1. About this policy
Feron ("we", "us", or "our") provides a workspace for managing customer accounts, conversations, and follow-ups. This policy covers feron.io, the application at app.feron.io, and communications with our team. It explains what personal data we handle, why we handle it, who receives it, and how you can exercise your rights.
You can contact us at privacy@feron.io or write to Feron, Founders House Stockholm, Stockholm, Sweden. Our Terms of Service describe the terms for using Feron. Services you connect to Feron or visit through an external link have their own privacy policies.
2. Our role and your organization
Feron acts as a data controller when we decide why and how to process personal data, such as managing our business relationship with you, responding to enquiries, and administering access to our service.
When a business customer instructs Feron to process personal data about its contacts, customers, or product users, that business determines the purposes of the processing and Feron acts as its processor. The customer's instructions and any applicable data processing agreement govern that processing. The customer is responsible for having a lawful basis to provide the data and for informing the people concerned.
If your information is in a customer's workspace, contact that organization about its use of your data. You can also contact us for help identifying the right organization. The Google data restrictions below apply regardless of these roles or a customer's instructions.
3. Information we collect and receive
Information you give us
- Account details: your name, work email address, organization, workspace membership, role, and account identifiers. Feron is available by invitation and uses a sign-in provider to authenticate users.
- Correspondence: the contact details and information you include when requesting access, asking for support, exercising a privacy right, or sending feedback.
- Workspace content: account and contact details, instructions, assistant conversations, follow-up settings, and other information you enter or save in Feron.
Information from connected services
Your organization chooses which services to connect. Connected product analytics can supply customer and account identifiers, names, email addresses, company details, feature usage, events, sessions, and activity over time. Feron uses this information to show account activity and help you prepare relevant follow-ups. What we receive depends on the source and the data your organization makes available.
When you connect Gmail, we receive or access:
- Google account information: the email address of the connected account, used to identify the mailbox in Feron. We request account identity and email permissions, but not the Google profile permission.
- Email content and metadata: sender and recipient addresses, subject, date, message text, snippets, labels, and message and thread identifiers for correspondence relevant to your request or a routine you configure. We do not download attachments.
- Connection records: access and refresh tokens, granted permissions, connection status, and timestamps. Tokens let Feron perform the authorized work without asking you to reconnect for each request.
Information created while you use Feron
We process answers, summaries, drafts, and sent-message records created through Feron. These can contain personal data from the information you supplied or connected, including Gmail content. Saved conversations, routine settings, and records of configured follow-ups are part of your workspace data.
Technical and usage information
Delivering and protecting the website and application involves processing technical request information, such as IP addresses, browser details, request times, and errors. In the application, product analytics records page visits, sessions, feature interactions, and performance information. Those events can be associated with your user ID, name, email address, role, and workspace details. The cookies section explains browser storage and session replay. This public website has no third-party analytics or advertising trackers.
4. How we use personal data
We use personal data to give you access to Feron, provide the features you use, answer requests, maintain the service, and meet our legal obligations. Where Feron acts as controller, we rely on the following legal bases as applicable:
- Providing the service and responding to requests: performance of a contract with you or steps you ask us to take before entering one. This includes managing access and providing support.
- Working with business customers: our legitimate interest in administering the customer relationship and supporting the people authorized to use Feron for that organization.
- Security, reliability, and product usage analysis: our legitimate interests in preventing abuse, resolving errors, and understanding how the service works, subject to consent where required. Gmail content is not used for product analytics.
- Optional processing that requires permission: your consent, which you can withdraw. Authorizing a Gmail connection permits the access described below; it does not permit unrelated uses of your Google data.
- Legal requirements: compliance with obligations that apply to Feron, including responding to valid legal requests.
When relying on legitimate interests, we consider the effects on your rights and reasonable expectations. You may object to that processing. Where we act as a processor, the customer is responsible for the legal basis for its instructions. None of these purposes expands the permitted uses of Google data described next.
5. Google account access and Limited Use
Connecting Gmail is optional. Access begins when you choose to connect an account and approve Google's consent screen. Feron uses the connection to find relevant correspondence, answer questions about an account, summarize conversations, and prepare follow-ups. The interactive assistant creates Gmail drafts for your review. Follow-up routines can send messages automatically according to the settings you choose.
Permissions we request
openid: Confirms which Google Account you are connecting.email: Shows which Gmail account is connected. Feron stores this address as the connection label.https://www.googleapis.com/auth/gmail.readonly: Lets Feron find and read relevant emails for summaries and follow-ups. This includes message headers, bodies, and snippets. Attachments are not downloaded.https://www.googleapis.com/auth/gmail.compose: Lets the assistant create drafts for you to review in Gmail. Automated follow-up routines use the same permission to send messages according to your settings.
