Privacy Policy
Last updated 26 August 2026
This describes what Framework collects, why, and what you can ask us to do about it. Section 4 says where your data is handled — including the parts that are not tidy, because a privacy policy that only mentions the flattering half is not worth reading.
1. What we collect
Account information — the name, email address, company name and role you provide when you create an account or are invited into a workspace.
Content you upload — the documents, forms, project details, personnel records, insurance, bonding and financial information you put into your knowledge base, and the forms you fill using it. This may include personal information about your employees and subcontractors, and commercially sensitive information about your business and your clients.
Usage records — what the service did on your behalf and what it cost, so we can show you your usage and enforce plan limits. Includes timestamps and which AI operations ran.
2. Why we use it
To operate the service for you: to answer your questions about your own documents, to propose values for the forms you are filling, to show you where each value came from, to meter usage against your plan, and to support you when something goes wrong.
We do not sell your information, and we do not use your documents or company data to advertise to you.
3. Who else processes it
Framework runs on third-party infrastructure and uses third-party AI models. That means some of your content is processed by service providers acting on our instructions.
These are all of them. Each acts on our instructions, under terms that limit them to providing their service to us.
- Anthropic — the AI models that read your documents, answer your questions and propose form values. Receives the text and page images of documents you ask it to work on, and what you type in chat.
- Microsoft — turns your documents into the numerical form that makes them searchable, through its Azure OpenAI service. Receives your document text in short passages. Until 25 August 2026 this step used OpenAI instead; passages sent before that date were processed in the United States. OpenAI is no longer sent anything and is no longer on this list.
- Supabase — our database, sign-in system and file storage. Holds your account, your knowledge base and the files you upload.
- Vercel — runs the application itself. Handles your requests as they pass through.
- DigitalOcean — runs the server that opens and reads your documents. Receives the file while it is being read.
- Resend — sends the emails we have to send you: invitations, password resets and account notices. Receives your email address and the links those emails carry.
We do not currently take payment through the product. There is no payment processor in this list because none is running. If that changes, the processor will be added here before it handles anything of yours.
We will tell you before adding a provider that processes your content, and the date at the top of this page will change. Where each of these runs is the subject of the next section.
4. Where your data is handled, and for how long
Your documents and your knowledge base are stored in Canada. Our database, sign-in system and file storage run in Supabase’s Canadian region, in Montréal. The server that opens and reads your uploaded files runs in Toronto.
Making your documents searchable also happens in Canada. Turning your document text into the numerical form that makes it searchable runs on Microsoft’s Azure OpenAI service in its Canada East region. That has been true since 25 August 2026. Before that date this step ran on OpenAI’s commercial service in the United States.
The AI model that reads your documents runs in the United States. Anthropic is our model provider, and there is no Canadian option on any route currently available to us. When you ask a question about your documents, fill a form, or have a scanned document read, the text and page images involved are processed in the United States under Anthropic’s commercial terms. If that is unacceptable for a particular document, do not upload it — and tell us, because we would rather know.
On training. Anthropic states: “By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.” We are on those commercial terms. We do not use your documents or your company data to train anything of our own either.
The part that is not tidy, said rather than left out. Vercel runs the application itself. We have pinned its server functions to Montréal, but Vercel deploys its routing layer to every region it operates in regardless of that setting — so the step that checks you are signed in may handle your user id and email address outside Canada. Your documents, your knowledge base and the AI calls do not go through it. We would rather write that down than let a simpler sentence do work it cannot do. The emails we send you go through Resend in the United States, carrying your email address and the links in them.
We do not have a zero-data-retention arrangement, and it is not for want of asking. Anthropic declined one on 14 July 2026, Microsoft declined on 17 August 2026, and Amazon declined us model access outright on 20 August 2026. So content sent to an AI provider may be held by that provider for a limited period under its standard abuse-monitoring practice, and seen by its authorised staff if something is flagged. Moving the searchable-form step to Canada bought Canadian processing and Microsoft’s enterprise terms. It did not buy an exemption from that, and we are not going to describe it as though it did.
How long we keep it. Your account information, your knowledge base and the files you upload are kept until you delete them or ask us to close your workspace, which is described in section 6. The one thing that outlives a deletion is the record of what the service did on your behalf, and we have not yet settled how long that should be held. That is the one figure still missing from this page. When we settle it we will write it here, and the date at the top of this page will change.
5. Keeping it separated and secure
Each customer’s data is isolated from every other customer’s, enforced in the database itself rather than only in application code. Access is over encrypted connections. Access to production systems is limited to people who need it to run the service.
No system is perfectly secure. If a breach affects your information, we will tell you.
If a breach affects your information, we will contact you without undue delay, and in any case within 72 hours of confirming it affects you. We will tell you what we know, what we do not yet know, what we are doing about it, and what we suggest you do. We will not wait until we have a complete picture before telling you there is one.
Two things support that. Every action the service takes in your workspace is written to a record that your workspace can read and cannot alter, so there is something to investigate with. And each customer’s data is separated in the database itself, so the question “could this have reached another customer’s data” has an answer rather than an opinion.
What we do not have yet, said plainly: Framework holds no third-party security certification, and we are not going to imply one. If your procurement process needs a completed security questionnaire or a signed data-processing agreement, ask us — we will complete the questionnaire honestly, including the parts where the answer is “not yet”.
6. Your choices
You can view and correct your company and account information in the product at any time, and delete documents you have uploaded. You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it.
To make any of those requests, email info@frameworkai.ca.
How long we take. We acknowledge a request within five business days and aim to finish it within 30 days. If a request is complicated enough to need longer, we will tell you why before that point rather than after it.
How a deletion is actually carried out, and what survives it. A person at Framework carries it out — there is no button in the product that erases a whole workspace, and we are not going to describe one that does not exist. When you ask us to delete your workspace we remove your account, your knowledge base, and the files you uploaded. What we do not remove is the record of what the service did on your behalf: that record is what lets us answer a security question later, and we have not yet settled how long it should be held. When we settle it, it will be written in section 4.
Inside the product you can already correct your company and account details yourself, and an administrator can delete individual uploaded documents. Anything broader than that comes to us by email.
Framework is a Canadian company and these requests are handled under Canadian federal privacy law, which gives you the right to see the personal information an organisation holds about you, to have it corrected, and to complain to the Office of the Privacy Commissioner of Canada if you are not satisfied with how we answer. If you are outside Canada, tell us and we will deal with your request under the law that applies to you.
7. Children
Framework is a tool for businesses and is not directed at children.
8. Changes
We will notify beta customers before a materially different version of this policy takes effect, and the date at the top of this page will change.
Questions about this document? Email info@frameworkai.ca.