Privacy notice
Draft — final terms before public launch.
This notice explains what personal data fraedi keeps, why, and your rights under UK data protection law (UK GDPR and the Data Protection Act 2018). To reach us, contact support@fraedi.ai.
Who is responsible
FyrmForge Limited, a company registered in England and Wales (company number [company number]), registered office [registered address], is the controller of the personal data described here.
For content an org publishes, we process it on the org's behalf, as its processor, and the org is the controller. A data processing agreement is available on request.
What we collect
- Your account: email address, display name and a hash of your password, or, when you sign in with Google, your Google account id, email and domain. Also your role and the orgs you belong to.
- What you publish: every file of every artifact and each of its revisions, titles, descriptions and folders, and whiteboard shape libraries. These are stored in our database and an object store.
- Share links: a hash of each link's token, a hash of its password if it has one, when it expires and who made it.
- Connections to agents: hashes of your API keys and OAuth access tokens, and when each was last used.
- Invites and waitlist: the email addresses invited or added to the waitlist.
- Sessions: a record of each sign-in, on the server.
- Billing: your Stripe customer and subscription ids and plan. Card details are handled by Stripe and never reach us.
- Server logs: each request's IP address, browser user agent, path (with tokens removed) and result.
Why we use it
- To provide fraedi to you: your account, storing and showing your content, sharing, exports, billing. Lawful basis: contract.
- To keep fraedi secure and working: logs, abuse handling, fraud prevention, fixing faults. Lawful basis: legitimate interests.
- To send service emails you need, such as invites, password resets and email changes. Lawful basis: contract.
- To send optional emails, such as product news, only if you opt in. Lawful basis: consent, which you can withdraw at any time.
- To keep invoices and records the law requires, and to answer lawful requests. Lawful basis: legal obligation.
Cookies
Every cookie here is strictly necessary for the site to work, so we don't ask for consent. There are no analytics or advertising cookies.
- Session: keeps you signed in.
- CSRF: stops other sites from sending forms as you.
- Flash: carries a one-time message, like "Saved.", to the next page.
- Share (
art_…): lets someone who opened a share link view that one artifact, for at most 30 days. - Google sign-in (
g_state): set only while you sign in with Google, to check the answer is for your request.
Who we share it with
We don't sell personal data. We use these providers to run fraedi, and they process data only on our instructions:
- our hosting provider, which runs the servers and database;
- our object storage provider, which stores artifact files;
- SMTP2GO, which sends our email;
- Google, when you choose to sign in with Google;
- Stripe, which takes payments and manages subscriptions.
We may also disclose data when the law requires it, or to protect our users or the service.
Artifacts are content from their authors. They run in a sandboxed frame, but a page can still load files from other sites, such as a script from a CDN, and those sites then see the visitor's IP address.
Where it is stored
Your data is stored in [data region]. If any of it is transferred outside the UK, we rely on UK adequacy regulations or, where there are none, the UK International Data Transfer Agreement (IDTA) or Addendum, or another lawful safeguard.
How long we keep it
- Account data: for the life of the account, then deleted within 30 days.
- Deleted artifacts and revisions: purged, including from backups, within 30 days.
- Server logs: up to 30 days.
- Invoices and billing records: 6 years, as tax law requires.
Your rights
- Access: ask for a copy of the personal data we hold about you.
- Rectification: change your name, email and password in Settings, or ask us to correct anything else.
- Erasure: delete your account in Settings → Delete account. This removes your personal artifacts, folders and shape library, takes you out of your orgs, deletes your API keys and connections, unlinks Google, cancels a paid plan and blanks your email, name and password. Artifacts you made in an org stay with the org. Billing records are kept for 6 years, as tax law requires.
- Portability: every artifact downloads as a .zip from its Details.
- Objection and restriction: object to processing based on legitimate interests, or ask us to limit it.
To use any of these rights, contact support@fraedi.ai. We reply within one month.
You can also complain to the Information Commissioner's Office at ico.org.uk. We'd appreciate the chance to sort it out first.
Security
All traffic is encrypted in transit. Passwords, share-link tokens and passwords, API keys and access tokens are stored only as hashes. Published artifacts run in a sandboxed frame with no access to your fraedi session, so a page can't act as you.
Children
fraedi is not for anyone under 16, and we don't knowingly collect their data. If you think a child has an account, contact us and we will delete it.
Changes to this notice
We may update this notice. For changes that matter, we will email account holders. The current version is always on this page.
See also the terms of service.