Privacy Policy

Effective Date: 1 June 2026

Last Updated: 14 July 2026

Version: 1.2.1

This Privacy Policy explains how Untitled Labs Limited ("Fraw," "we," "us," or "our") collects, uses, discloses, stores, and otherwise processes personal information when you use the Fraw mobile application, website, software, official functions, extensions, creator tools, and related services (collectively, the "Service").

By using the Service, you acknowledge that your information will be handled as described in this Privacy Policy.

If you do not agree with this Privacy Policy, please do not use the Service.

1. Scope of This Policy

This Privacy Policy applies to personal information we collect when you:

  • create or use a Fraw account;
  • subscribe to a plan or purchase top-up credits;
  • use official features such as Official Extensions or Rebuild / Blend;
  • create, edit, publish, or use extensions;
  • participate in referral, reward, or creator programs;
  • contact us for support;
  • visit our website or interact with our communications;
  • otherwise use the Service.

This Privacy Policy does not apply to third-party services that may be linked to or integrated with the Service, such as app stores, payment processors, analytics providers, or other third-party platforms, which are governed by their own privacy policies.

2. Information We Collect

We may collect the following categories of information.

2.1 Information You Provide Directly

Information you provide when you use the Service may include:

  • name, username, display name, or profile information;
  • email address, phone number, or other contact details;
  • login credentials or authentication information;
  • subscription, billing, or purchase-related information;
  • prompts, text, files, images, or other content you submit;
  • extension names, descriptions, configurations, and related creator content;
  • support requests, feedback, reports, or communications you send to us;
  • creator-program and withdrawal-related information you provide or generate through the Service, such as withdrawal requests, payout preferences where applicable, and related creator-program communications.

2.2 Information Collected Automatically

When you use the Service, we may automatically collect certain technical and usage information, including:

  • device type, operating system, app version, browser type, and language settings;
  • IP address, approximate location derived from IP, and general region;
  • identifiers associated with your device, app installation, or account;
  • crash logs, diagnostic data, performance data, and error reports;
  • usage data such as pages viewed, features used, button clicks, session duration, and timestamps;
  • transaction and activity logs relating to credits, subscriptions, top-ups, official functions, extensions, referrals, and creator activity.

2.3 Information From Third Parties

We may receive information from third parties such as:

  • app stores and payment processors regarding transactions, subscriptions, renewals, refunds, and chargebacks;
  • authentication providers if you sign in through third-party login tools;
  • analytics, security, fraud-prevention, and hosting providers;
  • payout providers where applicable, such as payout status, transaction references, payout-provider identifiers, or other limited payout-related records.

2.4 User Content and Generated Content

We may collect and process prompts, uploaded content, extension-related data, generated outputs, and other inputs and outputs associated with your use of the Service. This may include:

  • text prompts;
  • image uploads;
  • generated images or transformations;
  • extension configurations;
  • creator publication data;
  • moderation and review information.

3. Face-Containing Images and Facial Image Processing

Some features of the Service allow you to upload, capture, edit, transform, rebuild, blend, or otherwise process images that may contain a human face. This section describes in detail what Face-Containing Images we collect, how we use them, whether they are shared, where they are stored, and how long they are retained.

3.1 What Face-Containing Images We Collect

For purposes of this Privacy Policy, "Face-Containing Images" mean photographs, images, or visual content containing a human face that you voluntarily upload, capture through your device camera, select from your device photo library, or otherwise submit to the Service, together with non-identifying image characteristics that may be detected or processed from those images during generation.

Such characteristics may include face position, orientation, framing, alignment, image composition, or similar non-identifying information used only to generate the image transformation you request.

Some platform rules or privacy laws may refer to face-containing images or related image-processing information as face data, biometric-related data, sensitive personal information, or similar categories. In this Privacy Policy, we use the term "Face-Containing Images" to describe face-containing user images and related non-identifying image-processing information, and not to imply that Fraw creates biometric identifiers, biometric templates, faceprints, or face-geometry scans.

Fraw does not use Face-Containing Images to identify you as a real-world person, verify your identity, authenticate your account, perform facial recognition, perform identity matching, or create a biometric identification profile.

Fraw does not create or store biometric templates, faceprints, face-geometry scans, or other biometric identifiers from Face-Containing Images.

Specifically, the Service may collect or process the following Face-Containing Images or related non-identifying image-processing information when you use image-related features:

  • photographs or images containing human faces that you upload from your device photo library, capture using your device camera, or otherwise submit to the Service;
  • non-identifying image characteristics detected or processed from those images during AI processing, such as face position, orientation, framing, alignment, image composition, or similar information used solely to generate the requested image transformation;
  • original input images, reference images, thumbnails, generated examples, or other extension assets that may contain human faces, where you create, save, publish, or use an extension;
  • AI-generated or AI-transformed output images, which may also contain facial imagery.

