Frayme Privacy Policy
Last updated: 18 September 2026
This policy explains how Frayme Ltd ("Frayme", "we") handles personal data in connection with the frayme.ai website, the Frayme dashboard and the Frayme API (together, the "Service"). Frayme Ltd is a company registered in England and Wales (company number 17360941) with its registered office at 15 Carraway Street, Reading, England, RG1 3GB. Capitalised terms that are not defined here have the meaning given in the Frayme Terms of Service.
Contact for anything in this policy: support@frayme.ai.
1. Two roles: what this policy covers
Frayme processes personal data in two different capacities, and it matters which one applies:
- Frayme as controller. For the personal data of people who visit our site, create accounts, and operate customer workspaces (sign-up details, records of acceptance of our Terms, billing contacts, dashboard activity, site analytics, support correspondence), Frayme decides how and why the data is processed. That processing is what this policy describes.
- Frayme as processor. Our customers send API requests containing a prompt and, optionally, a DATA block of their own content. That content belongs to the customer and may include personal data about the customer's own end users. Frayme processes it only on the customer's instructions: to compose, validate and return an interface specification, and to hold the request content for up to 60 days in order to provide the Service including idempotent retries, for support and debugging, for investigating abuse, fraud and security incidents, for protecting the integrity of the Service and for attributing cost, after which the content is irreversibly deleted (section 6). That processing is governed by our Data Processing Agreement, not by this policy. If you are an end user of a product built on Frayme, the company operating that product is responsible for your data. Please contact them.
2. Personal data we collect as controller
- Account data: name, email address, password credentials, and workspace details you provide at sign-up. If you choose "Sign in with Google", we receive your name, email address and Google account ID from Google.
- Billing data: billing contact details, plan, transaction history and payment metadata, handled through our payment processor Stripe. Full card details never touch Frayme's systems.
- Acceptance records: when you accept our Terms of Service (when you create a workspace, in the dashboard, or at Stripe Checkout), we record your email address and user account, the workspace, which version of each legal document you were shown, the exact wording you were shown (including your confirmation that you are 18 or over and using Frayme for work or business), and the date and time. Where you accept when you create a workspace or in the dashboard, we also record the IP address and browser user agent the acceptance came from; where you accept at Stripe Checkout we record the Stripe Checkout session reference instead. Acceptance records cannot be edited once written.
- Usage and technical data: API request counts and Generation counts per workspace, latency and error metrics, hashed API-key identifiers, IP addresses and device/browser information from dashboard sessions, and security logs.
- Generation records: for each API request we record the time, the model that answered, token counts and cost, timings, the validation result and, where a generation fails, a technical failure signature (the failure category and the component and property names our validator flagged), together with the workspace, user and API-key identifiers the request was made under. These records carry no request content.
- Request content held for support and debugging: the prompt, the DATA block, each model output for that request and the interface specification we returned are stored in our database (Supabase, Frankfurt, EU) for up to 60 days and are then irreversibly deleted (section 6). Where that content contains personal data about a customer's own users it is customer content, which we hold as that customer's processor under the DPA rather than under this policy. Our tracing provider, Langfuse, receives no request content at all. It receives operational metadata only: timings, token counts, cost, the model name, the validation outcome and the failure category.
- Site analytics: page views on frayme.ai and app.frayme.ai, collected by Vercel Web Analytics. It is cookieless: it stores nothing on your device and does not track you across other websites. Vercel derives a short-lived pseudonymous visitor code from the incoming request on its servers, and that code resets every day; only totals are kept, and Frayme does not store the underlying data. You can switch analytics off (section 9).
- Communications: support requests, abuse reports and other correspondence with us.
We do not intentionally collect special categories of personal data as controller, and our Terms prohibit customers from sending them to the API.
You are not obliged by law to give us any of this data, but we cannot create an account, issue API keys or bill a plan without a name, an email address and, for paid plans, billing details: providing those is a condition of the contract, and without them we cannot provide the Service. Everything else (for example "Sign in with Google", or opting in to product news) is optional.
