Privacy Policy — Friends & Robots

1. Who we are (data controller)

Friends & Robots FZCO ("Friends & Robots", "we", "us", "our"), a company registered in the United Arab Emirates with registered address at Unit No: UT-12-CO-53 DMCC Business Centre Level No 12 Uptown Tower, Dubai, UAE, is the controller of personal data processed through our websites, desktop application, agents, hosted media operations, support services, and related features (together, the "Service").

For questions about this policy or your data, contact privacy@fnrb.com.

2. What personal data we collect

We collect the following categories of personal data, depending on how you use the Service:

Please do not submit special-category, highly sensitive, confidential, or legally protected information unless it is necessary for your requested use and you have the right and a lawful basis to provide it.

3. Local and hosted processing

Sessions are stored in folders on your Mac. Bundled media-processing tools run locally in the session folder and are designed to operate without internet access. We do not automatically receive every file stored in a session folder merely because it exists there.

Account functions, agent conversations, support, billing, and some media operations use hosted services. When you request or approve a hosted operation, the Service may transmit the relevant prompt, instructions, media, and metadata to our servers and the third-party provider needed to perform it. The result is returned to the application and may be saved in your local session folder.

4. Why we use personal data and our legal bases

Where we rely on legitimate interests, we balance those interests against your rights and reasonable expectations. We do not use your Input or Output to train general-purpose generative models, and we do not authorize model providers to do so, unless you affirmatively opt in through a training-data control that describes the use. Participation is optional and is not required to use the Service. You may withdraw your consent at any time for future use; withdrawal does not affect processing that occurred before it.

We do not sell personal data, share it for cross-context behavioural advertising, or use it to make solely automated decisions that produce legal or similarly significant effects.

5. Who we share personal data with

We share personal data only as reasonably necessary with:

Providers may process and temporarily retain prompts, media, and related data under their applicable terms, privacy notices, and agreements with us. Retention and processing locations may differ by provider and operation.

We may also disclose personal data in connection with a merger, financing, reorganization, sale of assets, insolvency, or acquisition; when required by law, court order, or lawful government request; or where reasonably necessary to protect the rights, safety, and security of users, the public, Friends & Robots, or the Service.

6. International data transfers

We are based in the United Arab Emirates and use providers in the United States and other countries. Your personal data may therefore be processed in countries whose privacy laws differ from those where you live.

Where required, we use recognized transfer safeguards, such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate. You may contact us for information about the safeguard relevant to your data.

7. How long we keep personal data

We retain personal data only for as long as reasonably necessary for the purposes described above. The period depends on the nature of the data, whether your account remains active, provider processing periods, security and support needs, limitation periods, and legal requirements.

Deletion from active systems may not immediately remove data from encrypted backups. Backup copies are isolated, retained for a limited period, and deleted or overwritten in the ordinary course. We may retain data longer where required by law, to resolve disputes, enforce agreements, prevent fraud or abuse, or protect legal rights.

8. Your privacy rights

Depending on where you live, you have the right to:

These rights vary by jurisdiction and may be subject to exceptions. California residents may also have rights to know, correct, delete, and obtain a copy of personal information and to limit certain uses of sensitive personal information. We do not sell personal information or share it for cross-context behavioural advertising. We will not discriminate against you for exercising a privacy right.

To exercise a right, request account deletion, or appeal a decision about a request, contact privacy@fnrb.com. We may need to verify your identity and authority before acting. Authorized agents may submit requests where permitted by law. You can opt out of marketing emails using the unsubscribe link in any such message; you may still receive transactional or service communications.

9. Cookies, analytics, and similar technologies

Our websites and Service use cookies, local storage, software development kits, and similar technologies for authentication, security, preferences, analytics, and performance. PostHog may receive page views, interactions, device information, approximate location derived from IP address, and identifiers used to distinguish browsers or sessions.

We do not use third-party advertising cookies. Where law requires consent for non-essential analytics, we request it before enabling those technologies. You can use available cookie controls, browser settings, or device settings to restrict them, although necessary features may not function correctly without essential storage.

10. Children

The Service is intended only for people aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided personal data through the Service, contact us so we can investigate and delete it where appropriate.

11. Security and your responsibilities

We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, use, alteration, disclosure, or destruction. These measures include access controls and safeguards appropriate to the nature of the data and processing.

No internet service, provider, sandbox, or device is completely secure. The desktop application can run commands within session folders, and a defect, model error, malicious file, or security failure could cause unintended access or disclosure. Use the command-approval setting when you want to review commands, maintain current backups, secure your sign-in account and device, and do not place secrets or irreplaceable material in a session folder.

If we become aware of a personal-data breach, we will investigate and notify affected people and regulators where required by applicable law.

12. Third-party services and links

The Service may link to or integrate with third-party services. Their handling of personal data for their own purposes is governed by their privacy notices, not this policy. Review those notices before providing data directly to them.

13. Changes to this Privacy Policy

We may update this policy to reflect changes to the Service, providers, law, or our practices. We will post the updated version with a new "Last updated" date. If a change materially affects your rights or how we use personal data, we will provide reasonable notice through the Service, by email, or on our website.

14. Contact

For any privacy question, complaint, or rights request, contact privacy@fnrb.com or write to Unit No: UT-12-CO-53 DMCC Business Centre Level No 12 Uptown Tower, Dubai, UAE.