Privacy Policy

Last updated: September 26, 2026. How Codebeatz Technologies Inc. handles data for Fractionalyse.

1. Who we are and what this policy covers

This Privacy Policy explains how Codebeatz Technologies Inc. (“Codebeatz”, “we”, “us”) collects, uses, shares, and retains personal information when you visit or use Fractionalyse (the “Service”), including app.fractionalyse.com, related marketing pages, the public demo, APIs, and emails we send.

The Service is a multi-client control center for fractional executives: a unified activity feed, AI urgency scoring, Catch Me Up digests, Client Memory (search and cited Ask), onboarding, billing, and read-only connections to tools you authorize.

If you use the Service on behalf of a company, this policy still applies to the personal information we process. Your clients’ information that you connect is treated as described in “Integrations and client workspace data.”

This policy does not apply to third-party products you connect (Slack, Asana, Jira, Notion, your email provider, and others). Those products have their own policies.

2. Information we collect

Account and authentication: name (if you provide it), email address, password or password hash, magic-link tokens, password-reset tokens, session identifiers, and authentication identifiers from our auth provider. If you sign in with Google, we receive the account identifiers Google shares for sign-in (typically email and a provider user id). Google sign-in is for authentication only. We do not connect or read a Gmail inbox. When you create an account, we store the time and the version of the Terms of Service and this Privacy Policy that you accepted. We do not store your IP address with that record.

Profile and preferences: timezone, digest hour, whether digest email is enabled, and similar settings you save.

Workspace and client records: client names and other labels you create; which integrations you connect to each client; and operational metadata such as connection status and last sync time.

Integration content you authorize: messages, email content you forward, tasks, issues, pages, and related metadata from connected tools, limited to the scopes and selections you grant. See section 5.

AI-derived data: urgency scores, summaries, digest text, search embeddings, Ask answers, and citations generated from a single client’s content.

Billing: plan, subscription status, customer and subscription identifiers, period dates, and payment-related records processed by our payment provider. We do not store full card numbers on our servers.

Communications: contact-form submissions (name, email, topic, message), support correspondence, and records of transactional or product emails we send (including unsubscribe state).

Usage and diagnostics: pages and routes requested, approximate location from IP address, browser and device type, timestamps, background processing outcomes, and error reports needed to operate, secure, and improve the Service.

First-party product analytics: events such as signup completed, client created, integration connected, portfolio activation, digest sent, Client Memory search or Ask, checkout started, and subscribed. These are stored in our database, not sold to ad networks.

We do not require you to provide information beyond what is needed to create an account and use the features you choose. If you choose not to connect a tool, we do not collect that tool’s workspace data.

3. How we use information

To provide the Service: authenticate you; isolate each client workspace; ingest and display a unified feed; score urgency; generate Catch Me Up digests; index and retrieve Client Memory; enforce plan limits; and process billing.

To operate the product: schedule sync, ingest, score, embed, digest, and activation-nudge jobs; send transactional email (confirmations, magic links, password reset, digests if enabled, day-2 activation nudges, billing notices); and respond to contact-form and support requests.

To secure the Service: encrypt tokens, verify incoming notifications, detect abuse, enforce acceptable use, rate-limit or block abusive traffic, and investigate incidents.

To measure and improve the Service using first-party funnel events and aggregated diagnostics — not for third-party advertising.

To communicate material product, security, or legal notices. Digest and similar product emails can be turned off in Settings or via an unsubscribe link where provided. We may still send transactional and security messages that are required to operate your account.

To comply with law, enforce our Terms of Service, and protect the rights, safety, and property of you, your clients, us, and others.

If we later use information for a new purpose that is not compatible with the purposes above, we will update this policy and, where required, obtain consent or give you a way to opt out.

4. Legal bases (where applicable)

Depending on where you live, we rely on one or more of: performance of a contract (providing the Service you request); legitimate interests (securing, operating, and improving the Service in a way that does not override your rights); consent (optional connections, optional emails, and any feature we mark as consent-based); and legal obligation (tax, accounting, security, or lawful requests).

