Privacy Policy
Effective date: July 22, 2026 Last updated: July 22, 2026
This policy explains what information Fewer collects, why we collect it, and what we do with it. We have written it in plain language on purpose. If anything is unclear, email us at privacy@usefewer.com and we will explain it properly.
Fewer ("we", "us", "our") operates usefewer.com and the Fewer service.
The short version
- Fewer helps companies find and remove wasted software spend and coordination overhead. To do that, we analyse data from business systems that your company chooses to connect — never anything we take without authorization.
- We collect very little about you directly: your name, work email, and sign-in details.
- We use a small number of carefully chosen service providers (listed below). We tell you exactly who they are and what they do.
- We do not sell your data. We do not run advertising. We do not use your data to train AI models. Our AI providers are contractually barred from training on it too.
- Employee information we see through your company's connected systems is processed on your company's instructions. Your company stays in control of it.
1. Who this policy covers
Two groups of people:
- Users — people who sign in to Fewer, usually finance, operations, or IT staff at a customer company.
- Employees of our customers — people whose information appears in the business systems a customer connects (for example, a staff directory showing who holds a software license). These people never interact with Fewer directly.
For users and website visitors, Fewer decides how the data is handled — in privacy-law terms we are the "business" or "controller". For employees of our customers, the customer decides and we act only on their instructions — we are their "service provider" or "processor". If you are an employee of a Fewer customer and have questions about your information, your employer is the right first contact; we will support them in answering you.
2. Information we collect
Directly from you
- Account details: your name, work email address, and the organization you belong to. Sign-in is handled by Clerk, our authentication provider — we never see or store your password.
- Things you do in Fewer: the reviews, approvals, and decisions you record. Keeping this trail is a feature — it is your audit record of what was changed and why.
- Messages you send us, for example support requests.
From systems your company connects
Fewer connects to a company's existing business systems, and the list of systems we support grows over time. A connection is only ever made after an administrator at your company explicitly authorizes it, and every connection falls into one of these categories:
- Identity and directory systems (for example, Microsoft 365 or Google Workspace): names, work email addresses, which software licenses are assigned to whom, and how recently accounts have signed in. We use this to spot paid licenses nobody is using.
- Calendar and scheduling systems: meeting titles, organizers, attendees, and recurrence patterns. We use this to spot recurring meetings that cost more than they return. Before Fewer changes anything, it saves a complete "before" snapshot so the meeting can be restored.
- Accounting and billing systems: supplier names, invoice amounts, and per-seat software costs.
- Workplace and collaboration tools: subscription and usage signals.
Whatever the specific system, the rule is the same: we collect this data to answer one question — what is this company paying for that it no longer needs — and we deliberately read only what that question requires. Fewer evaluates whether paid tools and capacity are worth keeping. It does not score, rank, or evaluate individual people, and it is not a monitoring or performance tool. Your company's administrators can see which systems are connected at any time, and can disconnect any of them.
Automatically
- Cookies and analytics. We use only what the product needs to work plus a small, privacy-safe measurement layer:
- A sign-in session cookie (so you stay logged in) and a small preference cookie (so we don't repeat the first-run introduction).
- Google Analytics 4 to understand which pages and calls-to-action are working on our marketing site (usefewer.com). It is loaded only after you accept on the consent banner shown on your first visit — if you reject, no analytics cookies are set and no data is sent. We enable IP-anonymization, we do not send Google any personal information (no name, email, or form contents), and we do not use Google Ads features, remarketing, or cross-site advertising signals. You can change your choice at any time using the "Analytics" link in the site footer.
- We use no advertising or ad-targeting cookies of any kind.
- Service logs. Standard technical logs (such as request times and error details) that we use to keep the service running and secure. Our logging pipeline automatically screens out passwords, tokens, and credentials, and logs are deleted on a rotation schedule.
3. How we use information
- To provide the service: finding waste, preparing evidence-backed recommendations, and carrying out the actions your team approves.
- To keep your audit trail: recording who reviewed and approved what.
- To operate, secure, and improve the service, and to fix problems.
- To communicate with you about the service.
That is the whole list. We do not use your information for advertising, we do not build profiles of individuals, and we do not disclose personal information for anyone else's marketing.
4. How AI is used — and its limits
Fewer uses large language models (AI) from Anthropic and OpenAI for one narrow job: turning the evidence we gather into a clear, plain-language recommendation you can review.
The guardrails matter more than the AI:
- The AI only receives a frozen evidence packet — the specific figures and facts relevant to one recommendation. Our system checks each packet before sending and refuses to send anything containing credentials or secrets.
- The AI cannot invent numbers. Every figure in a recommendation must come from the evidence packet, and our system rejects output that breaks this rule.
