LEGAL
Privacy Policy
How Fregio handles personal data across Muse, generated sites and hosting — including exactly which AI providers receive your prompts and where they process them.
Last updated: August 19, 2026
Who we are
Fregio is a trading name of Graphiq Studio LLC ("Graphiq Studio", "Fregio", "we", "us"), a limited liability company incorporated in the United States. We provide an AI website builder that designs, generates and hosts WordPress sites. For the account data and site content you give us, Graphiq Studio LLC is the data controller. Where you use Fregio to process personal data belonging to your own customers or site visitors, you are the controller and we act as your processor under our Data Processing Addendum. Contact: privacy@fregio.ai.
What we collect
- Account data — name, email address, hashed password, plan and credit balance.
- Billing data — subscription status, invoices and the last four digits of your card. Full card numbers are handled by Stripe and never reach our servers.
- Prompts and build content — the instructions you type to Muse, images, videos and 3D models you upload, and the pages, copy and media generated for your site.
- Site data — the WordPress database and files for sites you create, including anything you or your visitors later add.
- Technical data — IP address, browser and device information, request logs, error traces and security-scan results.
- Support data — messages you send us and their attachments.
Why we process it, and our legal basis
Under the GDPR and UK GDPR we rely on the following bases. Where we rely on legitimate interests, we have balanced them against your rights and you may object at any time.
| Purpose | Legal basis |
|---|---|
| Creating your account and providing the builder and hosting | Performance of a contract |
| Sending prompts and content to AI providers so Muse can build your site | Performance of a contract |
| Taking payment, invoicing and preventing payment fraud | Contract; legal obligation |
| Security monitoring, malware scanning, abuse prevention and rate limiting | Legitimate interests — keeping the platform and its users safe |
| Diagnosing faults and improving reliability and quality of the service | Legitimate interests — running a working product |
| Service emails about your account, builds and billing | Contract |
| Marketing email, where offered | Consent — withdrawable at any time |
| Retaining records for tax, accounting and legal claims | Legal obligation; legitimate interests |
AI processing — what leaves our servers
Fregio is built on third-party AI models. To generate or edit your site we transmit your prompt, relevant site content and any reference images you attach to the providers below. Please do not paste credentials, payment details, health information or other sensitive data into Muse: prompts are sent to these providers and are retained in your build history so you can revisit a conversation.
- Moonshot AI (Kimi) — text generation, planning and page building. Processed in China.
- OpenAI — image generation for the artwork placed on your site. Processed in the United States.
- We do not use your prompts, uploads or site content to train our own models, and we do not sell personal information or share it for cross-context behavioural advertising.
- Model providers operate their own retention and abuse-monitoring practices under our agreements with them. We do not control their internal processing.
- AI output can be wrong, generic or resemble existing work. It is generated by statistical models, not reviewed by a lawyer or a designer, and you are responsible for checking anything you publish.
AI transparency
Muse is an AI system and you are always interacting with software, never a human writing your site. Text, layouts, imagery and code produced through Fregio are artificially generated. Where we are required to mark synthetic media in a machine-readable way, we will apply that marking to media we generate. If you republish Fregio output elsewhere, disclosure obligations that apply to you — for example under the EU AI Act or state AI transparency laws — remain yours to meet.
International transfers
Our application, database and the WordPress sites we host run in Amazon Web Services in Frankfurt, Germany (eu-central-1). Some processing nevertheless takes place outside the EEA and the UK, in particular AI generation in China and the United States, and payments and email in the United States.
- Transfers are made under the European Commission's Standard Contractual Clauses, plus the UK International Data Transfer Addendum where UK data is involved.
- Where a provider is certified under the EU–US Data Privacy Framework, we also rely on that adequacy decision.
- China is not covered by an EU adequacy decision. Transfers there rest on Standard Contractual Clauses and supplementary measures. If that is unacceptable for your use case, do not put personal data of your own customers into Muse prompts.
Sub-processors
We use the following processors. We will update this list before adding a new one that handles personal data.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Application hosting, databases, customer WordPress sites | Germany (eu-central-1) |
| Moonshot AI | AI text generation and site building | China |
| OpenAI | AI image generation | United States |
| Stripe | Payments, subscriptions and invoicing | United States / global |
| Resend | Transactional email | United States |
How long we keep it
- Account and billing records — for the life of the account, then up to seven years where tax and accounting law requires it.
- Sites and site content — until you delete the site or close your account. Free-plan preview sites may expire earlier, as stated on the pricing page.
- Prompts and build history — for the life of the site, so you can revisit and continue a conversation.
- Backups — cycled out within 35 days of deletion.
- Security and abuse logs — up to 12 months.
Your rights
If you are in the EEA or the UK you may request access to your data, correction, deletion, restriction of processing, portability, and you may object to processing based on legitimate interests. Where we rely on consent you may withdraw it at any time. We do not make decisions producing legal or similarly significant effects about you by automated means.
- Californian residents may request the categories and specific pieces of personal information we hold, request deletion or correction, and are protected from discrimination for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of.
- Residents of other US states with comprehensive privacy laws have broadly equivalent rights.
- Email privacy@fregio.ai to exercise any of these. We reply within one month and may ask you to verify your identity first.
- You may complain to your local supervisory authority — in the EU, the authority where you live or work; in the UK, the Information Commissioner's Office.
Cookies
We set cookies that are strictly necessary to sign you in and keep your session secure. Where we use any analytics or non-essential cookies in the EEA or UK, we ask for consent first and you can change that choice at any time.
Security
Data is encrypted in transit with TLS. Passwords are hashed. Each customer site runs in its own isolated container with its own credentials, and access to production systems is limited to staff who need it. No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. If a breach affects your personal data we will notify you and the relevant regulator as the law requires. Report a vulnerability to security@fregio.ai.
Children
Fregio is not intended for anyone under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
Changes and contact
We will post any change here and update the date below. If a change materially affects how we handle your personal data we will tell you by email or in the product before it takes effect. Questions, requests or complaints: privacy@fregio.ai. Security: security@fregio.ai. Postal enquiries: Graphiq Studio LLC, attn. Privacy.

