FreNiMiGuard

Privacy Policy

Last updated: October 5, 2026

The short version

1. Who we are

FreNiMiGuard is a service of FreNiMi LLC, 1655 S Blue Island Ave, Suite 4050, Chicago, IL 60608, USA ("FreNiMi", "we", "us"). This policy covers the FreNiMiGuard website at frenimiguard.com and the FreNiMiGuard service.

Two roles apply:

2. What we collect

InformationWhere it comes fromWhy we have it
Email address, username, organization name and your roleYou, or an administrator who invites youTo create your account, sign you in and send service email
Password (stored only as a one-way hash), multi-factor settings, and hashes of sign-in codesYouTo keep your account secure
"Remember this device" records: a hash of a random token and your browser's user-agent stringYour browser, when you choose to be rememberedTo skip the emailed code on that browser for 30 days
Asset and software inventory: device names, IP addresses, operating systems, installed software and versions, update status, and any owner, department or location your team entersYour organization, through imports, connectors, the collector script or the agentTo match software against known vulnerabilities and track the fixes
Findings, tasks, incidents, notes, evidence and compliance recordsYour organizationTo run the service for your organization
Audit trail: who did what in the workspace, and whenThe service, as people use itSo your organization can review changes and show evidence
Plan, Stripe customer and subscription references, billing emailStripe, when you upgradeTo apply your plan. Stripe keeps your card details; we never see the full number
Server logs: IP address, time, page or API address requested, browser type and response codeYour browser or the agent, automaticallyTo keep the service secure, stop abuse and fix problems
Messages you send usYouTo answer you

The in-app assistant answers questions about your workspace by reading the same data you can see. Its conversation is kept in your browser for the current tab only; we don't store it on our servers.

3. What we don't do

4. Cookies and browser storage

FreNiMiGuard does not set cookies. Your browser keeps a few things locally so the app works the way you left it:

You can clear these at any time in your browser's settings.

5. How we use information

We don't send marketing email from FreNiMiGuard.

If you are in the European Economic Area or the United Kingdom, we rely on these legal bases: performing our contract with you or your organization; our legitimate interests in keeping the service secure and working; and complying with the law.

6. Who we share it with

We use a small number of companies to run the service. They may process personal information only on our instructions and must protect it.

CompanyWhat they do for usLocation
DigitalOcean, LLCHosting: the servers and storage the service runs onUnited States
Stripe, Inc.Payments and subscriptionsUnited States
Resend, Inc.Delivering email: sign-in codes, alerts and reportsUnited States

The current list is also kept in our Data Processing Addendum, and we tell customers before adding a new company.

We also share information:

To find vulnerabilities, the service downloads public data from CISA, the National Vulnerability Database, Microsoft and AlienVault OTX. These requests don't contain your data.

7. Where data is stored

We store and process data in the United States. If you use FreNiMiGuard from outside the US, your information is transferred there. For customers in the EEA, UK or Switzerland, our Data Processing Addendum includes the safeguards those laws require.

8. How long we keep it

An administrator can remove a person's account from a workspace at any time. Entries that person made in the audit trail stay, because the trail is the organization's record of who did what.

9. How we protect it

All connections use TLS. Passwords are stored as one-way hashes, and integration keys and signing keys are encrypted in the database. Each organization's data is kept apart by the application and again by the database itself. Sign-in supports multi-factor authentication and single sign-on, and every change in a workspace is recorded in its audit trail. The full list is in our Data Processing Addendum. No system is perfectly secure; if a breach affects your personal information, we will tell you as the law requires.

10. Your choices and rights

You can see and update your account details in the app. Depending on where you live, you may also have the right to ask for a copy of your personal information, to correct or delete it, to limit or object to how we use it, or to receive it in a portable format.

California residents: you have the right to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for using these rights. We don't sell or share personal information as those terms are defined in the California Consumer Privacy Act, and we don't use sensitive personal information to infer anything about you.

If you are in the EEA or UK and are unhappy with our answer, you can complain to your local data protection authority.

11. Children

FreNiMiGuard is a business service and isn't meant for anyone under 16. We don't knowingly collect information from children.

12. Changes to this policy

If we change this policy, we will update the date at the top. For significant changes, we will email workspace administrators at least 30 days before the change applies.

13. Contact

FreNiMi LLC, 1655 S Blue Island Ave, Suite 4050, Chicago, IL 60608, USA. Email info@frenimi.com.