Legal
Privacy Policy
Last updated: June 10, 2026
This policy explains how FRIXIA processes personal data, in accordance with the EU General Data Protection Regulation (GDPR).
1. Data controller
Lorenzo Frisoni, Italy ("FRIXIA"). Contact for any privacy matter: legal@frixia.ai.
2. Data we process
Account data: email address and authentication credentials (managed by Supabase; passwords are stored hashed; optional passkeys/Face ID use WebAuthn and never leave your device as biometrics).
Profile data: display name, language preference.
Legal/DMCA data: legal name, contact email, postal address — provided by you, used exclusively inside the takedown notices you generate.
Protection data: the public usernames/handles you ask us to monitor, scan results (URLs and titles of third-party pages), takedown history.
Original files: photos you upload as proof of ownership are stored in a private storage bucket, are never made public and are never used for any purpose other than providing the Service.
Billing data: subscription status and Stripe customer reference. Card details are processed by Stripe only; we never see or store them.
Technical data: standard server logs (IP, timestamps) for security and abuse prevention.
3. Purposes and legal bases
Providing the Service and billing — performance of a contract (art. 6(1)(b) GDPR).
Security, fraud and abuse prevention — legitimate interest (art. 6(1)(f)).
Leak notification emails — performance of a contract; you can disable them in Settings at any time.
Legal obligations (tax, accounting) — art. 6(1)(c).
We do not sell personal data and we do not use it for advertising.
4. Processors and recipients
We use the following processors: Supabase (database, authentication, file storage), Vercel (web hosting), Fly.io (backend hosting, EU region), Stripe (payments), Resend (transactional email, EU region), Serper (search queries — only the public handles you monitor are sent; your files and personal details never are).
Recipients of takedown notices (site operators, hosting providers) receive the legal details required by law for a valid notice, only when you generate one.
5. International transfers
Where a processor handles data outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses or an adequacy decision.
6. Retention
Data is kept for as long as your account exists. Deleting your account from Settings purges your profile, monitored handles, scan results and uploaded files. Billing records are kept as required by tax law (10 years in Italy).
7. Your rights
You have the right to access, rectify, erase, restrict, port and object to the processing of your data (arts. 15–21 GDPR). Write to legal@frixia.ai. You also have the right to lodge a complaint with your supervisory authority (in Italy: Garante per la Protezione dei Dati Personali).
8. Minors
The Service is restricted to adults (18+). We do not knowingly process data of minors.
9. Changes
We may update this policy; material changes will be notified by email or in the app.
Questions about this document: legal@frixia.ai