Privacy policy.
Effective and last updated: July 27, 2026
This policy explains what personal data Fraiwy collects, why, who processes it, and the rights you have under the GDPR. The short version is in section 2 — you should be able to understand it in thirty seconds. The rest is the detail behind it.
1. Who we are
Fraiwy (“we”, “us”) operates fraiwy.com — an AI creative studio that gives you access to image, video and audio generation models from multiple providers under one account, operated from Vilnius, Lithuania. The legal entity is being incorporated as [LEGAL_ENTITY], company code [COMPANY_CODE], registered at [REGISTERED_ADDRESS], Lithuania; this page will be updated with the registered details the day they exist.
We are the data controller for the personal data described in this policy. For privacy questions, data-rights requests, or anything else in this document, write to contact@fraiwy.com.
We have not appointed a Data Protection Officer, because our processing does not meet the thresholds in Article 37 GDPR. Requests to contact@fraiwy.com are handled by our team directly.
2. The short version
- We do not train AI models on your prompts, your uploads or your outputs. We have no training pipeline, and we send your content to a model provider only to produce the result you asked for. Each provider’s own retention and no-training terms are listed, per provider, on our Subprocessors page.
- Your work is private by default. Nothing you generate is published, shown to other users, or put in a public gallery unless you explicitly publish it — and you can unpublish at any time.
- You own your outputs. Our licence over your content is limited to what we need to run the service for you.
- We keep what we need to run the service, bill you correctly and stop abuse — and section 7 says exactly how long we keep each thing.
- You can export your data or delete your account at any time from your account settings.
3. What we collect
Data you give us:
| Category | Examples |
|---|---|
| Account data | Email address, display name, avatar, and your Google/OAuth identifier if you sign in that way. Passwords are handled by our authentication provider (Supabase) — we never see them. |
| Billing data | Plan, billing period, transaction references and invoice history. Card numbers never reach our servers — Stripe collects and stores them on its own checkout pages. |
| Creative content | Prompts, reference images, audio and video you upload, generation settings, and the outputs produced — stored in your private library. |
| Support data | Messages you send us via the contact form or the in-app support messenger, and any attachments. |
| Communication preferences | Notification settings (for example, whether we email you when a long video or audio generation finishes). |
Data we collect automatically:
| Category | Examples |
|---|---|
| Device and connection data | IP address, browser and OS type, device type and language. The free “try without an account” tool uses your IP address solely to enforce its small daily quota. |
| Usage data | Features used, models invoked, Essence consumed, generation timestamps, error events. Our product analytics (Plausible) is cookieless and aggregated. |
| Security data | Sign-in attempts, session tokens, fraud and abuse signals, rate-limiting counters. |
| Cookies and similar technologies | See our Cookie Policy. |
What we ask you not to send us. Please do not upload special category data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation — and do not upload identity documents or payment card images. The service is not designed for it and we cannot apply Article 9 safeguards to content we did not expect to receive.
If you upload an image or recording of an identifiable person, you are responsible for having their permission — this is also a condition of our Terms. Tools like face swap process such media solely to perform the edit you requested; we do not use it to identify people or build biometric profiles.
