top of page
Screenshot_38.jpg

Privacy Policy

Last updated: September 27, 2026
 

This Privacy Policy explains what personal information Frontline.io, Inc. ("frontline.io", "we", "us", "our") collects when you use our services, how we collect it, what we use it for, who we share it with, and the choices you have. It applies to Frontline One (the web application at app.frontline.io and the Frontline One app for iOS, iPadOS and Android), the frontline.io mobile and desktop applications, the frontline.io XR applications for headsets, and our website at www.frontline.io (together, the "Services").
 

Frontline One is a business tool. In most cases your account is created and managed by your employer or another organization that has a contract with us (your "Organization"). Your Organization is the controller of the personal information processed in its workspace; we process that information on its behalf and under its instructions. This Policy tells you what happens to your information either way. For questions about how your Organization uses the Services, contact your workspace administrator.
 

This Policy does not cover the practices of companies we do not own or control, or of people we do not employ.

What this Policy covers, in short

  • We collect the information you give us (your account details and the content you create) and information your device sends automatically (device, usage and diagnostic data).

  • We use it to run the Services, keep them secure, support you and improve them. We do not sell it and we do not use it for advertising.

  • Some features send your content to service providers to work: cloud hosting (Amazon Web Services) and, if your Organization has enabled them, AI features (Microsoft). Before any AI feature sends your content, the app tells you what is sent and to whom, and asks for your permission.

  • You can access, correct, export or delete your information, and withdraw permissions you have given, as described under Your rights.

Information we collect, at a glance

Account and contact details

 

Your name, work email, job title, country, user name, unique user ID and password (stored hashed). You or your Organization's administrator enter them when the account is created, or they arrive through your Organization's single sign-on. We use them to create and secure your account, identify you to colleagues and send service messages. They are shared with our cloud hosting provider.

 

Content you create

 

3D models, digital twins, procedures, videos, images, documents, notes, tasks, chat messages and whiteboard drawings that you upload or create in the Services. We use them to provide the Services to you and your Organization. They are shared with our cloud hosting provider, and with the AI sub-processor only when you use an AI feature and have given permission.

 

Remote support sessions

 

Live video and audio, screen shares, annotations, chat, captured images and session recordings, captured during a session you join using the camera and microphone you allow. We use them to run the session and to store the recordings and images your Organization keeps. They are shared with the other session participants and our cloud hosting provider, and with the AI sub-processor only for captions and transcription you have allowed.

 

AI inputs and outputs

 

Questions you type to AI Assist, documents you select for the Knowledge Hub, audio while transcription or live captions are on, files sent to Doc-to-Flow, text sent for translation, and the results returned. They are sent only when you use an AI feature after giving permission, used only to return the AI result you asked for, and shared only with the AI sub-processor (see AI Services).

 

Device and usage data

 

IP address, the approximate location derived from it, device model, operating system, browser, language, screens visited, features used and access times, sent automatically by your device and browser. We use them for security, abuse prevention, usage statistics and improving the Services. They are shared with our cloud hosting provider and, in aggregated form, with our analytics provider.

 

Diagnostic data

 

Crash reports, error logs and performance measurements, generated automatically when the app runs or fails. We use them only to find and fix bugs. They are shared with our error-monitoring provider.

 

Device permissions

 

Camera, microphone, photo library and notifications, used only after you grant each permission in the operating-system prompt and only for the feature that asked for it (see Device permissions). They are not shared as such; what you capture is treated as content.

 

We do not collect precise GPS location, health data, financial data, or government identifiers, and we do not track you across other companies' apps or websites.

Information you provide to us

Account information. To use the Services you need an account. Your Organization's administrator usually creates it and gives us your name and work email address; you may add a job title, a profile picture and language preference. If you sign in through your Organization's single sign-on (SAML 2.0), we receive the identity attributes your Organization's identity provider sends us, typically your name, email address and group membership. If you use a password, we store it only in hashed form. If you enable multi-factor authentication, we store the secret needed to verify your authenticator app.

 

Content you create or upload. The Services exist to hold your Organization's work: 3D models and digital twins, step-by-step procedures and flows, training content, videos, images, documents, tasks, notes, whiteboard drawings and chat messages. Content may include personal information about you or others, for example a name on a task or a face in a video. Your Organization decides who in its workspace can see each item.

 

Remote support sessions. When you join a remote support session, other participants see and hear what your camera and microphone capture, and can see your annotations, chat messages and shared screen. Sessions may be recorded, and participants may capture still images, if your Organization has enabled those options; the app shows a recording indicator while recording is on. Recordings and captures are stored in your Organization's workspace. Before an external guest joins a session, your Organization may require them to accept its own terms. If live captions or transcription are on, audio is processed as described under AI Services.

