Legal
Data Protection Notice
Last updated: 3 August 2026
This page explains how FrootAI (“we”, “us”) processes personal data when you visit frootai.dev. We are committed to the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the German Telecommunications-Telemedia Data Protection Act (TTDSG / TDDDG, §25), and the ePrivacy Directive (2002/58/EC).
1. Controller
The data controller within the meaning of Art. 4(7) GDPR is named in the Impressum. Contact: [email protected].
2. What we collect and why
2.1 Server logs (essential, no consent required)
Our website delivery provider automatically records technical access data whenever you load a page: IP address, user agent, referrer, requested URL, timestamp, HTTP status, bytes transferred. Logs are kept for at most 30 days for security and abuse prevention.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, stable service).
- Retention: up to 30 days, then deleted or anonymised.
2.2 Cookies & local storage
We use the minimum necessary set. You control optional categories via the cookie banner. Your choice is stored in your browser for 12 months, after which we ask again.
| Category | Purpose | Legal basis | Lifetime |
|---|---|---|---|
| Strictly necessary | Authentication session, request protection, and this consent choice. | Art. 6(1)(f) GDPR · TTDSG §25(2) | Session – 12 months |
| Analytics (opt-in) | Plausible Analytics — cookieless, EU-hosted, aggregate page views. | Art. 6(1)(a) GDPR · TTDSG §25(1) | No cookies; in-memory only |
| Marketing (opt-in) | Optional experience measurement, only when an applicable service is active and you opt in. | Art. 6(1)(a) GDPR · TTDSG §25(1) | Up to 12 months |
2.3 Analytics — Plausible
We use Plausible Analytics, a privacy-first analytics service hosted in the EU (Germany / Netherlands). Plausible does not use cookies, does not collect personal data, does not create user profiles or track you across sites. Even though Plausible is widely considered consent-exempt in the EU, we still load it only after explicit opt-in to give you maximum transparency.
- Processor: Plausible Insights OÜ (Estonia).
- Data transferred: URL, referrer, viewport, and privacy-preserving aggregate device information.
- No personal data, no cookies, no cross-site tracking.
2.4 Voice search (microphone)
Several search bars on this site (Search FAI, Solution Accelerator, Solution Plays, Primitives, Marketplace, Agent FAI, and others) expose an optional microphone button. Activating it asks your browser for microphone access and then uses your browser’s built-in Web Speech API to transcribe what you say into the search input. We do not record, store, transmit, or retain the audio. The audio stream stays inside your browser; only the text transcript reaches our search code, exactly as if you had typed it. You can revoke microphone permission at any time in your browser settings; the mic button auto-hides on browsers that don’t expose the API.
3. Third-party services
- Cloudflare — website delivery and security. Traffic may be processed at provider locations worldwide. Cloudflare DPA.
- Supabase — customer identity and account data services. Account data is processed in the European Union, subject to support and sub-processor transfers described in the provider terms. Supabase DPA.
- Loops — service email delivery when a relevant message is enabled. It receives the recipient address and delivery metadata.
- GitHub — links to public repositories; loading a repo page is governed by GitHub’s privacy statement.
- Plausible Analytics — see §2.3.
- Microsoft — optional customer-requested cloud or AI workloads. Processing scope and location depend on the selected service and applicable agreement.
3.1 Authentication and account services
User accounts are live. A managed identity provider operates customer authentication and sessions. Depending on the sign-in method you choose, it may exchange identifiers with Google, Microsoft, GitHub, or X. We receive account identifiers, email address, profile metadata, provider metadata, session information, and security events needed to operate your account. We do not receive plaintext passwords.
| Processor | Role & data categories | Operational status | Notice |
|---|---|---|---|
| Cloudflare | Restricted administrative identity verification. Processes authorized operator identity, authentication factors, session metadata, IP address, and user agent. | Used for restricted administration. | Cloudflare DPA |
| Supabase | Customer authentication, sessions, profile and entitlement records, account preferences, activity visible to the user, and deletion state. | Used for customer account services; primary processing is in the European Union. | Supabase DPA · Privacy |
| Clerk | Limited account and organization services for certain existing account paths. | Limited use. | Clerk DPA · Privacy |
3.2 Retention, export, and deletion
- Account and profile data: retained while your account is active.
- Account deletion: you can schedule deletion from account settings. A 30-day cooling-off period lets you cancel; after it expires, the account and associated user-owned records are deleted, subject to required legal retention.
- Data export: you can build a JSON export from account settings before deletion.
- Guest Agent FAI conversations: stored in your browser and pruned after 90 days.
- Product telemetry where enabled: raw event records are retained for up to 90 days; privacy-preserving aggregates may be retained for up to two years.
- Security, audit, billing, and legal records: may be retained longer where necessary for fraud prevention, dispute resolution, contractual evidence, or legal obligations. These records are access-controlled and are not used for advertising.
The current operational register, including processor status and region wording, is available in the sub-processor list.
4. Your rights under GDPR
You always have the right to:
- Access (Art. 15) — request a copy of personal data we hold about you.
- Rectification (Art. 16) — have inaccurate data corrected.
- Erasure / “right to be forgotten” (Art. 17).
- Restriction (Art. 18) of processing.
- Data portability (Art. 20).
- Object (Art. 21) to processing based on legitimate interest.
- Withdraw consent at any time (Art. 7(3)) — clearing your cookie choice re-opens the banner.
- Lodge a complaint with a supervisory authority (Art. 77). For Germany, the federal authority is the BfDI (bfdi.bund.de); a list of EU state authorities is at edpb.europa.eu.
To exercise any right, email [email protected].
5. International data transfers
FrootAI uses providers with processing locations in and outside the EU/EEA. Account data is processed primarily in the European Union. Optional customer workloads use the locations stated for the selected service or contract. Where transfer outside the EU/EEA occurs, the transfer is governed by the applicable vendor DPA and, where required, Standard Contractual Clauses (SCCs, Commission Decision 2021/914) and supplementary technical measures (TLS in transit, encryption at rest).
6. Security
The site is served over HTTPS using modern transport encryption. We apply browser security controls, consent-gated optional scripts, access controls, encrypted vendor transport and storage, least-privilege administration, and data minimisation. We publish only controls that are active and verifiable.
7. Children
This site is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16.
8. Changes to this notice
We may update this notice as our processing evolves. Material changes are highlighted with a new “Last updated” date and, where significant, re-trigger the consent banner.
9. Commercial services
FrootAI has no live paid plans in 2026. Before commercial services are offered, the applicable pricing, payment, tax, cancellation, refund, support, and service-level terms will be published and this notice will be updated for any new processing activity.
This document is provided in good faith and reflects our processing on the “Last updated” date. It is not legal advice. See also the Impressum.