3. Why we process it, and on what legal basis
- Providing the Service: creating and administering accounts and workspaces, authenticating API keys, metering Generations, handling retries of the same request, providing support. Legal basis: performance of a contract.
- Billing: charging subscriptions through Stripe, invoicing, tax records. Legal bases: performance of a contract; legal obligation.
- Recording the contract: keeping acceptance records so that we can show that the contract with your organisation was formed, on which terms, by whom and when, and so that we can establish, exercise or defend legal claims. Legal basis: legitimate interests (being able to prove what we and our customers agreed).
- Security and abuse prevention: monitoring for fraud, enforcing rate limits and the Acceptable Use Policy, investigating incidents, keeping security logs. Legal basis: legitimate interests (protecting the Service and its customers).
- Service operations and improvement: debugging using generation records and operational trace metadata; attributing cost; understanding how the site and dashboard are used through cookieless, aggregated analytics; improving the Service using aggregated telemetry that contains no request content and identifies no one. Legal basis: legitimate interests (operating, securing and improving the Service).
- Transactional email: account verification, sign-in links, and service, billing and security notices, sent through our authentication provider Supabase and our email delivery provider Resend. Open and click tracking is switched off. Legal basis: performance of a contract.
- Product news and marketing: only where you have opted in, or where permitted for existing customers about similar services (with an unsubscribe in every message). Legal bases: consent; legitimate interests.
- Legal compliance: responding to lawful requests, establishing or defending legal claims. Legal bases: legal obligation; legitimate interests.
Model training. We do not train, fine-tune or improve models on customer content. Where a generation fails validation, we may create anonymised material derived from it, from which all personal data and all information identifying the customer or any individual has been removed so that it can no longer be linked to them, and we may use that anonymised material to improve and train our models. Customers instruct us to carry out that anonymisation under the DPA. Because we carry out that anonymisation for our own purpose as well as on the customer's instruction, we act as controller for that step and rely on our legitimate interests in improving and securing the Service, assessed against the rights of the individuals concerned; the material stops being personal data once anonymised, and we never attempt to re-identify it. Raw prompts, raw DATA blocks and raw model outputs are never used for training.
We do not sell personal data. We make no decisions about individuals producing legal or similarly significant effects by solely automated means.
4. Who we share it with
We share personal data only with:
- Service providers listed at frayme.ai/sub-processors. For the personal data this policy covers (account, acceptance, billing, usage, analytics and support data, for which Frayme is the controller), those providers are Supabase (database, authentication and the sending of transactional email), Vercel (application and API hosting, AI Gateway routing, and cookieless site analytics through Vercel Web Analytics), Stripe (billing), Google (optional sign-in), Resend (email delivery) and Langfuse (operational trace metadata only, never request content). The providers that process customer API request content, namely Supabase (the 60-day store), Modal (Frayme's own model), Vercel (API routing) and, on the fallback path, Anthropic, do so as sub-processors under the DPA rather than under this policy;
- Professional advisers (lawyers, accountants, auditors) under confidentiality;
- Authorities where disclosure is required by law or to protect rights, safety or the integrity of the Service; and
- A successor in the event of a merger, acquisition or asset sale, with notice to you.
5. International transfers
Frayme Ltd is based in the United Kingdom. The overall picture is this: account data, workspace data and stored request content rest in the European Union (Frankfurt); the application, the API and model inference run on United States providers (Vercel and Modal) under standard contractual clauses; the fallback model (Anthropic) is also in the United States and is used only when the primary model's output fails validation.
In more detail:
- Supabase: our database and authentication service. The production project is in the EU (Frankfurt, eu-central-1), and this is where account data, workspace data, hashed API keys, usage counters and the 60-day store of request content rest. Our contracting entity is Supabase Pte. Ltd, which is established outside the EEA; our contract with it includes the EU Standard Contractual Clauses and the UK Addendum, which cover any access to that data from outside the UK or EEA.
