Privacy Policy
What we process, who can see it, and your choices.
On this page 22 sections
Effective date: October 3, 2026
Last updated: October 9, 2026
This Privacy Policy explains how frfr (“frfr,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you use frfr.link, related subdomains, applications, and services that link to this Policy (collectively, the “Service”).
frfr is designed around a simple distinction: some information is deliberately public because you choose to put it on your profile; other information is private and should stay private. This Policy explains both.
1. Who controls your information
The company responsible for your personal information and its mailing address are listed in Controller and contact at the end of this Policy.
Privacy and data-rights requests: contact@frfr.link. Account help: support@frfr.link.
See Contact & Legal Notices for the current contact channels. These channels do not imply that a local representative has been appointed in any jurisdiction.
2. Scope
This Policy applies to personal information processed through the Service and related support, safety, legal, and account operations.
It does not govern a third-party website or service merely because your frfr profile links to it. Those services have their own privacy practices.
3. Quick summary
- Public means public. Information you publish to a public frfr profile can be viewed without an account and may be indexed, cached, copied, or reshared by others.
- You choose what to publish. Do not put information on a public profile that you do not want available on the open internet.
- We do not currently sell personal information or use it for cross-context behavioral advertising.
- We do not require a legal name for ordinary account use unless a particular legally required process needs one.
- We do not permit accounts for users under 18.
- You can request access, correction, deletion, and portability. We offer a broad baseline of privacy rights globally, subject to legal exceptions.
- You can delete your account. Public profile content is removed from active public display promptly; some limited information can remain temporarily in backups, security records, legal holds, or copies independently retained by other people.
4. Information we collect
4.1 Account and authentication information
Depending on the sign-in methods we offer, we may process:
- email address;
- a phone number retained from an earlier phone-based account, if applicable; current sign-in uses email;
- authentication-provider identifiers for services such as Google or Apple;
- account ID, username, profile URL, and account status;
- age-eligibility confirmation and the version/date of policy acceptance;
- session identifiers, device tokens, recovery information, and security events; and
- login history needed for fraud prevention and account security.
We do not need your government-issued identification for ordinary account creation unless a specific legal, safety, age-assurance, or account-recovery process requires it. If such a process becomes necessary, we will provide an appropriate notice before collecting that information.
4.2 Profile and portfolio information you choose to provide
Your frfr page may contain information such as:
- name, chosen name, nickname, pronouns, profile photo, headline, and biography;
- profession, employer, education, skills, interests, hobbies, topics, and areas of expertise;
- projects, products, research, publications, portfolios, and things you are building or learning;
- photos, video, audio, documents, résumé/CV, captions, prompts, and answers;
- links to websites, social profiles, repositories, publications, or other external services;
- city, region, general location, travel status, or availability if you choose to provide it;
- what you are looking for, what you can help with, or other networking intent; and
- any other information you intentionally add to your profile or cards.
Public-profile warning: If you mark information public, it can be accessed by anyone, including people without an frfr account, search engines, archiving services, automated systems, and people in other countries.
Before uploading a résumé or document, remove addresses, phone numbers, signatures, identification numbers, or other information you do not want public.
4.3 Social and communication information
When social features are available, we may process:
- likes, reactions, notes, replies, and the profile card or content item that triggered them;
- chats, messages, attachments, message timestamps, delivery state, and participant identifiers;
- blocks, mutes, reports, moderation appeals, and safety preferences;
- inferred relationship state generated by product interactions, such as whether two users have an active conversation; and
- notification preferences.
Private messages are not public unless a participant independently discloses them. Do not send highly sensitive information through frfr chat.
4.4 Discovery, recommendation, and inferred information
Where discovery features are enabled, we may derive limited information from data you provide and activity on the Service, for example:
- interest or topic categories;
- similarity, relevance, or recommendation scores;
- possible reasons two users might want to speak;
- broad location relevance if location is enabled; and
- signals used to reduce spam, fraud, or abusive behavior.
We do not use these recommendations to make decisions that produce legal or similarly significant effects concerning employment, credit, housing, insurance, education, healthcare, or legal rights.
