Privacy Policy

Last updated: August 20, 2026

This legal document is provided in English.

1. Data Controller

The data controller for this service is:

FRITS AI ApS
CVR: 45733785
Nyhavn 38, 1051 København K
Denmark
Email: support@frits.ai

For any questions about this Privacy Policy or our data processing activities, please contact us at support@frits.ai. FRITS AI ApS is not required to formally appoint a Data Protection Officer under Art. 37 GDPR, but treats privacy questions as a first-priority matter and will respond promptly.

2. About the Service

GDPRchat is a general-purpose AI chatbot operated by FRITS AI ApS, a Danish company. All AI models, servers, and databases are located in the EU/EEA, and every company we engage to process your data is a European company. We are not tied to any single AI provider: we choose the strongest model we can run independently of its maker for each task, and operate it on European infrastructure, so the exact models and providers can change over time — the always-current list is published at gdprchat.eu/transparency. Today, our AI models are operated by Scaleway (France), which also performs voice transcription; our servers and database are hosted by Hetzner Online GmbH (Germany); and image generation is provided by IONOS Cloud GmbH (Berlin, Germany). The service includes a knowledge base of EU regulations and uses Linkup (France) for retrieving current information from the web. For payments we use Mollie B.V. (Amsterdam, Netherlands — an EU payment processor) on the web and Apple’s App Store in the iOS app. If you choose to sign in with a third-party account you can use Google, Microsoft or Apple — these US-based providers are covered by the EU-US Data Privacy Framework (see section 6). GDPRchat does not use any third-party analytics, tracking, or advertising services.

3. Personal Data We Collect

3.1 Account Data

When you create an account, we collect your name, email address, and a cryptographic hash of your password. If you sign up as part of an organisation, we also store the organisation name. If you choose to sign in via Google, Microsoft or Apple, we receive your name and email address from the chosen provider — we never receive or store the password you use with that provider. With Sign in with Apple you can choose to hide your real email address, in which case we only see Apple’s private relay address.

3.2 Chat Data

We store the conversations and messages you create when using the chatbot, including any documents you upload. This data is necessary to provide the service and allow you to return to previous conversations.

3.3 Technical Data

We process your IP address in three limited ways. First, for rate limiting and abuse prevention at authentication-related endpoints (sign-up, sign-in, password reset, invitation accept): these IPs are held only in server memory for a maximum of 15 minutes and are not written to our database. Second, in a security audit log: security-relevant account events (such as sign-up, account deletion, acceptance of legal documents, password and passkey changes, API-key changes, and data exports) are recorded together with the IP address and browser identifier from which the action was made, so that account takeover, fraud, and abuse can be investigated. These audit records are kept for 24 months (see section 7) and are retained after account deletion, because they exist precisely to resolve disputes and investigate abuse that may surface after an account disappears (Art. 17(3)(e) GDPR). Third, for a country-level location estimate where a feature needs your country (for example VAT display): this lookup runs against a local database on our own server, and your IP is not sent to any third party for it. Standard web-server access logs may retain request IPs for a limited operational period for security and diagnostics. We also process the Accept-Language header from your browser to provide the service in your preferred language.

3.4 Payment Data

On the web, payment processing is handled entirely by Mollie B.V. (Amsterdam, Netherlands). In the iOS app, purchases are made through Apple’s App Store and processed by Apple. With either provider, we do not receive, process, or store your credit card number, bank account details, or other financial payment instruments. We store only a customer identifier (Mollie) or a signed transaction reference (Apple) that allows us to link your account to your subscription.

3.5 Cookies and Local Storage

We do not use any tracking, analytics, or advertising cookies. Every cookie and every item we place in your browser’s localStorage is either strictly necessary for the service to function (authentication, security) or a preference or UI state tied to a service you have actively requested (language, theme, font size, and similar). Under Article 5(3) of the ePrivacy Directive and the European Data Protection Board’s Guidelines 2/2023 on the technical scope of Article 5(3), such storage is exempt from the consent requirement — which is why GDPRchat does not show a cookie consent banner. Showing one would imply that we ask your consent to track you, and we do not track you at all. We do keep a count of how often our public pages are read; how that is done, and why it puts nothing on your device, is described in 3.6 below.

