FairMind Legal Information
Privacy Policy
How FairMind collects, uses, shares, retains, and protects information through this website.
1. Scope
This Privacy Policy applies to the public FairMind website, consent-gated website analytics, and the information submitted through its contact and access-request forms. Product workspaces may present additional notices when their processing differs from this website.
2. Information you provide
When you contact FairMind or request access, we process the fields you choose to submit, which may include your name, business email, organization, role, selected use case, and message. Do not submit model secrets, production prompts, regulated datasets, credentials, or evaluation artifacts through the public website forms.
3. Consent-gated analytics
If you allow analytics through the external consent manager, FairMind uses PostHog to measure anonymous page and session activity, attribution, navigation, calls to action, viewed sections, scroll depth, product interactions, form-start and submit metadata, browser errors, performance, heatmaps, dead and rage clicks, media engagement, and masked session replay. FairMind does not call PostHog's identify API for public-site visitors.
Analytics excludes form values, field names, typed text, names, email addresses, messages, request and response bodies, network headers, copied text, and browser console logs. URLs and referrers are reduced to origin and path before capture. Personal-data query parameters are masked. Session replay masks all inputs and the complete form surface.
4. Website operation data
Hosting and delivery infrastructure may process routine request information such as time, requested path, response status, user agent, and network address for availability, security, and abuse prevention. This infrastructure processing is separate from optional PostHog analytics.
5. Purposes
- Respond to access requests and questions you initiate.
- Understand which product explanations and evidence journeys are useful.
- Find broken navigation, interaction friction, client errors, and performance regressions.
- Operate, secure, diagnose, and improve the public website.
- Keep records needed to manage a business relationship or meet legal obligations.
6. Providers and disclosure
Netlify hosts and delivers the website. Formspree receives contact and access-request form submissions. PostHog receives optional analytics only after the external consent manager opts analytics in. The consent manager itself processes the preference record under its configured notice. FairMind does not sell website-submission or analytics data.
FairMind may disclose information when required by law, to protect the service, or as part of a business transaction subject to appropriate safeguards. Provider locations may involve international processing; FairMind uses the provider account region and contractual controls selected for the service.
7. Retention and security
The Data Retention Policy publishes category-specific maximums, deletion timing, backup handling, and exceptions. No security method is absolute; FairMind uses proportionate technical and organizational measures rather than claiming perfect security.
8. Your choices
Use the external consent manager to allow or withdraw analytics. Where applicable, you may ask about, correct, or request deletion of information you submitted. Use the contact page and describe the request precisely enough for FairMind to locate the relevant submission. FairMind may retain limited records required for security, law, or an ongoing business relationship.
The short version
We receive what you deliberately submit, routine hosting logs, and—only after analytics consent—privacy-filtered PostHog events. We use the information to answer you, keep the site working, and learn where the explanation or journey fails.
Two separate data paths
A form submission can include your contact details because you asked for a reply. Analytics never receives those field values. It only learns that an anonymous visitor started or submitted the form. Device-scoped analytics consent is not person-scoped permission to contact you.
What not to send
Passwords, API keys, confidential prompts, customer records, regulated datasets, or raw evaluation evidence. The public website is not an evidence-ingestion channel.
Your control
Withdraw analytics through the external consent manager. Contact FairMind to ask about, correct, or delete a website submission where applicable.
Website data path
| Input | Destination | Purpose | Boundary |
|---|---|---|---|
| Access-request fields | Formspree, then FairMind request handling | Reply and qualification | Only fields you submit; not sent to PostHog |
| Contact message | Formspree, then FairMind communication workflow | Respond to your question | Not a product evidence channel; not sent to PostHog |
| Optional analytics | PostHog project region | Journey, interaction, reliability, and performance analysis | Consent-gated, anonymous, filtered, and masked |
| Request metadata | Netlify hosting and delivery logs | Availability and security | Infrastructure-level processing |
| Consent preference | External consent manager | Remember and prove your choice | FairMind's bridge keeps no separate durable copy |