These permissions apply to the Gmail account you connect. Feron does not request access to your Google Drive files or Calendar through this connector. Read the Gmail Connector page for more detail about what happens when you connect.
Limits on Google data use
Feron's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google data is used only to provide the features you request or configure. These restrictions also apply to summaries, drafts, and other derived data, including aggregated or anonymized Google data. We do not sell it, provide it to data brokers or information resellers, use it for advertising or retargeting, or use it to determine creditworthiness or make lending decisions.
Feron does not use data obtained through Google Workspace APIs, including the Gmail API, to develop, improve, or train generalized or non-personalized AI or machine-learning models. This restriction also applies to providers processing that data for Feron. Google data is not supplied for their independent model training or other unrelated purposes. The limits on sharing and human access apply to everyone handling this data for us.
6. The assistant and follow-up routines
Feron uses AI to generate answers, summaries, and drafts from the information relevant to your request or routine. The content sent for processing can include your instructions, account details, and relevant Gmail correspondence. Our model provider is identified in the section on service providers.
Generating a response is different from training a model. Feron does not use Gmail data to train AI models. The Google data restrictions above apply to both the information sent for processing and the resulting content saved in Feron.
Generated content can be incomplete or incorrect. Review assistant drafts before sending them in Gmail. If you enable a routine that sends automatically, review its recipients, instructions, and sending settings before enabling it. Feron is a tool for managing customer work; it is not intended to make decisions about a person's legal rights or access to essential services.
7. Cookies and browser storage
The public website does not use advertising cookies, third-party analytics, or session replay. Opening the website does not connect your Gmail account.
The application uses cookies and browser storage for sign-in, sessions, security, and saved interface preferences. Application analytics may also use browser identifiers to associate usage events with a session or account. Where session replay is enabled, it uses conservative masking. Form-content and network-request-body collection are disabled in our analytics configuration, and Gmail message content is excluded from analytics.
You can remove cookies and local storage through your browser settings. This may sign you out or reset preferences. Clearing browser storage does not revoke a Gmail connection or delete records held in Feron; those actions are described in the disconnecting and deletion section.
8. Who receives personal data
Personal data is shared as needed to operate Feron and carry out the work you authorize. Providers acting on our behalf process data under contractual obligations for the services they supply.
Service providers and connected services
- Slack receives the contact details, company information, and product-news preference you submit through our access request form, so our team can review and respond to your request.
- Specific hosts Feron and its storage, including account data, encrypted connection tokens, saved conversations, analytics records, and routine drafts and sent-message records.
- OpenAI processes the relevant instructions and content used to generate responses, summaries, and follow-ups. This can include Gmail message content. Feron does not authorize model training on Google data. See OpenAI's business data privacy information.
- WorkOS handles sign-in and sessions using identity, organization, and authentication information. We do not send it Gmail message content. See the WorkOS privacy policy.
- Amplitude receives application usage events and associated user and workspace details for product analytics. If enabled, it also processes masked session replay. Gmail message content is not shared for these purposes. Separately, customers can connect an Amplitude source to bring their own product-usage data into Feron.
- Google provides the Gmail connection. Feron retrieves authorized email data from Google and sends draft or message content back to Gmail when performing the work you request or configure.
Your organization and message recipients
Workspace information is available according to your organization's access permissions. Messages you send, or authorize a routine to send, are delivered to their recipients through your connected account. Your organization controls its workspace and is responsible for the information it chooses to share through Feron.
Legal requirements and business changes
We may disclose information where necessary to comply with law or investigate a security incident or abuse. If a merger, acquisition, or sale of Feron involves transferring personal data, it remains subject to the applicable privacy obligations. Google user data will only be transferred in such a transaction after obtaining your explicit prior consent.
Transfers of Google data to providers are limited to supplying the features you authorize, with your consent. The only other permitted transfers are for necessary security purposes, legal requirements, or the explicitly consented business transaction described above. We do not disclose it for unrelated third-party purposes. The Google Limited Use restrictions take priority over any more general description of sharing in this policy and also bind our providers.
9. International transfers
Our providers may process personal data outside the country where you live, including outside the EU/EEA. Where a transfer requires legal safeguards, we rely on the safeguards applicable to that transfer. A provider's processing location does not change the purposes or Google data restrictions described in this policy.
Contact privacy@feron.io for details about the locations and transfer safeguards relevant to your data, including how to obtain information about those safeguards.