Cookies we set:

  • NextAuth session cookies — a session token that keeps you logged in, together with a CSRF token, a PKCE verifier, and a callback-URL cookie used only during the sign-in flow. All strictly necessary for authentication and security.
  • Language-choice cookie (gdprchat-user-locale) — set when you actively pick a language in the interface. Lets us remember your choice across devices and survives a localStorage clear.
  • Administrator cookie— set only for site-administrator access (internal “god mode”). Never set for regular users.
  • Payment-provider cookies — when you visit a checkout or billing page, Mollie sets its own cookies inside its payment flow. These are strictly necessary for payment processing and fraud prevention and are controlled by Mollie (see mollie.com/privacy).

3.6 How we count visits to our public pages

We want to know which of our public pages people read, so we can write better ones. We do it without watching you, and without any third party: our own server keeps a tally as it sends each page out. No analytics service is used — Google’s or anyone else’s. Nothing is placed on your device, which is why there is no consent banner: under Article 5(3) of the ePrivacy Directive, consent attaches to storing or reading information on your device, and this stores and reads nothing — no cookie, no localStorage, no identifier.

There is one exception to “our server does it all”, and it is small enough to describe completely. Once we have sent you a page, our server cannot tell whether you read it for four minutes or left at once. So a few hundred bytes of our own code, on our own pages, holds a number of milliseconds while the page is in front of you and sends that one number back as you leave. It stores nothing, sets nothing, and reads nothing from your device; it cannot carry who you are, because it has no way of knowing. Only time when the page was actually visible counts — a tab behind another tab is not being read.

This applies only to our public pages — the ones anyone can see without signing in, such as the front page, pricing and the legal texts. Nothing you do inside the product is counted this way. Your conversations, your documents and your use of the assistant are not part of it, and no count is ever linked to your account.

What the tally holds for each page view: which page was asked for, which site you came from if your browser mentioned one, the language your browser prefers, whether the screen was a phone, a tablet or a computer, and how long the page was read. We also count the shape of a visit — how many pages it covered and which one it began on — but never the order in which you read them. A path through a site says far more about a person than a count does, and nothing we need to know requires it. To count people rather than page loads, your IP address and browser are combined into a short scrambled value using a secret that is generated fresh every night and never written down. Your IP address itself is never stored. Because that secret is discarded, the value cannot be turned back into you and today’s cannot be matched to tomorrow’s — so the count can tell that one person read two pages this afternoon, and can never tell that you came back next week.

The counts are kept on our own European servers. Detailed breakdowns are deleted after 400 days and the per-person rows behind the visitor count after 45 days; what remains is a daily number. Some of our own links carry a short marker such as ?k=front-start in the address, which names the button rather than the person and lets us see which links people actually follow.

Data we store in your browser’s localStorage: None of this data is transmitted to our servers — it stays on your device and exists only to remember your preferences and UI state between visits. You can clear all of it at any time by clearing your browser’s site data.

  • Appearance— theme (light/dark), accent-colour skin, font size, zen-mode font step, chat-display preferences, sidebar panel state.
  • Chat behaviour— auto-zen toggle.
  • Language— the interface language you last used.
  • Unsent draft— any text you have started typing but not yet sent in the composer, so you don’t lose it if you refresh. Stored locally only; never transmitted until you press send.
  • Location consent and short-lived cache — if you turn on the location feature, your consent choice is remembered, and a coarse location (coordinates rounded to approximately 1 km precision) is cached locally for 30 minutes before being discarded. See section 3.7.
  • PWA install-prompt state — whether you have seen or dismissed the “Install app” prompt, so we don’t nag you.

3.6 Voice Input

The voice-input feature is off by default and is only activated when you press the microphone button. When you do, your browser asks you for microphone permission (a native browser prompt, not controlled by us). If you grant permission, a short audio recording is captured on your device and sent to our servers, which forward it to our voice-transcription provider, Scaleway (Paris, France), for speech-to-text transcription. Only the transcribed text is kept; the audio itself is discarded after transcription. We never record audio in the background and the microphone is never active unless you tap the button.

