Privacy policy
Version 1, effective 4 September 2026. This covers the AuditFellow website, the account area, the browser extension and the command line tool.
1. The short version
What you write in your AI chat and what it answers never pass through AuditFellow. The extension adds your team's methodology to the request inside your browser and the request goes, as always, to the chat platform you use. The only traffic between your device and AuditFellow is a key check once a day and the download of the methodology pack.
2. What the extension collects
- Your key, stored in the extension's local storage on your device.
- A random device identifier and a device name, sent with the daily key check so the key can be bound to one device.
- Nothing else. No page content, no browsing history, no requests, no answers, no analytics.
Permissions: "storage" keeps the key and the pack on your device; "alarms" schedules the daily check; the host permissions cover only the AuditFellow servers and the three chat sites where the methodology is added.
3. What the website and account area store
- Account details: name, work email, password hash, organization, role, and how you heard about us.
- Organization data: members and roles, keys (hashed, and encrypted so an admin can show them again), one daily check per key (time, device name, result).
- Billing status from our payment provider (plan, subscription state, renewal date). Card details never reach us; the provider, acting as merchant of record, holds them.
- Website usage: pages, visits, referrer, country and device type, without cookies for advertising.
- Messages you send us through the contact form or the in-app Contact page.
4. The team methodology
Corrections your reviewers make become distilled rules. Your organization chooses where they live: on each device only, in AuditFellow's storage (encrypted on your devices before it reaches us, so we hold ciphertext), at an endpoint your company runs, or in a Google Drive folder you share with us. You can export or delete them at any time.
5. What we do not do
- We do not sell data and we do not share it with advertisers.
- We do not use your content to train models.
- We do not read your requests or answers; we cannot, because they do not reach us.
6. Providers
Hosting and database: Cloudflare. Payments and invoices: Lemon Squeezy (merchant of record). Transactional email: our email provider, for key delivery, trial notices and replies. Sign in with Google uses Google's OAuth; we receive your name, email and profile picture.
7. Retention and deletion
Account and organization data are kept while the account exists. When an organization is closed, its stored methodology is available for export for thirty days and is then deleted. Daily key checks are kept for ninety days. You can ask for deletion of your account through the contact form.
8. Your rights and contact
You can ask what we hold about you, correct it or delete it. Questions and requests go through the contact form or the Contact page inside the app.