 

Support requests and forms. When you contact support, book a demo or fill in a form on our website, we keep the information you send us, including your name, email address, company and the content of your message, so we can respond.

 

You can use some parts of the Services, such as viewing shared content, without providing personal information. If you choose not to provide information a feature needs, that feature may not work.

Information collected automatically

When you use the Services, your device and browser send us technical information, which our servers record. This includes your IP address and the approximate location derived from it (country or city), device model and name, operating system and version, browser type, language settings, screen size, the screens and features you use, search terms you enter in the Services, access dates and times, and the identifier of the workspace you are in.

 

We use this information to secure the Services, detect and prevent abuse and fraud, understand how the Services are used, and produce statistics. Statistics are aggregated so they do not identify you.

 

Diagnostic data. If the app crashes or an error occurs, a crash report is generated automatically. It contains the error, the state of the app at the time, device and operating-system details and a pseudonymous session identifier. We use crash reports only to find and fix problems.

 

Cookies and similar technologies. app.frontline.io uses strictly necessary cookies to keep you signed in and protect your session (for example a session cookie and a cross-site request forgery token). These cannot be switched off without breaking the Services. Our public website at www.frontline.io uses analytics and marketing cookies described in its cookie banner, which you can accept or decline there. The Frontline One app does not use advertising identifiers and does not track you across other companies' apps or websites.

Device permissions

The app asks for each permission only when a feature needs it, and only works with what you allow. You can change any permission later in your device's settings; the related feature will stop working until you allow it again.

 

Camera is used for live video in remote support sessions, capturing images, scanning QR codes to open content, and augmented-reality views that place 3D content in your surroundings. It is not used for face recognition or to identify you, and it captures nothing when you are not in a session or on a capture screen.

 

Microphone is used for your voice in remote support sessions, and for audio when you have turned on transcription or live captions. It does not listen when you are not in a session or have not started a transcription.

 

Photo library is used to choose an image or video from your library to upload, and to save images you capture. We do not read your library unless you choose a file.

 

Notifications tell you about tasks assigned to you, session invitations and mentions. They are never used for marketing.

 

TrueDepth API (iOS). On iPhone and iPad models with a TrueDepth front camera, the app may use the TrueDepth API through the AR framework to run the front camera during augmented-reality features and video calls. We do not collect, store or share facial-geometry or depth data through this API, and it is never used to identify you.

 

Calls on iOS (CallKit). On iOS the app can present an incoming remote support call using the system's native call screen so that you can answer it like a phone call. This uses the CallKit framework. The caller's display name is shown on that screen; no call information is shared with Apple or added to your phone's recent-calls list beyond what the operating system does for any app using CallKit. CallKit is not used in mainland China.

AI Services

The Services include optional AI features ("AI Services"). This section explains exactly what they send, to whom, and how you stay in control.

 

Off by default; your Organization turns them on. AI Services are disabled unless your Organization asks us in writing to enable them for its workspace. If they are not enabled for your Organization, nothing in this section applies to you and no content is sent to an AI provider.

 

Your permission, every time it matters. Even when your Organization has enabled AI Services, the app does not send your content to the AI sub-processor until you have agreed. The first time you use any AI feature, the app shows a notice that says what will be sent, who it is sent to and why, and asks you to allow it. If you choose "Not now", nothing is sent and the feature stays off for you. You can withdraw your permission at any time in Settings › AI, after which the app stops sending content to AI Services until you allow it again. Your permission is stored with your account so you are asked once per feature, not on every use.

 

Which features, and what each one sends

 

  • AI Assist sends the question you type, the conversation so far, and the content in your workspace that your role allows the assistant to read. It returns an answer, or performs an action such as opening a procedure or creating a task.

  • AI Knowledge Hub sends the documents your Organization has uploaded to the hub and the question you ask. It returns an answer with citations to the source documents.

  • AI Agents send the task you define and the workspace content within the scope your administrator has allowed. They return the completed task output.

  • Transcription and live translated captions send audio from your microphone while the feature is on, in a remote support session or recording. They return text captions in each participant's chosen language, and a transcript if your Organization keeps one.

  • Translate with AI sends the text of the procedure step, document or message you ask to translate, and returns the translated text.

  • Doc-to-Flow and AI Insight send the document, images or session data you select, and return a generated procedure, summary or analysis.

 

Content sent to AI Services may contain personal information, for example names in a document or voices in a session. Do not submit information you are not permitted to share.

 

Who processes it. We use OpenAI models deployed through Microsoft Azure AI Foundry, provided by Microsoft Corporation. The AI resources are deployed within frontline.io’s Microsoft Azure environment and are configured so that only authorized frontline.io internal services can access and invoke them. Customer content is submitted to the models through these internal services and is not directly accessible by other frontline.io customers.