3.7 Location Data

The location feature is off by default. If you choose to enable precise location, your browser asks you for geolocation permission. If you grant it, your coordinates are rounded down to approximately 1 km precision (two decimal places of latitude and longitude) before anything is cached, so an exact home address cannot be derived from the data. The rounded coordinates are reverse-geocoded into a city and country by calling OpenStreetMap Nominatim directly from your browser — the OpenStreetMap Foundation (United Kingdom, covered by the UK adequacy decision) receives only the rounded coordinates and your IP address for that single request. The resulting city-level location is cached in your browser’s localStorage for 30 minutes and then automatically discarded. You can withdraw location consent at any time in Settings, which immediately deletes the cache. If you decline precise location, we may still derive a country-level estimate from your connection’s IP address on the server side, using a local lookup database on our own server (your IP is not sent to any third party), for features that need it (for example, tax and currency); no coordinates are involved.

4. Legal Bases for Processing

We process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):

  • Performance of a contract (Art. 6(1)(b) GDPR) — Processing your account data, chat messages, and uploaded documents is necessary to provide you with the chatbot service you have requested. This includes account creation, message processing, conversation storage, and subscription management.
  • Legitimate interest (Art. 6(1)(f) GDPR) — We process IP addresses for security, rate limiting, and fraud prevention. Our legitimate interest is protecting the service and its users from abuse. We have conducted a balancing test and concluded that these interests are not overridden by your fundamental rights, given the limited nature of the data and the short retention period.
  • Consent (Art. 6(1)(a) GDPR) — Where we rely on consent (for example, for optional cookies or future newsletter communications), you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
  • Legal obligation (Art. 6(1)(c) GDPR) — We may retain certain transaction and invoicing records as required by Danish and EU tax law (Danish Bookkeeping Act, bogforingsloven).

4.1 Special category data (Art. 9 GDPR)

A chat interface lets you type anything — including, in principle, “special category” data under Article 9 GDPR (data revealing health, religion, political opinions, racial or ethnic origin, sexual orientation, trade union membership, genetic or biometric identifiers). GDPRchat does not request such data, does not analyse it, and does not use it for profiling or advertising. You are responsible for ensuring you have a lawful basis before you enter special category data — GDPRchat does not establish that basis for you. If you are using GDPRchat for your own personal purposes, you decide what you choose to share about yourself. If you enter other people’s personal data (for example in a professional or business context), you are acting as the data controller for that data and are responsible for the Article 9 condition and the other GDPR obligations that apply to you (see the Data Processing Agreement). GDPRchat processes what you send on your instruction, for the sole purpose of answering you.

You can reduce the risk by keeping PII Lockturned on (Settings → Data Protection): it masks names, emails, IDs and other identifying tokens client-side before your message leaves the browser. PII Lock is on by default. If a piece of special category data slips through, you can delete the conversation immediately (the row is removed from the live database; backups are purged on the schedule described in section 7).

5. Data Processors and Third-Party Services

We share personal data with the following third parties. These are processors acting on our instructions under data processing agreements (Art. 28 GDPR):

  • Scaleway (Paris, France) — A European AI inference provider (Iliad group), and since 11 September 2026 the only company that receives chat content for AI processing. We are not tied to a single AI provider — we operate the strongest model we can run independently of its maker for each task, on European infrastructure — so the models change while the processor stays the same. Chat messages, request understanding, document analysis, code generation, text embeddings and voice transcription are all sent to Scaleway. Scaleway is a French company and processes the data within the EU. Its Generative APIs run in Scaleway's own European data centres; the sub-processors Scaleway publishes are colocation and recycling suppliers, not AI processors.
  • Hetzner Online GmbH (Gunzenhausen, Germany) — Our infrastructure provider. All servers and databases are hosted in Hetzner data centres in Germany. All data at rest remains in the EU.
  • IONOS Cloud GmbH (Berlin, Germany) — Provides image generation and editing. When you generate an image your prompt is sent to the IONOS AI Model Hub for processing; when you edit an image, the image itself is sent with it. IONOS is a German company and the service runs in their Berlin data centre. Under the Special Terms for AI Services (§2.3) IONOS may use inputs and outputs only to provide the service and for technical security and troubleshooting — using them to develop, train or retrain AI models is expressly prohibited. IONOS have confirmed in writing that no third-party sub-processors are engaged for the AI Model Hub. Image prompts are therefore covered by our no-training commitment, like the rest of GDPRchat.
  • Mollie B.V. (Amsterdam, Netherlands) — Handles payment processing on the web. When you subscribe to a paid plan or buy credits, your payment details are collected and processed directly by Mollie, a Dutch, EU-regulated payment institution — they never touch our servers, and your chats never reach Mollie. Mollie's own privacy statement says that third parties outside the European Economic Area may process payment data in some cases, under Standard Contractual Clauses. Purchases made in the iOS app are processed by Apple instead (see the Apple entry below).
  • Scaleway (Transactional Email) (Paris, France) — Delivers transactional emails (password reset, invitation links, low-credit reminders and similar account-related messages). To send each email we share the recipient’s email address, the message subject and the message body with Scaleway. We do not send promotional or marketing email. Scaleway does not track opens or clicks and does not rewrite the links in our emails, so nothing records whether you opened a message or which link you followed. Scaleway is a French company and processes the data within the EU.

