Privacy Policy
Effective date: August 21, 2026
This Privacy Policy explains how Underbuild LLC (“Underbuild,” “we,” “us,” or “our”) handles personal data (“Personal Data”) when you use fariq.ai, a Fariq account, the Fariq desktop application, or related services (collectively, the “Services”), or when you contact us.
In this Privacy Policy, “Content” means prompts, messages, outputs, files, memories, instructions, tool results, and other information you or your organization provide to, generate through, or ask Fariq to access.
Underbuild is the controller for Personal Data used to administer accounts, communicate with users, protect the Services, prevent fraud, and meet our legal obligations. When an organization uses Fariq, the organization controls its organization Content and we process that Content on its behalf under our Data Processing Addendum.
1. Personal Data we collect
Personal Data you provide to us
- Account information. To create a Fariq account, you must provide your name and email address and authenticate your account. Without this information, we cannot create or administer your account. You may also choose to provide your gender.
- Content. We collect prompts, messages, files, agent instructions, memories, and other Content you provide.
- Organization and preference information. We collect organization and team names and the runtime and model preferences you provide.
- App connection information. We collect connection identifiers, metadata, permissions, encrypted credentials or authorization tokens, and information you provide through supported app connections that store connection information remotely.
- Communication information. We collect your contact details, the contents of your communications, language preference, and subscription status when you contact us or subscribe to product updates.
Personal Data from your use of Fariq
- Account, membership, and service information. We create account identifiers, account dates, and records of the organizations and teams associated with your account, including roles, access permissions, and service preferences.
- Authentication and log information. We receive login methods, email-verification records, session identifiers, authentication tokens, IP addresses, user-agent strings, request times, and service events when you use our remote services.
- Output and activity information. We receive assistant outputs, tasks, tool calls and results, session and agent activity, and information created to make conversations and memories searchable.
Personal Data stored on your device
- Fariq Browser information. Fariq Browser stores browsing history, cookies and site data placed by third-party websites, cached information, permissions, download records, and autofill information on your device. This information is transmitted to us only when it is included in Content or in a request to use a remote feature.
Personal Data we receive from other sources
- Information provided by other users. We receive information about your team membership, role, or reporting relationship when another organization member configures those relationships in Fariq.
- AI providers, connected services, and other resources. We receive Personal Data returned by AI providers and connected services and from files, pages, repositories, and other resources you ask Fariq to access. Some of those resources may be publicly available.
2. How we use Personal Data
We use Personal Data for the following purposes:
- To provide and maintain the Services, including administering accounts and organizations, processing Content with AI providers, providing search, and performing requested actions through connected services.
- To analyze product telemetry that has been aggregated or de-identified so it cannot reasonably be linked to a user or organization or reconstructed into Content.
- To personalize the Services using information such as your preferences and any gender you choose to provide.
- To provide support, respond to requests, and send service communications.
- To protect accounts and the Services, prevent abuse and unauthorized access, investigate incidents, and maintain reliability.
- To comply with legal obligations and lawful process and to establish, exercise, or defend legal claims.
- To send product-update marketing with your consent.
3. Disclosure of Personal Data
We disclose Personal Data in the following circumstances:
- Vendors and service providers. We disclose Personal Data to vendors and service providers that help us operate the Services, including providers of cloud hosting, databases, storage, email delivery, search, encryption, logging, and infrastructure services.
- AI providers and connected services you connect. Providers and services you connect through your own account receive the Personal Data needed to process your requests under your agreement with them. Information returned by those services may become part of Content.
- AI providers and connected services we procure. Providers and services we procure to provide part of Fariq receive the Personal Data needed to perform that function as our vendors or subprocessors.
- Other members of your organization. Other members of your organization may access Content associated with the organization. App connections may be accessed by their owner and by people who have been granted access.
- Public authorities and other third parties. We disclose Personal Data when required by law or lawful process or when necessary to establish, exercise, or defend legal claims, including to public authorities, professional advisers, courts, and counterparties.
4. Retention
We keep Personal Data for as long as reasonably necessary to fulfill the purposes described in this Policy. When we no longer require it, we and our service providers delete it or convert it into a form that no longer identifies you, unless applicable law permits or requires continued retention.
You may request deletion of your Personal Data by emailing contact@fariq.ai.
We retain remote API-access, application, and conversation-indexing logs for 30 days. Our production-database backup retention period is one day. Personal Data deleted from the production database may remain in encrypted automated backups until it leaves that retention period.
We keep authentication and verification records for as long as needed to operate and protect accounts. We keep support communications for as long as needed to respond and maintain appropriate records. We keep marketing subscription information until you withdraw consent and retain suppression records as needed to honor your choice.