4.5 Device, network, and usage information
We may automatically receive:
- IP address;
- browser type, operating system, device type, language, and time zone;
- pages or features viewed, approximate timestamps, referral source, and basic interaction events;
- required cookies, session tokens, and local-storage identifiers;
- crash, request, performance, and error logs; and
- security events, rate-limit events, and abuse-prevention signals.
IP addresses can provide an approximate region or city. We do not treat an IP-derived location as precise device geolocation.
We do not request precise GPS location unless a feature clearly asks for it and you affirmatively enable it.
4.6 Information from authentication and integrated services
If you choose a third-party login or integration, we receive the information that service is authorized to provide, such as your email address, name, profile image, or provider identifier. We do not receive your third-party password.
If you click an external link from a profile, the destination service may independently receive information such as your IP address and referring page.
4.7 Support, safety, legal, and rights-request information
If you contact us, report a user, file an appeal, submit a copyright request, make a privacy request, or communicate about security, we may collect:
- your contact information;
- the content of your request and related correspondence;
- account or content identifiers;
- supporting evidence you choose to provide; and
- verification information reasonably necessary to prevent unauthorized access to another person's data.
For sensitive safety reports, we minimize access to personnel who need the information to respond.
4.8 Information about non-users
A user may upload a photo or other content that includes another person. We ask users to respect the privacy and rights of people who appear in their content.
If you do not have an frfr account and believe information about you appears on the Service without an appropriate basis, contact contact@frfr.link or support@frfr.link.
4.9 Card recognition, profile updates and groups
Where card recognition is enabled, we collect bounded observations of visible, loaded photo/text cards, foreground video playback after a play or sound interaction, and project/document openings. We keep qualified exposure alongside attention to account for different viewing opportunities. These are approximate signals, not proof of reading, liking or quality. Card colours compare only the same content format on the same profile over seven days, after a seven-day observation period and minimum evidence. Sparse or tied evidence stays neutral. Card glow is private feedback shown only to the signed-in profile owner, not to visitors or other members. We do not show owners a visitor list, identity or numeric popularity score.
We use a keyed pseudonym derived from a signed-in account, or a monthly network pseudonym derived from the request's IP address for a signed-out visitor, to limit repeat contributions. The interaction table does not store raw IP addresses, browsing trails, per-frame playback or raw mouse/scroll events. Network pseudonyms are not unique people. Daily exposure, maximum bounded attention and opening signals age out after seven days; a card's observation-start date remains while it is eligible. A substantial rewrite, private/hidden state or owner opt-out clears its observation history. Existing owner opt-outs continue to be honored; changing Showcase consent does not re-enable recognition or measurement. We skip optional viewing measurement when a Global Privacy Control signal is present.
The profile badge is separate from viewing measurement and remains visible to its owner and visitors, except where an existing public-recognition opt-out applies. A successfully sent Real from a verified member with a published profile contributes once per sender–recipient pair, across all cards. We retain the pair and first-credit date to prevent repeat credit, without copying message contents into this record. Fixed milestones of 5, 10, 25, 50, 100, 250 and 500 distinct members earn seven badge colours. Opening a composer, anonymous viewing and group-message reactions do not earn a badge. Earned colours do not expire with card attention; they are recognition, not identity verification. Account deletion removes attributable credit pairs and the deleted owner's badge; it does not revoke another person's historical milestone.
To show existing connections that a published page has meaningfully changed, we keep a normalized comparison of public card text/media references and a per-connection last-seen version. Small edits do not always create an update. The green ring expires after seven days or clears for a viewer who opens the updated profile. This is not a public read receipt or a notification to the profile owner.
Groups contain up to 13 people. An invitation reveals the current member roster, but message history is available only after joining. Group members can view one another's messages, profile links and reaction counts. People need not be connected one-to-one to share a group. Leaving ends your access but does not by itself erase messages you already sent. Blocking leaves shared groups for the blocking member; an expired invitation cannot be accepted. See the retention rules below.
5. Sensitive information
frfr is not designed to collect government identifiers, financial-account credentials, medical records, biometric templates, precise home addresses, or other highly sensitive records.