The following services are not our processors. Each entry says what it receives and in what role — an independent controller you chose to involve, an element your browser loads directly, or a recipient of query text that carries nothing identifying you:

  • Linkup(France, EU) — Used for web search. When an answer needs current information, the AI assistant writes a search query of its own and our servers send it. Your message is not forwarded, and nothing that identifies you travels with the query: no account, no user identifier, no IP address, and no part of your conversation. Nothing in the request points back to you, so no personal data of yours reaches Linkup (see section 6), and we treat Linkup as a recipient of query text only, not as a processor with access to your data. We still tell you where that query goes: Linkup is a French company, but it runs its search infrastructure in several regions — the EU, the United States, Canada and Asia-Pacific — and spreads queries across them according to load. Its documentation states that local processing is not guaranteed, so we cannot tell you that an individual search is handled inside the EU. Linkup is the only company that receives search queries. Web search ran on Brave Search (US) until August 2026 and, until 3 September 2026, a failed Linkup search was automatically retried on Brave; that fallback has been removed. If a search fails now, it fails, and we answer without web results rather than asking anyone else.
  • DataForSEO (an Estonian company) — Used only when you tap the deep price-comparison button on a shopping answer. The AI assistant writes the product search term itself; we send that term, a country name and a language code. Calls are made from our servers, so DataForSEO never sees your IP address or any account identifier, and nothing in the request points back to you. This is the same mechanism as web search and it gets the same answer: a query the assistant composes, sent with nothing attached that identifies you, is not your personal data (see section 6). We treat DataForSEO as a recipient of query text only, not as a processor with access to your account data. DataForSEO collects the prices from Google Shopping, and its own infrastructure providers include Google and Microsoft in the United States as well as Hetzner in Germany, so we do not claim a request is handled on a machine inside the EU. Because the request carries no personal data, that is not a transfer of personal data.
  • OpenStreetMap Foundation (United Kingdom, UK adequacy decision) — If you render a map in a conversation, map tiles are loaded directly from OpenStreetMap into your browser; if you enable the precise location feature, your rounded coordinates are also sent to OpenStreetMap Nominatim for reverse geocoding (see section 3.7). In both cases your IP address is visible to OpenStreetMap for that request only; no account data is shared.
  • Apple(US, EU-US Data Privacy Framework certified) — Relevant only if you use Apple services with GDPRchat. If you choose Sign in with Apple, we receive the name and email address you approve (optionally Apple’s private relay address instead of your real one). If you purchase a subscription or credits in the iOS app, the purchase is processed by Apple through the App Store under Apple’s own terms, and we receive a signed transaction reference — never your payment details. In both roles Apple acts as an independent data controller.
  • Google / Microsoft (US, EU-US Data Privacy Framework certified) — Only if you voluntarily choose to log in with Google or Microsoft OAuth. In that case, your name and email address are received from the chosen provider. Both are certified under the EU-US Data Privacy Framework and act as independent data controllers for the sign-in itself.

6. International Data Transfers

The vast majority of your data is processed and stored within the EU/EEA — principally Germany, France and the Netherlands. Payment processing on the web is carried out by Mollie B.V. in the Netherlands; Mollie’s own privacy statement says third parties outside the EEA may process payment data in some cases, under Standard Contractual Clauses, and your chats never reach Mollie. Where data is transferred to the United States (Apple for App Store purchases and Sign in with Apple, and optionally Google or Microsoft for OAuth), these transfers are protected by the EU-US Data Privacy Framework adequacy decision adopted by the European Commission on July 10, 2023, in accordance with Art. 45 GDPR. Should the DPF adequacy decision be invalidated or suspended, we rely on Standard Contractual Clauses under Art. 46(2)(c) GDPR as an additional safeguard with each of these providers.

