Legal
Security & Data Use
Last updated: August 31, 2026
A plain-language map of what FRA reads, what it writes, and what always requires your explicit approval — described against what the scan, sign-in, and lifecycle system actually do today, not what's planned.
What FRA does with your data, by category
The scan reads connected account data described below; it never writes to it without your explicit approval. The breakdown:
Read permissions
Sign-in with Google reads only your name, email, and profile photo through the standard OAuth exchange — nothing from your inbox, calendar, or drive. On any FRA page we also read campaign parameters present in the URL.
Write permissions
FRA writes to its own systems only: your account record, your lead/scan record, lifecycle event history, and the fra_ft / fra_lt cookies on your own device. It never writes to your Google account, your calendar, or any account you connect.
Recommendation-only actions
The Future Ready Scan produces a score and a list of opportunities to act on. Today those are sample/demo data — the live scan engine has not shipped. Even once live, the scan surfaces recommendations; it does not act on them for you.
Approval-required actions
Nothing in the live product today executes a change on your behalf. If a future feature (like an automated campaign build) is added, it will require your explicit approval before anything is sent, published, or executed — that is a hard requirement for any such feature, not an aspiration.
Automated actions
Two things run automatically today: attribution capture (the cookies described in our Privacy Policy) and lifecycle event delivery — a webhook call to our CRM (GHL) when a milestone like "scan abandoned" or "results delivered" happens, so your own follow-up email or reminder can fire. Automated actions only send data out to trigger communications; they do not write back into any connected account.
Data in transit and at rest
- Lead and lifecycle data is sent to our CRM webhook over HTTPS, from our server — never directly from your browser, so the webhook destination and any credentials are never exposed client-side.
- If a webhook delivery fails, we retry a bounded number of times and then write the full payload to a durable local file rather than dropping it — the same pattern used for the data-rights requests on our Privacy Policy page.
- Because the live scan engine has not shipped yet, FRA does not currently store credentials for, or maintain a persistent connection to, any external account beyond the OAuth sign-in described above.
Vendors involved
- Google — OAuth sign-in only.
- GoHighLevel (GHL) — our CRM and marketing-automation provider; receives lead and lifecycle event data as described in our Privacy Policy.
- Google Analytics — page/event analytics, where configured.
Reporting a security concern
If you believe you've found a security issue with FRA, please tell us through the Contact page rather than filing it publicly, so we can look into it before any details are shared more broadly.