Please do not publish highly sensitive information in a public profile. If you voluntarily publish information that reveals sensitive characteristics, you are choosing to make that information public subject to the visibility setting you select.
Where applicable law requires separate or explicit consent for processing sensitive personal information, we will obtain that consent or avoid the processing. We do not use sensitive information to target advertising.
6. How we use information
We use personal information for the following purposes:
Scroll sideways to read this table.
| Purpose | Examples | Typical legal basis where one is required |
|---|---|---|
| Provide the Service | Create accounts, host profiles, publish chosen content, provide sharing, likes, messages, discovery, and account settings | Performance of our contract with you; steps you request before entering a contract |
| Personalize and recommend | Rank profiles, suggest people or content, explain common ground, remember preferences | Contract where necessary to provide a requested feature; otherwise legitimate interests, subject to applicable rights |
| Authenticate and secure | Verify sign-in, prevent account takeover, rate-limit abuse, detect spam/fraud, investigate security events | Contract; legitimate interests in security; legal obligations |
| Communicate | Verification, security alerts, support replies, moderation notices, product notices | Contract; legitimate interests; legal obligations; consent for marketing where required |
| Moderate and protect people | Enforce rules, investigate reports, prevent harassment, fraud, illegal content, and serious harm | Legitimate interests; legal obligations; substantial public interest or other legal bases where applicable |
| Maintain and improve | Debug, measure reliability, understand aggregate feature use, test improvements | Legitimate interests; consent where non-essential cookies/analytics require it |
| Legal and compliance | Respond to lawful requests, exercise or defend claims, keep required records, comply with regulators | Legal obligations; legitimate interests; establishment/exercise/defense of legal claims |
| Corporate transactions | Due diligence or transfer in a financing, merger, acquisition, restructuring, or sale | Legitimate interests and/or legal obligations, with appropriate safeguards |
Where we rely on legitimate interests, those interests generally include operating and securing a useful people/profile service, preventing abuse, understanding service reliability, protecting legal rights, and improving the Service. We consider the impact on users and do not rely on legitimate interests where your rights and interests override ours.
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not make prior lawful processing unlawful.
7. Public information and search engines
A central feature of frfr is the ability to create a shareable public page. Information that you designate as public may be:
- available at a public URL;
- visible without logging in;
- included in link previews;
- indexed or cached by search engines;
- copied, captured, quoted, downloaded, or reshared by visitors; and
- accessible internationally.
Deleting public content from frfr removes it from our active public Service, but we cannot guarantee immediate deletion of copies controlled by search engines, web archives, people who took screenshots, or third parties who lawfully or unlawfully copied it.
When an account or public page is deleted, we intend to return an appropriate unavailable response and use reasonable de-indexing measures within our control.
8. How we disclose information
We may disclose personal information as follows.
8.1 To the public or other users, at your direction
Information you mark public is disclosed publicly. Information you send to another user is disclosed to that user. Content marked for a limited audience is disclosed according to the feature's settings.
8.2 Service providers and processors
We use vendors to provide infrastructure, authentication, email delivery, media storage, content delivery, security, operational monitoring, support correspondence, and similar operations. The current providers are listed below.
They are authorized to process personal information on our behalf subject to contracts and instructions appropriate to the service they provide.
Providers used by the current beta
Scroll sideways to read this table.
| Provider | Purpose and information |
|---|---|
| Cloudflare Workers, D1, R2, Queues and Turnstile | Application hosting, delivery and security; profile, interaction and conversation records; uploaded media and documents; request and technical information. Assisted-preview queues carry job references, not résumé text; Turnstile verifies generation requests. |
| Google Firebase Authentication | Email-link sign-in; email, identity identifiers, legacy account phone numbers where retained, and technical information needed for verification and abuse prevention. Other sign-in providers are used only when offered and chosen. |
| Firebase Cloud Messaging | Opt-in push notifications, device registrations and delivery information |
| Upstash Redis | Session and identity metadata, rate limits, push registrations and notification retry records |
| Google Workspace | Business correspondence at support@frfr.link and contact@frfr.link; email contents, addresses and delivery information. |
| OpenAI API, optional assisted profile drafting | Only the reviewed text you explicitly choose to submit for drafting, after best-effort contact-detail minimization; generated suggestions. We do not send your photo, video or PDF files, their locally staged captions or filenames, or private chats to OpenAI. |
Verification emails are handled through Firebase Authentication. Phone-code sign-in is no longer offered. Interface fonts are served with the application, without a separate browser request to Google Fonts. There is no separate product-analytics provider. Infrastructure services can still collect operational and security information.