 

Microsoft acts as our AI sub-processor and is bound by applicable data-processing terms requiring it to protect personal information. A current list of AI sub-processors is available from Support@frontline.io. We will update this Policy before changing the AI sub-processor.

 

Where. AI Services are processed in Microsoft data centers in Germany.

 

No training, no retention by the AI provider. Your content is never used to train, fine-tune or improve any AI model, by us or by the AI sub-processor. The sub-processor processes each input only to return the output and does not retain it, other than brief, automated abuse-monitoring that Microsoft applies under its standard terms and that we have configured to the minimum available. We retain AI inputs and outputs only where a feature you used needs them, for example a transcript your Organization keeps, or the history of an AI Assist conversation you can delete yourself.

 

Outputs are suggestions. AI outputs are generated by probabilistic models and can be wrong, incomplete or unexpected. They are labeled as AI-generated in the interface and are not a substitute for your judgment. Your Organization is responsible for reviewing AI outputs before relying on them for operational, training, safety or compliance purposes.

 

No automated decisions with legal effect. We do not use AI Services to make decisions that produce legal or similarly significant effects on you, such as decisions about employment, certification or eligibility (Article 22 GDPR). AI Services assist people; they do not evaluate them.

 

Connected AI (your own assistant). Separately, your Organization may choose to connect its own AI assistant, such as Microsoft Copilot, ChatGPT or Claude, to the Services through an authenticated, permission-limited interface (Model Context Protocol). In that case content flows to your Organization's own AI provider under your Organization's agreement with that provider, not ours, and this section does not cover that provider's processing. That connection can only be set up by your Organization's administrator and can never access more than your own account permissions allow.

How we use your information

We use personal information only for the purposes below, and for nothing else without telling you first.

 

  • To create, secure and manage your account, including single sign-on and multi-factor authentication

  • To provide the Services: store and display content, run remote support sessions, deliver notifications, sync content for offline use, and return AI results you have asked for

  • To respond to support requests and send you service messages, such as a password reset or a notice of a change to this Policy

  • To keep the Services secure and detect, prevent and investigate abuse, fraud and security incidents

  • To measure how the Services are used, fix bugs and improve features, using aggregated or pseudonymous data wherever possible

  • To produce usage and completion reports for your Organization, such as which procedures were run and how far each user got; your Organization sees these under its own account

  • To comply with legal obligations and enforce our agreements

 

We do not sell personal information, do not use it for advertising, and do not use your content to train AI models.

 

Legal bases (EEA, UK and Switzerland). We process personal information under one or more of the following: performance of our contract with you or your Organization; your consent, where we ask for it (for example before an AI feature sends content, or for optional device permissions); our legitimate interests in securing, operating and improving the Services, balanced against your rights; and compliance with legal obligations. Where your Organization is the controller, its own legal basis applies to the content it processes in its workspace.

Who we share your information with

We share personal information only with the parties below, and only as far as needed for the purpose stated. Every service provider is bound by a written contract that limits it to processing on our instructions and requires it to protect your information to a standard at least equal to this Policy.

 

  • Your Organization and the people it authorizes receive your account details, the content you create, session recordings and usage reports for its workspace, because your Organization controls its workspace and manages your account.

  • Other participants in a session or in shared content receive what you say, show, annotate or write in a session, and the content you share with them. That is what a shared session or shared content is for.

  • Amazon Web Services, our cloud hosting provider, stores all data held in the Services, encrypted at rest. The default region is eu-central-1 (Frankfurt); your Organization may choose another region, a private tenant or an on-premises deployment.

  • Microsoft Corporation, our AI sub-processor, receives the content you send to an AI feature after giving permission (see AI Services), in order to return AI results. Processing takes place in Germany.

  • Error-monitoring and analytics providers [Frontline ONE] receive crash reports and pseudonymous usage events, never your content, so that we can fix bugs and understand usage.

  • Our customer-support platform [Frontline ONE] receives your name, email address and the content of support requests you send us, so that we can answer them.

  • Our affiliates and contractors receive only what is needed for the task they perform for us, under the same contractual limits, in order to operate the Services.

 

We may also disclose personal information where the law requires it, for example in response to a court order or lawful government request; to protect the rights, safety or property of frontline.io, our users or the public; to investigate fraud or security incidents; or as part of a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different privacy policy.

 

We do not share personal information with anyone for their own marketing purposes.

How long we keep information, and how to delete it

We keep personal information only as long as needed to provide the Services, meet legal obligations, resolve disputes and enforce our agreements.

 

  • Account details are kept while your account exists and deleted within 30 days after it is closed, except for records we must keep by law.

  • Content is kept while it is in your Organization's workspace. Items you or your Organization delete go to a recycle bin for 60 days, during which an administrator can restore them; after 60 days they are permanently deleted.

  • Session recordings and captured images follow your Organization's own retention setting; by default they are kept until deleted by your Organization.

