Privacy Policy
Frilly Inc
Last updated: March 2026
This Privacy Policy describes how Frilly Inc (“Frilly,” “we,” “our”) collects, uses, shares, and protects information in connection with the Frilly platform, including our websites (frillyconcierge.com, frilly.ai, and associated subdomains), APIs, AI-powered chat agents, embeddable widgets, and all related services. This policy applies to Customers, Free Listings, and End Users.
1. Information We Collect
1.1 From Customers
Customers’ business profiles are initially compiled by Frilly from publicly available sources using automated scraping and AI-assisted processing. When a Customer subscribes at frillyconcierge.com, they claim their profile and can review, refine, and supplement this data through their dashboard.
| Data Category | Examples | Collection Method | Visibility |
|---|---|---|---|
| Account Data | Name, email, password, billing info, subscription tier | Direct input during registration at frillyconcierge.com | Private |
| Business Content | Business name, description, FAQs, services, products, pricing, hours, contact info, images, logos | Initially compiled by Frilly via automated scraping and AI-assisted processing; Customer reviews and refines via dashboard | Public |
| Training Data | URLs submitted for scraping, uploaded documents (PDF, DOCX, TXT, MD) | Customer uploads via dashboard (paid tiers only) | Public — powers Smart Chat responses |
| Instagram Data | Instagram account ID, username, access token, recent post metadata (CDN URLs, captions, permalinks, timestamps) | Authorized by Customer via Instagram Business/Creator account connection | Public — displayed on Frilly profile |
| Usage Analytics | Login frequency, feature usage, Smart Chat conversation volume | Automated platform logging | Private |
Customers are informed during onboarding that all business content and training data submitted to the platform is intended for public-facing use across the Frilly network.
1.2 From Free Listings
Free Listings are created to ensure the mapped local ecosystem is comprehensive. Data is sourced from publicly available information.
| Data Category | Examples | Collection Method | Visibility |
|---|---|---|---|
| Public Business Info | Business name, address, phone, website, hours, social media links | Web scraping, public directories, manual research | Public |
| Logo / Branding | Business logo extracted from website | Extracted from the business's website via automated HTML scraping; processed into standardized directory formats using AI-assisted background color matching | Public |
| AI-Generated Summaries | Business descriptions, category tags, service summaries | Generated by Frilly's AI from scraped public data | Public |
When a business owner claims their Free Listing, they gain the ability to edit, enhance, or remove their profile. Logos are extracted directly from the business’s website and are not modified by AI — AI is used only to determine the background color for standardized display formatting.
1.3 From End Users
End Users interact with Frilly’s public-facing tools without creating an account.
| Data Category | Examples | Collection Method | Visibility |
|---|---|---|---|
| Conversation Data | Questions and messages submitted through Smart Chat or Smart Directory | Direct input by end user | Private |
| Device / Technical Data | IP address, browser type, device type, OS, timestamps | Automated (cookies, server logs) | Private |
| Approximate Location | City/region-level location | Derived from IP address | Private |
| Lead Information (optional) | Name, email, phone if voluntarily provided during Smart Chat | Direct input by end user | Shared with the relevant business Customer |
When End Users voluntarily provide personal information during Smart Chat conversations, that information may be shared with the relevant business Customer for lead generation purposes.
1.4 From AI Processing
When Customer Content (including Training Data) is processed by our AI systems, derivative data is created including text embeddings, summaries, conversational response templates, standardized logo images, and categorization metadata. This AI-Generated Content is associated with the relevant business listing.