- Vercel: application and API hosting, AI Gateway routing and site analytics. We do not pin a region, so Vercel's default applies and functions execute in Washington DC, United States. Vercel, Inc. is a US company. Safeguard: Vercel's Data Processing Agreement, incorporating the EU Standard Contractual Clauses and the UK Addendum.
- Modal: the hosting of Frayme's own model, which processes the prompts and DATA blocks customers send (customer content, governed by the DPA). We do not pin a region. Modal's documentation states that where no region is specified, all inputs to Modal Functions are routed through its servers in Virginia, USA (
us-east) before the container runs, and that containers run wherever Modal has capacity. So Frayme's model runs on Modal's global infrastructure, with requests routed through the United States and global locations. Two points are worth stating plainly, because they carry most of the weight here: Modal's security documentation states that for web endpoints, which is how we call the model, request and response payloads are not stored and are proxied directly to the container; and container logs are retained for 1 day on our current plan. Safeguard: Modal Labs, Inc.'s Data Processing Addendum, which is incorporated by reference into the agreement between Modal Labs, Inc. and its customer, incorporating the EU Standard Contractual Clauses (Modules 1 to 3 as applicable) and, for UK transfers, the ICO International Data Transfer Addendum. - Anthropic: model inference for the minority of requests where our primary model's output fails validation (the "fallback path"), reached through the Vercel AI Gateway. United States. Safeguard: Vercel's Data Processing Agreement, incorporating the EU Standard Contractual Clauses and the UK Addendum, with onward-transfer flow-down to Anthropic as Vercel's sub-processor, and the EU-US Data Privacy Framework and its UK Extension where Anthropic is certified. Anthropic is reached through Vercel's AI Gateway; we hold no separate contract with Anthropic for this path.
- Stripe: billing (US and EU entities).
- Google: only if you use "Sign in with Google".
- Resend: delivery of transactional email.
- Langfuse: operational trace metadata only; it receives no prompt, no DATA block and no model output.
Transfers from the UK to the EEA are covered by the UK's adequacy regulations for the EEA, and transfers from the EEA to the UK by the European Commission's UK adequacy decisions, which were renewed in December 2025 and which, like all adequacy decisions, are time-limited and subject to ongoing monitoring, review and possible suspension. If an adequacy decision or regulation we rely on is suspended, repealed or allowed to lapse, clause 10.3 of our Data Processing Agreement puts the EU Standard Contractual Clauses and the ICO International Data Transfer Addendum in place automatically, without either party having to take any further step.
Where personal data is transferred to a country without a UK or EU adequacy decision, we put safeguards in place: the EU Standard Contractual Clauses (2021/914), supplemented for UK transfers by the ICO International Data Transfer Addendum, or an adequacy decision including the EU-US Data Privacy Framework and its UK Extension where the recipient is certified. We do not rely on the Data Privacy Framework for Vercel, Modal or Supabase; transfers to those providers rest on the Standard Contractual Clauses and the UK Addendum. You can request details of the safeguards applicable to a given transfer via support@frayme.ai.
For clarity: Frayme has no relationship with OpenAI and sends no data to OpenAI. Our primary model is Frayme's own; the only third-party model provider that receives your requests is Anthropic, on the fallback path. The reason a package with "openai-compatible" in its name appears in our stack is explained on the sub-processors page: it is a protocol adapter to Frayme's own model, nothing more.
6. How long we keep it
- Account and workspace data: for the life of your account, then deleted within 30 days of account deletion or a verified erasure request, subject to the statutory billing retention below. Acceptance records are not part of this data and are kept for the period in the next item.
- Acceptance records: for 6 years after the account closes, which is the limitation period for contract claims in England and Wales, and then deleted or anonymised. We keep them for that period even if the account or workspace is deleted, or you ask us to erase your data, because we need them to establish, exercise or defend legal claims; during that period they are held under restricted access and used for nothing else.
