Last updated June 2026
Introduction and scope
Focor Inc. (“Focor”, “we”, “us”) is a Delaware corporation building the attention layer for your AI stack: a private model of how you actually work, assembled from the context your tools throw away, that surfaces what deserves your attention.
We serve people worldwide, including in the European Economic Area (EEA) and the United Kingdom, so this policy is written to meet the GDPR and UK GDPR as well as US laws such as the CCPA. It covers:
- Our website (focor.com), including the waitlist, contact forms, and analytics.
- The Focor product, including the data it reads from the tools you connect, the model it builds for you, and everything it surfaces.
One principle sits underneath all of it: the model Focor builds of you is yours. It is private, portable, and sovereign. We treat the data behind it accordingly.
Our roles: controller and processor
Data protection law distinguishes the controller (who decides the purposes and means of processing) from the processor (who processes on a controller's instructions). Depending on how Focor is used, we act in one of two roles:
- As a controller. For our website, and when you use Focor as an individual and connect your own accounts, we determine the purposes and means. We are the controller, and this policy describes that processing.
- As a processor. When a business or organization provides Focor to its people, that organization is the controller. We process on its documented instructions under a Data Processing Agreement (DPA), the providers listed below act as our sub-processors, and the organization's own privacy notice governs its people.
Whichever role applies, we hold the data to the standards described here.
Our privacy commitments
Your model is yours
The model Focor builds belongs to you. You can export it or delete it, and we never sell it or hand it to anyone else.
Zero-trust by default
Read-only by default, scoped least-privilege access, and nothing holding standing access to your data.
Data minimization
We only collect and process what the service needs. If we do not need it, we do not ask for it.
No training on your data
We do not use your connected-source content or your private model to train shared or public AI models.
Encryption and pseudonymization
Personal data is encrypted in transit and at rest, and pseudonymized where feasible (Art 32).
Transparency
You can ask what data we hold about you, and where it goes, at any time.
Information we collect
From website visitors
- Contact information: first name, last name, and email address when you join the waitlist or apply for access.
- Communications: comments, feedback, or messages you send us.
- Usage and device data: pages visited, time on page, click patterns, browser type, operating system, device type, and approximate location, collected through privacy-respecting analytics.
From product users
- Account information: name, email, authentication details, and workspace or organization settings.
- Connected-source data: when you connect a tool (for example email, calendar, messaging, documents, or task systems), Focor reads the data you authorize it to read in order to build your model. This can include message metadata and content, events, files, and the people, topics, and decisions referenced in them.
- Your model: the typed graph Focor derives from that context, including the entities, relationships, and signals it represents.
- Product usage and telemetry: how you interact with Focor, queries you run, features you use, and diagnostic and performance data.
You control which sources are connected, and you can disconnect any of them at any time.
People in your connected sources
The tools you connect contain personal data about other people: the colleagues, contacts, and senders referenced in your email, calendar, messages, and documents. To build your model, Focor processes that data too.
- Our legal basis is our legitimate interests (and those of our users) in providing the service (Art 6(1)(f)), balanced against those individuals' rights and freedoms, together with your authorization to connect the source.
- We minimize this to what is needed to represent your work, and pseudonymize it where feasible.
- We do not use it to contact those people or to build independent profiles of them. They may exercise their rights by contacting privacy@focor.com.
This is why, when you connect a source, you confirm that you have the right and any necessary permissions to do so.
How we use your information
We use the information we collect to:
- Provide, operate, and secure the website and the product.
- Build and maintain your private model and surface what deserves your attention.
- Respond to your inquiries and provide support.
- Send you updates about Focor, only if you have opted in.
- Understand and improve the service, using aggregated or de-identified data wherever possible.
- Detect, prevent, and address abuse, security, and fraud.
- Comply with legal obligations and enforce our terms.
We will never:
- Sell your personal data.
- Use your connected-source content or your private model to train shared or public AI models.
- Share your information with advertisers.
- Use your data for purposes beyond those stated here without your consent.
AI processing and model providers
To understand your work, Focor sends relevant context to large language model providers for inference. We use xAI (Grok) and Anthropic for this, through their enterprise and API offerings.
- These providers process the context only to return a result to Focor, under their API and enterprise terms.
