Privacy Policy
Last updated: October 5, 2026
The short version
- We collect what we need to run FreNiMiGuard: your account details, the inventory and security data your organization puts in, and basic server logs.
- We don't run advertising, analytics or tracking cookies, and we don't sell or share personal information.
- Stripe handles payments; we never see full card numbers.
- Your data is stored in the United States.
- When an account is closed, we delete its data within 30 days, and from backups within a further 35 days.
1. Who we are
FreNiMiGuard is a service of FreNiMi LLC, 1655 S Blue Island Ave, Suite 4050, Chicago, IL 60608, USA ("FreNiMi", "we", "us"). This policy covers the FreNiMiGuard website at frenimiguard.com and the FreNiMiGuard service.
Two roles apply:
- Workspace data. The inventory, findings, notes and other records an organization keeps in FreNiMiGuard belong to that organization. For that data we act as its service provider (a "processor" under laws like the GDPR), and our Data Processing Addendum sets out how. If your employer uses FreNiMiGuard, their privacy notice also applies, and they are the first place to go with requests about that data.
- Account, billing and website data. For information about the people who sign in, about billing, and about visits to our website, we decide how it is used. This policy explains that use.
2. What we collect
| Information | Where it comes from | Why we have it |
|---|---|---|
| Email address, username, organization name and your role | You, or an administrator who invites you | To create your account, sign you in and send service email |
| Password (stored only as a one-way hash), multi-factor settings, and hashes of sign-in codes | You | To keep your account secure |
| "Remember this device" records: a hash of a random token and your browser's user-agent string | Your browser, when you choose to be remembered | To skip the emailed code on that browser for 30 days |
| Asset and software inventory: device names, IP addresses, operating systems, installed software and versions, update status, and any owner, department or location your team enters | Your organization, through imports, connectors, the collector script or the agent | To match software against known vulnerabilities and track the fixes |
| Findings, tasks, incidents, notes, evidence and compliance records | Your organization | To run the service for your organization |
| Audit trail: who did what in the workspace, and when | The service, as people use it | So your organization can review changes and show evidence |
| Plan, Stripe customer and subscription references, billing email | Stripe, when you upgrade | To apply your plan. Stripe keeps your card details; we never see the full number |
| Server logs: IP address, time, page or API address requested, browser type and response code | Your browser or the agent, automatically | To keep the service secure, stop abuse and fix problems |
| Messages you send us | You | To answer you |
The in-app assistant answers questions about your workspace by reading the same data you can see. Its conversation is kept in your browser for the current tab only; we don't store it on our servers.
3. What we don't do
- We don't sell personal information, and we don't share it for cross-context behavioral advertising.
- We don't use advertising, analytics or tracking cookies on frenimiguard.com or in the app.
- We don't use workspace data for any purpose other than providing the service to the organization it belongs to, keeping it secure, and supporting that organization.
4. Cookies and browser storage
FreNiMiGuard does not set cookies. Your browser keeps a few things locally so the app works the way you left it:
- your sign-in session, in memory, until you close the tab or sign out;
- the "remember this device" token, if you chose it, for 30 days;
- layout preferences, such as a collapsed sidebar or your dashboard arrangement;
- the assistant conversation, for the current tab only.
You can clear these at any time in your browser's settings.
5. How we use information
- to provide and secure the service, including sign-in checks, rate limits and abuse prevention;
- to send email the service needs: sign-in and verification codes, alerts and reports your administrators set up, and notices about your account, billing or these policies;
- to answer support requests;
- to keep business and tax records, and to meet legal obligations.
We don't send marketing email from FreNiMiGuard.
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases: performing our contract with you or your organization; our legitimate interests in keeping the service secure and working; and complying with the law.
6. Who we share it with
We use a small number of companies to run the service. They may process personal information only on our instructions and must protect it.
| Company | What they do for us | Location |
|---|---|---|
| DigitalOcean, LLC | Hosting: the servers and storage the service runs on | United States |
| Stripe, Inc. | Payments and subscriptions | United States |
| Resend, Inc. | Delivering email: sign-in codes, alerts and reports | United States |
The current list is also kept in our Data Processing Addendum, and we tell customers before adding a new company.
We also share information:
- with services your administrators connect, such as Microsoft Intune, Jamf Pro, AWS, GitHub, or an email or webhook address, at their direction;
- when the law requires it, after checking that the request is valid. Where we can, we tell the affected organization first;
- with a company that takes over FreNiMi's business, which would have to keep the commitments in this policy.
To find vulnerabilities, the service downloads public data from CISA, the National Vulnerability Database, Microsoft and AlienVault OTX. These requests don't contain your data.
7. Where data is stored
We store and process data in the United States. If you use FreNiMiGuard from outside the US, your information is transferred there. For customers in the EEA, UK or Switzerland, our Data Processing Addendum includes the safeguards those laws require.
8. How long we keep it
- Account and workspace data: while the account is open. When an organization closes its account, we delete its workspace data within 30 days, and it leaves our backups within a further 35 days.
- Unfinished signups: deleted after 7 days.
- Sign-in codes: deleted a day after they expire. Remembered devices are deleted when their 30 days run out.
- Server logs: up to 30 days, unless we need them longer to investigate a security incident.
- Billing records: as long as tax and accounting law requires, usually 7 years.
An administrator can remove a person's account from a workspace at any time. Entries that person made in the audit trail stay, because the trail is the organization's record of who did what.
9. How we protect it
All connections use TLS. Passwords are stored as one-way hashes, and integration keys and signing keys are encrypted in the database. Each organization's data is kept apart by the application and again by the database itself. Sign-in supports multi-factor authentication and single sign-on, and every change in a workspace is recorded in its audit trail. The full list is in our Data Processing Addendum. No system is perfectly secure; if a breach affects your personal information, we will tell you as the law requires.
10. Your choices and rights
You can see and update your account details in the app. Depending on where you live, you may also have the right to ask for a copy of your personal information, to correct or delete it, to limit or object to how we use it, or to receive it in a portable format.
- For workspace data, ask your organization's administrator. They can export, correct or delete it, and we help them when asked.
- For your account or anything else in this policy, email info@frenimi.com. We reply within 30 days, or sooner where the law requires, and may need to confirm who you are first.
California residents: you have the right to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for using these rights. We don't sell or share personal information as those terms are defined in the California Consumer Privacy Act, and we don't use sensitive personal information to infer anything about you.
If you are in the EEA or UK and are unhappy with our answer, you can complain to your local data protection authority.
11. Children
FreNiMiGuard is a business service and isn't meant for anyone under 16. We don't knowingly collect information from children.
12. Changes to this policy
If we change this policy, we will update the date at the top. For significant changes, we will email workspace administrators at least 30 days before the change applies.
13. Contact
FreNiMi LLC, 1655 S Blue Island Ave, Suite 4050, Chicago, IL 60608, USA. Email info@frenimi.com.
