GFR Toolkit
Privacy Policy
This policy explains what information we collect, why we collect it, and how we protect it when you use the GFR Toolkit.
event Last updated: June 2026
This Privacy Policy applies to the GFR Toolkit web application and related services. By using the application, you acknowledge that your information will be handled as described below.
Information We Collect
We may collect information that you provide directly, information associated with your authenticated account, and usage information generated while you interact with the toolkit.
- Account details, such as name, email address, and authentication profile information.
- Survey or form responses submitted through the toolkit.
- Analytics, dashboard, and chat interactions required to provide application features.
- Technical data, such as browser, device, session, and log information used for security and operations.
Cookie Policy
We use essential cookies to provide our services. These cookies are strictly necessary for the application to function and cannot be switched off in our systems.
- __session: A Flask session cookie used to maintain your authenticated state and chat conversation context. On Firebase Hosting, this is the only cookie forwarded to the backend.
- Auth0: Cookies used by our authentication provider to ensure secure logins and prevent cross-site request forgery.
Most browsers allow you to control cookies through their settings. However, limiting cookies may impact your ability to use certain features of the toolkit.
How We Use Information
We use collected information to provide secure access, personalize the dashboard, generate reports, support analytics workflows, improve reliability, and protect the application from misuse.
Data Sharing
We do not sell personal information. Information may be shared with trusted service providers only when needed to operate authentication, hosting, analytics, data storage, support, or security services.
AI Features
When you use AI-assisted features, prompts and relevant context may be processed by configured model providers to generate responses. Avoid entering sensitive information unless it is necessary for the requested analysis.
Data Retention
We retain information for as long as needed to provide the toolkit, meet operational requirements, comply with legal obligations, resolve disputes, and enforce agreements.
Security
We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, and loss. No internet-based system can be guaranteed to be completely secure.
Your Choices
You may request access, correction, or deletion of personal information where applicable. Certain data may need to be retained when required for security, audit, legal, or legitimate operational purposes.
Contact
For privacy questions or requests, contact the GFR Toolkit administrator through your organization or the support channel provided for the application.