  • AI inputs and outputs are not retained by the AI sub-processor. We keep them only where a feature needs them (a transcript your Organization keeps, or an AI Assist conversation history you can clear yourself).

  • Device, usage and diagnostic data are kept for up to 12 months in identifiable form, then deleted or aggregated.

  • Backups are retained for up to 35 days and then overwritten; deleted data may persist in backups until then.

 

Deleting your account. If your account was created by your Organization, ask your workspace administrator to remove it; they can do so from the Members page. If you created your own account, you can request deletion from Settings › Account in the app or by emailing Support@frontline.io from your account email. We confirm deletion within 30 days. Content you created for your Organization may remain in its workspace, attributed to a deactivated user, because it belongs to your Organization.

 

After the retention period ends, information is deleted or irreversibly anonymized. We may keep aggregated statistics that do not identify you.

International transfers

The Services are hosted on Amazon Web Services in the European Union (eu-central-1, Frankfurt) by default, and AI Services are processed in Germany. Your Organization may have chosen a different hosting region (for example AWS Tokyo), a private tenant or an on-premises deployment; ask your administrator where your workspace is hosted.

 

Where personal information is transferred outside the European Economic Area, the United Kingdom or Switzerland, for example to our headquarters in the United States, to our engineering and support team in Israel, or to a service provider in the United States, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and, where applicable, the EU-US Data Privacy Framework, together with supplementary security measures. You can request a copy of the safeguards we use from Support@frontline.io.

Security

We protect your information with administrative, technical and physical safeguards appropriate to its sensitivity. These include encryption in transit (TLS 1.2 or higher) and at rest (AES-256), tenant isolation enforced on the server, role-based access control, multi-factor authentication for administrators, server-side sessions with short-lived signed URLs for stored files, static and dependency security scanning of our code, an annual penetration test by an independent firm, and defined response times for fixing vulnerabilities.

 

frontline.io is certified to SOC 2 Type II and ISO/IEC 42001 (AI management systems) and operates in compliance with the GDPR. Our current SOC 2 report and a security overview are available to customers under NDA from Support@frontline.io.

 

No method of transmission over the Internet or of electronic storage is completely secure. If we become aware of a breach affecting your personal information, we will investigate, notify the relevant authorities where required, and notify you without undue delay where there is a risk to you, by a notice in the Services and an email to the address on your account.

Your rights and choices

Wherever you are, you can:

 

  • Withdraw permissions you have given: AI permission in Settings › AI; camera, microphone, photo and notification permissions in your device settings.

  • Access your personal information and receive a copy of it.

  • Correct inaccurate or incomplete information; you can edit your own profile in Settings.

  • Delete your account and personal information, as described under How long we keep information.

  • Export the content you created, in a commonly used format.

  • Object to or restrict processing based on our legitimate interests, on grounds relating to your situation.

  • Complain to a data protection authority.

 

If you are in the EEA, the UK or Switzerland (GDPR / UK GDPR). You have the rights of access, rectification, erasure, restriction, data portability and objection, the right to withdraw consent at any time without affecting earlier processing, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we make no such decisions). You may lodge a complaint with your local supervisory authority.

 

If you are a California resident (CCPA/CPRA). You have the right to know what categories of personal information we collect, from where, why, and with whom we share it; to access, correct and delete it; to opt out of sale or sharing (we do not sell or share personal information as those terms are defined in the CPRA); to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. Voice recordings, when you enable transcription or captions, may be considered sensitive personal information; we use them only to provide the feature you asked for and not to infer characteristics about you. We do not use automated decision-making technology that produces legal or similarly significant effects.

 

How to exercise your rights. If your account is managed by your Organization, contact your workspace administrator first; we will help them respond. Otherwise, or if you prefer, email Support@frontline.io from the address on your account, or write to us at the address under Contact us. We may ask you to verify your identity. We respond within 30 days, or within the period your local law sets, and do not charge a fee unless a request is clearly unfounded or excessive.

Children

The Services are business tools intended for adults at work. We do not knowingly collect personal information from anyone under 18, and AI Services must not be used by anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.

Links to other services

The Services may contain links to websites or services we do not control, and your Organization may embed third-party applications in its workspace. Their privacy practices are their own; read their privacy statements before providing information to them.

Changes to this Policy

When we change this Policy we update the date at the top. For material changes, such as a new category of data, a new purpose or a new AI sub-processor, we notify you in advance by a notice in the Services or by email to your account address, and where the law requires it we ask for your consent again. We will not use your personal information in a way materially different from what this Policy said when it was collected without telling you first.

Contact us

Questions, requests or complaints about this Policy or your personal information:

 

Frontline.io, Inc.
701 Park of Commerce Blvd
Boca Raton, Florida 33487, USA
Email: Support@frontline.io
 

bottom of page