Providers may process information in the United States and other locations where they operate. We do not promise that information remains in your country, or a particular hosting region. You can ask contact@frfr.link about the processing relevant to your account.
If this schedule changes materially, we will update this Policy or a linked subprocessor list before or when the change becomes applicable, as required by law.
8.3 Legal, safety, and rights protection
We may disclose information when we reasonably believe disclosure is necessary to:
- comply with applicable law, regulation, subpoena, court order, or other valid legal process;
- protect the rights, property, or safety of users, frfr, or others;
- investigate or prevent fraud, security incidents, abuse, or illegal activity;
- respond to an emergency involving a credible risk of death or serious physical harm; or
- establish, exercise, or defend legal claims.
We evaluate legal requests and may challenge requests that are invalid, overbroad, or inconsistent with applicable law.
8.4 Business transfers
If frfr is involved in a financing, merger, acquisition, reorganization, bankruptcy, asset sale, or similar transaction, personal information may be reviewed or transferred as part of that transaction subject to confidentiality, notice, and applicable law.
8.5 With your consent or direction
We may disclose information for another purpose when you specifically direct us or provide legally valid consent.
9. Sale, targeted advertising, and profiling
As of the effective date of this Policy:
- we do not sell personal information for money;
- we do not sell personal information as “sale” is defined by major U.S. state privacy laws;
- we do not share personal information for cross-context behavioral advertising; and
- we do not use your private messages to build advertising profiles.
If we materially change these practices, we will update this Policy and provide legally required choices before the new practice begins.
Where applicable, we recognize legally required browser-based opt-out preference signals, including Global Privacy Control. Because we do not currently sell or share personal information for targeted advertising, there may be no sale/share to opt out of.
10. Cookies and similar technologies
We may use:
- strictly necessary technologies for sign-in, session security, load balancing, fraud prevention, and core functionality;
- preference technologies to remember settings; and
- analytics technologies to understand aggregate product use and reliability.
We will not load non-essential cookies or similar technologies before obtaining consent where applicable law requires prior consent.
We do not use advertising cookies for cross-site behavioral advertising as of the effective date of this Policy.
Browser settings can limit cookies, but blocking strictly necessary technologies may prevent sign-in or other core functions.
11. Communications and marketing
We may send service messages needed to operate your account, including login codes, security notices, moderation messages, support replies, and material policy notices.
Marketing email or SMS, if introduced, will be subject to applicable consent and opt-out requirements. You may opt out of marketing at any time without losing access to essential service communications.
Showcase is selected by people, not automatically from a popularity ranking. Featuring your public page requires a separate permission. Newsletter subscription and group-invitation email are separate opt-ins and are offered only when email delivery is enabled. Removing Showcase permission removes your page from live issues, but cannot recall a delivered newsletter or another person's copy.
FRFR does not collect friends’ email addresses or send join-FRFR email invitations. You can share your own profile link. Optional group-invitation email goes only to existing members who choose it; Showcase email requires a separate subscription. We honour opt-outs and suppress delivery after bounces or complaints. Group-invitation email and newsletters are not currently activated in this beta. We will identify the delivery provider here before activation.
12. Data retention
We keep personal information only as long as reasonably necessary for the purposes described in this Policy, including providing the Service, security, dispute resolution, legal obligations, and enforcement.
The current beta retains account and profile information while needed to provide your account, until you remove it or delete your account, subject to saved conversation context and limited security or legal exceptions.
