Frayme Sub-processors
Last updated: 17 September 2026 · Version 1.0
Frayme Ltd uses the providers below to deliver the Service. This page is the authoritative, current list referenced by our Data Processing Agreement (clause 6 and Annex C) and Privacy Policy. Capitalised terms have the meaning given in the Terms of Service.
Annex C of the DPA reproduces this page as at the DPA's own "Last updated" date. Where the two differ, this page, as updated by a notice given under clause 6.2 of the DPA, is the current list, and it is the list that forms Annex III of the Standard Contractual Clauses incorporated by clause 10.3 of the DPA.
Where your data rests. Request content (the prompt and DATA block you send, every model output for that request, and the interface specification returned to you) is stored in Frayme's database (Supabase, Frankfurt, European Union) for up to 60 days. We keep it to provide the Service including idempotent retries, for support and debugging, to investigate abuse, fraud and security incidents, to protect the integrity of the Service, and to attribute cost. At 60 days the content is irreversibly deleted from that record. What survives is non-identifying technical signal only (the failure category, the component and property names the validator flagged, timings, token counts, cost, which model answered and the validation result), with workspace, user, API-key and trace identifiers removed. Account data and workspace data also rest in the European Union.
Where inference runs. Account data, workspace data and stored request content rest in the European Union (Frankfurt); the application, the API and model inference run on United States providers (Vercel and Modal) under standard contractual clauses; the fallback model (Anthropic) is also in the United States and is used only when the primary model's output fails validation. Frayme's own fine-tuned model runs on Modal's global infrastructure, with requests routed through the United States: no region is pinned, so Modal routes inputs through its servers in Virginia before a container runs the request wherever Modal has capacity. Frayme calls that model through a web endpoint, and Modal's security documentation states that for web endpoints request and response payloads are "Not stored" and are "proxied directly to your container"; container logs are retained for one day on Frayme's current plan.
We do not train on your content. Request content is not used to train, fine-tune or improve models. On your instruction under the DPA we may create anonymised material derived from failed generations, from which all personal data and all information identifying you or any individual has been removed so that it can no longer be linked to you, and use that anonymised material to improve and train our models.
The list is split in two because the two groups do different legal work. Table 1 is the list of sub-processors that handle Customer Personal Data; these are the sub-processors under clause 6 of the DPA, and the ones a customer can object to. Table 2 is the providers that handle Frayme's own operational, account, billing, sign-in, email and website-analytics data, where Frayme is the controller.
Table 1: Sub-processors of Customer Personal Data (request content and generation records)
Clause 6 of the DPA (30 days' notice, objection, pro-rata exit) applies to this table.
| # | Sub-processor | What it does for Frayme | Data it receives | Region | Transfer safeguard |
|---|---|---|---|---|---|
| 1 | Supabase (Supabase Pte. Ltd; production database hosted on AWS eu-central-1, Frankfurt) | Database (the store of request content, and the generation and usage records), authentication, row-level security | Request content (the prompt and DATA block, every model output for the request and the returned interface specification) kept for up to 60 days and then irreversibly deleted, leaving only the non-identifying technical signal described above. Also holds account records, workspace records, hashed API keys and usage counters | European Union (Frankfurt) | Stored and processed in EU data centres; EU Standard Contractual Clauses and the UK Addendum in Supabase's data processing agreement cover any remote access from outside the UK or EEA |
| 2 | Modal (Modal Labs, Inc., United States) | Hosts and serves Frayme's own fine-tuned model (primary inference) | Prompt and DATA block content and the model's output for the request. Frayme calls the model through a web endpoint; Modal's security documentation states that request and response payloads for web endpoints are not stored and are proxied directly to the container. Container logs are retained for one day on Frayme's current plan | United States and global (no region is pinned: requests are routed through Modal's servers in Virginia and containers run where Modal has capacity) | Modal Labs, Inc.'s Data Processing Addendum, which is incorporated by reference into its agreement with Frayme, incorporating the EU Standard Contractual Clauses (Modules 1 to 3 as applicable) and, for UK transfers, the ICO International Data Transfer Addendum |
| 3 | Vercel (Vercel, Inc., United States) | Application and API hosting (serverless functions); AI Gateway routing for the fallback path | Request and response traffic in transit and in function memory; fallback requests routed to Anthropic; Vercel does not durably store request content, and its runtime logs are retained for a short period, typically one to seven days on Frayme's current plan | United States (default region, Washington DC) | Vercel's Data Processing Agreement, incorporating the EU Standard Contractual Clauses and the UK Addendum |
| 4 | Anthropic (Anthropic, PBC, United States), engaged through the Vercel AI Gateway as Vercel's sub-processor | Fallback model inference, used only when the primary model's output fails validation | Prompt and DATA block content, fallback requests only | United States | Vercel's Data Processing Agreement (EU Standard Contractual Clauses and the UK Addendum) with onward-transfer flow-down to Anthropic; EU-US Data Privacy Framework and UK Extension where Anthropic is certified |
Each provider above runs on underlying cloud infrastructure, for example AWS in Frankfurt for Supabase, under its own published sub-processor list, which we review as part of vendor due diligence. Security and platform logs held by these providers are retained by them for a short period, typically one to seven days on our current plans, unless we export them.
