Privacy Policy
Last updated July 22, 2026
This Privacy Policy explains how Fractional Engineer, operated by Lino Agency LLC (“we”), collects and uses information during our early-access validation. We collect only what we need to onboard you, message you, and (if you choose) reserve founding access.
Information we collect
- Your first name, provided during onboarding.
- Your phone number, used to verify your identity and send your first message.
- Optional research signals: the use cases and tools you tell us you’re interested in.
- Your messages with the assistant and related delivery metadata, such as timestamps and delivery status.
- Consent records, including the version of the consent text and the time you agreed.
- Reservation status, if you make a founding-access reservation. Payment card details are handled by our payment processor — we never see or store them.
- Basic acquisition data, such as referral source and campaign parameters.
- Limited technical data used to prevent abuse, such as a hashed IP address.
How we use your information
- To verify your phone number and deliver product messages you consent to.
- To understand which use cases and integrations matter most.
- To process a refundable founding-access reservation if you choose to make one.
Service providers
We rely on a small set of trusted providers, and each receives only the information it needs to do its job:
- Twilio — sends and checks your one-time verification code and delivers account and service text messages (SMS).
- Photon — delivers and receives your conversation with the assistant over iMessage, where available.
- Composio — connects the tools you choose to link (such as Gmail, GitHub, or your calendar) so the assistant can read and, with your confirmation, act on them on your behalf. Only the accounts you explicitly connect are accessed.
- Anthropic (Claude) — the AI that drafts replies, tickets, and summaries from your messages and connected-tool content. Every outbound action is shown to you for confirmation before it is sent.
- Stripe — processes the optional founding-access reservation. Stripe handles your card details directly.
- Cloudflare Turnstile — runs an invisible check during phone verification to protect it from bots and abuse. Your use of it is subject to Cloudflare’s Turnstile Privacy Addendum.
- PostHog — privacy-conscious product analytics, session replay, and error tracking. We use it to understand how the site is used, to replay anonymized sessions for usability and debugging (all form inputs — including your name, phone number, and verification code — are masked and never recorded), and to capture browser console logs and errors so we can fix crashes. We never send phone numbers, verification codes, or message contents to analytics, and you can opt out at any time (contact us, below).
- Google Analytics & Tag Manager — measures how the site is used (pages viewed, referrals, and aggregate usage), loaded through Google Tag Manager. Google sets cookies or similar identifiers for this and processes the data under its Privacy Policy. We never send phone numbers, verification codes, or message contents to it. You can opt out with Google’s opt-out browser add-on.
- Sentry — monitors our backend for errors and crashes so we can fix them. Diagnostic data may include technical context about a failed request; we do not send it phone numbers, verification codes, or message contents.
How we protect it
Phone numbers are encrypted at rest with a key held in our secrets manager; a one-way hash is used only to detect duplicate signups. We never log verification codes or provider secrets, and any retained IP data is hashed rather than stored in the clear. We verify the authenticity (signatures) of messages and events from our providers, and use separate credentials for each environment.
How long we keep it, and how to delete it
We keep your information only as long as we need it. As a guide: raw message payloads are purged after 90 days; if you opt out or abandon signup, your waitlist record is purged within 45 days; consent records are kept for as long as the law requires us to evidence your consent; and payment records are kept as long as tax and financial rules require. You can ask us to access, export, correct, or delete your data at any time by emailing hello@fractional.engineer — we honor verified requests within 30 days. We may retain a limited subset where the law requires it (for example, to handle a payment dispute or to evidence your messaging consent). Replying STOP removes you from messaging promptly, at the latest by the next business day.
Messaging consent
We send product messages only with your consent. Message frequency varies, and message and data rates may apply. Reply STOP to opt out or HELP for help at any time. Marketing messages are sent only if you separately opt in. We do not sell or share your mobile phone number or messaging opt-in with third parties or affiliates for their own marketing or promotional purposes.
Do Not Sell or Share My Personal Information (CCPA/CPRA)
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA). California residents also have the right to know, access, correct, and delete their personal information, and to be free from discrimination for exercising these rights. To exercise any of them, email hello@fractional.engineer.
Your choices
You can opt out of messages at any time by replying STOP, and decline analytics cookies with the banner shown on your first visit. Depending on where you live, you also have the right to access, export, correct (rectify), or delete your data, to object to or restrict certain processing, and to withdraw consent at any time. To exercise any of these, contact us at hello@fractional.engineer — we respond to verified requests within 30 days.
Contact
Questions about this policy? Email hello@fractional.engineer.