Scroll sideways to read this table.
| Information | Current behavior |
|---|---|
| Public profile and cards | Removed from your active public page when deleted or made private. An existing conversation snapshot can remain for its participants. |
| Conversation, originating card snapshot and message reactions | Kept for the connection; removing the connection or deleting either account removes access for both participants. |
| Uploaded media and documents | Kept while needed by the profile or a saved interaction. Account deletion removes owned active storage objects. |
| Sessions | The application session cookie expires after 30 days; sign-out or account deletion revokes applicable access. |
| Support correspondence, safety reports and security records | May be retained separately where needed to resolve requests, prevent abuse, satisfy legal obligations or handle disputes. These records have different retention needs from a public profile. |
| Deletion recovery records | Restricted records hold an internal account identifier, request time and completion status so a database restore does not silently restore a deleted account. They do not contain a copy of the deleted profile or messages and are retained only while needed for recovery or another applicable obligation. |
| Infrastructure backups and exported recovery copies | Can remain after live deletion, subject to provider retention and controlled recovery handling. They are not the live public profile. |
| Assisted-preview input and drafts | Encrypted private anonymous drafts expire 24 hours after creation; submitted source is removed no later than that expiry or within 24 hours after generation finishes. Claiming purges source text. A claimed preview expires seven days after its last explicit save, with a 30-day maximum from creation. Expired data is immediately inaccessible; bounded scheduled cleanup normally runs hourly. Discard and account deletion remove draft contents. |
| Assisted-preview job, invitation and accounting records | Content-free job/invitation evidence is cleaned up after 30 days. Aggregate spending records can remain without source text. Recovery copies follow the separate provider/backups handling above. |
| Card interaction evidence and recognition | Viewing evidence uses a rolling seven-day window and scheduled cleanup. Making a card private, hiding a profile, significantly rewriting a card or disabling recognition removes its evidence and observation-start date. Distinct sent-Real pairs remain for deduplication until either account is deleted. An earned badge remains historical until its owner's account deletion, and is hidden when public recognition is disabled. |
| Profile-change comparisons and last-seen versions | Kept for the current profile/connection experience; hidden-profile comparison text is cleared and account deletion removes owned comparisons and seen state. Update rings last at most seven days. |
| Groups and pending invitations | Groups become inaccessible seven days after the last new message. Pending invitations expire seven days after creation, or sooner if the group closes. Cleanup removes expired group records after a further 24-hour grace, in scheduled batches; a delayed cleanup does not extend access. Reported messages may be retained separately for safety review. |
| Group-invitation and newsletter delivery records, when enabled | Pending delivery/retry lifetime is at most 12 hours and never extends an expired group invitation. Recipient addresses are removed after delivery, suppression or expiry. Content-free delivery/retry records are cleaned up after 30 days. |
| Email preferences and suppression | Verified contact details are kept while an email preference is enabled; disabling both email preferences removes the saved contact. Account deletion stops queued mail and removes saved contacts. Keyed suppression hashes remain to honour opt-outs and prevent repeat unwanted mail. |
Some historical records from the retired meetup beta may remain subject to their original retention rules or account deletion. Pausing discovery or hiding a portfolio is not account deletion.
We do not represent that every provider backup or operational record is erased immediately or on a single universal deadline. Contact contact@frfr.link for a request concerning retained information or a particular system. Applicable legal deletion requirements still apply.
13. Account deletion and erasure
You can request account deletion through the Service or by contacting contact@frfr.link. See our Account & Data Deletion Policy for the detailed process.
Account deletion first hides the profile and prevents ordinary account activity. It removes active application records and owned uploads and requests deletion of the authentication identity. If a provider step fails, the account remains unavailable for ordinary use and Settings can ask you to retry to finish deletion. See the Account & Data Deletion Policy.
Removing a connection or deleting either account removes the conversation and its starting-card snapshot from both participants’ access. Separately retained safety or legal evidence, infrastructure backups, and copies independently saved outside frfr may remain subject to their own applicable handling.
