Frey · Privacy
What Frey sees, stores, and forgets.
Last updated 28 May 2026 · Frey is a product of Freydom UG (haftungsbeschränkt) i.G., Frankfurt am Main. Questions: info@freydom.app.
Who we are
Frey is operated by Freydom UG (haftungsbeschränkt) i.G., Frankfurt am Main, Germany. The data controller for the purposes of the DSGVO/GDPR is Freydom UG. Our Impressum and full Datenschutzerklärung are linked at the foot of every Freydom property.
What we access
When you connect a Google account, Frey requests:
- Google Calendar — event titles, times, attendees, locations, and free/busy, to brief you on your day and prep meetings. Frey can also add an event or time-block when you ask it to, with no attendees, so no invitations are ever sent to anyone.
- Gmail — message subjects, senders, bodies, and your contact directory, to triage and summarise. Frey can save a draft to your Drafts folder when you ask — but it never sends, deletes, labels, or moves anything. You review and send every email yourself.
How it's stored
Your Google OAuth tokens are encrypted at rest with AES-256-GCM, under a key separate from every other secret in our system. We never see or store your Google password. Message bodies and event details are processed in the moment to answer your request and generate your briefing; they are not retainedunless you explicitly save (“keep”) an item. Your chat history with Frey is stored per-account so conversations stay continuous.
One deliberate exception, because it powers the Spend view: when Frey scans your receipt and invoice emails, it stores the extracted facts only — vendor, amount, currency, date, billing cadence — never the email itself. You can remove any entry on the Spend page (✕), and the entire ledger is deleted with your account. Frey never connects to a bank.
One deliberate exception, because it powers the Spend view: when Frey scans your receipt and invoice emails, it stores the extracted facts only — vendor, amount, currency, date, billing cadence — never the email itself. You can remove any entry on the Spend page (✕), and the entire ledger is deleted with your account. Frey never connects to a bank.
Who processes it
To deliver the product we share the minimum necessary with:
- Google — the source of your calendar + mail data (your own accounts).
- Google (Gemini API) — the model that reads the relevant snippet to answer you. Google states Gemini API data is not used to train its models.
- Stripe — payment processing. We never see or store your card details.
- Resend / Amazon SES — transactional email (receipts, account notices).
- Hetzner — EU (Germany) hosting. Your data stays in the EU.
Google user data · Limited Use
Frey's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In concrete terms:
- Google user data is used only to provide the user-facing features described above — briefings, meeting prep, inbox triage, and drafts you explicitly request.
- We do not transfer Google user data to third parties except as necessary to provide these features (the processors listed above), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- We do not use Google user data for advertising of any kind.
- No humans read your Google data except (a) with your explicit consent for a specific item, (b) where necessary for security purposes such as abuse investigation, (c) to comply with applicable law, or (d) after aggregation and anonymisation for internal operations.
- Google user data is never used to train or improve generalised AI or machine-learning models. Snippets are processed transiently through the Gemini API solely to answer your specific request; Google states Gemini API data is not used to train its models.
Your rights (DSGVO Art. 15–21)
- Disconnect any Google account in one click at Connections — we revoke the grant with Google immediately and delete the stored tokens.
- Erase everything — delete your account and all data (connections, meetings, chat) permanently, anytime. Contact info@freydom.app or use the in-app delete control.
- Access & portability — request a copy of what Frey holds about you.
- You may also lodge a complaint with your local data-protection authority.
Retention
OAuth tokens persist until you disconnect or delete your account. Chat history persists until you delete it or your account. Anonymous chat counters expire after 24 hours. On account deletion, everything is removed within 30 days (immediately in most cases).
This page describes Frey specifically. It complements, and does not replace, the Freydom UG Datenschutzerklärung. If anything here conflicts with the master policy, the master policy governs. See also our Terms of Service and Impressum.