Privacy
Privacy Policy
Last updated 15 September 2026
1. The short version
We collect what we need to run shared agent sessions: who you are, what your team asked agents to do, what those agents did, and how much model usage a workspace has spent.
We do not sell personal data. We do not use your session content to train AI models, and we ask our model providers not to either. We show no adverts and set no tracking cookies.
Session content goes to AI model providers so agents can answer, and to any tool you connect so agents can use it. Everything else stays with us and the infrastructure we run on.
Questions, or a request about your data: privacy@tryfridaywork.com.
2. Who is responsible for your data
For your account and for this website, Friday Work is the controller of your personal data.
For what your team puts into a workspace, the organisation that owns the workspace is the controller and Friday Work is its processor, acting on that organisation’s instructions. If your employer gave you the workspace, ask them first about content in it.
3. What we collect
Account details. Your name, email address and profile picture from Google or GitHub, or the name, email address and password you give us directly. Passwords are stored only as a salted scrypt hash, never in a form anyone can read.
Session content. Every instruction, suggestion, message, question and answer in a session; the documents, decks, sheets and code agents write; files you upload; and what each tool call returned. It is kept as an append-only log, because showing who asked for what is the point of the product.
Workspace details. Workspaces, members and roles, invitations, projects, and the custom agents and skills you create.
Connections. For each MCP connection: the name and URL you gave it, and the access token from your sign-in with that provider.
Usage. Model credits a workspace spends in each 5-hour window, so plan limits apply, and who is present in a session.
Technical data. Ordinary server logs, including IP address, browser and timestamps, kept for security and debugging.
If you link your own machine. Which coding CLIs it has, the folders and repositories you choose to expose, the changes an agent makes there, and the output of commands it runs. We never receive your credentials for that CLI.
What we do not collect. We do not take payment card numbers ourselves — a payment processor handles those. We do not track you across other websites, and we do not buy data about you.
5. How we use it, and why we may
To run sessions and show them to the people you share them with; to send prompts to model providers and tools so agents can work; to apply plan limits; to keep the audit trail the product promises; to answer support requests; to keep accounts secure and detect abuse; and to bill paid plans.
Legal bases (UK/EU). Performing our contract with you, to run and bill the service. Our legitimate interests, for security, abuse prevention and improving Friday, balanced against your rights. Legal obligation, where we must keep records. Consent, where we ask for it — such as product emails you can unsubscribe from at any time.
We look at aggregated, non-identifying usage figures to understand how Friday is used. We do not read your session content except when you ask us to for support, when we must to investigate abuse, or where the law requires it.
7. How long we keep it
Session history follows the workspace plan: 30 days on Free, one year on Pro, and until you delete it on Max. Daily usage counters are kept for a short rolling window. Account details are kept while the account exists, then deleted.
Backups are kept briefly and overwritten in turn, so deleted content can persist there for a short time before it is gone for good.
Automatic deletion of expired sessions and self-service account deletion are still being built. Until they ship, email privacy@tryfridaywork.com and we will delete your account, your workspace and its sessions by hand, promptly and at no charge.
8. How we protect it
Traffic is encrypted in transit. Sign-in cookies are signed, HttpOnly and time-limited. Passwords are salted and hashed with scrypt, and repeated failed sign-ins on an address are rate-limited. Access to a session is checked on every action, and the control token that decides who may steer an agent is enforced by a single atomic database operation, so permission checks cannot be raced.
Access tokens for tools you connect are stored inside your workspace in our database. They are not yet encrypted at rest; that work is planned, and we would rather say so than imply otherwise. If that matters to your organisation, wait for it before connecting sensitive systems.
No service is perfectly secure. If you find a vulnerability, report it to security@tryfridaywork.com before disclosing it publicly and we will work with you on a fix.
9. Your rights
Depending on where you live, you may ask for a copy of your personal data, correct it, delete it, restrict or object to how we use it, or receive it in a portable form. You may also withdraw consent where we relied on it.
Sessions can be exported at any time as documents, and as a readable audit of who instructed what, so a copy of the work is always in your hands.
Email privacy@tryfridaywork.com and we will answer within 30 days. We will not charge you or treat you differently for asking. If our answer does not satisfy you, you can complain to your local data protection authority.
Where your workspace belongs to an organisation, we pass your request to them and help them answer it.
10. International transfers
Friday and the providers above process data in the United States and other countries. Where personal data leaves the UK or the EEA we rely on standard contractual clauses or another lawful transfer mechanism, alongside the protections described here.
11. Children
Friday is for work and is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us data, email privacy@tryfridaywork.com and we will delete it.
12. Changes to this policy
We post any change on this page and update the date at the top. If a change materially affects how we use your personal data, we will tell you in the app or by email before it takes effect.