Skip to content
Fraiwy
Legal

Privacy policy.

Effective and last updated: July 27, 2026

This policy explains what personal data Fraiwy collects, why, who processes it, and the rights you have under the GDPR. The short version is in section 2 — you should be able to understand it in thirty seconds. The rest is the detail behind it.

1. Who we are

Fraiwy (“we”, “us”) operates fraiwy.com — an AI creative studio that gives you access to image, video and audio generation models from multiple providers under one account, operated from Vilnius, Lithuania. The legal entity is being incorporated as [LEGAL_ENTITY], company code [COMPANY_CODE], registered at [REGISTERED_ADDRESS], Lithuania; this page will be updated with the registered details the day they exist.

We are the data controller for the personal data described in this policy. For privacy questions, data-rights requests, or anything else in this document, write to contact@fraiwy.com.

We have not appointed a Data Protection Officer, because our processing does not meet the thresholds in Article 37 GDPR. Requests to contact@fraiwy.com are handled by our team directly.

2. The short version

  • We do not train AI models on your prompts, your uploads or your outputs. We have no training pipeline, and we send your content to a model provider only to produce the result you asked for. Each provider’s own retention and no-training terms are listed, per provider, on our Subprocessors page.
  • Your work is private by default. Nothing you generate is published, shown to other users, or put in a public gallery unless you explicitly publish it — and you can unpublish at any time.
  • You own your outputs. Our licence over your content is limited to what we need to run the service for you.
  • We keep what we need to run the service, bill you correctly and stop abuse — and section 7 says exactly how long we keep each thing.
  • You can export your data or delete your account at any time from your account settings.

3. What we collect

Data you give us:

Data you give us
CategoryExamples
Account dataEmail address, display name, avatar, and your Google/OAuth identifier if you sign in that way. Passwords are handled by our authentication provider (Supabase) — we never see them.
Billing dataPlan, billing period, transaction references and invoice history. Card numbers never reach our servers — Stripe collects and stores them on its own checkout pages.
Creative contentPrompts, reference images, audio and video you upload, generation settings, and the outputs produced — stored in your private library.
Support dataMessages you send us via the contact form or the in-app support messenger, and any attachments.
Communication preferencesNotification settings (for example, whether we email you when a long video or audio generation finishes).

Data we collect automatically:

Data we collect automatically
CategoryExamples
Device and connection dataIP address, browser and OS type, device type and language. The free “try without an account” tool uses your IP address solely to enforce its small daily quota.
Usage dataFeatures used, models invoked, Essence consumed, generation timestamps, error events. Our product analytics (Plausible) is cookieless and aggregated.
Security dataSign-in attempts, session tokens, fraud and abuse signals, rate-limiting counters.
Cookies and similar technologiesSee our Cookie Policy.

What we ask you not to send us. Please do not upload special category data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation — and do not upload identity documents or payment card images. The service is not designed for it and we cannot apply Article 9 safeguards to content we did not expect to receive.

If you upload an image or recording of an identifiable person, you are responsible for having their permission — this is also a condition of our Terms. Tools like face swap process such media solely to perform the edit you requested; we do not use it to identify people or build biometric profiles.

5. Who we share it with

We share personal data only with the categories below, and only as far as needed.

Recipients of personal data
RecipientWhat they getRole
AI model providers — see the live Subprocessors page for every provider by nameThe prompt, uploads and settings for the generation you requested — and only what that generation needsProcessors, bound by data processing terms; retention limited per provider as listed
Stripe Payments Europe, Ltd.Billing data; payment card data collected directly by StripeIndependent controller for card data and fraud prevention; processor for the rest
Cloud hosting and storage (Vercel, Railway, Cloudflare R2, Supabase)Service data at rest and in transitProcessors
Email, support, analytics and error-tracking tooling (Resend, Intercom, Plausible, Sentry)Account data and support data as relevant; analytics is cookieless and aggregatedProcessors
Professional advisers (lawyers, accountants, auditors)Only what is relevantIndependent controllers
AuthoritiesOnly what we are legally required to disclose
A buyer or successor, if Fraiwy is acquired, merged or reorganisedService dataWe will tell you before your data becomes subject to a different privacy policy, and this policy continues to apply until we do

The Subprocessors page lists every processor by name, purpose, location and transfer safeguard. We update it before a new subprocessor starts, and we give 30 days’ notice by email of any addition that affects your creative content, so you can object or leave.

6. Where your data goes

We operate from the EEA, and some of our processors operate outside it — principally in the United States and, for some models you can choose, in China. Your prompt and any reference media go to the provider of the model you pick, so choose your model with this in mind.

Where we transfer personal data outside the EEA, we rely on one of:

  • an adequacy decision under Article 45 GDPR, including the EU–US Data Privacy Framework where the recipient is certified; or
  • the European Commission’s Standard Contractual Clauses under Article 46(2)(c), together with a transfer impact assessment and supplementary measures such as encryption in transit and at rest and minimised retention at the provider.

The current transfer mechanism for each recipient is stated on the Subprocessors page. You can request a copy of the relevant safeguards from contact@fraiwy.com.