How to read the "Transfer safeguard" column
For every transfer of personal data outside the UK and EEA we rely on the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), supplemented for UK transfers by the ICO International Data Transfer Addendum, or on an adequacy decision including the EU-US Data Privacy Framework and UK Extension where the recipient is certified. Where a row says "where the recipient is certified", we rely on the Framework only for so long as that provider is on the Data Privacy Framework list; the Standard Contractual Clauses and the UK Addendum apply in every case. For Supabase, Modal and Vercel we do not rely on the Framework at all: those transfers rest on the Standard Contractual Clauses and the UK Addendum in the provider's data processing agreement.
Table 2: Other service providers (Frayme as controller)
The processing listed in this table does not involve request content. It (and, for Google and Stripe, their role as independent controllers) is described in the Privacy Policy. Supabase and Vercel appear in Table 1 as well, for the different processing described there: in this table Supabase holds the account, workspace, billing-status and usage records for which Frayme is the controller, and Vercel hosts the marketing site and the dashboard and provides Vercel Web Analytics.
| # | Provider | What it does for Frayme | Data it receives | Region | Transfer safeguard |
|---|---|---|---|---|---|
| 1 | Supabase (Supabase Pte. Ltd; production database hosted on AWS eu-central-1, Frankfurt) | Authentication; account and workspace records; hashed API keys; usage and billing counters | Sign-up details, workspace records, hashed API keys, usage counters | European Union (Frankfurt) | Stored and processed in EU data centres; EU Standard Contractual Clauses and the UK Addendum in Supabase's data processing agreement cover any remote access from outside the UK or EEA |
| 2 | Langfuse Cloud (Finto Technologies GmbH, Germany) | Operational tracing, debugging and per-request cost attribution | Metadata only: timings, token counts, cost, model name, validation outcome and failure category, linked to workspace and API-key identifiers. No prompt, no DATA block and no model output is sent to Langfuse | European Union (Langfuse Cloud EU region, Ireland) | Processed and stored in EU data centres by an EU-established provider; no restricted transfer |
| 3 | Vercel (Vercel, Inc., United States) | Website and dashboard hosting; Vercel Web Analytics: cookieless page-view counts for frayme.ai and app.frayme.ai | Page URL, referrer, coarse device and browser information, and a short-lived pseudonymous visitor code that Vercel derives server-side from the incoming request and resets daily. Only totals are kept, and Frayme stores none of the underlying data | United States (default region) | Vercel's Data Processing Agreement, incorporating the EU Standard Contractual Clauses and the UK Addendum |
| 4 | Stripe (Stripe, Inc., United States) | Subscription billing | Billing contact and payment metadata; card details never reach Frayme | United States and European Union | EU Standard Contractual Clauses and the UK Addendum in Stripe's data processing agreement; EU-US Data Privacy Framework and UK Extension where the recipient is certified |
| 5 | Google (Google Ireland Limited for users in the EEA and the UK; Google LLC, United States) | Optional "Sign in with Google": Google acts as an independent identity provider, not as Frayme's processor | Name, email address and Google account ID, sent by Google to Frayme when a user signs in; Frayme sends Google only the sign-in request | Ireland and United States | Google processes sign-in data as an independent controller under its own terms; EU-US Data Privacy Framework and UK Extension where the recipient is certified |
| 6 | Resend (Resend, Inc., United States), used by Supabase Auth as its SMTP provider | Transactional email: sign-up verification, magic links and password resets. Open and click tracking are switched off | Email address and message content | United States | EU Standard Contractual Clauses and the UK Addendum in Resend's data processing agreement; EU-US Data Privacy Framework and UK Extension where the recipient is certified |
You can switch analytics off from the footer of frayme.ai and from the user menu in the app, and we honour the browser's Global Privacy Control and Do Not Track signals.
A note on OpenAI
Frayme sends no data to OpenAI and has no relationship with OpenAI. Frayme's codebase uses a package named @ai-sdk/openai-compatible; this is a protocol adapter used to communicate with Frayme's own model hosted by Modal, which exposes an OpenAI-shaped API. No OpenAI account, key or data flow exists.
Changes to this list
We update this page at least 30 days before a new or replacement sub-processor in Table 1 begins processing Customer Personal Data.
You do not need to subscribe to hear about it. When a Table 1 sub-processor changes we email the workspace owner and the billing contact on record for every account, paid and free, at least 30 days before the change takes effect. Please keep those addresses current in your dashboard: they are the addresses we use for notices under clause 6 of the DPA and for contractual notices under clause 23.2 of the Terms.
If you would like the notice to reach someone else as well (a security reviewer, a procurement contact, a shared inbox), write to support@frayme.ai with the subject "Sub-processor updates" and we will add the address.
Where a sub-processor has to be replaced urgently for security or service-continuity reasons we may give shorter notice, and will explain why; your objection right is unaffected.
Customers may object to a new sub-processor as described in clause 6.2 of the DPA. If no objection is made within the notice period, the sub-processor is treated as authorised.
Changes to the Table 2 providers are made under the Privacy Policy and are recorded in the change log below. They are not subject to the clause 6 objection process, because Frayme rather than you is the controller of that data.
Change log
| Date | Version | Change | Notice sent |
|---|---|---|---|
| 17 September 2026 | 1.0 | First published list | Not applicable |
Questions
support@frayme.ai · Frayme Ltd, 15 Carraway Street, Reading, England, RG1 3GB
Our representative in the EU under Article 27 is DPO Europe GmbH, Auguste-Viktoria-Allee 20A, 13403 Berlin, Germany (representative@data-privacy-office.eu).