1. Scope and contact
Fareground, Inc. (“Fareground,” “we,” “us”) operates fareground.com, fareground.ai, zigura.ai, and related applications, APIs, CLI and agent interfaces (the “Services”). We are the controller for account, billing, security, and product operations. For privacy requests contact hello@fareground.com. We are based in Austin, Texas, United States. For business workspace data, we may act as processor under our DPA.
2. Information collected
- Account: email, username, profile, avatar, authentication provider, verification and account timestamps.
- Customer content: prompts, simulations, configurations, agents, outputs, workspaces, files and history, tickets, proposals, chats, knowledge, comments, attachments, and metadata.
- Billing: plan, wallet and ledger entries, purchases, invoices, refunds, and Stripe identifiers. Card and bank details are collected by Stripe, not Fareground servers.
- Usage: IP address, device/browser, pages and features used, referral, API/MCP/CLI activity, storage/model usage, diagnostics, errors, and security events.
- Communications and integrations: waitlist, support, feedback, email, and data returned by services you connect, such as Google sign-in.
Do not submit regulated health data, card data, government identifiers, biometric templates, children’s data, or other sensitive data unless we expressly agree in writing.
3. Uses and legal bases
We use information to provide, synchronize, secure, support, bill for, analyze, and improve the Services; run requested model calls; prevent abuse; communicate about accounts and incidents; comply with law; and establish or defend claims. Where GDPR applies, bases include contract, legal obligation, legitimate interests in security and reliability, and consent for optional processing where required.
4. AI processing
A model request may send its prompt, instructions, context, attachments, and output to the selected model or routing provider. Do not include data you lack authority to disclose. We do not sell customer content or use private customer content to train public foundation models. Current providers appear in the Subprocessor Register.
5. Disclosure
We disclose data to providers for hosting, storage, delivery, email, analytics, payments, model inference, monitoring, and support; to workspace members and agents according to configured permissions; in a corporate transaction under safeguards; and where reasonably necessary for law, safety, security, or enforcement. We do not sell personal information for money or share it for cross-context behavioral advertising.
6. Sharing choices
Workspace content is visible to authorized members and agents. Public links and published content are visible as configured and may be copied by recipients. Revoking a link cannot retract copies already made.
7. Cookies and analytics
We use essential cookies/local storage for authentication, security, preferences, and continuity. Where configured, PostHog measures visits and product behavior. Product analytics excludes customer content and sensitive form values by design, uses opaque account IDs, and has session recording disabled. We honor consent and legally required opt-out signals where applicable.
8. Retention and deletion
We retain information while accounts are active and as needed for version history and recovery. Deleted files may remain in recoverable history during configured retention. Security, tax, billing, ledger, and audit records may remain as legally or operationally required. Backups expire on rotation and are used only for recovery.
Fareground and Zigura each have account-deletion controls. Fareground deletion deactivates and anonymizes the Fareground identity while retaining limited billing, ledger, security, and audit records. Zigura deletion removes its account, owned workspaces and memberships as described in its confirmation screen. Because operational stores are separate, delete each product account used or request coordinated deletion. Data controlled by another workspace owner and legally required records may remain.
9. Security and transfers
Controls include access restrictions, encryption in transit, production encryption at rest, password hashing, short-lived access tokens, rotating refresh tokens, audit logs, backups, monitoring, and recovery testing. No system is perfectly secure. Processing occurs principally in the United States; where required we use adequacy decisions, Standard Contractual Clauses, or another lawful transfer mechanism.
10. Rights
Depending on location, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent and may appeal a denial or complain to a regulator. California residents may request categories and specific pieces, correction, deletion, disclosure information, and non-discrimination. We do not sell/share data for cross-context advertising. Email hello@fareground.com; identity verification may be required.
11. Children and changes
The Services are not directed to children under 13. A higher local age of digital consent applies where required. We will post changes here and provide additional notice or consent for materially reduced protections where required.