7. How long we keep it

Retention schedule
DataRetention
Account dataFor as long as your account is open. Deleting your account starts a 30-day recovery window; when it ends, your account data is permanently purged.
Creative content (prompts, uploads, outputs)Until you delete it, or purged with your account after the 30-day recovery window. Residual copies in encrypted infrastructure backups expire within 90 days of deletion.
Content sent to a model providerOnly for the duration of the request on our side; the provider’s own maximum retention is listed per provider on the Subprocessors page.
Billing records and invoices10 years from the end of the financial year, as required by the Lithuanian Law on Financial Accounting and EU VAT rules. This survives account deletion — we cannot delete it on request.
Security and usage logsUp to 12 months
Support conversationsUp to 24 months from the last message
Content-safety incident recordsUp to 24 months, or longer where needed to defend a legal claim or comply with a reporting obligation
Consent records (cookie choices, withdrawal-waiver confirmations)For as long as the consent is live, plus 3 years as proof of consent

Where we are legally required to keep something, we isolate it from further processing rather than continuing to use it.

8. Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you (Art. 15)
  • Rectification — correct anything inaccurate (Art. 16)
  • Erasure — have your data deleted, where no legal basis requires us to keep it (Art. 17)
  • Restriction — have us pause processing while a dispute is resolved (Art. 18)
  • Portability — receive the data you gave us in a structured, machine-readable format (Art. 20)
  • Object — object to processing based on legitimate interests (Art. 21). You can object to direct marketing at any time and we will always stop.
  • Withdraw consent — at any time, without affecting processing already carried out (Art. 7(3))
  • Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22) — see section 9

How to exercise them. Most of this is self-serve in Account → Settings: export all your data as a machine-readable file, delete individual generations from your library, or delete your account. For anything else, email contact@fraiwy.com.

We respond within one month (Art. 12(3)). If your request is complex, we may extend by two further months and will tell you why within the first month. It is free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse and explain why. We may ask you to confirm your identity, but only where we have a genuine doubt — we will not use identity verification as a way to stall.

9. Automated decisions

We use automated systems to screen prompts for content we are legally prohibited from producing, and to react to payment fraud signals (for example, a card chargeback automatically places a hold on the associated Essence).

These systems can block a generation or, in serious or repeated cases, restrict an account. Where an automated decision has a legal or similarly significant effect on you — such as restricting a paid account — you have the right to:

  • obtain human review of that decision,
  • express your point of view, and
  • contest the decision.

Write to contact@fraiwy.com with the subject line “Automated decision review”. A person, not a model, will look at it. We aim to respond within 5 working days.

We do not use automated decision-making to set your prices, and we do not profile you for advertising.

10. Security

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): encryption in transit (TLS) and at rest, role-based access control, multi-factor step-up authentication for administrative access, webhook signature verification and idempotency on the payment pipeline, audit logging, and production access restricted to a named list of personnel. The full picture — including how to report a vulnerability — is on our security page.

No internet service can promise perfect security. If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the Valstybinė duomenų apsaugos inspekcija (VDAI) within 72 hours (Art. 33) and, where the risk is high, we notify you directly without undue delay (Art. 34).

11. Children

Fraiwy is not for children. You must be 18 or over to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a minor has an account, contact contact@fraiwy.com and we will delete it.

Lithuanian law sets the Article 8 GDPR digital consent age at 14 for information society services generally; we set a higher bar because Fraiwy involves payments, commercial content licensing, and generative tools that need adult judgement.

12. Cookies

See our separate Cookie Policy. In short: strictly necessary cookies run without consent; everything else — currently only the support messenger — runs only if you say yes, and “Reject all” is exactly as easy as “Accept all”. Change your mind any time from the Cookie settings link in the footer.

We honour Global Privacy Control signals as a rejection of all non-essential categories.

13. AI-generated content and transparency

Content you create with Fraiwy is generated by artificial intelligence. In line with Article 50 of the EU AI Act, generated images, video and audio carry machine-readable provenance metadata marking them as AI-generated (the IPTC trainedAlgorithmicMedia digital source type), and where a model provider embeds its own Content Credentials (C2PA) we preserve them untouched — our pipeline never strips provenance metadata. AI-generated content shown on Fraiwy’s public pages is visibly labelled.

If your generation depicts a real, identifiable person, you must disclose that it is AI-generated when you publish it — see our Terms for what this means in practice.

14. Complaints

If you are unhappy with how we handle your data, please tell us first at contact@fraiwy.com — it is usually the fastest fix.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement (Art. 77 GDPR). Our lead supervisory authority is:

Valstybinė duomenų apsaugos inspekcija (VDAI)
L. Sapiegos g. 17, 10312 Vilnius, Lithuania
vdai.lrv.lt

A list of all EEA supervisory authorities is at edpb.europa.eu. For consumer (non-privacy) disputes, see the Refunds & Cancellation policy State Consumer Rights Protection Authority (Valstybinė vartotojų teisių apsaugos tarnyba) handles out-of-court consumer disputes in Lithuania.

15. Changes

We will update this policy as the service changes. For material changes — a new purpose, a new legal basis, a new category of recipient, or a longer retention period — we will email you at least 30 days before they take effect, and we keep the dated changelog at the bottom of this page. Continuing to use Fraiwy after that date means the updated policy applies.

We will never make a material change retroactive to data already collected without a fresh legal basis.

16. Contact

[LEGAL_ENTITY] (Fraiwy, operated from Vilnius, Lithuania)
[REGISTERED_ADDRESS], Lithuania
Company code [COMPANY_CODE] · VAT [VAT_ID]
contact@fraiwy.com

Changelog

  • July 27, 2026Rewrote the policy: legal-basis table, full retention schedule, subprocessor register, automated-decision review rights, AI Act transparency section. Raised the account age to 18.
  • July 5, 2026First version.