For groups, deleting a participant removes their active messages and reactions; deleting the creator closes and removes their groups. Account deletion also removes profile recognition, live Showcase entries and attributable signed-in card-interaction evidence. We cannot reliably attribute earlier signed-out network evidence to a particular account; it remains subject to the short retention window. Mail already accepted by a delivery provider and copies held by recipients cannot be recalled.
We may verify ownership before acting on a request sent by email. We will explain any applicable exception or extension when required.
14. Security
We use technical and organizational safeguards designed to protect personal information in light of the sensitivity and risk involved. Measures may include:
- encrypted transport using HTTPS/TLS;
- access controls and least-privilege administrative access;
- secure authentication and session controls;
- secrets management;
- rate limits and abuse detection;
- logging and monitoring appropriate to security needs;
- encryption or provider-managed encryption at rest where supported;
- data minimization and retention controls;
- vulnerability and dependency management; and
- incident-response procedures.
No internet service can guarantee absolute security. If you believe your account or information has been compromised, contact support@frfr.link.
Where applicable law requires notification of a qualifying personal-data breach to users or regulators, we will provide that notification within the legally required timeframe.
15. International data transfers
frfr is being developed as a United States-based service and may use providers that process information in the United States and other countries. Those countries may have privacy laws different from the laws where you live.
International transfers are subject to applicable law and the arrangements with the relevant providers. A provider's global infrastructure does not by itself establish that every transfer or market is covered by an approved mechanism.
For information about safeguards relevant to your information, contact contact@frfr.link. We will not describe a representative, contract, certification, or transfer assessment as in place unless it has actually been established.
16. Your privacy rights — global baseline
Regardless of where you live, you may ask us to:
- confirm whether we process personal information about you;
- give you access to personal information associated with your account;
- correct inaccurate or incomplete information;
- delete information, subject to lawful exceptions;
- provide a portable copy of information you provided to us where technically feasible;
- withdraw consent where processing is based on consent;
- object to or request restriction of certain processing;
- opt out of sale, sharing for targeted advertising, or qualifying profiling if such practices ever apply;
- appeal a denial of a privacy request where applicable; and
- explain material automated recommendation logic when applicable law requires it.
You can make a request through available account settings or by emailing contact@frfr.link.
We may need to verify that you are the person to whom the information relates. We will not require more verification data than reasonably necessary. Authorized agents may submit requests where applicable law permits, but we may require proof of authority and verification of the user.
We aim to respond to verified privacy requests within 30 days. If applicable law permits or requires a different timeframe, that timeframe controls. If we need an extension, we will explain why where required.
We do not discriminate against you for exercising a privacy right.
17. Jurisdiction-specific information
The following provisions supplement the global baseline. They apply only when the relevant law applies to our processing. Mandatory local rights prevail over inconsistent language in this Policy.
17.1 European Economic Area (EEA)
If the EU General Data Protection Regulation (GDPR) applies, you may have rights to access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and rights relating to qualifying automated decision-making.
Our principal legal bases are described in Section 6. You also have the right to lodge a complaint with the data-protection authority in the EEA country where you live, work, or believe an infringement occurred.
If Article 27 GDPR requires frfr to appoint an EU representative, that representative's details will be listed in Contact & Legal Notices.
Direct-marketing objection: Where GDPR applies, you have the right to object at any time to processing of your personal data for direct marketing, including related profiling. We will stop that processing when you object.
17.2 United Kingdom
If the UK GDPR and Data Protection Act 2018 apply, you may have rights broadly corresponding to the EEA rights above. You may complain to the UK Information Commissioner's Office.
If UK law requires us to appoint a UK representative, the representative's details will be listed in Contact & Legal Notices.
17.3 California and other U.S. states
Depending on the state and whether statutory thresholds are met, U.S. residents may have rights to know/access, delete, correct, obtain a portable copy, opt out of sale, targeted advertising or qualifying profiling, limit certain uses of sensitive personal information, use an authorized agent, appeal certain request denials, and receive equal service when exercising rights.
For transparency, during the preceding 12 months we may have collected the following broad categories of personal information: identifiers; internet/network activity; professional or educational information; audio/visual information; general geolocation or location information you provide; user-generated content and communications; and inferences such as interests or recommendation relevance. We collect these categories from you, your device/browser, authentication providers you choose, other users when they interact with or report content, and service providers operating on our behalf.
