Frey · Privacy
What Frey sees, stores, and forgets.
Last updated 15 August 2026 · Frey is a product of Freydom UG (haftungsbeschränkt), Frankfurt am Main. Questions: info@freydom.app.
Who we are
Frey is operated by Freydom UG (haftungsbeschränkt), Frankfurt am Main, Germany. The data controller for the purposes of the DSGVO/GDPR is Freydom UG. Our Impressum and full Datenschutzerklärung are linked at the foot of every Freydom property.
What we access
When you connect a Google or Microsoft account, Frey requests:
- Google Calendar — event titles, times, attendees, locations, and free/busy, to brief you on your day and prep meetings. Frey can also add an event or time-block when you ask it to, with no attendees, so no invitations are ever sent to anyone.
- Gmail — message subjects, senders, bodies, and your contact directory, to triage and summarise. By default Frey only reads and can save a draft to your Drafts folder when you ask. Two actions are off until you switch them on in Preferences: Send (Frey sends a reply it drafted, only after you read the full email and confirm) and Triage (Frey archives a thread or marks it read when you ask). Both always ask first, are written to your activity log, and Frey never deletes mail or moves anything to Trash.
- Outlook and Microsoft 365 mail — the matching Microsoft entitlement for reading, organising, and saving drafts. Sending and triage use the same off-by-default Preferences switches, confirmation step, limits, and activity log as Gmail. Frey never deletes Microsoft mail or moves it to Deleted Items.
- Microsoft Calendar — the matching calendar entitlement for reading events and adding a personal block when you ask. Frey-created blocks have no attendees, so Frey does not send invitations.
How it's stored
Your Google and Microsoft OAuth tokens are encrypted at rest with AES-256-GCM, under a key separate from every other secret in our system. We never see or store your Google or Microsoft password. Message bodies and event details are processed in the moment to answer your request and generate your briefing; they are not retainedunless you explicitly save (“keep”) an item. Your chat history with Frey is stored per-account so conversations stay continuous. Personal notes and files you deliberately attach to them are retained until you remove the attachment, delete the note, or delete your account. Attachment bytes and their bounded searchable text context are encrypted at rest with AES-256-GCM and are always scoped to the owning account and note.
One deliberate exception, because it powers the Spend view: when Frey scans your receipt and invoice emails, it stores the extracted facts only — vendor, amount, currency, date, billing cadence — never the email itself. Spend is temporarily paused: no receipt scanning runs and no new entries are added. Anything collected before the pause is deleted with your account, or sooner on request at info@freydom.app. Frey never connects to a bank.
One deliberate exception, because it powers the Spend view: when Frey scans your receipt and invoice emails, it stores the extracted facts only — vendor, amount, currency, date, billing cadence — never the email itself. Spend is temporarily paused: no receipt scanning runs and no new entries are added. Anything collected before the pause is deleted with your account, or sooner on request at info@freydom.app. Frey never connects to a bank.
Who processes it
To deliver the product we share the minimum necessary with:
- Google — the source of your calendar + mail data (your own accounts).
- Microsoft — the source of Outlook and Microsoft 365 mail and calendar data from accounts you choose to connect.
- Google (Gemini API) — the model that reads the relevant snippet to answer you, transcribes audio when you choose dictation in the iPhone app, and creates temporary read-aloud audio when you request it. Dictation audio and generated speech are processed for that request and are not retained by Frey. Google states paid Gemini API data is not used to train its models.
- Apple — iOS in-app purchase processing and signed subscription-status events. Frey stores Apple's transaction identifiers, product, status, and expiry date to provide access; we never receive your full card details.
- Stripe — web payment processing. We never see or store your card details.
- Resend / Amazon SES — transactional email (receipts, account notices).
- Google Ads and X Ads — optional, consent-gated website measurement used only to attribute visits and registrations to advertisements. We do not send either provider your account email or private Frey content.
- Hetzner — EU (Germany) hosting. Your data stays in the EU.
Optional advertising measurement
On Frey's website, the Google Ads and X Ads tags are off by default. If you choose “Allow measurement”, Google and X may use cookies and browser signals to tell us whether an advertisement led to a visit or registration. We do not send either provider your Frey inbox, calendar, meeting notes, documents, prompts, account email, name, or phone number for this purpose. The legal basis is your consent under Art. 6(1)(a) GDPR. Refusing has no effect on Frey, and you can change the choice here at any time.
Current choice: measurement off.
First-party service measurement
Frey keeps privacy-minimised aggregate countersfor the steps needed to understand whether the service works: for example, landing viewed, signup opened, account created, mailbox connected, checkout started, and subscription started. An event is added directly to a daily total. We do not put your name, email address, IP address, browser fingerprint, message content, full referrer URL, or URL query string in this ledger, and it cannot reconstruct an individual browsing journey. Campaign labels and the referring site's hostname may be counted so we can compare our own outreach. Short-lived hashed retry receipts prevent the same technical event being counted twice and are deleted after seven days. This operational measurement is separate from the optional Google Ads and X Ads tags above.
Google user data · Limited Use
Frey's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Because Gmail is a Google Workspace API, the use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. In concrete terms:
- Google user data is used only to provide the user-facing features described above — briefings, meeting prep, inbox triage, and drafts you explicitly request.
- We do not transfer Google user data to third parties except as necessary to provide these features (the processors listed above), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- We do not use Google user data for advertising of any kind.
- No humans read your Google data except (a) with your explicit consent for a specific item, (b) where necessary for security purposes such as abuse investigation, (c) to comply with applicable law, or (d) after aggregation and anonymisation for internal operations.
- Google user data is never used to train or improve generalised AI or machine-learning models. Snippets are processed transiently through the Gemini API solely to answer your specific request; Google states Gemini API data is not used to train its models.
Your rights (DSGVO Art. 15–21)
- Disconnect any Google or Microsoft account in one click at Connections. We delete the stored encrypted tokens immediately. Google grants are also revoked at Google; Microsoft lets you revoke the grant separately in your Microsoft account or organisation portal.
- Erase everything — delete your account and all data (connections, meetings, chat) permanently, anytime. Contact info@freydom.app or use the in-app delete control.
- Access & portability — request a copy of what Frey holds about you.
- You may also lodge a complaint with your local data-protection authority.
Retention
OAuth tokens persist until you disconnect or delete your account. Chat history persists until you delete it or your account. Personal notes and their attachments persist until you delete the file, note, or account. Dictation clips and read-aloud audio are transient and are not retained by Frey. Anonymous chat counters expire after 24 hours. Aggregate first-party funnel totals are kept as an operational audit record; their non-identifying retry receipts expire after seven days. On account deletion, everything is removed within 30 days (immediately in most cases).
This page describes Frey specifically. It complements, and does not replace, the Freydom UG Datenschutzerklärung. If anything here conflicts with the master policy, the master policy governs. See also our Terms of Service and Impressum.