Fren One Privacy Policy

Last updated: July 17, 2026

1. About This Policy

This Privacy Policy explains how Fren One Digital Inc. ("Fren One", "we", "us", or "our") collects, uses, shares, and protects personal information across our products: the Fren One Telegram agent and Discord agent, the management dashboard at app.fren.one, our optional integrations (such as X and Slack), and our AI-assisted and Web3 features. Together these are the "Service."

Our roles. When we process personal data of Community Members on behalf of and on the instructions of a Community owner or admin ("Operator"), we act as a data processor and the Operator is the controller. We act as an independent controller for account, billing, security, support, and aggregated or de-identified analytics data. Where we are a processor, the Operator is responsible for having a lawful basis and for notifying Members.

2. Definitions

  • "Agent" — a Fren One automated assistant added to Telegram or Discord.
  • "Community" — a Telegram group/channel or Discord server where an Agent operates.
  • "Member" — a participant in a Community.
  • "Operator" — the account holder who connects and administers an Agent or Community.

3. Information We Collect

Account information (Operators)

  • Identity and contact details: name, username, email address(es), profile image, language, and timezone, provided via our authentication provider (Clerk), including via Google, Discord, or other sign-in methods you choose;
  • Connected-account tokens for platforms you link (e.g., Discord, Telegram, X, Slack), stored in encrypted form;
  • Account, team, project, and role settings, and onboarding responses.

Community data (processed for Operators)

  • Message content and metadata (text, author ID and username, channel, timestamps, edits, replies, message type, and attachment metadata) needed to provide the features you enable;
  • Member directory data (member IDs, display names, usernames, avatars, role assignments, and join dates) used to provide role management, verification, analytics, and moderation features;
  • Member activity and lifecycle events (joins, leaves, reactions, and similar), including invite attribution (which invite link a Member joined through and the inviting Member) where invite tracking is enabled;
  • Moderation and audit records (warnings, mutes, bans, approvals, and the admin and target involved), including contextual notes our AI moderation features retain about moderation-relevant activity in the Community;
  • Support ticket conversations, including transcripts, notes, and attachments, where the ticketing feature is enabled;
  • Verification and onboarding data, such as captcha completion status;
  • Gamification data, such as activity points ("XP"), levels, and quest completions;
  • Derived signals generated from the above, such as sentiment labels and relevance scores.

Discord privileged intents. To provide these features, our Discord agent uses Discord's Message Content intent (to read messages in servers where it is installed, powering moderation, spam and raid protection, tickets, analytics, and the other features Operators enable) and the Server Members intent (to access the server's member list and role information, powering verification, role management, welcome features, and member analytics). We collect this data only from Communities where an Operator has installed the Agent, and we use it only to provide the features described in this Policy.

Cross-platform bridging. If an Operator enables our bridge feature between connected Communities (for example, between a Discord server and a Telegram group), messages posted in a bridged channel — including the message text, attachments, and the sender's display name, username, and avatar — are relayed to the linked Community on the other platform. Relayed content on the destination platform is governed by that platform's own terms and policies.

X (Twitter) integration data (Operators)

  • Details of X accounts you connect (handle, profile information, and verification status), with access tokens stored in encrypted form;
  • Posts you draft, schedule, or publish through the Service, including review and approval history. If you generate a shareable preview link for a scheduled post, anyone with that link can view the post content;
  • Public X content (posts, profiles, and engagement data) retrieved for the keywords and accounts you choose to monitor, along with derived relevance and opportunity scores.

Web3 data

  • Wallet addresses you or your Members provide for token-gating, and the on-chain balances or activity queried to evaluate access;
  • Public on-chain transaction data (such as swaps) used for price feeds and activity notifications.

Billing information

  • Plan, subscription status, and billing identifiers from our payment processor (Stripe). We do not store full payment-card numbers.

Automatically collected information

  • Usage, log, and diagnostic data, device and browser information, and IP address, used to operate, secure, and improve the Service.

