Manifesto

Privacy Policy

Effective date: July 22, 2026 Last updated: September 8, 2026

This policy explains what information Fewer collects, why we collect it, and what we do with it. We have written it in plain language on purpose. If anything is unclear, email us at privacy@usefewer.com and we will explain it properly.

Fewer ("we", "us", "our") operates usefewer.com and the Fewer service.


The short version

  • Fewer helps companies find and remove wasted software spend and coordination overhead. To do that, we analyse data from business systems that your company chooses to connect — never anything we take without authorization.
  • We collect very little about you directly: your name, work email, and sign-in details.
  • We use a small number of carefully chosen service providers, each doing one specific job for us. The roles they play are described below, and customers can request the current named list at any time.
  • We do not sell your data. We do not run advertising. We do not use your data to train AI models. Our AI providers are contractually barred from training on it too.
  • Employee information we see through your company's connected systems is processed on your company's instructions. Your company stays in control of it.

1. Who this policy covers

Two groups of people:

  1. Users — people who sign in to Fewer, usually finance, operations, or IT staff at a customer company.
  2. Employees of our customers — people whose information appears in the business systems a customer connects (for example, a staff directory showing who holds a software license). These people never interact with Fewer directly.

For users and website visitors, Fewer decides how the data is handled — in privacy-law terms we are the "business" or "controller". For employees of our customers, the customer decides and we act only on their instructions — we are their "service provider" or "processor". If you are an employee of a Fewer customer and have questions about your information, your employer is the right first contact; we will support them in answering you.

2. Information we collect

Directly from you

  • Account details: your name, work email address, and the organization you belong to. Sign-in is handled by our authentication provider — we never see or store your password.
  • Things you do in Fewer: the reviews, approvals, and decisions you record. Keeping this trail is a feature — it is your audit record of what was changed and why.
  • Messages you send us, for example support requests.
  • Files you send us for a free audit. If you ask for the free audit on our website, you give us a work email address and then upload one or two files exported from your own systems (for example a supplier list from your accounting system, or a license report from Microsoft 365 or Google Workspace). Those files can contain your colleagues' names, work email addresses, and license assignments. We use them for one purpose: to prepare the recommendations we send back to you. The upload link is private to you, the files are stored encrypted, and only the people doing your audit can read them.

From systems your company connects

Fewer connects to a company's existing business systems, and the list of systems we support grows over time. A connection is only ever made after an administrator at your company explicitly authorizes it, and every connection falls into one of these categories:

  • Identity and directory systems (for example, Microsoft 365 or Google Workspace): names, work email addresses, which software licenses are assigned to whom, and how recently accounts have signed in. We use this to spot paid licenses nobody is using.
  • Calendar and scheduling systems: meeting titles, organizers, attendees, and recurrence patterns. We use this to spot recurring meetings that cost more than they return. Before Fewer changes anything, it saves a complete "before" snapshot so the meeting can be restored.
  • Accounting and billing systems: supplier names, invoice amounts, and per-seat software costs.
  • Workplace and collaboration tools: subscription and usage signals.

Whatever the specific system, the rule is the same: we collect this data to answer one question — what is this company paying for that it no longer needs — and we deliberately read only what that question requires. Fewer evaluates whether paid tools and capacity are worth keeping. It does not score, rank, or evaluate individual people, and it is not a monitoring or performance tool. Your company's administrators can see which systems are connected at any time, and can disconnect any of them.

Automatically

  • Cookies. We use only cookies the product needs to work: a sign-in session cookie (so you stay logged in) and a small preference cookie (so we don't repeat the first-run introduction). We use no advertising or analytics tracking cookies, so you won't see a cookie consent banner — there is nothing to consent to.
  • Service logs. Standard technical logs (such as request times and error details) that we use to keep the service running and secure. Our logging pipeline automatically screens out passwords, tokens, and credentials, and logs are deleted on a rotation schedule.

3. How we use information

  • To provide the service: finding waste, preparing evidence-backed recommendations, and carrying out the actions your team approves.
  • To keep your audit trail: recording who reviewed and approved what.
  • To operate, secure, and improve the service, and to fix problems.
  • To communicate with you about the service.

That is the whole list. We do not use your information for advertising, we do not build profiles of individuals, and we do not disclose personal information for anyone else's marketing.

4. How AI is used — and its limits

Fewer uses large language models (AI) from established AI providers for one narrow job: turning the evidence we gather into a clear, plain-language recommendation you can review.

