System-sovereign deployments
Friday can be deployed inside a customer-controlled VPC, private cloud, or on-premise environment with an approved open model running in the same boundary. In this mode, the Friday vendor does not receive or retain company artifacts, prompts, or generated outputs. The customer controls storage, access, retention, deletion, and infrastructure logs.
Information Friday processes
Friday receives basic account information from the configured identity provider, including your name and email address. It also stores workspace configuration, membership and invitation details, selected source scopes, subscriptions, and audit events needed to operate and secure the service.
When a workspace connects a source, Friday processes the work artifacts made available by that authorized connection. Depending on the selected tool, this can include messages, issues, pull requests, documents, projects, user directory fields, and source metadata. Workspace owners control which accounts and scopes are connected.
How the information is used
- Authenticate members and maintain secure workspace sessions.
- Sync and normalize authorized source activity into the company knowledge base.
- Generate operating briefs, search results, historical editions, and scoped views.
- Send workspace invitations or requested digest emails when those features are configured.
- Record administrative actions for security, support, and audit review.
Connected services and service providers
Google may be used as the configured identity provider. Composio is used to authorize and operate connected source accounts. Friday also relies on configured hosting, database, email-delivery, and AI-processing providers to deliver the service. Each connection is limited by the authorization and source selection available to the workspace. In a system-sovereign deployment, the customer selects and operates the equivalent infrastructure and open-model components inside its boundary.
Cookies and sessions
Friday uses essential cookies for authentication sessions and temporary OAuth state. These cookies are required for account and connection security. The public website also uses PostHog to understand visits, navigation, and product interest. PostHog is used for first-party product analytics and is not used to serve advertising. Browser or network privacy controls may prevent that analytics collection.
Public-site analytics are separate from customer company artifacts processed by a system-sovereign Friday deployment. The zero-vendor-retention commitment for that mode continues to cover company artifacts, prompts, and generated outputs inside the customer-controlled product boundary.
Retention, access, and deletion
Account and connected-source data is retained while needed to provide the workspace and maintain its requested history. Administrators can disconnect sources and review or export audit activity. To request access, correction, or deletion of account information, use the contact page. Friday may need to verify the requester and workspace before completing a request.
Changes to this overview
This page will be updated when Friday's data practices or core service providers materially change. The latest revision date appears above.