Privacy Policy
Last updated 28 July 2026
This describes what Framework collects, why, and what you can ask us to do about it. Sections that would state where your data is stored or how long we keep it are deliberately left open — we would rather say nothing than say something we cannot yet stand behind.
1. What we collect
Account information — the name, email address, company name and role you provide when you create an account or are invited into a workspace.
Content you upload — the documents, forms, project details, personnel records, insurance, bonding and financial information you put into your knowledge base, and the forms you fill using it. This may include personal information about your employees and subcontractors, and commercially sensitive information about your business and your clients.
Usage records — what the service did on your behalf and what it cost, so we can show you your usage and enforce plan limits. Includes timestamps and which AI operations ran.
2. Why we use it
To operate the service for you: to answer your questions about your own documents, to propose values for the forms you are filling, to show you where each value came from, to meter usage against your plan, and to support you when something goes wrong.
We do not sell your information, and we do not use your documents or company data to advertise to you.
3. Who else processes it
Framework runs on third-party infrastructure and uses third-party AI models. That means some of your content is processed by service providers acting on our instructions.
To be completed. The full sub-processor list, each provider’s role, and the data processing terms we have in place with them. We will publish this list before the beta ends and notify customers when it changes.
4. Where your data is handled, and for how long
To be completed. Storage location, processing locations, retention periods, and any arrangements with AI providers about whether prompts and documents are retained. We are deliberately not making a claim here yet. Framework is a Canadian company and reducing what leaves Canada is an active engineering priority, but the precise, accurate statement will be published here once that work is finished and verified — not before. If this matters to your procurement process, ask us and we will tell you exactly where things stand today.
5. Keeping it separated and secure
Each customer’s data is isolated from every other customer’s, enforced in the database itself rather than only in application code. Access is over encrypted connections. Access to production systems is limited to people who need it to run the service.
No system is perfectly secure. If a breach affects your information, we will tell you.
To be completed. Breach-notification timelines and the formal security commitments we are prepared to make contractually.
6. Your choices
You can view and correct your company and account information in the product at any time, and delete documents you have uploaded. You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it.
To make any of those requests, email support@frameworkai.ca.
To be completed. Our response times for access, correction and deletion requests, and how they map to your rights under applicable privacy law.
7. Children
Framework is a tool for businesses and is not directed at children.
8. Changes
We will notify beta customers before a materially different version of this policy takes effect, and the date at the top of this page will change.
Questions about this document? Email support@frameworkai.ca.