We disclose applicable categories to the public or other users at your direction and to processors/service providers, legal recipients, and transaction counterparties for the purposes described in this Policy.
We do not currently sell personal information or share personal information for cross-context behavioral advertising.
17.4 Canada
Where Canadian private-sector privacy law applies, you may request access to personal information we hold about you, information about its use and disclosure, and correction of inaccuracies. You may withdraw consent subject to legal or contractual limits and reasonable notice. You may raise a privacy concern with contact@frfr.link and, where applicable, with the Office of the Privacy Commissioner of Canada or the relevant provincial privacy regulator.
17.5 Brazil
Where Brazil's Lei Geral de Proteção de Dados (LGPD) applies, you may have rights including confirmation of processing, access, correction, anonymization/blocking/deletion of unnecessary or unlawfully processed data, portability where regulated, information about sharing, withdrawal of consent, deletion of data processed on consent where applicable, objection, and review or explanation of certain automated decisions.
Our privacy contact acts as the initial point of contact for LGPD requests unless and until a separately designated encarregado is listed in Contact & Legal Notices. You may also petition Brazil's ANPD where legally available.
17.6 India
Where India's Digital Personal Data Protection Act, 2023 and rules in force under it apply, frfr acts as a Data Fiduciary for covered processing. You may have rights to obtain information about processing, correction, completion, updating and erasure, grievance redressal, and nomination as provided by applicable law.
You may submit a grievance to contact@frfr.link. Our intended grievance-response period is 30 days and in all cases will not exceed a shorter statutory deadline that applies to us. Rights and obligations that become effective on phased statutory commencement dates will apply when legally in force.
17.7 Australia
Where the Australian Privacy Act and Australian Privacy Principles (APPs) apply, you may request access to and correction of personal information. You may complain to contact@frfr.link about our handling of personal information. We will investigate and respond within a reasonable period.
We may disclose personal information to overseas recipients or processors, including in the United States and other locations listed in our provider schedule. Where APP 8 applies to a disclosure, we will take the steps required by applicable law to address cross-border protection.
17.8 New Zealand
Where the New Zealand Privacy Act 2020 applies, you may request access to and correction of your personal information. Where applicable, cross-border disclosures are made subject to Information Privacy Principle 12 or another lawful basis.
17.9 Singapore
Where Singapore's Personal Data Protection Act (PDPA) applies, you may have rights to withdraw consent and request access to and correction of personal data, subject to statutory exceptions. We apply retention limitation, reasonable security, and applicable cross-border transfer protections. Our privacy contact is contact@frfr.link.
17.10 Japan
Where Japan's Act on the Protection of Personal Information (APPI) applies, you may have rights regarding disclosure, correction, suspension of use, or deletion of retained personal data as provided by law. Cross-border transfers will be handled using a basis permitted under APPI.
17.11 South Korea
Where South Korea's Personal Information Protection Act (PIPA) applies, you may have rights including access, correction/deletion, suspension of processing, and other rights provided by law. Cross-border processing or transfers will be handled using required notices, consent, contractual safeguards, or another valid basis as applicable.
If Korean law requires a domestic agent based on our scale or activities, the agent's details will be listed in Contact & Legal Notices.
17.12 China
Where the People's Republic of China's Personal Information Protection Law (PIPL) applies, you may have rights to know, decide, restrict or refuse certain processing, access/copy, correct/complete, and request deletion as provided by law.
Where PIPL applies to an overseas processor and requires a representative or specialized agency in China, the applicable details will be listed in Contact & Legal Notices. Cross-border processing will be handled using any notice, separate consent, contract, certification, security assessment, or other mechanism required by applicable law.
17.13 Switzerland
Where the Swiss Federal Act on Data Protection (FADP) applies, you may request information about processing and request correction or deletion where provided by law. Cross-border disclosures will use adequate destinations, recognized safeguards, or another lawful basis where required.
