Frayme Privacy Policy

Last updated: 18 September 2026

This policy explains how Frayme Ltd ("Frayme", "we") handles personal data in connection with the frayme.ai website, the Frayme dashboard and the Frayme API (together, the "Service"). Frayme Ltd is a company registered in England and Wales (company number 17360941) with its registered office at 15 Carraway Street, Reading, England, RG1 3GB. Capitalised terms that are not defined here have the meaning given in the Frayme Terms of Service.

Contact for anything in this policy: support@frayme.ai.

1. Two roles: what this policy covers

Frayme processes personal data in two different capacities, and it matters which one applies:

2. Personal data we collect as controller

We do not intentionally collect special categories of personal data as controller, and our Terms prohibit customers from sending them to the API.

You are not obliged by law to give us any of this data, but we cannot create an account, issue API keys or bill a plan without a name, an email address and, for paid plans, billing details: providing those is a condition of the contract, and without them we cannot provide the Service. Everything else (for example "Sign in with Google", or opting in to product news) is optional.

3. Why we process it, and on what legal basis

Model training. We do not train, fine-tune or improve models on customer content. Where a generation fails validation, we may create anonymised material derived from it, from which all personal data and all information identifying the customer or any individual has been removed so that it can no longer be linked to them, and we may use that anonymised material to improve and train our models. Customers instruct us to carry out that anonymisation under the DPA. Because we carry out that anonymisation for our own purpose as well as on the customer's instruction, we act as controller for that step and rely on our legitimate interests in improving and securing the Service, assessed against the rights of the individuals concerned; the material stops being personal data once anonymised, and we never attempt to re-identify it. Raw prompts, raw DATA blocks and raw model outputs are never used for training.

We do not sell personal data. We make no decisions about individuals producing legal or similarly significant effects by solely automated means.

4. Who we share it with

We share personal data only with:

5. International transfers

Frayme Ltd is based in the United Kingdom. The overall picture is this: account data, workspace data and stored request content rest in the European Union (Frankfurt); the application, the API and model inference run on United States providers (Vercel and Modal) under standard contractual clauses; the fallback model (Anthropic) is also in the United States and is used only when the primary model's output fails validation.

In more detail:

Transfers from the UK to the EEA are covered by the UK's adequacy regulations for the EEA, and transfers from the EEA to the UK by the European Commission's UK adequacy decisions, which were renewed in December 2025 and which, like all adequacy decisions, are time-limited and subject to ongoing monitoring, review and possible suspension. If an adequacy decision or regulation we rely on is suspended, repealed or allowed to lapse, clause 10.3 of our Data Processing Agreement puts the EU Standard Contractual Clauses and the ICO International Data Transfer Addendum in place automatically, without either party having to take any further step.

Where personal data is transferred to a country without a UK or EU adequacy decision, we put safeguards in place: the EU Standard Contractual Clauses (2021/914), supplemented for UK transfers by the ICO International Data Transfer Addendum, or an adequacy decision including the EU-US Data Privacy Framework and its UK Extension where the recipient is certified. We do not rely on the Data Privacy Framework for Vercel, Modal or Supabase; transfers to those providers rest on the Standard Contractual Clauses and the UK Addendum. You can request details of the safeguards applicable to a given transfer via support@frayme.ai.

For clarity: Frayme has no relationship with OpenAI and sends no data to OpenAI. Our primary model is Frayme's own; the only third-party model provider that receives your requests is Anthropic, on the fallback path. The reason a package with "openai-compatible" in its name appears in our stack is explained on the sub-processors page: it is a protocol adapter to Frayme's own model, nothing more.

6. How long we keep it

The 60-day deletion runs automatically. From the dashboard you can rotate and revoke API keys and cancel your plan. To delete request content early, or to delete your account and workspace, email support@frayme.ai; we complete verified requests within 30 days, subject to the statutory retention and the acceptance records above. On termination, or on a verified request, request content is deleted and the remaining records anonymised within 30 days, except for the abuse signals, billing records and acceptance records listed above.

