Privacy
What we measure
First-party, anonymized operational analytics only — page views, flow progression, content engagement. Event names are neutral operational terms. No advertising pixels, no third-party trackers, no health-adjacent retargeting. Ever.
Screening responses
Safety-related screening responses (Section 3.3 of the intake) are stored encrypted (AES-256-GCM) with restricted, role-based access, in a store separate from marketing and analytics. No Section 3.3 response is ever passed to analytics, advertising, or third-party tooling.
Retention
Covered records — screening responses, uploads, screening and diversion decisions, and crisis records — are retained at least 7 years from the last applicable event (for minors, the later of 7 years or age 21). Crisis records receive clinical-grade retention even for applicants who are never accepted. Every data entry, upload and access is audit-trailed. Records under legal hold are never deleted. End-of-retention destruction is documented.
Payments
Payments are processed by Stripe. Card data never touches Fronys servers. Stripe is the single source of revenue truth.
Clinical data
Components touching clinical data run on HIPAA-compliant hosting under business associate agreements. Uploaded video streams via secure, download-disabled delivery.
Your choices
Decline measurement in the consent banner and nothing is measured. Request your record, or its correction, at support@fronys.com.