Privacy Policy
Privacy Policy v1.0 — effective 2026-05-16
What we collect
The events, metadata, and hashes we record as you use the platform.
When you use the FCMF platform, we record what happens — which Vehicles you create, which Forge invocations you make, which Avatars you talk to, which governance decisions occur in your Boards and Panels, and the metadata around those events (timestamps, durations, success/failure outcomes, hashes of message content for integrity verification). We do not record the body of your conversations, the content of your collateral, or the text of your forged Packages in our analytics store; those live only in your tenant's workspace and are encrypted at rest.
Why we collect it
The three purposes the data is allowed to serve, and the consent posture for each.
The data has three purposes:
- Customizing your Avatars and Roster. Your Avatars learn from your interactions — which Board members you defer to, which positions you challenge, which Panel cohorts you re-summon. This data stays inside your tenant. It never leaves.
- Improving the FCMF platform. Aggregated data, with all personal and tenant identifiers stripped out and combined across at least 50 distinct customer organizations, helps us improve Avatar synthesis quality, Roster agent behavior, Forge output quality, and platform reliability. This aggregation is opt-in: by default it is off, and you can turn it on or off at any time in Settings. Your contribution to these aggregates is removable for 90 days from the date we collected it. If you withdraw consent, close your account, or invoke right-to-be-forgotten within that window, we will re-derive the affected aggregates without your data. After 90 days, the cryptographic key that links the aggregate back to your account is destroyed, and from that point on your contribution is mathematically anonymous and cannot be individually removed — but, equally, it is no longer linked to you in any way.
- Operating the platform safely. A small set of operational data — billing meters, security events, governance decisions — is collected as a baseline and cannot be turned off. We are required to retain this for legal and safety reasons.
Who sees it
Per-tier access boundaries inside FCMF.
- Your Tier 1 (per-tenant) data is visible only to your Garage's Roster agents and to authorized members of your tenant. It does not leave your tenant.
- Tier 2 (aggregated) data is visible to FCMF authority and on-call platform engineers, with every query audit-logged.
- Tier 3 (operational) data is visible to authority, on-call platform engineers, and (where applicable) you — for example, your own security event log.
How we delete it
Tenant-deletion and right-to-be-forgotten semantics by tier.
When you close your account or invoke right-to-be-forgotten, we purge all Tier 1 and Tier 3 data attributable to you within 30 days. For Tier 2 (aggregate) data, the rule depends on age: contributions are removable from the aggregate within 90 days of collection; after 90 days, contributions are anonymized and remain in the aggregate but are no longer linked to you.
How to control it
Where the toggles live inside the platform.
Settings → Privacy → “Help improve the platform” toggle controls Tier 2. Settings → Account → “Delete account” purges Tier 1 / Tier 3.