Frey · Privacy
What Frey sees, stores, and forgets.
Last updated 28 May 2026 · Frey is a product of Freydom UG (haftungsbeschränkt), Frankfurt am Main. Questions: info@freydom.app.
Who we are
Frey is operated by Freydom UG (haftungsbeschränkt), Frankfurt am Main, Germany. The data controller for the purposes of the DSGVO/GDPR is Freydom UG. Our Impressum and full Datenschutzerklärung are linked at the foot of every Freydom property.
What we access
When you connect a Google account, Frey requests:
- Google Calendar — event titles, times, attendees, locations, and free/busy, to brief you on your day and prep meetings. Frey can also add an event or time-block when you ask it to, with no attendees, so no invitations are ever sent to anyone.
- Gmail — message subjects, senders, bodies, and your contact directory, to triage and summarise. By default Frey only reads and can save a draft to your Drafts folder when you ask. Two actions are off until you switch them on in Preferences: Send (Frey sends a reply it drafted, only after you read the full email and confirm) and Triage (Frey archives a thread or marks it read when you ask). Both always ask first, are written to your activity log, and Frey never deletes mail or moves anything to Trash.
How it's stored
Your Google OAuth tokens are encrypted at rest with AES-256-GCM, under a key separate from every other secret in our system. We never see or store your Google password. Message bodies and event details are processed in the moment to answer your request and generate your briefing; they are not retainedunless you explicitly save (“keep”) an item. Your chat history with Frey is stored per-account so conversations stay continuous.
One deliberate exception, because it powers the Spend view: when Frey scans your receipt and invoice emails, it stores the extracted facts only — vendor, amount, currency, date, billing cadence — never the email itself. Spend is paused during the pilot: no receipt scanning runs and no new entries are added. Anything collected before the pause is deleted with your account, or sooner on request at info@freydom.app. Frey never connects to a bank.
One deliberate exception, because it powers the Spend view: when Frey scans your receipt and invoice emails, it stores the extracted facts only — vendor, amount, currency, date, billing cadence — never the email itself. Spend is paused during the pilot: no receipt scanning runs and no new entries are added. Anything collected before the pause is deleted with your account, or sooner on request at info@freydom.app. Frey never connects to a bank.
Who processes it
To deliver the product we share the minimum necessary with:
- Google — the source of your calendar + mail data (your own accounts).
- Google (Gemini API) — the model that reads the relevant snippet to answer you. Google states Gemini API data is not used to train its models.
- Apple — iOS in-app purchase processing and signed subscription-status events. Frey stores Apple's transaction identifiers, product, status, and expiry date to provide access; we never receive your full card details.
- Stripe — web payment processing. We never see or store your card details.
- Resend / Amazon SES — transactional email (receipts, account notices).
- Hetzner — EU (Germany) hosting. Your data stays in the EU.
Google user data · Limited Use
Frey's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Because Gmail is a Google Workspace API, the use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. In concrete terms:
- Google user data is used only to provide the user-facing features described above — briefings, meeting prep, inbox triage, and drafts you explicitly request.
- We do not transfer Google user data to third parties except as necessary to provide these features (the processors listed above), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- We do not use Google user data for advertising of any kind.
- No humans read your Google data except (a) with your explicit consent for a specific item, (b) where necessary for security purposes such as abuse investigation, (c) to comply with applicable law, or (d) after aggregation and anonymisation for internal operations.
- Google user data is never used to train or improve generalised AI or machine-learning models. Snippets are processed transiently through the Gemini API solely to answer your specific request; Google states Gemini API data is not used to train its models.
Your rights (DSGVO Art. 15–21)
- Disconnect any Google account in one click at Connections — we revoke the grant with Google immediately and delete the stored tokens.
- Erase everything — delete your account and all data (connections, meetings, chat) permanently, anytime. Contact info@freydom.app or use the in-app delete control.
- Access & portability — request a copy of what Frey holds about you.
- You may also lodge a complaint with your local data-protection authority.
Retention
OAuth tokens persist until you disconnect or delete your account. Chat history persists until you delete it or your account. Anonymous chat counters expire after 24 hours. On account deletion, everything is removed within 30 days (immediately in most cases).
This page describes Frey specifically. It complements, and does not replace, the Freydom UG Datenschutzerklärung. If anything here conflicts with the master policy, the master policy governs. See also our Terms of Service and Impressum.