Privacy
How Frissbi handles your data
Frissbi is a browser extension and a server. You use the extension to save web pages and upload requirement documents, such as tender specifications and job descriptions; the server analyzes them for your organization. This page explains, in plain language, what is sent, where it is processed and what is kept.
- Everything you save is stored on your organization's Frissbi server, over encrypted connections.
- AI runs on the Frissbi server. By default, page text and documents are not sent to an outside AI provider.
- Web page text sent to the server is used for the analysis and then discarded. Frissbi keeps the results.
- Flash page reading is off unless your organization turns it on. When it is on, pages are read on your organization's own model and only derived features are kept, for 7 days.
- Candidate profiles are visible only to your HR team and global administrators, are analyzed only on your organization's own model, and are deleted after your organization's retention period.
- No ads, no analytics and no third-party trackers, in the extension or on these pages.
Your Frissbi server
The extension talks to one Frissbi server: the hosted service at api.frissbi.com, or a server your organization runs itself and sets in the extension's Options page. All of your organization's saved pages, documents and results are stored in that server's database. Connections to the hosted service use HTTPS.
Your organization is the boundary. Saved pages and their results are shared with the members of your organization and are not visible to other organizations. Candidate profiles are the exception: inside your organization only your HR team and global administrators can see them (see Candidates). Requirement documents are visible to the person who uploaded them, to anyone they share them with (a named colleague, or the whole organization) and to your organization's global administrators.
What the extension sends, and when
The extension reads a page when you ask it to: when you click Save or Enrich, or open the Smart Tray on that page. Otherwise it runs no code on the pages you visit, unless your organization has turned on page reading (see Flash page reading).
Signing in
- Your email and password are sent to the server when you sign in. The server stores only an Argon2id hash of your password, never the password itself.
- You stay signed in with a session cookie that page scripts can't read. The server keeps only a digest of the session identifier, and the extension's own code never reads or stores it.
Saving a page
- The page's address and title, together with your account, so your organization knows who saved it.
- HR users can save a person's public profile page as a candidate. Candidates are handled differently; see Candidates.
Enriching a page
- A bounded extract of the page you're on: its address, title, description, up to 12 headings, up to 30 facts from tables and definition lists, and up to 6,000 characters of visible text.
- Forms, input fields, buttons, scripts, hidden elements, navigation and footers are left out.
- Before analysis, the server removes text that looks like a password, an API key or an access token, and drops address parameters with names such as "token", "key" or "session".
- The extract is used for the analysis and is not stored. Frissbi keeps the results (summary, category, tags, brand and specifications) and a record of how they were made: which task, model and policy, and when.
Uploading requirement documents
- PDF files you upload are stored privately on the server, so you can open them again from the dashboard. Job descriptions can also be Word (.docx) files.
- The server reads the text of each document to analyze it, and stores the results together with the quoted passages they are based on.
- Job descriptions are analyzed only on your organization's own model. Email addresses and phone numbers are removed from their text before analysis.
Checking for updates
- The popup asks the server for its public settings (the current extension version and whether sign-up is open). That request carries no cookies or account details.
Flash page reading
Flash compares the address and title of the pages you open with your organization's saved pages and requirements, on your computer. Page reading goes one step further: it lets your organization's own model read the pages you stay on, so Flash can tell you which requirements a page fits. It is off by default.
Who turns it on
- Only a global administrator of your organization can turn page reading on, and only while Flash is on. Every change is recorded in your organization's audit log.
- Chrome asks each person once to allow the extension to read pages ("Allow page reading" in the Smart Tray). While page reading is on, the Smart Tray says "Page reading is on for your organization", and Flash can't be paused from the tray.
- If your company manages your browser, its IT team can turn Flash off by policy, which also stops page reading.