17.14 South Africa
Where South Africa's Protection of Personal Information Act (POPIA) applies, you may have rights to access, correct, delete, or object to processing as provided by law. We apply purpose limitation, information quality, openness, security safeguards, and applicable cross-border requirements when POPIA applies.
17.15 Other jurisdictions
Other countries and states may provide additional rights, restrictions, breach-notification requirements, localization requirements, representative requirements, or consumer protections. Nothing in this Policy limits a mandatory right that applies to you. Contact contact@frfr.link to exercise a right not expressly listed above.
18. Automated systems and AI
Optional assisted profile drafting
Assisted profile drafting is available in the public beta and is optional. Before generation, you review the text and explicitly approve sending it to the OpenAI API. Use only your own material and remove private or sensitive details; automated minimization can miss details. If you use a résumé to help draft your page, text is extracted locally for your review; the original PDF is not uploaded for AI drafting. You can use the manual path without sending text to OpenAI.
Photos, an optional video and an optional résumé PDF added to your page preview, along with their captions and filenames, stay in this browser. These files and their locally staged captions and filenames are not sent to OpenAI or uploaded with an anonymous text draft. Local preview files are available for up to 24 hours; expired copies are removed when the local file store is next accessed. They do not follow email verification to another device, where you must select them again.
After email verification, you can explicitly bring these files into your profile editor in the same browser and upload them when saving. This is separate from using résumé text for AI drafting. New imported media and résumé cards start private; review their visibility before sharing. The display photo is public when your profile is published. Removing a local file or discarding its draft removes that local copy; clearing this site's browser data also removes it. Avoid leaving local previews on a shared device. Uploaded files follow the profile-media and document rules elsewhere in this Policy.
We request a non-stored API response (store: false), with no browsing or external
tools. This is not a promise of zero provider retention: OpenAI documents default
abuse-monitoring logs that may retain customer content for up to 30 days, subject
to its stated exceptions. We have not enabled Zero Data Retention. OpenAI states
API data is not used for model training by default. See
OpenAI's API data controls.
Suggestions can be inaccurate. You can edit or discard them; nothing is published without your explicit action. Drafting does not enroll you in discovery or grant Network access. Review your text, files and their visibility before publishing.
frfr may use automated systems to identify spam, detect abuse, organize profile content, calculate relevance, or generate recommendations and explanations.
As of the effective date of this Policy:
- we do not use automated systems to make decisions that have legal or similarly significant effects on you;
- we do not use private messages for cross-context advertising; and
- we do not provide private messages or non-public profile content to third parties for training general-purpose generative-AI models without a separate lawful basis and appropriate notice/consent where required.
If these practices materially change, we will update this Policy before the new processing begins and obtain consent where law requires it.
19. Children and teenagers
frfr accounts are limited to people 18 and older. See our Age Policy.
If we learn that an account belongs to someone under 18, we may suspend the account and delete personal information associated with it, subject to limited retention needed for safety, legal compliance, or prevention of repeated attempts to evade the age rule.
If you believe a person under 18 has created an account or personal information about a minor is being unlawfully displayed, contact support@frfr.link or contact@frfr.link.
20. Complaints and appeals
If you believe we have mishandled your personal information, contact contact@frfr.link first. Please describe the issue and the outcome you are seeking.
We will investigate in good faith and respond within a reasonable period, generally within 30 days. If applicable law provides a right to appeal our decision, you may reply to the decision or use the appeal method we provide.
You may also lodge a complaint with a competent privacy or data-protection regulator where applicable law gives you that right.
21. Changes to this Policy
We may update this Policy as the Service, our providers, or applicable laws change. We will post the revised Policy with a new “Last updated” date.
For a material change that meaningfully expands how we use personal information, we will provide additional notice and obtain renewed consent where required by law.
22. Controller and contact
Account help and safety reports: support@frfr.link
Privacy, data rights, copyright, and legal notices: contact@frfr.link
See Contact & Legal Notices for reporting instructions.
frfr-HQ LLC, a Delaware limited liability company, operates frfr and is responsible for the personal information described in this Policy. Our business mailing address is 121 Portland St. #304, Boston, MA 02114, United States.