- The AI is instructed to judge tools and spend, not people, and recommendations are written that way.
- A person at your company approves every action. The AI recommends; humans decide. No AI output changes anything in your systems on its own.
- We use both AI providers under their standard commercial API terms, which means your data is not used to train their models.
5. Who we share information with
We share data only with service providers who help us run Fewer, each doing one specific job, each bound by contract to protect your data and use it only to provide their service to us. Our current providers:
| Provider | What they do | What they handle |
|---|---|---|
| Clerk | Sign-in and account security | Your name, work email, sign-in sessions |
| Contabo | Cloud hosting for our servers | All service data (encrypted) |
| Anthropic and OpenAI | AI-generated recommendation text | Screened evidence packets (see section 4) |
| Sentry | Error monitoring | Technical error reports, screened for credentials |
| Google Analytics 4 | Aggregated marketing-site usage measurement (only if you accept) | Anonymized page views and CTA events — no name, email, or form contents |
- Provider
- Clerk
- What they do
- Sign-in and account security
- What they handle
- Your name, work email, sign-in sessions
- Provider
- Contabo
- What they do
- Cloud hosting for our servers
- What they handle
- All service data (encrypted)
- Provider
- Anthropic and OpenAI
- What they do
- AI-generated recommendation text
- What they handle
- Screened evidence packets (see section 4)
- Provider
- Sentry
- What they do
- Error monitoring
- What they handle
- Technical error reports, screened for credentials
- Provider
- Google Analytics 4
- What they do
- Aggregated marketing-site usage measurement (only if you accept)
- What they handle
- Anonymized page views and CTA events — no name, email, or form contents
As the service grows this list may change — for example, we may change hosting providers. When it does, we will update this policy; the version at this address is always current.
Beyond these providers, we disclose information only if the law requires it, or as part of a business transfer such as a merger (in which case this policy still applies to your data and we will notify you).
We never sell personal information, and we never share it for advertising or cross-context behavioral advertising. Nobody pays us for access to your data.
6. Where your data lives, and how we protect it
Our servers are currently hosted in Singapore. As the service grows we may move hosting to another region or provider; if we do, we will update this policy, and the same protections will apply. Because our customers and providers span countries, data may be transferred internationally — where the law requires it, we use recognized safeguards (such as Standard Contractual Clauses) for those transfers.
Security measures we operate include:
- Encryption of data in transit and of backups at rest.
- Credentials for your connected systems are held in a dedicated encrypted vault — never in our application database, logs, or code.
- Automated screening that blocks secrets and credentials from appearing in logs, error reports, or anything sent to an AI provider.
- Strict separation between customers: your workspace's data is fenced from every other customer's.
- Encrypted off-site backups with routinely tested restores, so we can recover your data if something fails.
- Access to production systems is limited to the small number of people who operate the service, and their actions are logged.
No system is perfectly secure, but if a breach ever affects your personal information, we will notify you and any relevant regulator as the law requires.
7. How long we keep information
- Account and workspace data: for as long as your company's account is active. When an account closes, we delete or anonymize its data within 90 days, except records we must keep for legal reasons.
- Data from connected systems: refreshed while the connection is active; when your company disconnects a system or asks us to, we delete the data from it.
- Audit records (who approved what, and the "before" snapshots that make actions reversible): kept for the life of the account, because their whole purpose is to be a durable record.
- Logs and error reports: deleted on a short rotation schedule.
- Backups: expire automatically on a fixed schedule after deletion from live systems.
8. Your rights and choices
Depending on where you live, privacy laws — such as the California Consumer Privacy Act (CCPA), other US state privacy laws, or the EU GDPR — give you specific rights over your personal information. Whatever applies to you, our practice is the same for everyone: you can ask us to
- See the personal information we hold about you, and get a copy in a portable format.
- Correct it if it is wrong.
- Delete it.
- Limit how we use it, or object to a particular use.
Email privacy@usefewer.com and we will respond within the time the applicable law allows — and in any case within 30 days for straightforward requests. We will never treat you differently for exercising a privacy right. Since we do not sell or share personal information for advertising, there is nothing to opt out of on that front.
If you are an employee of a Fewer customer, we may route your request through your employer, since they control that data — but we will never leave you without an answer. You can also complain to your privacy regulator, though we would appreciate the chance to fix the problem first.
9. Children
Fewer is a workplace tool for business use. It is not directed at children, and we do not knowingly collect information from anyone under 16.
10. Changes to this policy
If we change this policy in a way that matters, we will notify account holders by email and post the new version here with an updated date. The current version always lives at this address.
11. Contact us
If you have any question about your data, ask. Explaining what we do with data is part of the job.