2. How We Use Information
2.1 Customer Content and Training Data
- Powering Smart Chat conversational agents for the Customer's business
- Displaying business information across the Frilly network via the Smart Directory at frilly.ai
- Generating AI-enhanced summaries, recommendations, and discovery content
- Processing Training Data (URLs and documents) to improve Smart Chat response quality
- Powering Smart Directory discovery results and the conversational search agent
2.2 Account Data
- Managing Customer accounts, authentication, and billing at frillyconcierge.com
- Communicating with Customers about their account, service updates, and support
- Internal analytics to improve the platform
2.3 End User Data
- Delivering relevant discovery and engagement experiences
- Improving AI response quality across the network using aggregated conversation patterns
- Generating aggregate, anonymized analytics for Customers (e.g., conversation volume, common questions)
- Facilitating lead generation when End Users voluntarily provide contact information through Smart Chat
2.4 Instagram Data
- Displaying the Customer's recent Instagram posts on their public Frilly profile at frilly.ai
- Allowing the Customer to show or hide individual posts from their dashboard at frillyconcierge.com
Instagram data is not sold, shared with third parties, or used for advertising purposes. Instagram data is used solely to display the Customer’s own content on their Frilly profile.
3. How We Share Information
3.1 Within the Frilly Network
Customer Content and AI-Generated Content are shared across the Frilly network to power discovery and engagement tools. This is a core function of the Service and is consented to by Customers when they submit content to the platform.
3.2 With AI Providers
Customer Content is transmitted to third-party AI Providers for processing. Frilly selects AI Providers whose terms prohibit the use of API input data for general model training. Where available, Frilly uses private or enterprise-tier API access that contractually prohibits use of input data for model training.
3.3 With Third-Party Service Providers
We share information with service providers who assist in operating the platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Convex | Database hosting and backend infrastructure | All platform data (multi-tenant with logical isolation) |
| Stripe | Payment processing | Customer billing data (Frilly does not store payment card numbers) |
| DreamHost VPS | Web application hosting | Application assets across frillyconcierge.com and frilly.ai |
| Firecrawl | Web scraping | Public URLs for Free Listing data and Training Data URL ingestion |
| Google Gemini | AI processing | Business content for chat responses, summaries, and logo background analysis |
| LangFuse | AI pipeline observability | AI processing logs (may include conversation snippets) |
| Meta / Instagram API | Third-party platform integration | Instagram access tokens and post retrieval for authorized Customer accounts |
3.4 With Business Customers (Lead Data)
When End Users voluntarily provide personal information during Smart Chat conversations (such as name, email, or phone number), this information may be shared with the relevant business Customer for lead generation purposes.
3.5 Third-Party Platform Integrations (Instagram)
Customers may connect their Instagram Business or Creator account to their Frilly profile to display recent posts on their public Smart Directory listing at frilly.ai. This integration uses the official Instagram API provided by Meta Platforms, Inc. and requires the Customer’s explicit authorization.
Information we collect from Instagram: Instagram account ID and username, a long-lived access token (refreshed approximately every 50 days), and recent post metadata including image/video URLs (referencing Instagram’s CDN, not downloaded or stored by Frilly), captions, permalinks back to Instagram, and publish timestamps.
Information we do NOT collect from Instagram: Follower or following lists, direct messages or private communications, analytics or engagement metrics, any data from the business’s followers or audience, or data from personal Instagram accounts. Only Business or Creator accounts may be connected.
We do not download or store Instagram images or videos. Frilly references Instagram’s CDN URLs to display media, which expire naturally and are refreshed on a daily basis. Instagram data is not sold, shared with third parties, or used for advertising purposes.
3.6 As Required by Law
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of Frilly, our users, or the public.
3.7 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, user information may be among the transferred assets. We will notify affected users of any such transfer and any resulting changes to this Privacy Policy.
4. Data Retention
4.1 Customer Content and Training Data
Customer Content and Training Data remain on the platform for the duration of the Customer’s active account. Upon account termination, Customer Content is removed from active display within 30 days. Training Data is purged from the Smart Chat knowledge base. Account Data is permanently deleted from primary systems within 90 days, with the exception of billing records retained as required by applicable tax and financial regulations.
4.2 Free Listing Data
Free Listing data sourced from public sources is maintained to support the integrity of the Frilly network. Business owners may request removal of their Free Listing at any time by claiming their listing at frilly.ai or by contacting us. Removal requests are processed within 30 days.