Web search is not a transfer of your personal data. When the assistant searches the web it sends a query it composed itself. No account, no user identifier, no IP address and no conversation content travel with it. Nothing links it to a person. It is our system's own outbound request — the same as a browser fetching a page — not your data. No personal data leaves the EU when a search runs. Chapter V of the GDPR does not apply to it.

We still tell you where a search can be handled, because that is a fact you are entitled to. Linkup runs its own search infrastructure in the EU, the United States, Canada and Asia-Pacific and allocates queries across those regions by load. It does not guarantee that an individual search is handled locally, and its API has no region parameter, so we cannot pin one search to Europe. We say so rather than imply every search stays in the EU. Whenever an answer needs current information from the web. Linkup is the only company that receives a search: the United States standby we used when a Linkup call failed was removed on 3 September 2026, so a failed search now simply fails rather than being retried somewhere else.

Until 3 September 2026 this policy described web search as a transfer of your personal data outside the EU that we had no Chapter V footing for. Two things changed on that date: Brave Search, Inc. (United States) was removed as the standby provider, and we determined — on the verified contents of the request, which have not changed — that a query the assistant composes and sends with nothing attached that identifies you is not your personal data. The earlier wording is superseded. Nothing about what is sent, or where it goes, is any different; we have withdrawn no disclosure.

For transfers to the United Kingdom (OpenStreetMap Foundation), we rely on the European Commission’s UK adequacy decision of 28 June 2021.

Our providers’ own suppliers. Every company we engage to process your data is a European company. Those companies in turn buy infrastructure of their own, and some of those suppliers are businesses incorporated outside the EU that operate equipment inside the EU/EEA. Scaleway, which performs all of our AI processing, publishes its own list at scaleway.com/en/subprocessorlist: it is data-centre suppliers, and three of them — Equinix, Iron Mountain and Digital Realty — are US-incorporated companies providing Scaleway with building and rack space in Italy, the Netherlands and Poland. No sub-processor is listed against Scaleway’s AI services, which Scaleway runs on its own infrastructure — so your chats are processed on machines owned by a European company. We state this level too so that you can check what “100% European” covers for yourself: renting a data-centre rack is a different relationship from renting the computers that run a model. Your data continues to be processed within the EU/EEA, so this is not a third-country transfer under Chapter V GDPR, and no supplier may use your data for their own purposes or to train models. Each provider publishes its own current list.

We do not transfer personal data to any country outside the EU/EEA that lacks an adequate level of data protection, unless an appropriate safeguard under Chapter V of the GDPR is in place.

7. Data Retention

  • Account data — Retained for as long as your account exists. When you delete your account, all account data is permanently deleted.
  • Chat data— Retained until you delete individual conversations or delete your account, whichever comes first. In addition, conversations you have not starred are deleted automatically after a retention period (default: 30 days of inactivity). You can change the period or turn auto-deletion off entirely (“Never”) in Settings → Data Protection; starred conversations are never auto-deleted.
  • Shared chat links — Expire after 30 days; expired links are deleted by a nightly cleanup. Revoking a link stops it working immediately, and deleting the conversation or your account deletes its shared links at the same time.
  • Tax and invoicing records — Retained for the period required by applicable Danish and EU law (currently 5 years under the Danish Bookkeeping Act).
  • IP addresses— For rate limiting: held only in server memory for a maximum of 15 minutes while the anti-abuse window is open, then discarded. For security-relevant account events: stored in the security audit log (below). Standard web-server access logs may retain request IPs for a limited operational period for security and diagnostics.
  • Security audit log— Records of security-relevant account events, including the IP address and browser identifier they came from (see section 3.3), are kept for 24 months and then deleted. These records are retained after account deletion so that fraud and abuse can still be investigated (Art. 17(3)(e) GDPR).
  • Backups— Encrypted database backups for disaster recovery are kept for up to 30 days and then destroyed. Data you delete is removed from the live system immediately and ages out of backups within that window; backups are only ever read to recover from infrastructure failure.
  • Voice audio— Audio you record for voice input is discarded immediately after speech-to-text transcription; only the resulting text is stored (as a chat message you then send).