You may withdraw consent where processing is based on consent, without affecting processing that already occurred or that we must continue for other lawful reasons.

5. Integrations and client workspace data

You decide which client workspaces to create and which tools to connect. Each connection is bound to one client. We design the Service so data from two clients is not mixed in the feed, in a prompt, in search, or in an Ask session.

Current connections (all read-only; we do not post, send, edit, create, transition, comment, or delete in the connected tool): Slack (as-yourself user token and/or a workspace app for real-time events — channel history and member names within the scopes granted); Email bridge (only messages you or your client forward to a per-client inbound address — this is how email works in the product today; it works with Gmail, Outlook, and other providers via forwarding, without connecting the inbox); Asana (tasks assigned to you, including names, notes, and due dates); Jira Cloud (issues assigned to you on the site you authorize, including summary, description, status, and due dates); Notion (only pages you select during connect).

If we add another integration later, we will request only the access needed to provide the feature, keep it scoped to the client you assign, and describe it on the Security page and in a policy update when the change is material.

You represent that you have the right to connect those workspaces and to process the related information through the Service, including under your clients’ NDAs and the third-party provider’s terms. Do not connect a workspace you are not authorized to access.

We do not offer a native Gmail inbox connection. Do not assume we can read a mailbox unless mail is forwarded to that client’s inbound address.

6. AI processing

Urgency scores, summaries, Catch Me Up digests, embeddings, and Client Memory Ask answers are generated by a hosted AI service. If we add another provider for these features, we will update this policy.

Each AI request is scoped to a single client’s activity. Data from two clients does not appear in the same prompt, embedding index lookup, or Ask session.

Embeddings are used only to index and retrieve that client’s Client Memory.

We do not train our own foundation models on your content. The AI provider processes prompts and completions under its terms. We do not sell your content for model training.

AI output can be incomplete or incorrect. It is an aid for triage and recall, not legal, financial, medical, or compliance advice, and not a substitute for reading the source item.

If we add a provider or expand AI features (for example drafting or meeting prep), we will treat that as a material change to this section.

7. Client Memory

Non-noise activity may be indexed into a durable per-client knowledge store so you can search and ask about prior context after the live feed ages out.

Client Memory remains bound to the same user and client isolation rules as the rest of the product.

Access to search and Ask depends on your plan: Pro and Agency have Client Memory while the subscription is active; Free includes a time-boxed Memory trial starting at portfolio activation (two clients, each with at least one integration); Solo includes a one-time time-boxed Memory trial from Solo checkout. Temporary grants are subject to a lifetime cap described on the pricing page. After a temporary window ends, search, Ask, and new embedding are soft-walled; stored knowledge is retained until you purge the connection or delete the client, unless we must delete it sooner for legal or security reasons.

Deleting a client or using Disconnect & purge removes related Client Memory documents and chunks for that engagement or connection.

8. How we share information

We do not sell your personal information and we do not share it for cross-context behavioral advertising.

Service providers process data only to help us run the Service, under their terms and, where applicable, a contract. They cover hosting, database and sign-in, payments, email delivery, AI processing, and error monitoring. Uptime checks cover public availability only, not your client workspace content.

Connected tools (Slack, Asana, Atlassian/Jira, Notion, and your email provider) process data under their own terms when you authorize a connection or forward mail.

We may disclose information if required by law or lawful process; to protect rights, safety, and security; or in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards. If we cannot verify a request or believe it is unlawful, we may refuse or narrow it.

We may share aggregated or de-identified information that cannot reasonably identify you or a specific client.

9. Retention

Feed items are retained for 90 days by default, then deleted, unless a longer period is required for security, billing, dispute, or legal reasons.

Client Memory is retained until you delete the client or purge the connection, so durable context can outlive the feed window, subject to section 7.

Billing and security records are kept for as long as the account is active and for a reasonable period afterward as needed for tax, accounting, chargebacks, abuse prevention, and legal claims.