4.3 End User Data
Conversation logs and device data collected from End Users are retained for platform improvement purposes. Aggregate and anonymized analytics derived from End User interactions may be retained indefinitely. End Users may request deletion of their data by contacting us.
4.4 Instagram Data
When a Customer disconnects their Instagram account from Frilly via their dashboard at frillyconcierge.com, we immediately clear the stored access token, revoking our ability to fetch new data from Instagram. Post metadata (captions and permalinks) is retained so that if the Customer reconnects, their display preferences are preserved. Image and video URLs expire naturally since Frilly does not store media files. Upon full account deletion from Frilly, all Instagram-related data is permanently deleted along with the rest of the Customer’s account data.
4.5 AI-Generated Content
AI-Generated Content (summaries, embeddings, processed logo images, cached responses) derived from Customer Content may persist in the system after the source data is removed from active display. Complete purging of all derivative data from every system is not guaranteed, though active display of such content is removed.
5. Data Deletion
You may request deletion of your data through the following methods:
| Data Type | How to Delete | What Happens |
|---|---|---|
| Full Frilly Account | Contact support@frilly.ai or delete your account through your dashboard at frillyconcierge.com | All account data, business content, training data, Instagram data, and associated AI-generated content is permanently deleted within 90 days |
| Instagram Integration | Disconnect Instagram from your Frilly dashboard at frillyconcierge.com, or contact support@frilly.ai | Access token is immediately cleared; post metadata is retained for preference preservation but media URLs expire naturally; full deletion occurs on account deletion |
| Smart Chat Training Data | Remove individual URLs or documents from your dashboard at frillyconcierge.com | Training data is purged from the Smart Chat knowledge base |
| Free Listing | Claim your listing at frilly.ai and request removal, or contact support@frilly.ai | Listing is removed from active display within 30 days |
| End User Data | Contact support@frilly.ai with your request | Conversation logs and associated data are deleted |
6. Data Security
Frilly implements commercially reasonable technical and organizational measures to protect information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Multi-tenant database architecture with logical data isolation (Convex)
- Encryption in transit (TLS/HTTPS) for all data transmission across all domains
- Encryption at rest through our infrastructure providers
- Role-based access controls for internal personnel
- Stripe handles all payment card data (PCI compliance delegated to Stripe)
In the event of a data breach affecting your personal information, we will notify affected users in accordance with applicable law, including Wisconsin’s breach notification requirements.
7. Your Rights and Choices
7.1 Customer Rights
- Access and update Customer Content at any time through the dashboard at frillyconcierge.com
- Upload, modify, or remove Training Data for Smart Chat
- Connect or disconnect third-party platform integrations (e.g., Instagram) at any time, with immediate revocation of access tokens upon disconnection
- Export Customer Content before account termination
- Request deletion of Account Data following account closure
7.2 Free Listing Rights
- Claim and manage a Free Listing at any time via frilly.ai
- Request correction or removal of Free Listing information, including extracted logos
7.3 End User Rights
End Users may request information about what data has been collected, request deletion of conversation data and lead information, or opt out of data collection by contacting us at support@frilly.ai.
7.4 California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale or sharing of personal information. Frilly does not sell personal information. To exercise your rights, contact us at support@frilly.ai.
8. Cookies and Tracking Technologies
Frilly uses cookies and similar technologies across our platforms (frillyconcierge.com, frilly.ai) and within embedded Smart Chat widgets served from smartchat.frilly.ai. These technologies are used for essential platform functionality, authentication, and analytics. When Smart Chat is embedded on a Customer’s website, the widget may set cookies or collect device data in the context of that site.
9. Children’s Privacy
The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.
10. International Data Transfers
Frilly’s primary infrastructure is based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States. By using the Service, you consent to such transfers.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify Customers of material changes via email or in-platform notification at frillyconcierge.com at least 30 days before the changes take effect. The “Last updated” date at the top of this policy reflects the most recent revision.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