8. Your Rights Under the GDPR

Under the GDPR, you have the following rights with respect to your personal data:

  • Right of access (Art. 15 GDPR) — You have the right to obtain confirmation as to whether personal data concerning you is being processed and, if so, to access that data together with supplementary information.
  • Right to rectification (Art. 16 GDPR) — You have the right to have inaccurate personal data corrected and incomplete data completed.
  • Right to erasure ("right to be forgotten") (Art. 17 GDPR) — You have the right to have your personal data deleted. You can delete individual conversations directly in the app, and you can delete your entire account — including all conversations, messages, documents, and usage records — from the Your Data Rights section of your Profile page. Account deletion is immediate, permanent, and includes automatic cancellation of any active subscription.
  • Right to data portability (Art. 20 GDPR) — You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. You can export all your data as a JSON file at any time from the Your Data Rights section of your Profile page — no need to contact us.
  • Right to restriction of processing (Art. 18 GDPR) — You have the right to request that we restrict the processing of your personal data in certain circumstances.
  • Right to object (Art. 21 GDPR) — You have the right to object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Right to withdraw consent (Art. 7(3) GDPR) — Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
  • Right to lodge a complaint (Art. 77 GDPR) — You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet):
    Datatilsynet
    Carl Jacobsens Vej 35
    2500 Valby, Denmark
    Email: dt@datatilsynet.dk
    Website: www.datatilsynet.dk

To exercise any of these rights, please contact us at support@frits.ai. We will respond to your request within one month, as required by Art. 12(3) GDPR. In complex cases, this period may be extended by a further two months, in which case we will inform you of the extension and the reasons for the delay.

9. Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, in accordance with Art. 32 GDPR. These measures include:

  • Encryption of data in transit (TLS 1.2+)
  • Application-layer AES-256-GCM encryption of uploaded-document text, with the encryption key held outside the database and backups
  • Password hashing using bcrypt with cryptographic salting
  • EU-only hosting with no data stored outside the European Union, in Hetzner’s ISO 27001-certified data centres (Germany)
  • Rate limiting and IP-based abuse prevention
  • Built-in PII (Personally Identifiable Information) filter that detects sensitive data — including names, emails, phone numbers, national ID numbers, IBANs, and passport numbers across all 27 EU member states — before your message is sent to the AI. When enabled, detected PII is highlighted and the message is blocked from transmission. This filter runs entirely on your device; the detected data is never sent to our servers
  • Input sanitisation to prevent cross-site scripting (XSS) and injection attacks
  • AI safety measures designed to reduce the risk of the chatbot disclosing internal configuration, other users' data, or generating content that violates privacy rights
  • Shared chat links that strip all user identity information (name, email, user ID) from the shared content

10. No Analytics, No Tracking, No Advertising

GDPRchat does not use any third-party analytics services (such as Google Analytics), does not deploy tracking pixels or fingerprinting technologies, does not serve advertisements, and does not engage in profiling or automated decision-making as defined in Art. 22 GDPR. We do not sell, rent, or share your personal data with third parties for marketing purposes.

11. Children's Privacy

GDPRchat is intended for adults and older teens. You must be at least 16 years old to create an account, regardless of where you live in the EU or EEA. Article 8 GDPR sets the digital age of consent at 13–16 depending on national law; we apply a single, higher floor of 16 across every Member State so that the same legal basis applies to every account, the same Terms apply to every account, and we never need to verify a user’s country of residence to determine whether they are old enough. This is stricter than the legal minimum and is our deliberate business policy. The signup form requires you to confirm your age before an account can be created.

We do not knowingly collect personal data from anyone under 16. If you believe an account has been created on behalf of a child under 16, please contact us at support@frits.ai and we will delete the account and all associated data without delay.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify registered users by email or by a prominent notice in the service. The "Last updated" date at the top of this page indicates when the policy was last revised.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact us:

FRITS AI ApS
CVR: 45733785
Nyhavn 38, 1051 København K
Denmark
Email: support@frits.ai