4. How We Use Information

  • Provide, maintain, and secure the Service and the features you enable;
  • Moderate content, detect spam and abuse, and support onboarding and verification;
  • Generate analytics, insights, and reports for Operators about their own Communities;
  • Provide AI-assisted features (see Section 6);
  • Communicate with you about support, security, updates, and (where permitted) product news;
  • Process payments and manage subscriptions;
  • Detect, investigate, and prevent fraud, abuse, and security incidents; and
  • Comply with legal obligations and enforce our terms.

We do not sell personal information, and we do not use Community data to build datasets or train our own or third parties' machine-learning models. Where we improve the Service using Community data, we use aggregated or de-identified data that cannot reasonably be used to identify an individual.

5. Legal Bases for Processing (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Contract (Art. 6(1)(b)): to provide the Service to Operators under our Terms.
  • Legitimate interests (Art. 6(1)(f)): to operate Community features, moderate content, secure the Service, prevent abuse, and produce analytics for Operators, balanced against the rights of Members. Where we act as processor, the Operator determines the applicable basis for Member data and is responsible for notifying Members and obtaining any consents required by local law.
  • Consent (Art. 6(1)(a)): for optional features and communications where we ask for it; you may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): to comply with applicable law.

Some features (such as sentiment analysis) could incidentally process information that reveals sensitive characteristics. We do not seek to derive special-category data, and Operators should enable such features only where lawful for their Community.

6. AI Processing

To provide AI-assisted features — such as moderation, sentiment analysis, knowledge-base assistants, and reporting — we send relevant content to trusted third-party AI providers acting as our subprocessors (see Section 7). We instruct these providers, by contract and/or API configuration, not to use your data to train their models, and we use their business/API tiers for this purpose. We send only the data needed for the requested feature and retain AI inputs and outputs in line with Section 9. AI output may be inaccurate and should be reviewed before reliance.

7. How We Share Information

We do not sell your personal information. We share it only as described here.

Subprocessors

We use trusted service providers who process data on our behalf under contractual confidentiality and data-protection obligations. As of the date above, these include:

  • Cloud hosting and storage: Amazon Web Services and MongoDB Atlas (databases, compute, and file storage), and Amazon CloudFront (content delivery).
  • Authentication: Clerk.
  • Payments: Stripe.
  • Email delivery: Resend.
  • Bot/abuse protection: hCaptcha.
  • AI providers: OpenAI, Google, xAI, Fireworks AI, ASI, Cohere, and Tavily, used to deliver the AI features described in Section 6.
  • Platform data services: third-party data providers used to power optional integrations (for example, social-media data, public web content retrieval, and transcript services).
  • Workspace integrations: Slack, where you connect a Slack workspace to receive alerts and notifications from the Service.

This list may change as our Service evolves; we will keep it current and provide notice of material changes as required.

Other platforms

To operate within Telegram and Discord, we exchange data with those platforms as needed, and where you connect X or Slack we exchange data with those platforms to provide the integrations you enable. If an Operator enables cross-platform bridging, message content and sender details are relayed between the linked Communities as described in Section 3. Each platform's handling of your data is governed by its own policies.

Legal and safety

We may disclose information where required by law or valid legal process, or to protect the rights, safety, and security of Fren One, our users, or the public.

Business transfers

If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

8. International Data Transfers

We are based in Canada, and our infrastructure and subprocessors are located primarily in the United States. Your information may be transferred to, stored in, and processed in countries other than your own, which may have different data-protection laws. Where we transfer personal data from the EEA, the UK, or other regions with transfer restrictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or other lawful transfer mechanisms. You may request more information using the contact details below.

