Skip to content
Friday
Docs
GuidePricingLog in Sign up
Menu
GuidePricingLog inSign up

All documentation

Privacy and Security

2026-09-13

Friday privacy and security begin with separate owner accounts and private client links. Owners sign in to manage projects. Clients use a private project link to read updates, download attachments, and reply without creating an account.

Private links and account controls reduce access, but they do not replace your own judgment about what to post. Use the service only for content you are allowed to share, and send each private link only to intended recipients.

Understand what the service stores

Friday stores the account owner's name, email address, and a password hash. It also stores projects, client email addresses, update text, attachments, replies, email delivery records, and subscription details when billing is enabled.

The service also uses signed session cookies to keep you logged in and protect forms. Short lived rate limit records derived from IP addresses help prevent abuse. Password reset records contain a protected digest of the reset token and expire after one hour.

Cloudflare hosts the app, D1 database, and KV attachment storage. AgentMail processes outgoing email. Dodo Payments processes billing information only when billing is enabled. Payment providers handle card details, and the app does not store card details.

For the governing description of storage, use, providers, retention, and privacy requests, read the current Privacy Policy. The policy takes priority over this practical guide.

Know who can see a project

An owner account can access its own workspace. Each client page uses a long random token in its private link. The service checks that token in the D1 database before returning the project or an attachment.

Anyone who has the current private link can read the project's updates, download its attachments, and reply. A client can forward the link to another person. Client pages do not require the recipient to prove an email address or sign in, so possession of the link is the access method.

Private client pages are marked so search engines should not index them, and public site pages do not link to them. Crawlers can ignore indexing instructions, so the token check remains the access control. Do not publish a private project link on a public page.

Read Client Page before you send a link, and use Client Replies and Comments to understand what a link holder can submit.

Regenerate a link when access should end

Regenerating a project link replaces its token. The old page and its attachment links then return 404, while the new link continues to show the project's existing content.

Use link regeneration when the old link was sent to the wrong person, posted in the wrong place, or may have been copied outside the intended group. After regeneration, send the new link only to people who should retain access.

Regeneration cannot retract an email, erase a downloaded attachment, or remove a copy that someone already made. It only prevents later requests that use the old token. Follow your own response process if private information may already have been copied.

The Managing Projects guide explains regular project controls. The Attachments guide explains the separate owner and client file limits.

Protect your account session

Account sessions use a signed cookie with Secure, HttpOnly, SameSite Lax, and host only settings. An authenticated session lasts up to 12 hours. Owner forms also require a session protection value that helps prevent another site from submitting an action through your browser.

Logging out revokes all older sessions for the account, including a copied session that has not reached its normal expiry. A successful password reset also revokes all older sessions. You will need to log in again in browsers where an older session was active.

Use a unique password with 12 to 128 characters. Do not share your account login with a client as a way to give project access. Send the project's private link instead, because an owner login can reach the full workspace.

Read Password Reset for the one hour, single use reset flow. Use Account Settings for account guidance.

Friday privacy and security limits

Friday is not end to end encrypted. End to end encryption would mean that only the communicating users hold the keys needed to read content. The current service must process project text and files to display pages, provide downloads, and send email.

Do not describe a private link as encryption. The link is a bearer credential, which means anyone holding it can use it. The service uses HTTPS, but it is not end to end encrypted. No guarantee about encryption of stored data is stated here.

The app has no product analytics or advertising trackers. Operational records still exist, including short lived rate limit records derived from IP addresses and email delivery records. Mail providers also process records needed to deliver messages.

Use the Terms for service commitments and limits. Do not rely on this guide as a security certification or an independent penetration test.

Choose suitable content before posting

Review each update and attachment before you post it:

  1. Confirm that the project has the correct client email address.
  2. Remove passwords, access tokens, and credentials from the update body.
  3. Check every attachment for unrelated client or personal information.
  4. Confirm that the private link is going to the intended recipient.
  5. Regenerate the link if its previous distribution is uncertain.

An update email goes to the one client email address stored for the project. Reply notification email goes to the freelancer. Email can be forwarded, copied, or retained outside the service, so keep sensitive detail out of an update when email is not an approved channel for it.

Read Writing an Update for content steps and Email Delivery for delivery behavior.

Export and retain what you need

The account export contains project names, client emails, dates, update bodies, replies, authors, and attachment filenames. It leaves out attachment bytes, private tokens, passwords, and credentials. It is not an import or restore file.

Store the export as private data, because a single file can contain records from several clients. Download important attachment files separately if your retention needs require them. See Exporting Your Data for the complete process.

Project content and email records remain stored for the service until removed. The privacy policy provides the current route for requests to access, correct, or delete information. Do not assume that deleting a downloaded copy changes the service record.

Ask for help without exposing data

Use the Support email link in the site footer when you need help.

Describe the page, action, time, and visible error. Do not send passwords, session cookies, private project links, or full exports. No guaranteed response time or round-the-clock support is promised.

Friday privacy and security depend on careful link sharing, secure account access, and choosing suitable content before posting. For setup help, begin with Getting Started. For common status responses and safe retry steps, read Troubleshooting. The main Guide covers the wider update workflow.

Guide · Blog · Docs · Pricing · Terms · Privacy · Support