Privacy Policy
1. Scope and Introduction
Foreman ("Foreman," "we," "our," or "us") respects your privacy. This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have when you use our AI agent orchestration platform (the "Service").
United States only. The Service is offered solely to users located in, and residents of, the United States. This policy is written for U.S. privacy law, including the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") and comparable state privacy laws. The Service is not directed to individuals in the European Union, the United Kingdom, or other jurisdictions outside the United States, and we do not offer it to them.
2. Information We Collect
We collect the following categories of information to provide and improve the Service:
- Account Information: Name, email address, authentication credentials, and billing details.
- Business Context: Company profiles, team rosters, and operational preferences you provide during onboarding or normal operation.
- Usage Data: Chat logs, interaction metrics, and system activity logs generated as you interact with the Chief of Staff and Workspace Agents.
- Agent-Generated Data: Deliverables, memory entries, summaries, routing metadata, model-provider metadata, and inferred business context generated by agents while operating in your workspace.
- Integration Data: OAuth connection metadata, scoped tool-execution payloads, channel/message metadata, consent records, suppression records, and audit events for actions performed through connected accounts.
- Customer-Sourced Third-Party Data: Business contact and prospect information you supply or obtain through a customer-connected platform or enrichment provider, including professional identifiers, employer and role information, and contact details.
- Approximate Location: A coarse country/region derived from your IP address, used only for eligibility and sanctions screening (see Section 8).
3. Notice at Collection — Categories, Sources, Purposes, and Retention
The table below is our "notice at collection" under the CCPA/CPRA. It identifies the categories of personal information we collect, where each comes from, why we use it, and how long we keep it. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
| Category | Sources | Primary Purpose | Retention |
|---|---|---|---|
| Identifiers & account data (name, email, credentials) | You; your identity provider (e.g., Google, GitHub) if you use social sign-in | Create and secure your account; authenticate you; communicate with you | While your account is active; deleted within 45 days of a verified deletion request or account closure |
| Business & workspace content (profiles, uploaded files, deliverables, agent memory) | You and your organization; generated by agents in your workspace | Operate the Service; generate deliverables; maintain workspace memory | While your account is active; deleted within 45 days of a verified deletion request or account closure |
| Commercial & billing information | You; our payment processor (Stripe) | Process payments and subscriptions; prevent fraud | Retained as required by tax and accounting law (typically up to 7 years) |
| Usage & device data (logs, interaction metrics, IP address) | Automatically from your use of the Service | Operate, secure, debug, and improve the Service | Up to 12 months, then deleted or de-identified, unless needed for security or legal reasons |
| Integration & audit data (OAuth metadata, execution and audit records) | You (by connecting accounts); the connected platforms | Execute the integration actions you authorize; maintain an audit trail | While the integration is connected, plus up to 12 months of audit history |
| Customer-sourced contact, prospect & enrichment data | You and your organization; public or licensed sources you select; customer-connected platforms and enrichment providers | At your direction, organize prospects, enrich business records, prepare outreach, and perform connected-account actions | While maintained in your active workspace; deleted within 45 days of a verified deletion request or account closure, subject to suppression and legally required records |
| Approximate location (country/region) | Derived from your IP address via a geolocation provider | Confirm U.S. eligibility; sanctions and jurisdiction screening (a legal obligation) | Screening records retained as required by law |
| Consent & privacy-request records | You; your browser (e.g., Global Privacy Control signal) | Honor your choices; evidence compliance with your requests | Up to 24 months after the request or consent event |
4. How We Use Information
Your information is used primarily to operate the Service: generating contextual deliverables, maintaining your workspace memory, executing the integration actions you authorize, processing payments, providing support, and securing the platform. We also review usage and system logs — which are workspace-scoped — to identify bottlenecks, optimize agent orchestration, and improve reliability. We do not use your information for third-party advertising.
5. AI & Data Use
Foreman is an AI platform, so we want to be explicit about how your data relates to AI models.
- Your content is not training data. We do not use your User Content — your prompts, uploaded files, business data, or agent deliverables — to train or fine-tune AI models.
- We learn how the work gets done, not your work. To make agents more reliable and effective, we use de-identified operational signals about how tasks are executed — for example, which tools and steps succeeded or failed, error traces, routing outcomes, and generalized task-execution patterns — with your identifiers and proprietary content removed. This improves the methods and skills agents use to do their jobs; it does not reproduce or expose your content.
- Foreman-managed model providers. To generate outputs, prompts and context may be sent to model providers Foreman engages and lists on our Subprocessor List. We contract for API or non-training terms where available, apply our DPA's subprocessor framework, and remain responsible for our selection, instructions, and disclosures. A provider's own infrastructure and service remain subject to its terms, but that does not eliminate Foreman's obligations for Foreman-managed processing.
- Bring Your Own Key (BYOK). If you use BYOK, prompts are routed to the provider whose key you supply, and that provider's terms govern the inference (see Section 7).
- Changes require your consent. We will not materially expand AI use of your previously submitted content without first giving notice and obtaining your opt-in consent.
6. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share data with the service providers and subprocessors necessary to operate the Service, and only for the purposes described here. These include, among others: Descope (authentication), Neon (database hosting), Fly.io (application hosting), Cloudflare R2 (private object storage), Stripe (payments), model providers including OpenAI, DeepInfra, and OpenRouter (inference and routing), Resend (transactional email), Nylas (managed email and calendar connectivity), managed web-search backends such as Tavily, Brave Search, and SerpApi (agent research), Composio and Pipedream (integration execution), cron-job.org (scheduled-job triggering), ipapi.co (IP-based jurisdiction screening), and the U.S. Department of Commerce screening API (sanctions compliance). We also transmit data to Customer-Directed Services, such as a mailbox, calendar, Buffer, connected social platform, CRM, or enrichment provider, when you configure and direct that transmission. Where you sign in with a third-party identity provider (such as GitHub), that provider receives the identity attributes needed to complete the login.
A complete, current list — including each provider's purpose, data categories, and region — is maintained on our Subprocessor List. We may also disclose information if required by law or in response to valid legal process, and in connection with a merger, acquisition, or sale of assets (subject to this policy).
Customer-Directed External Platforms
Foreman does not issue or host your mailbox, calendar, social-network account, CRM, or third-party prospect database. When you connect your own account or provider, you direct Foreman to exchange data with that external platform under the permissions you grant. That platform's privacy notice and your direct agreement with it govern the platform's independent collection and processing. Foreman is responsible for its own access, use, transmission, retention, and protection of data as described here; it is not responsible for the external platform's independent practices.
For Google user data, Foreman's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
7. BYOK Data Processing
If you use Bring Your Own Key (BYOK) functionality, Foreman submits the prompts, context data, and queries needed for the inference call to the provider you select using the API credential you supply. Your direct provider agreement and data-processing terms govern that provider's processing for the call; the provider acts as your Customer-Directed Service rather than Foreman's subprocessor. Foreman remains responsible for securing the stored credential and for its own routing and handling of the request.
8. Sensitive Personal Information
We do not seek to collect "sensitive personal information" as defined by the CCPA/CPRA (such as government IDs, precise geolocation, or information about health, race, religion, or sexual orientation), and you should not submit it to the Service.
For sanctions and jurisdiction screening — which we perform because U.S. law requires it — we submit your name and a coarse, IP-derived country/region to screening providers (a government sanctions-list API and a geolocation service). We use this data only for that legal-compliance purpose; we do not use or disclose it to infer characteristics about you, and we do not use it for advertising. To the extent any of this is treated as sensitive personal information, our use is limited to the purposes permitted under CCPA/CPRA § 7027(m).
9. Data Retention & Deletion
This is our single, authoritative retention schedule; the Terms of Service and Beta Terms reference it. We keep each category of personal information only as long as needed for the purposes in the table in Section 3, then delete or de-identify it. In summary:
- Active workspace & account data: retained while your account is active.
- On verified deletion request or account closure: your workspace and account data are deleted within 45 days; agent-generated and inferred personal information are included, not just account records.
- Backups: after production deletion, residual copies remain only in our encrypted point-in-time backups, from which individual records are not separately retrievable; those copies roll off under our backup-retention window within 30 days.
- Legally required records: billing/tax records and sanctions-screening records are retained only as long as applicable law requires.
Submit a verified deletion request from Settings → Privacy, or email privacy@foreman.company.
10. Data Security
We implement commercially reasonable security measures, including encryption in transit and at rest and role-based access controls, described in our Security Overview. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your Privacy Rights
Depending on your state of residence, you may have the right to:
- Know / Access: the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients.
- Delete: the personal information we hold about you, subject to legal exceptions.
- Correct: inaccurate personal information.
- Portability: a copy of certain information in a portable format.
- Opt out of sale/sharing and targeted advertising: although we do not sell or share personal information or use it for targeted advertising, you may still exercise and record this choice (see Section 12).
- Non-discrimination: we will not discriminate against you for exercising any of these rights.
To exercise a right, use the Privacy tab in Settings or email privacy@foreman.company. We will verify your request against your account. You may use an authorized agent to submit a request on your behalf with proof of authorization. If we decline a request, you may appeal by replying to our decision or emailing privacy@foreman.company with the subject line "Privacy Appeal."
12. Your Privacy Choices — Do Not Sell or Share
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. Even so, you can record and manage your privacy choices:
- Use the "Your Privacy Choices" / "Do Not Sell or Share My Personal Information" link in our website footer, which opens your cookie and privacy controls.
- We honor the Global Privacy Control (GPC) browser signal as a valid opt-out of sale, sharing, and targeted advertising. When GPC is detected, we treat it as your opt-out and record it, including across devices where you are signed in. See our Cookie Policy.
14. Children's Privacy
The Service is a business tool available only to people age 18 or older and is not directed to minors. We use an age gate during signup and do not knowingly allow anyone under 18 to create or use an account. If you believe a minor has provided us personal information, contact us at privacy@foreman.company so we can investigate and remove it as appropriate.
15. Changes to This Policy
We may update this Privacy Policy. We will notify you of material changes via email or in-app notice, and we will not materially expand AI use of your previously submitted content without your opt-in consent (see Section 5).
16. Contact
Foreman LLC (a Utah limited liability company) is the entity responsible for the personal information described here. Questions about this Privacy Policy or our data practices? Contact our privacy contact at privacy@foreman.company.