1. Scope
Froppy creates software products and experiments. This policy applies to the public website at froppy.ai, Froppy-wide update subscriptions, messages sent through the Froppy contact form, and the administration of those services.
A Froppy product may publish its own privacy notice for information it handles. That product-specific notice applies to the product, while this policy continues to apply to your use of froppy.ai and any brand-wide interaction.
2. Information we handle
Information you provide
- Froppy-wide updates: your email address, optional name, consent wording and version, subscription scope and status, signup source, and signup time.
- Support and contact: your name, email address, selected product and topic, optional subject, message, reply permission, and the time and status of the request.
- Privacy requests: the information needed to understand, verify, and respond to your request.
- Authorised administration:an administrator's email address, authentication events, and session information used to protect private management tools.
Context collected with a form
When you submit an updates or contact form, Froppy also records the form source, a same-site source URL without its query string or fragment, and limited browser context such as user agent. Update signups may also include browser-provided locale and time zone. This context helps Froppy keep a consent record, route support, diagnose failures, and prevent abuse.
Information generated by the service
Froppy assigns records identifiers and timestamps and may keep delivery status, support status, product scope, environment, and coarse event or reliability information as described below.
3. How we use information
Froppy uses information to:
- record and honour the subscription choice you make;
- send requested brand updates and manage unsubscribe status;
- store, route, investigate, and reply to support messages;
- send support notifications and submission receipts;
- protect forms, data, and administrator access from misuse;
- measure aggregate product activity and service reliability;
- diagnose operational failures and improve Froppy services; and
- comply with applicable obligations and enforce these policies.
Where applicable law requires a legal basis, Froppy relies on your consent for marketing, on steps you request when you contact Froppy, and on legitimate operational and security interests where those interests are not overridden by your rights. Froppy may also process information where required by law.
4. Froppy-wide updates and consent
The updates form asks for express consent to receive email about Froppy and any of its current or future products. The resulting subscription is stored under the Froppy-wide scope. It is not treated as consent for unrelated third parties.
A signup on an individual product website is a separate, product-specific scope. Product consent is not automatically expanded into Froppy-wide consent, and a support or privacy message never creates a marketing subscription.
You can unsubscribe using the link in a marketing email or by sending a privacy request. Froppy may retain a minimal suppression record, usually the normalised email address, scope, status, and relevant dates, so that an unsubscribe, complaint, or delivery block is not accidentally ignored. A later resubscription requires an affirmative action through the appropriate signup flow.
5. Support messages and email
Accepted contact submissions are stored in Froppy's support database before an email notification is attempted. Froppy uses Resend to notify the configured support inbox and to send a short receipt to the address you supplied. A notification or receipt failure does not remove an already stored message.
If Froppy sends a support reply through its administration tools, the reply history may retain the sender and recipient addresses, subject, message body, delivery identifier and status, attempt information, and relevant timestamps. Replies you send back may remain in the configured support mailbox unless a product offers a separate inbound support system.
Support content is used for the request you made. Please do not send passwords, payment card details, private documents, or other secrets that are not needed to resolve the issue.
6. Download counters, telemetry, and crash reports
Aggregate download counters
Froppy products may use shared counters to record a total for a product and download type, together with the last update time. These counters do not contain an email address or a per-person download history.
Privacy-safe telemetry
This website currently records coarse events when an updates subscription or contact submission is accepted. Event data is limited to an allowlisted event name, route, result, product scope, runtime environment, source, and timestamp. It does not include your name, email address, message content, full URL query string, network address, or browser fingerprint.
Reliability and crash information
Where crash reporting is enabled for a Froppy product, a report may include the product, error kind, environment, app version, platform, process type, short reason or error name, a limited message, stack signature, route, whether the failure was fatal, and time. Froppy's crash reporting design excludes raw crash stacks, screenshots, local file paths, private documents, and user content.
Hosting and email providers may also create short-lived operational logs needed to deliver requests, detect failures, and secure their services. Froppy does not use this operational data to build advertising profiles.
