Privacy Policy

Effective: August 30, 2026

This policy describes how Frix Ops handles information when you authenticate to and use the service.

Information processed

How information is used

Information is used only to authenticate users, enforce tenant and host authorization, perform requested VPS operations, prevent unauthorized access, diagnose service problems, and maintain security and operational auditability.

Credentials and secrets

Frix Ops verifies OAuth bearer tokens for authorized requests. The service is designed not to expose agent secrets, controller administrative tokens, SSH credentials, OAuth tokens, or private keys to ChatGPT tool output or public pages.

Sharing

Frix Ops does not sell personal data. Authentication is provided by the configured OAuth identity provider. Infrastructure providers may process network or hosting data as necessary to deliver the service. Information is otherwise disclosed only when required to operate the service, protect users or systems, or comply with applicable law.

Retention

Operational response data is processed to answer authorized requests. Frix Ops audit records currently have no automatic expiry and are retained until an authorized administrator removes them or the relevant deployment is decommissioned. OAuth-provider logs are retained according to that provider's policies. Support records are retained as needed to resolve the request and maintain an appropriate history of the resolution.

User controls and requests

You may request access, correction, or deletion of personal information associated with Frix Ops through the support channel. Requests are subject to identity verification and to security, legal, and operational obligations that may require limited retention.

Security

Frix Ops uses scoped OAuth authorization, tenant and host isolation, loopback-only application listeners behind controlled ingress, bounded tool surfaces, explicit mutation planning and approval, and audit attribution. No internet service can be guaranteed to be perfectly secure.

Changes

If this policy materially changes, the effective date above will be updated before a new public plugin version is submitted where required.