ferrule

Privacy Policy

Effective date: April 21, 2026

Ferrule ("we", "us", "our") operates a multi-tenant dual-protocol gateway (MCP + REST) that connects your third-party service accounts to AI assistants and HTTP-capable clients, together with a platform layer for stored prompts, role-based access control, and audit logging. This Privacy Policy describes what data we collect, how we use it, the legal bases for processing, and your rights.

1. Definitions

2. Information We Collect

2.1 Account Information

When you create a Ferrule account, we collect your email address and a hashed password. If you enable multi-factor authentication, we store TOTP secrets and/or WebAuthn credential identifiers. If you create or join an organization, we collect the organization name and your role within it.

2.2 OAuth Tokens

When you connect a third-party integration (e.g., PracticePanther, Lawmatics, Zoom Phone, Zoom Users, CallRail, QuickBooks Online, Slack, Google Search Console, Google Analytics, Notion, Google Drive, Google Calendar, Google Docs, Google Sheets, Box), we store the OAuth access and refresh tokens required to call those APIs on your behalf. All tokens are encrypted at rest using AES-256-GCM. Tokens are never logged or exposed in plaintext.

2.3 API Keys

If you generate a Ferrule API key for programmatic access, we store a SHA-256 hash of the key. The plaintext key is shown once at creation and is never stored.

2.4 Stored Prompts and Role Definitions

If you use the platform layer, we store the prompts, role definitions, and other configuration that you or your organization members create. Stored prompts are associated with your organization and are visible to members of that organization according to the roles you assign.

2.5 Usage Data and Audit Log

As you use the Service, we automatically collect Usage Data including IP addresses, user-agent strings, request timestamps, tool-call metadata, and similar signals. The Service's audit log records authentication events, tool calls, and configuration changes along with the actor, timestamp, category, IP address, and relevant metadata. Usage Data and audit log entries are used to operate, secure, and debug the Service and to provide organization administrators visibility into activity within their organization.

2.6 Third-Party Data Accessed via Integrations

Ferrule acts as a pass-through gateway. When an AI assistant or REST client calls a tool through Ferrule, we forward the request to the connected service and return the response. We do not persist, index, or cache the data returned by third-party APIs beyond the duration of the request.

2.7 Website Analytics (ferrule.io)

The ferrule.io website no longer uses analytics of any kind. Google Analytics, the consent banner, and the ferrule-consent cookie were all removed. The site sets no cookies, loads no third-party scripts, and makes no requests to any external service. If you still have a ferrule-consent, _ga, or _ga_* cookie stored from a previous visit, it is no longer read or written by us and can be cleared in your browser.

2.8 Sensitive Data and Children

We do not intentionally collect special categories of sensitive personal data (such as health, biometric, or precise location data) through the Service. The Service is not directed to children under 18 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

3. QuickBooks Online Integration

The Ferrule QuickBooks Online integration provides read-only access through 67 tools covering find, get, and report operations. These tools access data including but not limited to:

No create, update, or delete operations are performed. Ferrule does not modify your QuickBooks data.

4. Google API Integrations

Ferrule integrates with the following Google services via OAuth:

Google Drive, Google Calendar, Google Docs, and Google Sheets are personal-scope integrations — they access data associated with the authenticated user's Google account only, not organization-wide data.

Ferrule accesses Google user data only to provide and improve the Ferrule gateway service. Ferrule does not use Google user data for any other purpose, and specifically does not use it to develop, improve, or train generalized artificial intelligence or machine learning models. Ferrule acts as a pass-through and does not persist, cache, or store data returned by Google APIs beyond the duration of the request.

Ferrule's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

5. Box Integration

Ferrule integrates with Box via OAuth. Ferrule accesses your Box account data including:

Box is a personal-scope integration — it accesses data associated with the authenticated user's Box account only.

Ferrule acts as a pass-through and does not persist, cache, or store data returned by the Box API beyond the duration of the request.

6. How We Use Your Information

7. Legal Bases for Processing (EU/UK/EEA)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

8. Data Sharing and Service Providers

We do not sell or rent your personal information or Third-Party Data. Data retrieved through Ferrule is only sent to the AI assistant or client that initiated the request through your authenticated session or API key.

We share limited personal data with vetted service providers that help us operate the Service, including cloud infrastructure, database hosting, email delivery, and error monitoring providers. These providers are bound by contract to use the data only to provide services to Ferrule and to maintain appropriate security controls. A current list of sub-processors is available on request from [email protected].

We may also disclose information if required by law, to comply with a valid legal process, to protect the rights, property, or safety of Ferrule, our users, or the public, or in connection with a merger, acquisition, or sale of assets — in which case we will take reasonable steps to ensure your data remains protected.

We do not transfer or disclose Google user data to third parties for purposes other than providing the Ferrule service. Specifically, Google user data is never used for:

9. International Data Transfers

Ferrule is operated from the United States and processes personal data there. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where required by applicable law (including the GDPR), we rely on appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses with our service providers.

10. Data Security

No system can be guaranteed 100% secure. If a security incident affects your personal data, we will notify you and the appropriate regulators without undue delay in accordance with applicable law (and in any case within 72 hours where required by the GDPR).

11. Data Retention and Deletion

We retain your personal information only for as long as necessary to provide the Service and fulfill the purposes described in this policy:

If you delete your account, all associated data (account information, integrations, API keys, stored prompts, role definitions) is permanently removed, subject to the retention periods above. You may request deletion of your data at any time by contacting [email protected].

12. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before responding and will respond within 30 days (or inform you of any extension required to do so).

13. California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) provides you with specific rights regarding your personal information, including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of the "sale" or "sharing" of personal information as defined under that law. Ferrule does not sell or share your personal information for cross-context behavioral advertising or otherwise. To exercise your California rights, contact [email protected]. You may designate an authorized agent to make a request on your behalf, and we will not discriminate against you for exercising any of these rights.

14. Do Not Track

The marketing site at ferrule.io respects the Global Privacy Control (GPC) signal where applicable. In addition, because we do not sell or share personal information, the distinctions Do Not Track signals were designed to express do not apply to our processing. See Section 2.7 for details on how analytics cookies are controlled through our consent banner.

15. Automated Decision-Making

Ferrule does not make decisions that produce legal or similarly significant effects about you based solely on automated processing.

16. Third-Party Links

The Service may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email and update the "Effective date" above.

18. Contact

If you have questions about this Privacy Policy or wish to exercise any right under it, contact us at [email protected].