Security
Fervid reads your customer conversations. This page describes how that data is handled, and what we do not do with it.
Our role in your data
For the customer conversations you connect or upload, you are the data controller and Fervid acts as a data processor on your behalf. We process that data only to produce themes, insights, and reports inside your own workspace, following your instructions.
For your own account information, such as your name, email address, and billing details, Fervid is the data controller.
Data processing agreement
If you are subject to GDPR or UK GDPR, we will sign a data processing agreement with you. Request it at contact@fervidai.com and we will send our standard DPA, which incorporates the EU Standard Contractual Clauses for international transfers.
What we do not do
- We do not sell your data, or share it with anyone outside the sub-processors listed below.
- We do not use your customer feedback to train AI models. Feedback is sent to Anthropic for analysis and is not retained by them for training under their API terms.
- We do not use your data to serve or improve any other customer's account.
- Integrations request read access only. Fervid does not write to your support tools.
How data is protected
- Encrypted in transit with TLS, and encrypted at rest by our database provider.
- Integration credentials are encrypted before storage.
- Every account is isolated at the database level using row level security, so one customer's queries cannot reach another customer's data.
- Access to production data is limited to what is required to operate the service.
Sub-processors
Fervid relies on the following providers:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | United States |
| Vercel | Application hosting | United States |
| Anthropic | AI analysis of feedback text | United States |
| Stripe | Payment processing | United States |
| Resend | Transactional email | United States |
Anonymising customer data
Feedback often contains names and email addresses. Fervid includes a setting that replaces customer names with initials and masks email addresses to the domain only, so you can share insights internally without exposing personal details.
Deleting your data
Disconnecting an integration stops any further collection. Deleting a project removes its feedback, themes, and taxonomy. To have your account and all associated data erased, email contact@fervidai.com.
Certifications
Fervid is an early stage company and is not yet SOC 2 or ISO 27001 certified. We would rather say so plainly than imply otherwise. If a certification is a requirement for your procurement process, contact us and we will tell you honestly where we are.
Reporting a problem
If you believe you have found a security issue, email contact@fervidai.com and we will respond within two business days. If we discover an incident affecting your data, we will notify you at your account email within 72 hours of becoming aware of it.