The guardrails matter more than the AI:

  • The AI only receives a frozen evidence packet — the specific figures and facts relevant to one recommendation. Our system checks each packet before sending and refuses to send anything containing credentials or secrets.
  • The AI cannot invent numbers. Every figure in a recommendation must come from the evidence packet, and our system rejects output that breaks this rule.
  • The AI is instructed to judge tools and spend, not people, and recommendations are written that way.
  • A person at your company approves every action. The AI recommends; humans decide. No AI output changes anything in your systems on its own.
  • We use our AI providers under their standard commercial API terms, which means your data is not used to train their models.

5. Who we share information with

We share data only with service providers who help us run Fewer, each doing one specific job, each bound by contract to protect your data and use it only to provide their service to us. The roles they fill:

Role What they handle
Sign-in and account security Your name, work email, sign-in sessions
Cloud hosting for our servers All service data (encrypted)
AI-generated recommendation text Screened evidence packets (see section 4)
Error monitoring Technical error reports, screened for credentials
Encrypted credential storage Connection credentials for your connected systems — system secrets, not personal data

The specific companies filling these roles may change as the service grows, and customers can request the current named list at any time by emailing privacy@usefewer.com. If we add a new role that handles customer data, we will add it to this table before it does.

Beyond these providers, we disclose information only if the law requires it, or as part of a business transfer such as a merger (in which case this policy still applies to your data and we will notify you).

We never sell personal information, and we never share it for advertising or cross-context behavioral advertising. Nobody pays us for access to your data.

6. Where your data lives, and how we protect it

Our servers are currently hosted in Singapore. As the service grows we may move hosting to another region or provider; if we do, we will update this policy, and the same protections will apply. Because our customers and providers span countries, data may be transferred internationally — where the law requires it, we use recognized safeguards (such as Standard Contractual Clauses) for those transfers.

Security measures we operate include:

  • Encryption of data in transit and of backups at rest.
  • Credentials for your connected systems are held in a dedicated encrypted vault — never in our application database, logs, or code.
  • Automated screening that blocks secrets and credentials from appearing in logs, error reports, or anything sent to an AI provider.
  • Strict separation between customers: your workspace's data is fenced from every other customer's.
  • Encrypted off-site backups with routinely tested restores, so we can recover your data if something fails.
  • Access to production systems is limited to the small number of people who operate the service, and their actions are logged.

No system is perfectly secure, but if a breach ever affects your personal information, we will notify you and any relevant regulator as the law requires.

7. How long we keep information

  • Account and workspace data: for as long as your company's account is active. When an account closes, we delete or anonymize its data within 90 days, except records we must keep for legal reasons.
  • Data from connected systems: refreshed while the connection is active. When your company disconnects a system, we immediately stop collecting from it; data already collected stays part of your workspace records and is deleted with the rest of your account data when the account closes.
  • Audit records (who approved what, and the "before" snapshots that make actions reversible): kept for the life of the account, because their whole purpose is to be a durable record.
  • Logs and error reports: deleted on a short rotation schedule.
  • Free-audit files: deleted automatically 30 days after upload, and sooner if the audit closes without your company going ahead. If you do go ahead, the same data is collected again through a proper connection and the rules above apply. Email addresses left on the website form are kept so we can reply, and deleted on request.
  • Backups: expire automatically on a fixed schedule after deletion from live systems.

8. Your rights and choices

Depending on where you live, privacy laws — such as the California Consumer Privacy Act (CCPA), other US state privacy laws, or the EU GDPR — give you specific rights over your personal information. Whatever applies to you, our practice is the same for everyone: you can ask us to

  • See the personal information we hold about you, and get a copy in a portable format.
  • Correct it if it is wrong.
  • Delete it.
  • Limit how we use it, or object to a particular use.

Email privacy@usefewer.com and we will respond within the time the applicable law allows — and in any case within 30 days for straightforward requests. We will never treat you differently for exercising a privacy right. Since we do not sell or share personal information for advertising, there is nothing to opt out of on that front.

If you are an employee of a Fewer customer, we may route your request through your employer, since they control that data — but we will never leave you without an answer. You can also complain to your privacy regulator, though we would appreciate the chance to fix the problem first.

9. Children

Fewer is a workplace tool for business use. It is not directed at children, and we do not knowingly collect information from anyone under 16.

10. Changes to this policy

If we change this policy in a way that matters, we will notify account holders by email and post the new version here with an updated date. The current version always lives at this address.

11. Contact us

Fewer privacy@usefewer.com

If you have any question about your data, ask. Explaining what we do with data is part of the job.

ManifestoPrivacyTermsContact