Legal
Privacy policy
Last updated 20 September 2025. Loggit is a product of FocusFlowAI, LLC
1. Scope
This policy covers this website (focusflowai.app), the Loggit pilot programme, and the Loggit service and dashboard. Where a managed service provider (MSP) connects Loggit to its systems, the MSP is the data controller and FocusFlowAI, LLC acts as processor under a Data Processing Addendum, available on request.
2. What the website collects
- Pilot form: work email, company, PSA, number of technicians, role, submission time and the page you submitted from. We derive country from your IP address for scheduling and do not store the raw IP.
- Contact form: name, email, message.
- Dashboard accounts: email, password hash, display name, role, and the organisation you belong to.
- Server logs: standard request logs retained for up to 30 days for security.
- Cookies: only those strictly necessary to serve pages and keep you signed in. No analytics or advertising cookies, no third-party pixels.
3. What Loggit reads from your systems
Loggit connects server to server, by API, using credentials your administrator creates. Nothing is installed on any technician or client computer.
- From your PSA (ConnectWise PSA, HaloPSA or Autotask): tickets, time entries, notes, schedule entries, agreements and work types, configurations (devices), companies, contacts and members.
- From your remote session tool (ScreenConnect through an extension on your ScreenConnect server; N-able Take Control through its API): the session record your server already keeps: connect and disconnect times, host and machine names, commands run and their output, tools executed, file names transferred, chat messages between technician and end user, and notes typed in the session.
- Passwords, payment card numbers and personal identifiers found in chat or command output are redacted before any language model sees them, and redacted text never appears in a note.
4. What Loggit never collects
- Anything from a technician's or client's computer directly: no agent, no screenshots, no keystrokes, no window titles, no browsing history.
- Email, calendar or chat platforms (Outlook, Microsoft 365, Teams, Slack).
- Session video recordings. Where ScreenConnect keeps a recording, we note that it exists and never open it.
- Per-technician rankings or productivity scores.
5. What Loggit writes
Draft time entries, notes and, where you enable it, suggested tickets are written into your PSA marked as Loggit drafts and not billable. They become billable only when a person approves them in your PSA or in the Loggit dashboard. Every write is tagged, logged in your History, and reversible for 24 hours unless the entry has been invoiced.
6. Use of language models
Notes, answers to questions and summaries are produced by a language model from a structured list of facts drawn from the session record and the ticket. The model runs in your region (AWS Bedrock, United States for US customers), keeps no logs of your content, and is never trained on your data. Every claim in a note is checked against the fact list; anything without a source is removed. Drafts are proposals until a person approves them.
7. Retention
- Pilot form records: until the pilot decision plus six months, or 24 months, whichever is sooner, unless you become a customer.
- Session facts, drafts and the History record: for the life of your subscription plus 90 days, then deleted. Export in CSV or JSON on request.
- Approved time entries live in your PSA and are governed by you.
- On offboarding, all your data is deleted within 30 days and we confirm in writing.
8. Security and isolation
- Each MSP is a separate tenant with its own database schema, row-level security and its own encryption key.
- API credentials are stored in AWS Secrets Manager, encrypted at rest, rotated every 90 days, readable only by your tenant's processing role. No person can read them.
- The PSA API member we ask you to create has the smallest useful scope: time entries create, read and update; tickets read on the boards you choose; agreements, configurations, companies and contacts read. No invoices, no deleting tickets, no writing contacts.
- Dashboard sign-in supports single sign-on with your identity provider and multi-factor authentication.
9. Sub-processors
- Amazon Web Services (hosting, database, secrets and language models, United States).
- Our transactional email provider, for account and pilot email.
10. Your rights
You may ask what we hold about you, ask us to correct or delete it, or withdraw consent to pilot email at any time by replying "unsubscribe" or writing to contact@focusflowai.app. We do not sell personal information. Residents of the EU, UK and California have additional rights under GDPR, UK GDPR and the CCPA/CPRA; we honour them regardless of where you live.
11. Notice to technicians
Loggit reads records your systems already keep about work sessions. MSPs should tell their technicians that session records are used to draft time entries, as required by applicable law. We provide a notice template with every pilot.
12. Contact
FocusFlowAI, LLC · contact@focusflowai.app