- We use them under terms and settings intended to prevent your data from being used to train their models, and to apply limited or zero retention.
- We minimize what is sent, and pseudonymize the context where feasible, sending only what a given request needs.
AI outputs (summaries, rankings, and what Focor surfaces) are assistive suggestions. They can be incomplete or wrong, and you remain responsible for your decisions.
Legal bases for processing (GDPR)
If you are in the EEA or UK, we rely on the following legal bases:
- Consent: for optional communications and for connecting sources that contain personal data.
- Performance of a contract: to provide the service you sign up for.
- Legitimate interests: to provide, secure, maintain, and improve the service, including processing data about people referenced in your sources, balanced against their rights.
- Legal obligation: where the law requires it.
How we share information
We do not sell your personal data. We share it only:
- With processors: service providers who process data on our behalf under contract (see the next section).
- At your direction: with the tools you choose to connect, and with anyone you choose to share output with.
- For legal and safety reasons: to comply with law, enforce our terms, or protect rights, safety, and security.
- In a business transfer: in connection with a merger, acquisition, or sale of assets, subject to this policy.
Processors and sub-processors
We rely on a small set of vetted providers, each bound by a data processing agreement. Where Focor is a controller they act as our processors; where Focor is a processor for a business customer, they act as our sub-processors:
- Supabase: database, authentication, and storage.
- Vercel: application hosting and website analytics.
- PostHog: product and website analytics.
- xAI (Grok) and Anthropic: large language model inference.
- Resend: transactional and account email.
We maintain a current list and will provide notice of material changes. To request the latest list, contact privacy@focor.com.
International data transfers
Focor is committed to data sovereignty. We may process data in the United States and other countries. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum. A copy of the safeguards we use is available on request.
Data retention
We retain personal information only as long as necessary for the purposes in this policy, or as required by law.
- Connected-source data and your model are retained while your account is active and the source is connected.
- When you disconnect a source, delete your model, or close your account, we delete or anonymize the associated data within a reasonable period, except where retention is legally required.
Your choices and controls
- Connections: connect or disconnect any source at any time.
- Portability and deletion: export your model or delete it. It is yours.
- Communications: opt out of non-essential email at any time.
- Cookies: control non-essential cookies through your browser.
Your rights (GDPR)
If you are in the EEA or UK, you have the right to:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data (the right to be forgotten).
- Restriction: limit how we process your data.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: at any time, without affecting prior processing.
To exercise these rights, contact privacy@focor.com. Where Focor acts as a processor for your employer, please direct requests to them as the controller. You also have the right to lodge a complaint with your local supervisory authority.
Your rights (US and CCPA)
If you are a California resident, you have the right to know, access, correct, and delete your personal information, and to opt out of its sale or sharing. Focor does not sell your personal information and does not share it for cross-context behavioral advertising. We will not discriminate against you for exercising these rights. You may use an authorized agent to make a request. Contact privacy@focor.com.
Security
We apply the technical and organizational measures the GDPR expects (Art 32), including:
- Encryption of personal data in transit (TLS) and at rest.
- Pseudonymization of personal data where feasible, separating identifiers from the working data.
- Zero-trust architecture and least-privilege access controls.
- Authentication, logging, and regular security review.
- Secure development practices, designed to collect and expose the minimum data necessary (data protection by design and by default, Art 25).
We are pursuing SOC 2 Type II and ISO 27001. No method of transmission or storage is 100% secure, so while we work hard to protect your data, we cannot guarantee absolute security.
Cookies and tracking
focor.com uses minimal cookies:
- Essential cookies: required for functionality, such as session and authentication.
- Analytics cookies: used by our privacy-respecting analytics, which you can disable in your browser.
We do not use advertising or cross-site tracking cookies.
Children's privacy
Focor is not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice here or emailing you. Your continued use of Focor after changes take effect constitutes acceptance of the updated policy.
Contact us
For questions about this policy or how we handle your data:
- Privacy and data protection: privacy@focor.com
- Address: Focor Inc., 1111b S Governors Ave, Suite 97911, Dover, DE 19904 US.
- EEA and UK: if you are in the EEA or UK, you can reach us about data protection at privacy@focor.com. Our Article 27 representative details will be published here once appointed.