Other retention periods depend on the type and sensitivity of the Personal Data, why we process it, the potential harm from unauthorized use or disclosure, and applicable legal requirements.
5. Data controls
The Services provide controls for managing certain Personal Data:
- You can review, edit, and delete saved memories in Fariq.
- You can disconnect app connections and revoke access granted to them.
- You can unsubscribe from marketing using the link in a marketing email.
- You can request access to, correction of, or deletion of Personal Data by emailing
contact@fariq.ai.
6. Your rights
Depending on applicable law, you may request access to, correction of, deletion of, restriction of, or portability of your Personal Data.
You may object at any time to processing based on legitimate interests. You may object at any time to direct marketing, and we will stop processing your Personal Data for that purpose.
When processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You may exercise these rights using the contact details below.
You may lodge a complaint with the data protection authority where you live or work or where an alleged infringement occurred.
7. Children
The Services are intended only for people who are at least 18 years old. We do not knowingly collect Personal Data from anyone under 18.
If you believe that a person under 18 has provided Personal Data to us, email contact@fariq.ai. We will investigate and, where appropriate, delete the Personal Data.
8. Security
We use technical and organizational safeguards designed to protect Personal Data against loss, misuse, and unauthorized access, disclosure, alteration, or destruction.
No method of transmitting information over the Internet or by email is completely secure, so you should take care when deciding what Personal Data to provide through the Services.
9. Legal bases for processing
Where the GDPR or UK GDPR applies, the following table identifies our purposes, the types of Personal Data processed depending on the activity, and the applicable legal bases.
| Purpose | Types of Personal Data processed, depending on the activity | Legal basis |
|---|---|---|
| Provide and administer the Services, including accounts, organizations, model processing, search, and connected-service actions | Name and email address; authentication and session information; Content; organization, team, runtime, and model preferences; app connection information; account and membership records; output and activity information | Performance of a contract |
| Operate Fariq Browser on your device | Locally stored Fariq Browser information | Performance of a contract |
| Personalize the Services | Gender; Content; organization, team, runtime, and model preferences; relevant membership and activity information | Legitimate interests in providing a personalized service based on information you choose to provide |
| Analyze and maintain the Services | Account, membership, and service information; authentication and log information; aggregated or de-identified product telemetry | Legitimate interests in understanding use of and maintaining the Services |
| Provide account support and necessary service communications | Name and email address; communication information; authentication and session information | Performance of a contract |
| Respond to other inquiries | Communication information | Legitimate interests in responding to inquiries |
| Protect accounts and the Services, prevent abuse and unauthorized access, investigate incidents, and maintain reliability | Account, membership, and service information; authentication and log information; output and activity information | Legitimate interests in security, fraud prevention, and service integrity |
| Comply with law and lawful process | The categories necessary for the relevant obligation or process | Legal obligation |
| Establish, exercise, or defend legal claims | The categories necessary for the relevant claim | Legitimate interests in protecting our legal rights |
| Send product-update marketing | Email address and marketing subscription information | Consent |
10. International transfers
We and our vendors and service providers may process Personal Data outside the jurisdiction where you live. Data protection laws in those jurisdictions may differ from those that apply where you live, but we apply the protections described in this Policy wherever we process Personal Data.
When we transfer Personal Data outside the European Economic Area, Switzerland, or the United Kingdom, we rely on a legally recognized transfer mechanism. Depending on the destination, this may include a European Commission adequacy decision, a United Kingdom adequacy regulation, the European Commission’s Standard Contractual Clauses, or the United Kingdom International Data Transfer Addendum to those clauses.
AI providers and connected services you use through Fariq may process Personal Data in the countries where they operate.
You may request information about safeguards for transfers under our control using the contact details below.
11. California disclosures
The Fariq website counts visits even when a browser sends the legacy “Do Not Track” signal, but its analytics does not use persistent identifiers or track visitors across websites.
Third-party websites may collect Personal Data about your online activities over time and across different websites when you visit them through Fariq Browser. Those websites determine how they respond to browser privacy signals and process Personal Data.
12. Changes to this Privacy Policy
When we make material changes to this Privacy Policy, we will publish the updated Policy and its effective date on this page and provide any additional notice required by applicable law.
13. Controller and contact information
Underbuild LLC is the controller responsible for the Personal Data to which this Privacy Policy applies.
Underbuild LLC’s mailing address is 5830 E 2nd St, Ste 7000 #31643, Casper, Wyoming 82609, United States.
If you have a privacy question or wish to exercise your rights, email contact@fariq.ai or write to the mailing address above.