Legal
Privacy Policy
Last updated July 29, 2026
1. Overview
This Privacy Policy describes how FYSA (“FYSA,” “we,” “us,” or “our”) collects, uses, and shares information in connection with the FYSA website, applications, and related services (the “Service”). FYSA provides situational awareness tooling for dual-use and defense-tech business development and capture teams, primarily by organizing and analyzing publicly available information (PAI).
By using the Service, you acknowledge this Policy. If you use the Service on behalf of an organization, that organization is responsible for ensuring your use complies with its own policies and applicable law.
2. Data posture — PAI only
FYSA is built for PAI and other non-controlled commercial information. The Service is not intended to store, process, or transmit:
- Classified national security information
- Controlled Unclassified Information (CUI), including CUI marked or otherwise identified under U.S. government handling requirements
- Federal Contract Information (FCI) that your organization must keep out of commercial SaaS environments
- Export-controlled technical data or technology under ITAR, EAR, or similar regimes, except to the extent such material is already lawfully and publicly available as PAI
- Other government-sensitive or restricted datasets that require FedRAMP Moderate (or higher), DFARS 252.204-7012-covered systems, or equivalent authorized environments
Do not upload, paste, email, or otherwise introduce prohibited categories into FYSA. Customers remain solely responsible for classifying their own data and for preventing introduction of CUI or other restricted information into the Service.
3. Information we collect
Account and authentication data. When you create or access an account, we (and our authentication provider) may process identifiers such as name, work email, phone number used for one-time passcodes, organization membership, and role. Authentication is handled by a third-party identity provider.
Customer workspace content. Content you or your organization submit to the Service—such as company profile details, watchlists, notes, branding assets, campaign drafts, presentation materials, recipient lists you configure for digests, and similar operational inputs.
Publicly available information (PAI). The Service may collect, index, enrich, and display information from public or commercially available sources, including public websites, public government postings, public news, and public social or professional profiles, subject to source terms and applicable law. PAI may include names, titles, affiliations, and other details that appear in public sources. FYSA does not claim those public sources as private personal data of FYSA’s creation.
Usage and technical data. We may collect logs and diagnostics such as IP address, device/browser type, timestamps, feature usage, and error reports needed to operate, secure, and improve the Service.
4. How we use information
We use information to:
- Provide, maintain, and improve the Service
- Authenticate users and administer organizations
- Generate situational awareness, summaries, drafts, and related outputs you request
- Send operational messages you configure (for example, sitrep digests)
- Monitor reliability, prevent abuse, and secure the Service
- Comply with law and enforce our Terms of Service
We do not sell personal information. We do not use customer workspace content to train public foundation models for unrelated third parties. Model providers used to generate outputs process prompts and context as needed to deliver the feature you invoke, subject to their terms and our agreements with them.
6. Retention
We retain account, workspace, and operational data for as long as your organization maintains an account and as reasonably necessary to provide the Service, resolve disputes, enforce agreements, and meet legal obligations. PAI indexes and derived artifacts may be retained or refreshed on schedules tied to product operation. You may request deletion of account data as described below, subject to legal holds and backup cycles.
7. Security
We use administrative, technical, and organizational measures designed to protect information processed by the Service. No method of transmission or storage is fully secure. Because FYSA is a commercial PAI-oriented service and not a FedRAMP-authorized CUI environment, you must not treat it as approved infrastructure for controlled government information.
8. Your choices and rights
Depending on your location and role, you may have rights to access, correct, delete, or export certain personal information, or to object to certain processing. Organization admins control much of the workspace data associated with a tenant. For requests, contact privacy@fysa.ai. We may need to verify your identity and authority before acting on a request.
If you believe public information about you appears in FYSA outputs and you want it reviewed, contact us with sufficient detail to locate the record. We will evaluate requests consistent with law, source availability, and the legitimate interests of customers using PAI for business development awareness.
9. International transfers
The Service may be hosted and accessed from the United States and other jurisdictions where our processors operate. If you access the Service from outside those locations, you consent to processing in those jurisdictions as needed to provide the Service.
10. Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
11. Changes
We may update this Policy from time to time. We will post the updated version with a revised “Last updated” date. Material changes may also be communicated through the Service or by email where appropriate. Continued use after an update constitutes acceptance of the revised Policy.
12. Contact
Privacy questions: privacy@fysa.ai
Related terms: Terms of Service