10. How long we keep information
Retention depends on the type of record, the feature it supports, whether the account or connection is active, your instructions, and any legal requirement to keep it. We retain data for the purpose described in this policy and delete it when it is no longer needed for that purpose, subject to the limited exceptions below.
- Account, workspace, and connected analytics records are retained to provide the customer's workspace and its saved history, subject to customer instructions and deletion requests.
- Gmail messages retrieved for processing are fetched when needed for a request or routine. Feron does not keep a copy of your mailbox or store fetched bodies as standalone email records. Content used in saved work is handled as described below.
- Assistant conversations remain available so you can return to them. If a conversation includes Gmail content, that content remains until the conversation or account is deleted.
- Routine drafts and sent-message records can contain recipient details, subject, body, a short explanation of the draft, and sending status. Sent records also include Gmail message and thread identifiers. These records remain until deleted; the fetched correspondence is not separately kept as a mailbox copy.
- Connection tokens and metadata are retained while the connection is active. Disconnecting removes stored access and refresh tokens and requests revocation at Google. Removing access directly at Google stops future authorized access but does not itself delete Feron's saved records.
- Support correspondence is kept as needed to handle your request and retain a relevant record of the response. Application logs and product analytics follow the retention cycles of the services that hold them.
- Backup copies expire according to our hosting platform's backup cycle. Deleting data from active systems may therefore precede its expiry from backups. Records required by law are kept only for the applicable legal purpose and period.
We do not publish a fixed period for every category. You can ask about the retention that applies to your records at privacy@feron.io. The Data Deletion page explains how to request removal. Drafts, sent messages, and recipients' copies held in email accounts are governed by those accounts; deleting data in Feron does not remove them.
11. Security and access to data
We use TLS to protect data in transit, encrypt connection tokens at the application layer using AES-256-GCM, restrict access to production systems, and enforce workspace boundaries. These measures protect against unauthorized access, disclosure, alteration, and loss. See our Security page for further details. No system can guarantee complete security.
Human access to Google data
Email processing is automated. Authorized personnel may access systems only as needed for their responsibilities. A person may read specific Gmail content to help with a support request only after you affirmatively agree to that access. Without that agreement, human access is limited to what is necessary to investigate a security issue or abuse, or comply with law. The same limits apply to people working for providers that process Google data for Feron.
12. Your privacy rights
Depending on the law that applies and the circumstances, you can ask us to:
- Confirm whether we hold personal data about you and provide access to it.
- Correct information that is inaccurate or incomplete.
- Delete personal data or restrict its processing.
- Provide eligible data in a portable format.
- Stop processing based on legitimate interests where your objection applies.
You can withdraw consent for processing based on consent at any time. Withdrawal does not affect processing that was lawful before you withdrew it. You also have the right to object to direct marketing.
Send requests to privacy@feron.io. We may need enough information to verify your identity and locate the relevant records. We respond within the time limits required by applicable law. Some rights have exceptions; if we cannot fulfil a request, we will explain why. For data processed on a customer's behalf, we assist the customer in responding to the request.
You may complain to the data protection authority where you live or work, or where an alleged infringement occurred. In Sweden, you can contact the Swedish Authority for Privacy Protection (IMY).
13. Disconnecting and deleting your data
- To stop Gmail access, open Connections in Feron and disconnect Gmail, or remove Feron from your Google Account permissions. This stops future authorized reading, drafting, and routine sending for that connection.
- To delete data already stored in Feron, email privacy@feron.io from your Feron account address with the subject "Data deletion request." Tell us whether the request concerns your account or particular records so we can identify its scope.
After verifying and confirming the scope of your request, we delete the relevant account data, stored tokens, connection records, conversations, and routine records from active systems, subject to applicable legal requirements and customer instructions. Limited backup retention is described above. Disconnecting alone does not delete saved conversations or drafts. See the Data Deletion page for the full process and what remains in Gmail.
14. Children
Feron is intended for business users aged 18 and over, as described in our Terms of Service. It is not directed to children, and we do not knowingly collect personal data directly from children. Contact us if you believe a child has provided personal data to Feron so we can investigate and address it.
15. Changes to this policy
We update this policy when our service or data practices change. The date above shows the latest revision. We provide additional notice for material changes as required by law.
Before accessing additional Google user data or using it for a new purpose, we will explain the change and obtain your consent. Continued use of Feron alone does not authorize new uses of your Google data.
16. Contact
For privacy questions and requests, email privacy@feron.io. For help using Feron, email support@feron.io. Our postal contact is Feron, Founders House Stockholm, Stockholm, Sweden.