Back to Frugl

Privacy Policy

Last updated June 21, 2026

This Privacy Policy explains what data Frugl collects, how we use it, and the choices you have. Frugl is a hosted, multi-tenant service operated by Frugl Dev ("we", "us", or "our") that analyzes anonymized AI coding sessions. Privacy is built into how the product works, not bolted on afterward.

Anonymization happens before upload

The Frugl CLI anonymizes your session data on your own machine before any byte leaves it. The CLI fails closed: when it is uncertain whether something is sensitive, it removes or redacts it rather than risk leaking it. We never receive your raw, un-anonymized sessions.

What we collect

How we use it

We use your data to provide the service: parsing sessions, generating waste analysis and recommendations, showing reports to you and your organization, and keeping the platform secure and reliable. We do not train machine-learning models on your sessions.

Cookies, analytics, and your choices

We use a small number of strictly necessary cookies to keep you signed in and to operate the service securely. These are not advertising or cross-site tracking cookies, and we do not share them with advertisers.

We also collect first-party product analytics to understand how Frugl is used and where to improve it. This is deliberately privacy-preserving: events record only coarse, bucketed facts (such as a page being viewed or an upload starting) keyed by already-anonymized identifiers. By design they never include session or transcript content, prompt text, file paths, repository names, email addresses, or exact dollar amounts tied to a person. Product analytics is tied to the same opt-out as model-assisted enrichment: if you opt out of enrichment in your account settings, we stop emitting analytics for you as well.

How it is stored and isolated

Anonymized raw uploads are held in private object storage; parsed data lives in a Postgres database. Every user-data table is protected by row-level security, and each organization's data is isolated from others. Access to raw objects is limited to server-side processing that needs it; our service credentials are never exposed to your browser.

Data security

We protect your data in transit and at rest, restrict access to it on a need-to-know basis, and rely on per-organization isolation enforced at the database layer. No method of transmission or storage is perfectly secure, but we work to keep our safeguards proportionate to the sensitivity of the data we hold. If we become aware of a breach that affects your personal data, we will notify you as required by applicable law.

Sharing

We do not sell your data. We share it only with infrastructure providers that host and operate the service on our behalf, under contracts that require them to protect it, and where required by law. Within your organization, your sessions and analysis are visible to authorized members according to their role.

International data transfers

Frugl and the infrastructure providers we rely on may process and store data in countries other than the one you live in. Where we transfer personal data across borders, we use appropriate safeguards — such as standard contractual clauses — to protect it in line with applicable data protection law.

Retention and deletion

We treat the two copies of your data differently. The raw uploaded objects in private storage are a short-lived backup: they are automatically deleted after a retention window (currently 30 days) once they have been parsed. The parsed analysis in our database — the insights and reports you actually use — is kept for as long as your account is active so your history stays available. Account and billing records are kept while your organization is active and for as long as needed to meet legal and accounting obligations.

You can request export or deletion of your data at any time. Deleting your account removes your parsed data and any remaining raw objects and cancels any active subscription; we complete deletion within a reasonable period unless we are required to retain specific records by law.

Your privacy rights

Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, to object to certain processing, and to withdraw consent. If you are in the European Economic Area or the United Kingdom, our legal bases for processing are performing our contract with you, our legitimate interest in operating and securing the service, and your consent where applicable. If you are a California resident, we do not sell or share your personal information as those terms are defined under the CCPA, and we will not discriminate against you for exercising your rights. To exercise any of these rights, contact us using the details below.

Your choices

Children's privacy

Frugl is a tool for software developers and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes are reflected in the "Last updated" date above and, where appropriate, communicated to you directly.

Contact

Questions about your privacy, or want to exercise a data right? Emailhello@frugl.dev.