security alerts, and support responses.
- Enterprise features: Provide SSO, audit logs, role-based access control, and API key management.
We do not:
- Sell your personal data to third parties.
- Use your content to train general-purpose AI models. Our AI providers are contractually prohibited from using your data for model training.
- Share your data with advertisers.
- Access your data without a legitimate business purpose (e.g., support requests you initiate).
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data under the following legal bases:
- Contract performance: Processing necessary to provide the Service you requested.
- Legitimate interests: Improving our Service, ensuring security, and preventing fraud. We balance these interests against your rights and do not process data where our interests override yours.
- Legal obligation: Compliance with applicable laws and regulations.
- Consent: Where required, such as for marketing communications. You may withdraw consent at any time.
5. How We Share Your Information
We share data only with service providers necessary to operate the platform:
| Service | Purpose | Location |
|---|---|---|
| Google OAuth | Authentication | USA |
| Neon Database | Primary PostgreSQL database | USA (Azure East US 2) |
| Vespa / OpenSearch | Vector search and document indexing | USA |
| Redis | Celery task broker, caching, distributed locks, and rate limiting | USA |
| OpenAI | AI processing and embeddings | USA |
| Anthropic | AI processing | USA |
| Google Gemini | AI processing | USA |
| AssemblyAI | Audio transcription | USA |
| Polar.sh | Payment processing | EU |
| Coolify | Application hosting and deployment | Self-hosted infrastructure |
| SendGrid | Transactional email | USA |
AI provider data handling:
We use enterprise API agreements with OpenAI, Anthropic, and Google Gemini that explicitly prohibit using your data to train their models. Your content is processed to generate responses but is not retained by these providers for model improvement.
6. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of account deletion.
- Connected source indexes: Retained while the integration is active. Removed when you disconnect a source or delete your account. Fenlo periodically syncs content and prunes documents that have been removed from the source application.
- Chat history: Retained while your account is active. You may delete individual conversations at any time.
- AI-processed content: Chunks, vector embeddings, and AI-generated summaries are retained while the associated source is connected and deleted when the source is disconnected or your account is deleted.
- Audit logs: 90 days (customizable for Enterprise plans).
- Backups: Encrypted backups retained for 30 days for disaster recovery, then permanently deleted.
7. Data Security
- Encryption in transit: TLS 1.3 for all connections.
- Encryption at rest: AES-256 for database and file storage. OAuth tokens and connector credentials are encrypted at the application level.
- Tenant isolation: Each organization's data is stored in a separate PostgreSQL schema. Cross-tenant data access is not possible at the database level.
- Access control: Role-based access for employees; all access is logged and auditable.
- API key security: SHA-256 hashed storage. Keys are never stored in plaintext.
- SSRF protection: Multi-level validation prevents server-side request forgery in web connectors.
- SOC 2 Type II: Certification in progress (target Q3 2026).
8. Your Rights
8.1 All Users
- Access: Request a copy of your personal data.
- Correction: Update inaccurate or incomplete data.
- Deletion: Delete your account and all associated data from Settings.
- Export: Export your data in a portable format.
8.2 EU/EEA Residents (GDPR)
- Restriction: Request restriction of processing.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdrawal: Withdraw consent at any time (where processing is based on consent).
- Complaint: Lodge a complaint with your local supervisory authority.
8.3 California Residents (CCPA/CPRA)
- Right to know: Request disclosure of personal information collected, used, and shared.
- Right to delete: Request deletion of personal information.
- Right to opt-out: We do not sell personal information; no opt-out required.
- Right to non-discrimination: Equal service and pricing regardless of privacy choices.
- Right to correct: Request correction of inaccurate personal information.
To exercise any of these rights, contact us at team@fenlo.io. We will respond within 30 days (or sooner as required by law).
9. International Data Transfers
Your data is primarily processed in the United States. For transfers from the EU/EEA/UK, we rely on:
- Standard Contractual Clauses (SCCs): EU Commission-approved contractual safeguards incorporated into our agreements with subprocessors.
- Subprocessor agreements: Binding data protection terms with all service providers listed in Section 5.
10. Cookies
We use cookies and similar technologies to provide and improve the Service.
- Essential cookies: Strictly necessary for authentication, security (CSRF protection), and load balancing.
- Functional cookies: Remember your preferences (theme, language) and settings.
- Analytics cookies: Help us understand how you use the Service. These are anonymized.
- Local storage: We use browser LocalStorage for UI state and session tokens.
You can control or delete cookies through your browser settings. Disabling essential cookies will prevent you from logging in or using core features.
11. Children's Privacy
Fenlo is a B2B platform intended for professionals. We do not knowingly collect personal information from children under 13 (or the applicable age of consent). If we become aware that we have collected data from a child, we will delete it. Contact us at team@fenlo.io if you believe we have such data.
12. Third-Party Links
Our Service may contain links to third-party websites (e.g., GitHub, identity providers, connected tools). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a new “Last Updated” date.
- Sending an email notification to the address associated with your account for significant changes.
- Displaying a notice within the application.
Continued use of the Service after changes are posted constitutes your acceptance of the updated Privacy Policy.
14. Contact Us
For privacy questions, data requests, or concerns:
Email: team@fenlo.io
Security issues: team@fenlo.io