Legal
Privacy Policy
Last updated: August 27, 2026
Overview
Fossil is a hosted Cloud service that scans eligible web applications in a managed browser and presents the resulting screens, states, flows, and history in a Cloud workspace. This policy explains the personal data and Customer Content we process to provide, secure, improve, and support that service.
Who is responsible for your data
Fossil is the controller for account, workspace administration, billing, security, support, and its own service analytics. For Customer Content that an organization chooses to submit for a scan or collaboration, that organization determines the purpose of the processing and Fossil processes the content on its behalf to provide the service. Contacthello@fossil.design with privacy questions or requests.
Data we process
- Account and workspace data. Name, email address, authentication identifiers, workspace membership, roles, invitations, project access, and security events. WorkOS provides authentication and organization identity.
- Hosted scan content. The submitted target URL, scan instructions, required screenshots, browser observations, captured interface content, derived screens, states and flows, selected evidence, immutable results, and status records needed to operate and recover a scan.
- Collaboration content. Comments, mentions, project names, and other content you add to a workspace.
- Billing data. Plan, subscription, invoice, payment status, tax, and customer identifiers provided by Polar. We do not receive your full card number.
- Website and service telemetry. Technical request data, page path, referrer host, campaign parameters, device category, coarse workflow status, counts, and duration. Target URLs, screenshots, prompts, profile instructions, model output, typed values, and provider identifiers are excluded from analytics and ordinary application logs.
- Support communications. Your email, message, and any identifiers or files you choose to send.
Hosted browser and model processing
Browser Use provides the managed browser used to reach and interact with eligible targets. Fossil uses OpenAI to interpret only the screenshots and instructions required for the scan. OpenAI requests usestore: false; applicable provider abuse-monitoring retention may still apply, so this is not described as zero retention. Fossil does not use Customer Content to train generative AI models.
Raw runner reports, prompts, model outputs, tool-call chains, command receipts, memory, coordinates, and provider diagnostics are kept separate from customer-visible results, access-controlled, and retained only for a bounded operational period where needed.
Why we use data
- To authenticate users and provide trial credits, hosted scans, results, workspaces, and collaboration.
- To validate targets, enforce safe actions, prevent abuse, manage capacity, and recover failed jobs.
- To administer Solo and Team subscriptions, invoices, taxes, and customer support.
- To understand coarse product outcomes and improve reliability without placing Customer Content in analytics.
- To comply with legal, accounting, security, and consumer-protection obligations.
Legal bases
Where GDPR or similar law applies, we rely on contract to provide Fossil, legitimate interests to secure and improve it, legal obligation for required records, and consent where non-essential analytics requires it.
Analytics and the URL handoff
PostHog provides privacy-limited website and product analytics. Landing-page text and form inputs are masked, network bodies and console logs are not recorded, and query strings and fragments are stripped from captured URLs. The URL pasted into the landing scan form is transferred through a short-lived client-side fragment rather than a request query and is not included in landing analytics. The authenticated Fossil service receives the target through its authorized validation and scan workflow.
Processors
- WorkOS for authentication, account recovery, organizations, and invitations.
- Browser Use for hosted browser sessions and related execution infrastructure.
- OpenAI for the model processing required by hosted scans.
- Polar for checkout, subscriptions, payments, taxes, invoices, and the customer portal.
- Render for hosting and technical infrastructure.
- Cloudflare R2 for private storage of screenshots, attachments, and other scan evidence in an EU-jurisdiction bucket.
- PostHog for privacy-limited analytics.
- Resend for transactional security emails, including account-deletion confirmation.
Provider access is limited to the service each provider supplies. Their processing, retention, locations, and transfer safeguards are reviewed under the applicable contractual terms before production use.
Access, security, and disclosure
We do not routinely inspect Customer Content. Exceptional human access is limited to authorized, time-bounded, and logged security, legal, or support needs. Provider credentials, browser connection details, object-store keys, and other infrastructure secrets are never exposed to the target, model, public renderer, analytics, or customer-visible result.
We do not sell Customer Content or personal data.
Retention and deletion
Signup-credit scan results and their customer-visible evidence expire after 14 days. Solo results expire after 180 days and Team results after 365 days, unless an earlier workspace or account deletion applies. Expiration is evaluated per immutable result; subscribing before an unexpired signup-credit result's deadline may extend that result to the selected plan's retention period. Following termination or a valid deletion request, content is made inaccessible and queued for deletion, subject to limited backups, bounded private operational evidence, abuse-prevention records, and records required by law. Billing and support records are retained only as long as needed for their stated purpose or a legal obligation.
Account deletion requires a fresh authentication and a short-lived confirmation sent to the account’s verified email address. Deleting a team member removes and pseudonymizes that person’s account and access but does not delete Customer Content owned by the shared workspace. A shared workspace owner must transfer ownership first. When the sole owner deletes their account, the personal workspace, its scans, attachments, screenshots, and other stored images are made inaccessible immediately and queued for permanent deletion. Minimal pseudonymized billing, security, abuse-prevention, and audit records may remain where required for legal or operational integrity.
International transfers
Production Cloudflare R2 object storage uses an EU-jurisdiction bucket. Other processors may handle data outside your country. Where required, we use appropriate contractual and legal safeguards for international transfers.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability and may withdraw consent. Contact hello@fossil.design. You may also complain to your local data-protection authority.
Changes
We may update this policy as Fossil changes. Material changes will be identified by the updated date above.