7. Form protection and network data
Public forms are protected by validation, same-site checks, honeypots, and rate limits. For rate limiting, the request's network address and route scope are used transiently as input to a secret-keyed HMAC. Froppy stores the resulting opaque rate-limit key with a count and reset time, either in process memory for local use or in Supabase for shared deployments. The rate limiter does not store the raw network address or user-agent value.
A limited user-agent value may separately be stored with a valid support message or subscription as form context, as described in section 2. Froppy does not attempt to reverse the HMAC identifier or combine it into a cross-site profile.
8. Service providers and disclosures
Froppy relies on service providers to operate this release:
- Vercel hosts and delivers the website and may process request and operational log data.
- Supabase provides the database and server services, administrator authentication, and session handling.
- Resend delivers support notifications, receipts, replies, and Froppy email when it is sent.
These providers process data on Froppy's behalf under their own service terms and security practices. Froppy may also disclose information where required by law, to protect people or services from harm, or as part of a genuine business transfer subject to appropriate safeguards. Froppy does not sell personal information.
9. Retention and deletion
Froppy keeps information only for as long as it remains reasonably needed for the purpose described, to protect the service, to honour a choice, or to meet an applicable obligation. Retention is reviewed by data category rather than treating every record the same.
- Active subscriptions are kept while the subscription remains active. Minimal suppression records may be kept after opt-out.
- Support messages and replies are kept while needed to resolve the request, maintain a useful support history, handle disputes, and secure the service, then deleted or de-identified when no longer required.
- Rate-limit entries expire after their configured protection window. Coarse telemetry, crash records, and operational logs are reviewed and removed or aggregated when individual records are no longer useful.
- Authentication sessions expire under the authentication provider's session controls. Audit records may be kept longer when needed to investigate protected administrator actions.
Deletion from active systems may not immediately remove a record from encrypted backups or provider logs; those copies are isolated and age out through normal backup and security cycles.
10. Security
Froppy uses server-side validation and privileged operations, restricted database access, row-level security, secret-keyed form protection, administrator email allowlisting, and password authentication. Service-role credentials and email provider keys are kept out of browser code.
No internet service or email delivery system can be guaranteed completely secure. Froppy limits collection and access, but cannot promise that loss, misuse, or unauthorised access will never occur.
11. Your choices and privacy requests
Depending on the law that applies, you may ask to access, correct, or delete personal information; object to or restrict certain use; or withdraw consent. You may always unsubscribe from marketing without withdrawing a support request.
Send a privacy request and choose the privacy-request topic. Include enough detail to identify the relevant interaction. Froppy may ask for proportionate verification before disclosing or changing information. Some data may be retained where required to honour suppression, protect security, resolve a dispute, or comply with law. Froppy will explain when a request cannot be completed in full.
12. Children's privacy
Froppy.ai is a general-audience brand website and is not directed to children. Froppy does not knowingly ask children to provide personal information through the updates or support forms. A parent or guardian who believes a child submitted information can send a privacy request so the record can be reviewed and, where appropriate, deleted.
13. International processing
Vercel, Supabase, Resend, and their infrastructure may process or store information in countries other than the country where you live. Privacy rules and government access standards can differ between countries. Froppy uses provider and contractual safeguards available for the service and will provide further location information where applicable law requires it.
14. Product-specific policies
Individual Froppy products can have different features and data practices. A product-specific privacy notice applies to data handled by that product and takes priority if it directly conflicts with this brand-site policy. It does not broaden a Froppy-wide marketing choice or change how a message submitted on froppy.ai is handled.
Review the notice presented by a product before using features that collect account, device, payment, or other product-level information. Froppy.ai itself does not offer public customer accounts, billing, or payment collection in this first release.
15. Changes, history, and contact
Froppy may update this policy as the site, products, providers, or legal requirements change. Material changes will be identified by a new effective date and change-history entry. Where required, Froppy will provide additional notice or seek renewed consent.
Questions about this policy can be sent through the same route: Send a privacy request.
Change history
- Version 1.0
First public release of the Froppy Privacy Policy and Terms.