Privacy by design: how Frae handles your event data

Dr Marcus Judge, CEO of Frae · · Updated · 7 min read

Last checked against the shipped product and Frae privacy policy on 8 August 2026. The privacy policy is the legal source of truth and will be updated before any material processing change.

The fastest way to lose trust is to be vague about data. Frae coordinates real people's social plans, so names, invitations and availability deserve a concrete explanation. This is what the current product needs, what it deliberately leaves alone and how long records remain.

Data Frae needs to run a plan

A registered account can include:

A guest can respond from an invite link without creating an account. Frae still needs the guest information and availability submitted through that flow so the response belongs to the right participant and the organiser can use it.

IP addresses are for security, not proximity

Like any online service, the server receives an IP address with a request. Frae processes it for security, abuse prevention, rate limiting and bounded operational logging. It is not used to build a location profile or power a nearby-friends feature.

Optional calendar checks stay on the phone

The iPhone and Android apps offer an optional calendar-conflict view. It is off by default and needs system permission. When enabled, the app reads entries for the date range being viewed, computes busy days in memory and does not upload calendar titles, descriptions, attendees, locations or events to Frae's servers. The web app does not offer this feature. Turning the setting off or revoking the operating-system permission stops the checks.

Location and diagnostics

Frae does not request precise GPS location. An event organiser can type a location label. If they interact with Google Places suggestions, the typed characters are sent to Google to return matching places; choosing a suggestion is optional.

Frae has optional reliability and diagnostics integrations. The current privacy policy names Sentry when enabled and lists the processors used to host the service and deliver email, sign-in and push notifications. Product analytics cannot be enabled as an undisclosed shortcut: the release policy requires the relevant privacy disclosures to be updated first. Frae does not use advertising trackers, sell personal data or train machine-learning models on event data.

Who can see event information

Participants need enough shared context to coordinate. Within an event:

Retention and deletion have explicit clocks

Cancelled events are deleted after 30 days. Past events are deleted 365 days after the event date. Guest records are anonymised 90 days after the related event ends. Inactive accounts receive a warning after 24 months; if the person does not return, deletion starts at 30 months. Rolling backups expire within 14 days.

Starting account deletion immediately removes active invitations, friendships, device tokens and active events organised by the account, and anonymises past participation. The remaining account record has a 30-day grace period before permanent deletion. Signing in during that period cancels final deletion, but it cannot restore data already removed. The exact steps are on the account deletion page.

Where data is protected

Application and database hosting is in DigitalOcean's London region. Data is encrypted in transit, backups are encrypted, passwords are stored as salted BCrypt hashes and access tokens are short-lived. The privacy policy lists every current subprocessor and the safeguards used for international transfers.

Check the source of truth

This article is an explanation, not a substitute for the policy. Read the full privacy policy for lawful bases, rights, subprocessors and contact details. Questions or deletion requests can go to privacy@frae.app.

← Back to all posts