Front Products and Services Privacy Notice
Effective as of September 10, 2026. View the prior version here.
This Products and Services Privacy Notice (“Notice”) describes how FrontApp, Inc. ("Front," "we", "us" or "our") handles personal data as instructed by our Customers in the course of providing certain features of our Services to them, including through cookies and similar technologies. We engage in the activities described in this Notice as a service provider to our Customers and subject to our agreements with them.
For information about how Front handles personal data when we determine how and why it is used, such as when we collect personal data through our websites or in connection with our marketing activities, see the Front Privacy Notice and Front Cookie Notice.
As used in this notice, “Customers”, “Services,” “Customer Data” and other capitalized terms used but not otherwise defined in this notice have the meanings given in the Front Software-as-a-Service Agreement.
Index
Click the following links to jump to the section of this Notice for the following products/services:
Front Knowledge Base
Front Knowledge Base product employs the following technologies:
Cookies, which are text files stored on a visitor’s device to uniquely identify the visitor’s browser or to store information or settings in the browser for purposes such as allowing Customers to track and analyze Knowledge Base visitor use, navigation, and other statistical information. You can learn more about cookies and how they can be controlled at www.allaboutcookies.org.
Browser web storage, also known as locally stored objects, functions like cookies but enables the storage of a larger amount of data.
The specific cookies and web technologies used by the Knowledge Base are as follows:
| Name of the cookie/technology | Purpose | Duration of the storage after visit | Who serves the cookie/technology |
|---|---|---|---|
| Cookie: _ga | When Customers choose to integrate their instance of Google Analytics with the Front Knowledge Base, this cookie is set to distinguish one visitor from another, allowing Customers to gain insights into the use of their Knowledge Base functionality. | 13 months | |
| Cookie: _ga_<id> | When Customers choose to integrate their instance of Google Analytics with the Front Knowledge Base, this cookie is set to identify and track an individual session on a visitor’s device. | 13 months | |
| Local storage: _front_kb_visitor_id | When Customers are on a subscription plan that includes the Knowledge Base Analytics feature, JavaScript local storage is used to establish unique visitor IDs, allowing Customers to gain insights into the use of their Knowledge Base functionality. | Persists until cleared by the visitor | Front |
| Cookie: front-customer-portal-session-cookie | When Customers use the Knowledge Base Customer Portal, this cookie is set when a visitor to the Customer Portal verifies their email address to access their past conversations. | 7 days | Front |
Third Party Services
Customers can choose to integrate into their Knowledge Base instance certain Third Party Services that may collect personal data from their Knowledge Base visitors, including through cookies and other technologies. For example, when Customers embed videos from third party platforms such as YouTube, Vimeo, and Loom into their Knowledge Base, these embedded videos may use cookies and other technologies to function and collect personal data for other purposes. For information about how Third Party Services handle personal data and use cookies, consult their respective privacy policies and relevant product documentation.
Visitor choices
Most browsers will let Knowledge Base visitors reject and clear cookies and local storage in their browser settings. Knowledge Base visitors may also use features provided by Google, such as this one, to opt-out of being tracked by its Google Analytics service.
Applicable laws in some jurisdictions may require Customers to inform visitors as to the nature of cookies or other technologies utilized by their Knowledge Base, and in certain circumstances, obtain visitors’ prior consent to the placement and/or use of those cookies or other technologies.
If visitors elect not to activate certain cookies or disable and clear cookies and local storage, certain visitor-facing and Customer-facing features of the Knowledge Base may not function. For example, the cookies/technologies listed in the chart above must be active to enable the corresponding purposes.
Front Chat
Front Chat product employs the following cookies:
Name of the cookie/technology |
Purpose |
Duration of storage after visit |
Who serves the cookie/technology |
Local storage: fcuid |
Distinguishes one chat visitor from another. For Customers on a subscription plan that includes the Chat Analytics feature, supports analytics metrics (chat flows initiated, chat flows completed, average time to completion, and similar). |
Persists until cleared by the visitor |
Front |
Local storage: fccid |
Identifies an individual conversation belonging to a chat visitor, so the visitor can return to it. Also supports the Chat Analytics metrics described above. |
Persists until cleared by the visitor |
Front |
Local storage: frontChatChannelToken |
Holds a token that authenticates the visitor and restricts access to their own conversations over Chat. |
Persists until cleared by the visitor |
Front |
| Local storage: frontChatChannelToken | Holds a token that authenticates the visitor and restricts access to their own conversations over Chat. | Persists until cleared by the visitor | Front |
Local storage: fcgdpr |
Records that the visitor dismissed the Chat consent banner, so it is not shown again. |
Persists until cleared by the visitor |
Front |
| Local storage: fcce | Records that a conversation has ended, and keeps that status in step across the visitor’s open browser tabs. | Persists until cleared by the visitor | Front |
| Local storage: fcaacg | Records that the visitor gave consent to the AI Answers feature. | Persists until cleared by the visitor | Front |
| Local storage: frontChat:store | Stores widget state so a chat survives a page reload: time of last activity, chatbot and proactive message progress, AI query and pre-processing state, and message read status. | Persists until cleared by the visitor | Front |
| Local storage: frontChat:wms | Records that the welcome message was already shown to the visitor. | Persists until cleared by the visitor | Front |
| Local storage: frontChat:hasPlayedStartAnimation | Records that the widget’s opening animation already played. | Persists until cleared by the visitor | Front |
| Session storage: frontChat:tabId | Identifies a single browser tab, so the widget can tell a visitor’s open tabs apart. | Until the browser tab is closed | Front |
| Cookie: _dd_s | Identifies the visitor’s diagnostic logging session, so log events raised by the Chat widget can be grouped together for troubleshooting. | 15 minutes from the visitor’s last activity, 4 hours maximum | Datadog |
| Local storage: bugsnag-anonymous-id | Gives the browser an anonymous identifier, which is attached to crash and error reports raised by the Chat widget. | Perpetual | Bugsnag (SmartBear) |
| Local storage: ably-transport-preference | Records which real-time connection method worked in this browser, so Chat reconnects the same way. | Perpetual | Ably |
| Session storage: ably-connection-recovery | Holds the real-time connection identifier, so an open chat connection can resume after a page reload. | Until the browser tab is closed | Ably |
Most browsers will let Chat users reject and clear cookies in their browser settings. If visitors reject or clear cookies, certain visitor-facing and Customer-facing features of Chat may not function. For example, the cookies listed in the chart above must be active to enable the corresponding purposes.
