Legal
Privacy Policy
Effective date: [EFFECTIVE DATE] · Version: 1.1-draft · Contact: privacy@frugalai.io
FrugalAI ("we," "us") is operated by Jake Bauman d/b/a FrugalAI, [BUSINESS ADDRESS], California, USA. This policy explains what we collect, why, and your choices when you use frugalai.io, the FrugalAI dashboard, and the FrugalAI gateway (together, the "Service").
1. Two roles: controller and processor
- Our own data (we are the controller/business): account, billing, site, support, and marketing data described in Section 2.
- Customer Content (we are the processor/service provider): prompts, responses, and related content that business customers route through the gateway. We process it only on the customer's instructions under our Data Processing Agreement. If your personal data reached us inside a customer's traffic, that customer controls it: contact them, and we will assist them as their processor.
2. What we collect
Account data. Email address, authentication events (we use magic-link sign-in via Supabase; no passwords), organization and team membership, and settings.
Billing data. Plan, subscription state, billing email, and Stripe customer and invoice identifiers. Card details go directly to Stripe; we never receive or store card numbers.
Usage and telemetry. For each gateway request: routing decision and reason, models involved, token counts, estimated cost, cache status, latency, and organization/team/key attribution. The gateway does not record IP addresses, user agents, or device or location data with requests.
Customer Content. By default the gateway stores only a cryptographic hash of each prompt, not its content. Prompt previews and cached prompt text are off by default; if an organization admin enables them, values are scanned and redacted for common secret patterns before storage, and cached responses are stored to serve repeats. Tool-calling and high-temperature requests bypass the cache.
Website data. Cookies and analytics described in the Cookie Policy (Google Analytics 4 and Google Tag Manager, with advertising features disabled and consent controls described there).
Support and communications. Messages you send us, beta release-notification signups, and, if you opt in, marketing email preferences and consent records.
3. Why we process it (purposes and lawful bases)
| Purpose | Data | Lawful basis (GDPR/UK GDPR) |
|---|---|---|
| Provide and operate the Service, route requests, meter spend | Account, usage, Customer Content | Contract performance; customer instructions (Art. 6(1)(b); DPA) |
| Billing and tax | Billing | Contract; legal obligation |
| Security, abuse prevention, incident response | Account, usage, logs | Legitimate interests (protecting the Service and customers) |
| Service analytics and improvement | Telemetry, aggregated/de-identified data | Legitimate interests |
| Website analytics | Cookie data | Consent (EEA/UK); legitimate interests elsewhere |
| Marketing email | Email, consent record | Consent |
| Legal compliance and claims | As needed | Legal obligation; legitimate interests |
We do not use Customer Content to train machine-learning models, and we do not sell personal information or share it for cross-context behavioral advertising.
4. Who receives data
Subprocessors and service providers. Supabase (database, authentication), Vercel (dashboard hosting), Cloudflare (gateway runtime), Stripe (payments), OpenAI (semantic-cache embeddings and sampled quality judging, when enabled), and Resend (transactional email). The current list, what each receives, and our change-notice process live at frugalai.io/subprocessors.
Model providers you configure. Requests are sent to the providers the customer connects (for example OpenAI or Anthropic) under the customer's own agreements with them. Cross-provider disclosure: when semantic caching or quality evaluation is enabled, cacheable prompts (for embeddings) and a small sampled fraction of prompt-and-response pairs (for scoring, on the order of 2% of requests) are sent to the embeddings/judge provider, currently OpenAI, regardless of which provider served the request. Only the hash and score persist from judging. Organizations can turn both flows off at any time in the dashboard (Policies, "Privacy controls").
Legal and safety. We may disclose data to comply with law or valid legal process, or to protect the rights, safety, and security of FrugalAI, our customers, or the public, and we will notify affected customers where lawful.
Business transfers. If the FrugalAI business is transferred to a successor entity (including an entity formed by the founder) or acquired, data transfers with it under this policy, with notice of any material change.
5. Retention
| Data | Retention |
|---|---|
| Account data | Life of account + 30 days after deletion request |
| Request ledger (hashes, routing, costs) | 13 months rolling |
| Cache entries | TTL (default 24 hours), purged on schedule |
| Quality evaluation scores | 13 months rolling |
| Billing and tax records | 7 years (legal obligation) |
| Support communications | 24 months |
| Marketing consent and suppression records | Life of consent + 3 years |
| Backups | Rolling window (35 days or less), after which deleted data ages out |
Where an organization is deleted, its child records are deleted with it. See the DPA for deletion on termination.
6. Security
BYOK provider keys are encrypted with AES-256-GCM before storage and are never sent to browsers; gateway virtual keys are stored only as one-way hashes; caching is partitioned per organization; transport is TLS; payment card data is handled by Stripe. Details are on our Security page. No system is perfectly secure; we notify affected customers of personal data breaches as described in the DPA and applicable law.
7. International transfers
We process data in the United States (with content transiting Cloudflare's global edge). Where GDPR or UK GDPR applies to a transfer to us, we rely on the European Commission's Standard Contractual Clauses (2021/914, Module Two) and the UK Addendum, incorporated in our DPA. We are not currently certified under the EU-U.S. Data Privacy Framework.
8. Your rights
You may request access to, correction of, deletion of, or a portable copy of your personal data, and may object to or restrict certain processing. Email privacy@frugalai.io from your account email; we verify requests by confirming control of that email. We respond within 30 days (GDPR: one month; California: 45 days), extendable where the law allows, and we do not discriminate against you for exercising rights. We honor these rights for all users, whether or not a specific statute applies to you.
California (CCPA/CPRA). In the last 12 months we collected these categories: identifiers (email); commercial information (subscription records); internet/network activity (usage telemetry, site analytics); professional information (organization affiliation); and inferences are not compiled for profiling. Sources: you, your organization, our systems. Purposes: Section 3. Disclosed for business purposes to the service providers in Section 4. We do not sell or share personal information as the CCPA defines those terms, and we do not use or disclose sensitive personal information beyond permitted purposes. You have the rights to know, delete, correct, and to opt out of sale/sharing (not applicable, as we do none); exercise them via privacy@frugalai.io. We honor Global Privacy Control signals. Authorized agents may submit requests with proof of authorization.
EEA/UK. Lawful bases are in Section 3. You may withdraw consent at any time (without affecting prior processing), and may lodge a complaint with your supervisory authority or the UK ICO. We will appoint an EU and/or UK representative when our processing requires one and will list them here.
Other U.S. states. Residents of states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, and others) may exercise equivalent rights through the same channel, including appeal of a refusal by replying to our decision.
9. Children
The Service is for business users 18 and older. We do not knowingly collect personal information from anyone under 18; if you believe we have, contact privacy@frugalai.io and we will delete it.
10. Automated decision-making
FrugalAI's routing decisions select AI models for API requests; they are not decisions about people and produce no legal or similarly significant effects on individuals.
11. Changes and contact
We will post changes here with a new effective date and version history, and give email or dashboard notice of material changes. Questions and requests: privacy@frugalai.io, or write to Jake Bauman d/b/a FrugalAI, [BUSINESS ADDRESS], California, USA.
Version 1.1-draft · sha256 821a1c10c96f