9. Data Retention

We keep personal information only for as long as necessary for the purposes described in this Policy, after which we delete it or irreversibly anonymize it. Our retention targets are:

  • Message content: retained for up to 90 days to provide moderation and the features you enable, then deleted or anonymized, unless a longer period is needed for an active moderation matter or to comply with law.
  • Moderation and audit records: retained for up to 12 months to support accountability and dispute resolution.
  • Support ticket transcripts: retained while the Community remains connected so Operators can reference support history, then deleted or anonymized with the associated Community data.
  • Member directory data: kept current while the Agent operates in a Community and deleted or anonymized within a reasonable period after the Agent is removed.
  • Verification status (e.g., captcha): retained for up to 30 days.
  • Aggregated or de-identified analytics: retained on an ongoing basis, as it no longer identifies individuals.
  • Account, profile, and configuration data: retained for the life of your account and deleted within a reasonable period after account closure.
  • Billing records: retained as required by tax and accounting law.
  • Backups: routine backups are retained on a short rolling cycle and then overwritten.

When an Agent is removed from a Community or an Operator deletes a Community, we delete or anonymize the associated Community data within a reasonable period, except where retention is required by law or for legitimate security purposes.

10. Data Security

We implement technical and organizational measures designed to protect personal information, including:

  • Encryption of data in transit and at rest;
  • Access controls, authentication, and the principle of least privilege;
  • Encrypted storage of sensitive credentials such as connected-account tokens; and
  • Monitoring, logging, and regular review of our security practices.

No method of transmission or storage is completely secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities where required by law.

11. Your Rights and Choices

Depending on where you live, you may have some or all of the following rights regarding your personal information:

  • Access a copy of the personal information we hold about you;
  • Correct inaccurate or incomplete information;
  • Delete your personal information;
  • Port your data to another service in a structured, machine-readable format;
  • Object to or restrict certain processing, including processing based on legitimate interests;
  • Withdraw consent where processing is based on consent; and
  • Opt out of marketing communications.

To exercise these rights, email privacy@fren.one. We will respond within the period required by applicable law (and within 30 days where we can). Because much Member data is processed on behalf of an Operator (who is the controller), we may direct your request to, or fulfill it in coordination with, the relevant Operator. You also have the right to lodge a complaint with your local data-protection authority; in the EEA/UK you may contact your national authority, and in Canada the Office of the Privacy Commissioner of Canada or the BC Office of the Information and Privacy Commissioner.

We will not discriminate against you for exercising your privacy rights.

12. Children and Minors

Account holders must be at least 18 years old. The Service is not directed to children under 13, and we do not knowingly collect personal information from them. Members of a Community must meet the minimum age required by Telegram or Discord (generally 13, or higher in some countries). If you believe a child under 13 has provided us personal information, contact us and we will take steps to delete it.

13. Cookies and Similar Technologies

We use a limited set of cookies and similar technologies that are necessary to operate the Service — for example, authentication/session cookies set by our login provider on the fren.one domain, and short-lived security cookies used during account-linking flows. We do not use third-party advertising or cross-site tracking cookies.

14. Notice to Community Members

If you are a Member of a Community that uses a Fren One Agent, the Operator of that Community decides which features are enabled and is responsible for notifying you and for the lawful basis of processing your data within their Community. We process that data on the Operator's behalf to provide the Service. Questions about a specific Community are best directed to its Operator; you may also contact us using the details below.

15. Region-Specific Disclosures

EEA and United Kingdom

If you are in the EEA or UK, you may contact us about this Policy and your rights at privacy@fren.one. We will identify our appointed EU and UK representatives here where one is required.

California

We do not sell or share personal information for cross-context behavioral advertising. California residents may exercise the access, deletion, and correction rights described in Section 11 and may designate an authorized agent to act on their behalf.

Canada

We comply with applicable Canadian privacy law, including PIPEDA and BC's Personal Information Protection Act. Our Privacy Officer can be reached at privacy@fren.one.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version here, change the "Last updated" date, and, for material changes, provide additional notice where appropriate. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

17. Contact Us

For privacy questions or to exercise your rights, contact our Privacy Officer:

Fren One Digital Inc.

300 - 1095 McKenzie Ave

Victoria, BC V8P 2L5

Canada

Privacy: privacy@fren.one

General: hello@fren.one