The Service does not use the TrueDepth camera, ARKit, or any on-device facial-recognition, face-mapping, or biometric-authentication framework. Fraw does not perform facial recognition for account login, identity verification, biometric identification, identity matching, or user authentication. Face-related image processing occurs on our servers or through our third-party AI image-generation or image-processing service providers only for the purposes described in this Privacy Policy.

3.2 How We Use Face-Containing Images

We use Face-Containing Images exclusively to provide the image-processing features you request. Specifically, Face-Containing Images are used to:

  • apply AI-powered image transformations you initiate, including Rebuild, Blend, style transfer, and Extension-based image generation;
  • transmit your uploaded image, which may contain a human face, to our servers and, where necessary, to third-party AI image-generation or image-processing providers solely to generate the requested output, perform related safety or abuse-prevention checks, maintain service reliability, or support the requested feature;
  • return the generated or transformed image to you within the app;
  • save the original and generated images to your account gallery if you choose to keep them;
  • detect and prevent abuse, fraud, or policy violations, for example content moderation to block prohibited imagery;
  • comply with applicable legal obligations and enforce our Terms of Service.

3.3 We Do Not Use Face-Containing Images To

We do not use Face-Containing Images to:

  • identify you as a real-world person;
  • perform facial recognition for authentication or identity verification;
  • build a facial-recognition profile or template of any user;
  • determine your race, ethnicity, religion, health status, sexual orientation, or other sensitive attributes;
  • create or store biometric templates, faceprints, face-geometry scans, or other biometric identifiers;
  • serve advertising, marketing, use-based data mining, cross-context behavioral advertising, or interest-based advertising, including by third parties;
  • sell, rent, or trade Face-Containing Images to any third party;
  • train general-purpose artificial intelligence or machine-learning models, including facial-recognition, general-purpose image-generation, identity-matching, or biometric-identification models, unless we obtain your separate consent where required by applicable law.

3.4 Sharing of Face-Containing Images with Third Parties

We do not sell, rent, or trade Face-Containing Images. We may share Face-Containing Images only in the following limited circumstances.

Third-Party AI Image-Generation Providers

  • When you initiate an image transformation, your uploaded image, which may contain a human face, may be transmitted to one or more third-party AI image-generation or image-processing providers only where necessary to generate the requested output, perform related safety or abuse-prevention checks, maintain service reliability, or support the requested feature.
  • We require our third-party AI providers to process uploaded images and related Face-Containing Images only under contractual terms, platform terms, data-processing agreements, or equivalent safeguards that restrict their use of such data to providing, securing, supporting, or improving the specific service requested by Fraw, and that prohibit use of your Face-Containing Images for unrelated advertising, resale, or independent profiling.
  • We do not authorize third-party AI providers to use your Face-Containing Images to identify you as a real-world person, build a facial-recognition profile, determine sensitive attributes, or use your Face-Containing Images for unrelated model training. Where required by applicable law, we will obtain any required consent before using Face-Containing Images in a materially different way.
  • When Face-Containing Images are transmitted to a third-party AI image-generation or image-processing provider, the provider may temporarily process uploaded images or related processing data for limited technical, safety, security, debugging, abuse-prevention, service-reliability, or legal purposes, as permitted by the applicable provider terms and service configuration.

We seek to use providers and service configurations that support appropriate privacy, security, confidentiality, retention, and deletion safeguards. We do not authorize providers to use Face-Containing Images for unrelated advertising, resale, independent profiling, facial recognition, biometric identification, unrelated model training, or any purpose not described in this Privacy Policy.

Where supported by the applicable provider terms or service configuration, we require or configure providers to delete or de-identify input images and related Face-Containing Images after processing or after any limited technical, safety, security, abuse-prevention, service-reliability, or legal retention period.

Cloud Hosting and Storage Providers

  • Original images, generated images, extension assets, account data, and related service records may be stored on secure cloud infrastructure provided by our hosting and storage providers, including Google Cloud Platform or other infrastructure providers we may use from time to time. These providers process data on our behalf and are subject to contractual, technical, and organizational safeguards designed to protect personal information.

Safety, Security, and Moderation Providers

  • Where necessary, we may share limited information, including uploaded or generated content, with service providers that help us detect fraud, abuse, security incidents, prohibited content, policy violations, or misuse of the Service. These providers are permitted to process such information only for the purposes of providing safety, security, moderation, compliance, or fraud-prevention services to us.

Legal and Safety Reasons

  • We may disclose Face-Containing Images where reasonably necessary to comply with applicable law, legal process, valid governmental requests, court orders, or regulatory obligations, or to investigate, prevent, or address fraud, abuse, security incidents, violations of our Terms, or threats to the rights, safety, or property of Fraw, our users, or others.
  • Except as described in this Privacy Policy, we do not provide third parties with access to Face-Containing Images.

