Privacy Policy
Effective June 10, 2026
This policy describes how Foglamp ("we", "us") handles personal data when you use the hosted Foglamp service at foglamp.dev. If you self-host Foglamp on your own infrastructure, we don't receive your data and this policy doesn't apply to that deployment — your organization is the data controller.
1. What we collect
Account information. Your name and email address when you sign up. If you sign in with Google, we receive your name, email, and profile picture from your Google account — nothing else.
Telemetry you send us. Foglamp is an observability product: your applications send us traces, spans, and metadata via the SDK, which can include LLM prompts, completions, tool calls, token counts, and costs. You control what your instrumentation sends; treat this data as yours — we process it only to provide the service.
Billing information. Payments are processed by Stripe. We never see or store your full card details — we keep only your subscription status and billing history.
Usage data. Basic product analytics (pages visited, features used) to understand how Foglamp is used and improve it, plus standard server logs (IP address, browser type) for security and debugging.
2. How we use it
- To provide, maintain, and improve the service.
- To authenticate you and secure your account.
- To send transactional email: sign-in links, team invitations, alert notifications, and quota warnings.
- To bill you for paid plans.
- To respond to support requests.
3. What we don't do
- We don't sell your personal data or your telemetry data.
- We don't use your telemetry data (prompts, completions, traces) to train AI models.
- We don't send you marketing email without your consent.
4. Who we share data with
We share data only with the service providers we need to run Foglamp, and only what each one needs:
- Cloud hosting providers — run our servers and databases where your data is stored.
- Stripe — payment processing.
- Resend — transactional email delivery.
- PostHog — product analytics.
- Google — only if you choose to sign in with Google.
We may also disclose data if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to data collected before the change).
5. Data retention
Telemetry data is retained according to your plan's retention period, after which it is automatically deleted. Account information is kept while your account is active.
When you delete your account or workspace, we delete the associated data within 30 days, except where we're legally required to keep it (e.g. billing records).
6. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is limited to the people who need it to operate the service. Any provider API keys you store for evals are encrypted with AES-256-GCM before they touch the database. No system is perfectly secure, but if we learn of a breach affecting your data we will notify you without undue delay.
7. Cookies
We use cookies only to keep you signed in and to remember preferences like your theme. We don't use third-party advertising cookies.
8. Your rights
You can access and update your account information in Settings. You can ask us to export or delete your personal data at any time by emailing support@foglamp.dev. Depending on where you live (e.g. the EU/EEA under GDPR or California under CCPA), you may have additional rights to access, correct, delete, or port your data — email us and we'll honor them.
9. Children
Foglamp is not directed at children under 16, and we don't knowingly collect their data.
10. Changes to this policy
If we make material changes, we'll update the effective date above and notify you by email or in the app before the changes take effect.
11. Contact
Questions about privacy? Email support@foglamp.dev.