7. Security

We protect personal data with technical and organisational measures including encryption in transit and at rest, tenant isolation with row-level security, hashed storage of API keys, least-privilege access controls, multi-factor authentication on the production systems we administer, separation of production and development environments, automated dependency scanning, logging retained by our hosting providers for the short periods described in section 6, tested restores, a written incident process and vendor due diligence. Payment card processing is handled entirely by Stripe (PCI DSS certified). A fuller description is in Annex B of our DPA, and a public summary is at frayme.ai/security. No system is perfectly secure; if a breach affects your data, we will notify you and regulators as the law requires.

8. Your rights

Under UK and EU data protection law you have rights, in the circumstances the law provides, to: access your personal data; correct it; delete it; restrict or object to processing (including objecting to processing based on our legitimate interests, and to direct marketing, which we always honour); data portability; and to withdraw consent at any time where processing is based on consent.

To exercise a right, email support@frayme.ai. We respond within one month; for complex or numerous requests we may take up to two further months, and we will tell you within the first month if that happens. We may need to verify your identity. If your data reached Frayme through a customer's application, we will refer your request to that customer, who is the controller of it.

Complaining to us. You have the right to complain to Frayme directly about how we have handled your personal data. Send your complaint to support@frayme.ai with the subject line "Privacy complaint". Any other means or wording is also fine, and you do not need to use a particular template. We will acknowledge your complaint within 30 days of receiving it, begin looking into it without undue delay, carry out an investigation proportionate to what you have raised, and tell you the outcome without undue delay. We keep a record of complaints we receive, how and when we acknowledged them, what we did and how they were resolved.

Complaining to a regulator. You can also complain to the UK Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113) or, if you are in the EEA, to the supervisory authority of the country where you live or work. Under UK law the ICO may ask you to raise your complaint with us first and to give us a reasonable time to respond before it takes the matter up; raising it with us first is usually the quickest way to resolve it. If you are in the EEA you may go to your supervisory authority, or to our EU representative (section 13), directly.

9. Cookies and other browser storage

We do not show a cookie banner, because we use essential cookies only.

The cookies we use are:

Other things stored in your browser are set only by your own action: your light or dark theme choice on frayme.ai, and a flag remembering that you dismissed a notice in the app.

Stripe Checkout and "Sign in with Google" happen on Stripe's and Google's own sites, so any cookies set there are theirs, governed by their policies.

Our site analytics (Vercel Web Analytics, section 2) is cookieless: it stores nothing on your device and reads nothing from it. You can still switch it off (from the footer of frayme.ai, or from the user menu in the app), and we honour the browser's Global Privacy Control and Do Not Track signals. We do not block or treat visitors differently by country. We use no advertising cookies and no third-party analytics cookies. If that changes, we will update this policy and, where required, ask for your consent first.

10. Children

The Service is for business users aged 18 or over. It is not directed at children and we do not knowingly collect children's data. If you believe a child has provided us personal data, contact support@frayme.ai and we will delete it.

11. US state privacy rights

This section applies if you are a resident of California or another US state with a comprehensive privacy law, and it concerns the personal information Frayme handles as a business or controller: account, acceptance, billing, usage, analytics and support data. Personal information that a customer sends to the API is handled under the DPA, where Frayme is a service provider or processor to that customer.

12. Changes to this policy

We will post updates here. For material changes we notify account holders by email or dashboard notice, and we do so before the change takes effect wherever we can.

13. Contact

Frayme Ltd, 15 Carraway Street, Reading, England, RG1 3GB · support@frayme.ai

All privacy matters (requests, questions and complaints) go to support@frayme.ai. Frayme has not appointed a Data Protection Officer; one is not required for our processing.

ICO registration. Frayme Ltd is registered with the UK Information Commissioner's Office, registration number ZC206815.

EU representative. Because we offer the Service to customers in the European Union without being established there, we have appointed DPO Europe GmbH, Auguste-Viktoria-Allee 20A, 13403 Berlin, Germany (HRB 235801), representative@data-privacy-office.eu, as our representative in the EU under Article 27 of the EU GDPR. If you are in the EU, you or your supervisory authority may contact our representative about any matter relating to our processing of your personal data under the EU GDPR. DPO Europe GmbH acts as our Article 27 representative only; it is not our Data Protection Officer. Writing to support@frayme.ai remains the fastest route for requests, questions and complaints.