Certain Third Party Services enabled by Customers may collect personal data from their Front Chat visitors, including through cookies and other technologies. For information about how Third Party Services handle personal data and use cookies, consult their respective privacy policies and relevant product documentation.
Autopilot Resolve
Autopilot Resolve employs the following cookies:
Name of the cookie/technology | Purpose | Duration of storage after visit | Who serves the cookie/technology |
| Local storage: froyo:root-<id> | Stores the visitor’s session so a chat can continue across page reloads, including the session token that authenticates the visitor and restricts access to their own conversations, the associated user ID and email, email verification status, and the visitor’s place in the conversation. | Persists until cleared by the visitor. The session token itself expires on the date it carries. | Front |
| Local storage: front-companion-visitor-id | Set to distinguish a returning visitor from a first-time visitor, so the widget can present the appropriate experience. | Persists until cleared by the visitor | Front |
| Local storage: froyo.locale | Stores the visitor’s chosen display language so it is reapplied on later visits. | Persists until cleared by the visitor | Front |
| Local storage: ably-transport-preference | Set by Ably, which powers the real-time message delivery in the chat, to remember which connection method worked on the visitor’s browser so later sessions connect faster. | Persists until cleared by the visitor | Ably |
| Local storage: bugsnag-anonymous-id | Set by Bugsnag to assign an anonymous identifier to the visitor’s browser, so that repeated application errors can be grouped and diagnosed. | Persists until cleared by the visitor | Bugsnag |
| Cookie: _dd_s | Set by Datadog to group log events from a single visitor session together, for service monitoring and troubleshooting. | 15 minutes, extended on activity | Datadog |
Autopilot Resolve may collect and process limited page-context events as part of delivering the Service. You may also choose to set custom SDK events that we may collect on your behalf. All SDK events are collected and processed for the purpose of providing context to generate relevant responses during an end user’s chat session only. Once a chat session ends, no further collection takes place through these SDK events.
Google User Data Privacy Notice
Certain features of the Services, including our Omnichannel Inbox, Collaboration, and Workflow Automation features, need to process information from users’ Google Workspace applications, such as Gmail and Calendar, which we access through Google’s Workspace APIs (“Google User Data”). Google User Data is part of the Customer Data that we handle on behalf of Customers subject to our Customer agreements. However, our handling of Google User Data is also restricted by Google’s API Terms of Service and Google User Data Policy, including its Limited Use requirements (collectively, “Google Requirements”). We are providing this Google Workspace API Privacy Notice as required by the Google Requirements to explain how we access, use, store, and share Google User Data. Please note that the other sections of this Notice do not apply to Google User Data.
When you choose to use these features, we access your Google User Data with your authorization and we use, store and share Google User Data to enable and improve these features in accordance with the Google Requirements. This means, for example, that we do not use Google Workspace APIs or Google User Data to develop, improve, or train generalized AI and/or ML models. It also means that we do not share, transfer or disclose it to third parties except as follows, and only if allowed by the relevant Customer agreement: (a) to service providers who help us provide our services; (b) for security purposes (for example, investigating abuse); (c) to comply with applicable laws; or (d) as part of a merger, acquisition, or sale of assets of the developer after obtaining explicit prior consent from the user. We do not sell Google User Data.
We use technical, organizational, and physical measures designed to protect the confidentiality, integrity and availability of Google User Data and we retain and delete Google User Data in accordance with Customer instructions. For details on these practices, see the Front Software-as-a-Service Agreement, Front Data Processing Addendum and/or other applicable Customer agreement.
Changes
The technologies we use may change from time to time and this Notice is subject to change at any time.
Questions
If you have any questions about this Notice, please contact us at [email protected].
English version controls
Non-English translations of this Notice are provided for convenience only. In the event of any ambiguity or conflict between translations, the English version is authoritative and controls.
