Legal
Privacy Policy
How FM Dojo collects, uses, protects, exports, deletes, and shares data for the service.
FM Dojo treats privacy and customer content handling as part of the product, not as a separate paperwork exercise. This notice is written to support customer security review and DPA discussions without claiming a completed legal certification or audit.
1 - Scope and roles
- This Privacy Policy applies to fmdojo.com and FM Dojo products or services that link to it. It does not apply to third-party websites, applications, or services that publish their own privacy notices.
- FM Dojo may act as a controller for account, billing, marketing, and support information. For customer content submitted to the service, FM Dojo generally acts as a processor or service provider according to the customer agreement, order form, or DPA in place.
- FM Dojo is a live and evolving service. We update product behavior, vendors, and data flows as the service changes, and we keep this notice and our security packet aligned with those changes.
2 - Information we collect
- Account and contact information, such as name, email address, company details, billing contact details, and support communications.
- Subscription and payment information needed to process purchases, renewals, invoices, taxes, fraud checks, refunds, and account administration. FM Dojo does not store full payment card numbers.
- Product content you choose to submit, including chat messages, FileMaker schema or script content, diagrams, snapshots, server metadata, validation requests, attachments, and voice dictation audio or transcripts.
- Usage, device, log, and security information, including IP address, browser, operating system, timestamps, request metadata, feature usage, error details, cookie or similar identifiers, and authentication events.
- Information from third parties that support account access, billing, analytics, error monitoring, email delivery, customer support, fraud prevention, or customer-requested integrations.
3 - How we use information
- To provide, secure, maintain, debug, and improve FM Dojo and related support workflows.
- To provision accounts, authenticate users, process payments, manage subscriptions, provide customer support, and send administrative messages.
- To send product updates or marketing messages when permitted. You can unsubscribe from promotional messages, but we may still send transactional or service messages.
- To comply with legal obligations, enforce our agreements, protect users and FM Dojo, investigate abuse, and preserve records needed for legitimate business or legal purposes.
- To generate AI-assisted responses, validation results, summaries, transcripts, and other product outputs requested by users.
4 - AI processing and customer content
- FM Dojo may send prompts, messages, attachments, validation requests, diagrams, FileMaker reference context, voice dictation audio, and related metadata to third-party AI or transcription providers so the service can respond to your request.
- Customer content is used to provide the service to you. FM Dojo does not sell, publish, or use your code, conversations, diagrams, snapshots, or other customer content to train FM Dojo-owned AI models.
- FM Dojo selects AI providers that offer business or API data-use commitments designed to avoid training on submitted API inputs, but provider-specific terms may apply. Customers should avoid submitting secrets, passwords, payment card numbers, health information, government identifiers, or other sensitive data unless their agreement expressly permits it.
- Voice dictation audio is used to generate a transcript and is not intended for account-history storage.
5 - When we share information
- We share information with subprocessors and vendors only as needed to operate FM Dojo, including hosting, database, payment, email, analytics, error monitoring, authentication, security, AI processing, and customer-requested integrations.
- Our vendors may process data under their own privacy, security, and subprocessors terms. We review vendors for fit, limit their access to the service they provide, and maintain a subprocessor list for customer review.
- We may share information when required by law, legal process, security investigation, corporate transaction, or to enforce our agreements and protect rights, safety, or service integrity.
- We do not sell personal information.
6 - Security and retention
- FM Dojo uses reasonable administrative, technical, and organizational safeguards, including access controls, encryption in transit, encryption at rest where supported by the platform, password hashing, logging, and least-privilege practices.
- No internet service or storage system is perfectly secure. FM Dojo cannot guarantee absolute security, but we work to reduce risk and respond to security issues that materially affect users.
- We retain personal information and customer content for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support ordinary business records.
- When information is no longer needed, we delete, anonymize, or aggregate it unless retention is required or permitted by law, security, backup, audit, dispute, or billing needs.
7 - Deletion and export requests
- You may request access, correction, export, or deletion of personal information by emailing [email protected]. We may need to verify your identity, account authority, and the scope of the request before acting.
- Administrators may request account-level exports or deletion for their organization where permitted by the applicable agreement and law. Some information may be retained for billing, fraud prevention, security logs, backups, legal compliance, dispute handling, or other legitimate business needs.
- Product surfaces may also let users delete certain conversations, diagrams, snippets, snapshots, or other content directly. In-product deletion affects the active service record first; backup and log copies age out under the relevant retention process.
- If FM Dojo acts as a processor for customer content, we handle data subject requests according to the customer agreement, DPA, and the customer controller instructions that apply.
8 - International processing
- FM Dojo and its vendors may process information in the United States and other countries where FM Dojo or its subprocessors operate.
- For customers that need a data processing addendum or transfer terms, FM Dojo can provide a DPA-ready packet describing current processing roles, subprocessors, request handling, and security posture. This packet is readiness documentation and is not a statement that FM Dojo has completed a legal certification such as SOC 2, ISO 27001, or another audit unless separately stated in a signed agreement.
9 - Google Workspace API data
- When you connect Gmail, Google Sheets, Google Calendar, Google Drive, or Google Meet, FMDojo shows the service-specific data categories, supported read or write operations, and purpose before sending you to Google's authorization screen. Each service is connected separately with its own scopes.
- Gmail connections may send messages, with or without one selected attachment. Sheets connections may read bounded ranges and append or update values. Calendar and Meet connections may list, read, create, or update events and conferences. Drive connections use drive.file access for files FMDojo creates or that you explicitly open with FMDojo, including selected metadata and bounded file content.
- OAuth refresh tokens and advanced Workspace service-account credentials are encrypted in the saved connection. They are retained while the connection exists. Disconnecting deletes the saved credential and stops future access; it does not erase data already retained in Flow run history.
- Flow run history records trigger data, step inputs, bounded outputs, timing, and errors so users can compose later steps and troubleshoot runs. Deleting the Flow deletes its run history from the active database through the Flow's dependent records. Backup, security, legal, billing, or dispute copies may age out under the retention practices described above.
- FMDojo uses Google data only to run the user-configured integration, provide its results, secure and troubleshoot that workflow, and meet legal obligations. Authorized FMDojo personnel may access stored service data only when needed for support, security, abuse investigation, or legal compliance and subject to applicable access controls.
- A Google connection does not by itself send Google data to an AI provider. When a Flow references Google-derived values in an OpenAI step, the runtime identifies the source and blocks the transfer unless the step shows the provider and purpose, the user gives current input-and-source-bound consent, and FMDojo has certified the exact effective provider configuration's applicable API terms as prohibiting generalized model training for this use. Generic OpenAI-compatible endpoints fail closed unless separately certified, and generic HTTP or automation-webhook destinations cannot carry Google-derived values because they cannot prove the receiving provider or terms. The audit records the decision, provider, purpose, and source services without recording API keys in that decision.
- FMDojo Desktop can process user-selected context with Ollama through a loopback-only connection on the user's computer. In that local mode, FMDojo does not send the model input to a hosted model provider. This local processing statement does not apply if the user deliberately chooses a hosted provider or sends the result through another connector.
- FMDojo may transfer Google-derived values to FileMaker or another non-AI destination only when the user configures that destination in the Flow. Users control the selected fields and bounded results and should approve every destination for the data involved.
- FMDojo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
10 - Contact and updates
- Questions, privacy requests, security concerns, and vendor review requests can be sent to [email protected].
- We may update this Privacy Policy as FM Dojo changes. Material changes take effect when posted or otherwise communicated as required by law or contract.
Effective July 29, 2026