Contact-form messages and support correspondence are kept as long as needed to handle the request and maintain a support history.

You can disconnect an integration and purge ingested data for that connection, or delete a client workspace, which removes related feed items, digests, tokens, and Client Memory for that engagement. Deleting your account in Settings removes the profile, the terms-acceptance record, client workspaces, connections, tokens, feed items, digests, and Client Memory from the live service at that time. Invoices stay with our payment provider for tax, accounting, and disputes. Copies in encrypted backups remain until those backups rotate. You can also ask privacy@codebeatz.com to delete an account.

If we cannot complete a deletion request (for example, a legal hold or an unverified requester), we will say so and keep only what we must.

10. Security

Connection tokens are encrypted at rest, traffic is encrypted in transit, incoming notifications are signature-checked, and each client’s data stays bound to its owner.

Tokens are not written to application logs or exposed to the browser.

No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal information, we will notify you and regulators as required by applicable law.

More operational detail is on our Security page. Security reports: security@fractionalyse.com.

11. International transfers

Primary application hosting and AI processing are in Canada.

Some subprocessors and connected tools may process or store information in the United States or other countries. Where required, we rely on appropriate transfer mechanisms (such as contractual clauses) provided by those vendors.

By using the Service, you understand that your information may be processed outside the country where you live, including in jurisdictions with different data-protection rules.

12. Cookies and similar technologies

We use cookies and similar technologies that are necessary to sign you in, keep a session, remember operational preferences, and protect the Service (including short-lived security cookies during maintenance).

We do not use third-party advertising cookies. First-party product analytics are stored as account events in our database, not as an ad-pixel profile.

You can block cookies in your browser. If you do, sign-in and other authenticated features may not work.

13. Your choices and rights

In the product you can update profile and digest preferences, connect or disconnect integrations, purge a connection, delete a client, manage billing through the customer portal when billing is enabled, and delete your account.

Depending on where you live (including Canada, the EEA/UK, and certain U.S. states), you may have rights to access, correct, delete, or export personal information; to restrict or object to certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority. We will respond to verified requests as required by applicable law.

We may need to verify your identity before acting. We will not discriminate against you for exercising privacy rights.

If you are in a “sale” or “sharing” jurisdiction: we do not sell personal information and we do not share it for cross-context behavioral advertising. If that changes, we will update this policy and honor required opt-outs, including browser opt-out signals where we are legally required to do so.

14. Automated processing

Urgency scores and digest selection are automated classifications meant to help you triage. They do not, by themselves, produce legal or similarly significant effects about you. You can always open the source item and act in the original tool.

Plan limits, rate limits, and abuse detections may be applied automatically. If you believe a decision is wrong, contact us.

15. Children

The Service is for professional use by adults. It is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided information, contact us and we will delete it.

16. Public demo, marketing pages, and unknown or future cases

The public demo uses fictional sample data. It does not access your accounts or client tools.

Marketing and documentation pages may describe roadmap tools (for example Microsoft Teams). Those tools are not connected until we ship them and update this policy if the data practices change.

If you submit information about someone else (a client contact, a teammate), you must have a lawful basis to do so.

If a situation is not named here — a new feature, a new subprocessor, a lawful request we did not anticipate, or a failure of a vendor — we will apply the closest principles in this policy: minimize collection, isolate clients, avoid mixing prompts, keep tokens encrypted, and delete or restrict data when the purpose ends. We will update this page when the change is material.

17. Changes

We may update this policy from time to time. We will post the revised version with an updated date. If changes are material, we will provide additional notice where required (for example in-product or by email).

Continued use after the effective date means you accept the updated policy, except where applicable law requires a different standard.

18. Contact

Privacy questions, access or deletion requests: privacy@codebeatz.com. Sales: hello@fractionalyse.com. Security and DPA requests: security@fractionalyse.com. Billing, and Support: support@fractionalyse.com.

Controller: Codebeatz Technologies Inc., operating the Fractionalyse Service.