- Request content (the prompt, the DATA block, each model output for that request and the returned interface specification): stored for up to 60 days from the request, for the purposes in section 1, and then irreversibly deleted. The content itself is deleted, not masked or hidden. What survives is non-identifying technical signal only: the failure category, the component and property names our validator flagged, timings, token counts, cost, which model answered and the validation result, with the workspace, user, API-key and trace identifiers removed. We describe that as the record being anonymised. Content deleted at 60 days leaves our database backups as those backups roll over, within a further 7 days. Deletion on request or on termination is described in the DPA. We keep request content beyond 60 days only where we must: while we investigate a suspected breach of the Acceptable Use Policy, while a complaint under the IP and Content Complaints Policy is open, where we have referred a matter to law enforcement or a regulator, or where a legal hold or a legal claim requires it. Those records are held under restricted access, only for that purpose, and are deleted when it ends (see clause 8.4 of the DPA and section 7 of the Acceptable Use Policy).
- Usage and billing records (workspace, timestamp, model, token counts, cost and validation result; never request content): for the life of the account, so that we can meter plans and answer billing questions. The billing totals we need for invoices and tax are kept for approximately 6 years, as UK law requires; that statutory duty overrides an erasure request for those records.
- Abuse and fraud signals: hashed API-key identifiers and abuse event records, approximately 12 months.
- Security and platform logs: retained by our hosting providers for a short period, typically 1 to 7 days on our current plans, unless we export a log while investigating a specific incident.
- Support, complaint and other correspondence: for as long as we need it to deal with the matter and with anything arising from it, including any related claim, and then deleted. Records of complaints made under the IP and Content Complaints Policy are kept for 12 months after the complaint is closed.
- Marketing preferences: until you unsubscribe or your account is deleted.
The 60-day deletion runs automatically. From the dashboard you can rotate and revoke API keys and cancel your plan. To delete request content early, or to delete your account and workspace, email support@frayme.ai; we complete verified requests within 30 days, subject to the statutory retention and the acceptance records above. On termination, or on a verified request, request content is deleted and the remaining records anonymised within 30 days, except for the abuse signals, billing records and acceptance records listed above.
7. Security
We protect personal data with technical and organisational measures including encryption in transit and at rest, tenant isolation with row-level security, hashed storage of API keys, least-privilege access controls, multi-factor authentication on the production systems we administer, separation of production and development environments, automated dependency scanning, logging retained by our hosting providers for the short periods described in section 6, tested restores, a written incident process and vendor due diligence. Payment card processing is handled entirely by Stripe (PCI DSS certified). A fuller description is in Annex B of our DPA, and a public summary is at frayme.ai/security. No system is perfectly secure; if a breach affects your data, we will notify you and regulators as the law requires.
8. Your rights
Under UK and EU data protection law you have rights, in the circumstances the law provides, to: access your personal data; correct it; delete it; restrict or object to processing (including objecting to processing based on our legitimate interests, and to direct marketing, which we always honour); data portability; and to withdraw consent at any time where processing is based on consent.
To exercise a right, email support@frayme.ai. We respond within one month; for complex or numerous requests we may take up to two further months, and we will tell you within the first month if that happens. We may need to verify your identity. If your data reached Frayme through a customer's application, we will refer your request to that customer, who is the controller of it.
Complaining to us. You have the right to complain to Frayme directly about how we have handled your personal data. Send your complaint to support@frayme.ai with the subject line "Privacy complaint". Any other means or wording is also fine, and you do not need to use a particular template. We will acknowledge your complaint within 30 days of receiving it, begin looking into it without undue delay, carry out an investigation proportionate to what you have raised, and tell you the outcome without undue delay. We keep a record of complaints we receive, how and when we acknowledged them, what we did and how they were resolved.
Complaining to a regulator. You can also complain to the UK Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113) or, if you are in the EEA, to the supervisory authority of the country where you live or work. Under UK law the ICO may ask you to raise your complaint with us first and to give us a reasonable time to respond before it takes the matter up; raising it with us first is usually the quickest way to resolve it. If you are in the EEA you may go to your supervisory authority, or to our EU representative (section 13), directly.