4. Why we use it, and our legal basis
Article 13(1)(c) GDPR requires us to tell you the legal basis for each purpose. Here it is.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and maintain your account; authenticate you | Account data | Contract — Art. 6(1)(b) |
| Run generations: send your prompt and uploads to the model provider you selected, return and store the output | Creative content, usage data | Contract — Art. 6(1)(b) |
| Meter and deduct Essence; enforce plan limits | Usage data, account data | Contract — Art. 6(1)(b) |
| Take payment, issue invoices, process refunds and withdrawals | Billing data | Contract — Art. 6(1)(b) |
| Retain invoices and accounting records | Billing data | Legal obligation — Art. 6(1)(c) (Lithuanian Law on Financial Accounting: 10 years; EU VAT rules) |
| Provide support and respond to you | Support data, account data | Contract — Art. 6(1)(b) |
| Service emails: receipts, generation-complete notices you opted into, renewal reminders, security alerts, material changes to these terms | Account data, billing data | Contract — Art. 6(1)(b), and legitimate interests — Art. 6(1)(f) — in fair, surprise-free billing |
| Keep the service secure: detect and block fraud, credential abuse, payment abuse and automated scraping | Security data, device data, usage data | Legitimate interests — Art. 6(1)(f): protecting the service, our users and our margins from abuse. We use the minimum data needed and keep it briefly. |
| Content safety: automated screening of prompts against prohibited-use rules (CSAM, non-consensual intimate imagery and other content we are required to prevent) | Creative content, account data | Legal obligation — Art. 6(1)(c) — and legitimate interests — Art. 6(1)(f) — in operating a lawful service. See section 9 on automated decisions. |
| Diagnose faults and improve reliability (error tracking, aggregated cookieless telemetry) | Usage data, device data | Legitimate interests — Art. 6(1)(f) |
| In-app support messenger (sets cookies) | Support data, cookie identifiers | Consent — Art. 6(1)(a), via the cookie banner’s functional category. Withdraw at any time. |
| Marketing emails about Fraiwy features and offers | Account data, communication preferences | Consent — Art. 6(1)(a). We currently send none; if we start, it will be opt-in with one-click unsubscribe. |
| Establish, exercise or defend legal claims; respond to lawful requests from authorities | Whatever is strictly relevant | Legal obligation — Art. 6(1)(c) — or legitimate interests — Art. 6(1)(f) |
What we do not do:
- We do not train, fine-tune, benchmark or evaluate any AI model on your prompts, uploads or outputs. We run no training of our own, and we pass your content to model providers only to produce your result. Each provider’s retention and no-training terms are listed on the Subprocessors page — you can ask us to confirm the current terms for any provider at contact@fraiwy.com.
- We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
- We do not make your content public. Your generations are private to your account unless you explicitly publish them to the community feed — and you can unpublish at any time.
- We do not use your creative content for marketing or public showcases without asking you first, separately, and getting a yes.
6. Where your data goes
We operate from the EEA, and some of our processors operate outside it — principally in the United States and, for some models you can choose, in China. Your prompt and any reference media go to the provider of the model you pick, so choose your model with this in mind.
Where we transfer personal data outside the EEA, we rely on one of:
- an adequacy decision under Article 45 GDPR, including the EU–US Data Privacy Framework where the recipient is certified; or
- the European Commission’s Standard Contractual Clauses under Article 46(2)(c), together with a transfer impact assessment and supplementary measures such as encryption in transit and at rest and minimised retention at the provider.
The current transfer mechanism for each recipient is stated on the Subprocessors page. You can request a copy of the relevant safeguards from contact@fraiwy.com.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | For as long as your account is open. Deleting your account starts a 30-day recovery window; when it ends, your account data is permanently purged. |
| Creative content (prompts, uploads, outputs) | Until you delete it, or purged with your account after the 30-day recovery window. Residual copies in encrypted infrastructure backups expire within 90 days of deletion. |
| Content sent to a model provider | Only for the duration of the request on our side; the provider’s own maximum retention is listed per provider on the Subprocessors page. |
| Billing records and invoices | 10 years from the end of the financial year, as required by the Lithuanian Law on Financial Accounting and EU VAT rules. This survives account deletion — we cannot delete it on request. |
| Security and usage logs | Up to 12 months |
| Support conversations | Up to 24 months from the last message |
| Content-safety incident records | Up to 24 months, or longer where needed to defend a legal claim or comply with a reporting obligation |
| Consent records (cookie choices, withdrawal-waiver confirmations) | For as long as the consent is live, plus 3 years as proof of consent |
Where we are legally required to keep something, we isolate it from further processing rather than continuing to use it.
8. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you (Art. 15)
- Rectification — correct anything inaccurate (Art. 16)
- Erasure — have your data deleted, where no legal basis requires us to keep it (Art. 17)
- Restriction — have us pause processing while a dispute is resolved (Art. 18)
- Portability — receive the data you gave us in a structured, machine-readable format (Art. 20)
- Object — object to processing based on legitimate interests (Art. 21). You can object to direct marketing at any time and we will always stop.
- Withdraw consent — at any time, without affecting processing already carried out (Art. 7(3))
- Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22) — see section 9
How to exercise them. Most of this is self-serve in Account → Settings: export all your data as a machine-readable file, delete individual generations from your library, or delete your account. For anything else, email contact@fraiwy.com.
We respond within one month (Art. 12(3)). If your request is complex, we may extend by two further months and will tell you why within the first month. It is free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse and explain why. We may ask you to confirm your identity, but only where we have a genuine doubt — we will not use identity verification as a way to stall.
9. Automated decisions
We use automated systems to screen prompts for content we are legally prohibited from producing, and to react to payment fraud signals (for example, a card chargeback automatically places a hold on the associated Essence).
These systems can block a generation or, in serious or repeated cases, restrict an account. Where an automated decision has a legal or similarly significant effect on you — such as restricting a paid account — you have the right to:
- obtain human review of that decision,
- express your point of view, and
- contest the decision.
Write to contact@fraiwy.com with the subject line “Automated decision review”. A person, not a model, will look at it. We aim to respond within 5 working days.
We do not use automated decision-making to set your prices, and we do not profile you for advertising.
10. Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): encryption in transit (TLS) and at rest, role-based access control, multi-factor step-up authentication for administrative access, webhook signature verification and idempotency on the payment pipeline, audit logging, and production access restricted to a named list of personnel. The full picture — including how to report a vulnerability — is on our security page.
No internet service can promise perfect security. If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the Valstybinė duomenų apsaugos inspekcija (VDAI) within 72 hours (Art. 33) and, where the risk is high, we notify you directly without undue delay (Art. 34).
11. Children
Fraiwy is not for children. You must be 18 or over to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a minor has an account, contact contact@fraiwy.com and we will delete it.
Lithuanian law sets the Article 8 GDPR digital consent age at 14 for information society services generally; we set a higher bar because Fraiwy involves payments, commercial content licensing, and generative tools that need adult judgement.
13. AI-generated content and transparency
Content you create with Fraiwy is generated by artificial intelligence. In line with Article 50 of the EU AI Act, generated images, video and audio carry machine-readable provenance metadata marking them as AI-generated (the IPTC trainedAlgorithmicMedia digital source type), and where a model provider embeds its own Content Credentials (C2PA) we preserve them untouched — our pipeline never strips provenance metadata. AI-generated content shown on Fraiwy’s public pages is visibly labelled.
If your generation depicts a real, identifiable person, you must disclose that it is AI-generated when you publish it — see our Terms for what this means in practice.
14. Complaints
If you are unhappy with how we handle your data, please tell us first at contact@fraiwy.com — it is usually the fastest fix.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement (Art. 77 GDPR). Our lead supervisory authority is:
A list of all EEA supervisory authorities is at edpb.europa.eu. For consumer (non-privacy) disputes, see the Refunds & Cancellation policy — State Consumer Rights Protection Authority (Valstybinė vartotojų teisių apsaugos tarnyba) handles out-of-court consumer disputes in Lithuania.
15. Changes
We will update this policy as the service changes. For material changes — a new purpose, a new legal basis, a new category of recipient, or a longer retention period — we will email you at least 30 days before they take effect, and we keep the dated changelog at the bottom of this page. Continuing to use Fraiwy after that date means the updated policy applies.
We will never make a material change retroactive to data already collected without a fresh legal basis.
16. Contact
[REGISTERED_ADDRESS], Lithuania
Company code [COMPANY_CODE] · VAT [VAT_ID]
contact@fraiwy.com
Changelog
- July 27, 2026 — Rewrote the policy: legal-basis table, full retention schedule, subprocessor register, automated-decision review rights, AI Act transparency section. Raised the account age to 18.
- July 5, 2026 — First version.