What is read
- A page is read only after it has been open in the active tab for about 8 seconds, passes a quick check on your computer (it must be an ordinary page with something in common with what your organization works on: a starred requirement's terms, a site where someone saved a page, or the tags and brands of saved pages), and is not on the never-read list. A page someone in your organization has already saved is not read. The extension then sends the same bounded extract as Enrich to your organization's Frissbi server.
- Never read: http pages, IP addresses and internal host names, mail and messaging, banking and payments, health sites, private workspaces such as documents, drives, team tools and AI assistant chats, social networks and people profiles, search results, sign-in, account, checkout and payment pages, sites on your organization's own exclusion list, and private (incognito) windows.
What is kept
- The server reads the extract once, on your organization's own local model (local-only: never an outside AI provider), and then discards the text. The model is given the page's address without its query string.
- It keeps only derived features, for 7 days: categories, brand and vendor, tags, and feature names with their values, together with how well the page fits your organization's requirements. It keeps no page text, title or address, only a one-way hash of the address and the site's host name, and no record of who read the page.
- Within those 7 days the same features are reused for anyone in your organization who opens the page, so it is not read again.
- Turning page reading off deletes the stored features at once.
Candidates (HR)
- Candidate profiles saved by HR users are visible only to people with an HR persona and to your organization's global administrators. For everyone else they don't appear in lists, searches or counts.
- Candidate profiles are analyzed only on your organization's own local model, never on a cloud model, whatever the server's policy. Email addresses and phone numbers are removed from the text first.
- CVs attached to a candidate as PDF or Word (.docx) files can be read for matching. The text is used for the analysis and not stored; only the derived skills, experience and similar details are kept.
- Searches of the public web (alternatives, reviews, contacts and videos) never run for candidates.
- Candidates and everything attached to them, such as CV files, comments and match results, are permanently deleted once your organization's retention period has passed since the candidate was last saved or updated. The default is 12 months; global administrators can set 1 to 120 months.
- The hosted service's backups keep deleted data until they rotate out, after 14 days (see Running the service).
Where AI processing happens
Frissbi's AI features run through the Frissbi server. The default policy is local-only: models run on hardware the server controls, and page text and documents are not sent to an outside AI provider. The hosted service at api.frissbi.com runs its models on its own server. A self-hosted server follows the policy its administrator sets.
Some work always stays on your organization's own model, whatever the policy: Flash page reading, candidate profiles and CVs, job descriptions, and fit checks that involve a candidate or a job description.
Frissbi doesn't add your name or email address to what the models are given.
Searching the public web
Some features look for related information on the public web: alternatives, reviews, contacts and videos. When you use one, the Frissbi server builds search terms from the saved page's details, such as its title, brand and category. Depending on your server's settings, it sends those terms to a search service that forwards them to public search engines, or it gives you a search link to open yourself. The server may then visit the public pages it found to check them.
These searches contain the search terms only, not your name, email or the page's full text. They never run for candidate profiles.
These web pages
The download page and this page load nothing from other sites: no third-party scripts, fonts or analytics. The download page reads one small file from this server, the list of current release files.
If you open an invite link, the invite code sits after the # in the address. Browsers never send that part of an address to a server, and the download page doesn't send, store or record it.
The administration sites
- Your organization's administrators manage its members and settings at
app.frissbi.com. The Frissbi operator manages organizations, their seats and their first administrators atadmin.frissbi.com. Both sites run on the same Frissbi server and use the same account data as the extension; there is no separate copy of your account. - Links to set or reset a password are single use and expire (after 72 hours by default). The code sits after the
#in the link, so it is not sent to the server as part of the address. Using a link signs that account out everywhere and cancels its other open links.
Running the service
- To operate and protect the service, the server keeps request logs: the time, the address requested and the network address the request came from. They don't include page text, document contents or passwords.
- The hosted service backs up its database, uploaded documents and attached files every night, on its own server, and keeps each backup for 14 days. Data you delete, including candidates removed after the retention period, stays in those backups until they rotate out.
Questions
Your Frissbi account belongs to your organization. For questions about your data, ask your organization's Frissbi administrator.