9. Cookies and other browser storage
We do not show a cookie banner, because we use essential cookies only.
The cookies we use are:
- Login and session cookies set by Supabase in the app, which keep you signed in;
- Security cookies set by Vercel when its firewall challenges a request, to tell a legitimate visitor from an attack; and
- `frayme_analytics_off`, set only if you choose to switch analytics off. It is shared across frayme.ai and app.frayme.ai and kept for a year, so that your choice sticks.
Other things stored in your browser are set only by your own action: your light or dark theme choice on frayme.ai, and a flag remembering that you dismissed a notice in the app.
Stripe Checkout and "Sign in with Google" happen on Stripe's and Google's own sites, so any cookies set there are theirs, governed by their policies.
Our site analytics (Vercel Web Analytics, section 2) is cookieless: it stores nothing on your device and reads nothing from it. You can still switch it off (from the footer of frayme.ai, or from the user menu in the app), and we honour the browser's Global Privacy Control and Do Not Track signals. We do not block or treat visitors differently by country. We use no advertising cookies and no third-party analytics cookies. If that changes, we will update this policy and, where required, ask for your consent first.
10. Children
The Service is for business users aged 18 or over. It is not directed at children and we do not knowingly collect children's data. If you believe a child has provided us personal data, contact support@frayme.ai and we will delete it.
11. US state privacy rights
This section applies if you are a resident of California or another US state with a comprehensive privacy law, and it concerns the personal information Frayme handles as a business or controller: account, acceptance, billing, usage, analytics and support data. Personal information that a customer sends to the API is handled under the DPA, where Frayme is a service provider or processor to that customer.
- What we collect and why: the categories in section 2 of this policy (identifiers, commercial and billing information, internet and device activity, and the content of your correspondence with us), for the purposes in section 3, and for the periods in section 6. We collect it from you, automatically from your device and browser when you use the site or dashboard, and from Stripe and Google where you use them.
- We do not sell or share your personal information, and we do not process it for targeted or cross-context behavioural advertising. We have not done so in the preceding 12 months. We honour the Global Privacy Control as an opt-out preference signal.
- We do not use or disclose sensitive personal information for any purpose other than those permitted without an opt-out.
- Your rights: subject to the law that applies to you, you may request to know what we hold and how we use it, receive a copy or a portable copy, have it corrected, have it deleted, and limit our use of sensitive personal information. You may appeal a decision we make on your request.
- No discrimination: we will not deny you the Service, charge you a different price or give you a lower quality of service because you exercised a right. We do not offer financial incentives for personal information.
- How to exercise a right: email support@frayme.ai. We will verify your identity against the information we hold and respond within the period the applicable law allows. An authorised agent may act for you with written authorisation.
12. Changes to this policy
We will post updates here. For material changes we notify account holders by email or dashboard notice, and we do so before the change takes effect wherever we can.
13. Contact
Frayme Ltd, 15 Carraway Street, Reading, England, RG1 3GB · support@frayme.ai
All privacy matters (requests, questions and complaints) go to support@frayme.ai. Frayme has not appointed a Data Protection Officer; one is not required for our processing.
ICO registration. Frayme Ltd is registered with the UK Information Commissioner's Office, registration number ZC206815.
EU representative. Because we offer the Service to customers in the European Union without being established there, we have appointed DPO Europe GmbH, Auguste-Viktoria-Allee 20A, 13403 Berlin, Germany (HRB 235801), representative@data-privacy-office.eu, as our representative in the EU under Article 27 of the EU GDPR. If you are in the EU, you or your supervisory authority may contact our representative about any matter relating to our processing of your personal data under the EU GDPR. DPO Europe GmbH acts as our Article 27 representative only; it is not our Data Protection Officer. Writing to support@frayme.ai remains the fastest route for requests, questions and complaints.