3.5 Where Face-Containing Images Are Stored

  • Face-Containing Images may be processed and stored on secure cloud servers provided by our cloud hosting and infrastructure providers, including Google Cloud Platform or other service providers we use to operate the Service. Data may be processed and stored in regions outside your country or region of residence. Please see Section 10, "International Data Transfers," for more information.
  • Face-Containing Images are protected using reasonable technical and organizational safeguards, including encryption in transit using TLS and encryption at rest where supported by the applicable storage system. Access to Face-Containing Images is limited to authorized personnel, systems, and service providers who need access to provide, secure, support, or legally operate the Service.

3.6 Retention of Face-Containing Images

We retain Face-Containing Images only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to applicable legal, security, fraud-prevention, dispute-resolution, creator-program, payout, tax, accounting, audit, enforcement, backup-retention, and operational requirements.

  • Temporary processing images: Images uploaded for AI processing that are not saved to your account gallery, associated with a saved extension, or otherwise retained as part of an account feature are automatically deleted from our active systems within 48 hours after generation is complete, unless a longer period is necessary for security, abuse prevention, legal compliance, dispute resolution, technical troubleshooting, enforcement of our Terms, or protection of legal rights.
  • Gallery images and generated content: If you choose to save generated images or other generated content to your account gallery, the saved content is retained for as long as your account is active, or until you delete it through available in-app controls, subject to the exceptions described in this Privacy Policy.
  • Original input images: If an original input image is saved to your account, gallery, extension, project, history, or other account feature at your request or as part of a feature you use, it is retained for as long as needed to provide that feature, or until you delete the relevant image, gallery item, project, account content, or account, subject to the exceptions described in this Privacy Policy.
  • Draft, temporary, or unsaved extension assets: If you create a draft, temporary, or unsaved extension that includes reference images, thumbnails, before-and-after images, generated examples, prompts, configurations, or other assets that may contain Face-Containing Images, those assets are retained while the draft, temporary, or unsaved extension remains available in your account or in the relevant creation flow. Draft, temporary, or unsaved extensions may be deleted individually through available in-app controls where such controls are provided. If you delete one through available controls, we will delete, remove, or de-identify associated assets from active systems within a reasonable period, subject to legal, security, fraud-prevention, dispute-resolution, enforcement, and backup-retention requirements.
  • Saved private extension assets: If you create or save a private extension that includes reference images, thumbnails, before-and-after images, generated examples, prompts, configurations, or other assets that may contain Face-Containing Images, those assets are retained while the private extension remains active, archived, visible in your account, or otherwise available through the Service. Individual deletion may not be available for saved private extensions. Instead, saved private extensions may be archived through available in-app controls. Archiving a private extension does not delete the extension or its associated assets.
  • Published or public extension assets: If you create, publish, or make available a public extension that includes reference images, thumbnails, before-and-after images, generated examples, prompts, configurations, or other assets that may contain Face-Containing Images, those assets are retained while the extension remains published, active, archived, visible in your account, previously used by a user, or otherwise available through the Service. Individual deletion may not be available for saved published or public extensions. Published or public extensions may be archived, unpublished, or otherwise managed through available in-app controls.
  • Archived extensions: Archiving an extension does not delete the extension or its associated assets. Archived extensions and related assets may remain stored and visible where needed to support account history, prior-use records, creator-program administration, fraud prevention, dispute resolution, audit, security, legal compliance, enforcement of our Terms, and backup-retention purposes.
  • Archived public extensions: When a public extension is archived, it is no longer made available for new public use, and users cannot initiate new generation or active extension-based image-processing functions from that archived extension. However, users who previously used the public extension may still be able to open limited general information, history, or record views relating to that archived extension, including related before-and-after images or generated results associated with their prior use. Archived public extension assets may therefore be retained for account history, prior-use records, creator-program administration, fraud prevention, dispute resolution, audit, security, legal compliance, enforcement of our Terms, and backup-retention purposes.
  • Unpublished public extensions: If you unpublish a public extension without deleting it, we will remove it from public availability, but may retain the extension and associated assets in your account or internal systems as described in this Privacy Policy. Users will not be able to initiate new public use of an unpublished extension unless it is republished or otherwise made available again through the Service.
  • Account deletion: When you delete your account, associated Face-Containing Images, including gallery images, original input images, generated content, draft or unsaved extension assets, saved extension records, archived extension records, and related account content, will be scheduled for deletion or de-identification from active systems within 30 days, unless retention is required or permitted by law, security needs, fraud-prevention obligations, creator-program administration, payout, tax or accounting obligations, audit requirements, dispute resolution, enforcement of our Terms, backup-retention practices, or protection of legal rights.
  • Third-party AI providers: When Face-Containing Images are transmitted to a third-party AI image-generation or image-processing provider, the provider may temporarily process and retain uploaded images or related processing data for limited technical, safety, security, debugging, abuse-prevention, service-reliability, or legal purposes, as permitted by the applicable provider terms and service configuration. During such temporary processing or retention, the provider processes the data under contractual terms, platform terms, data-processing agreements, or equivalent safeguards that restrict use of the data to providing, securing, supporting, or improving the specific service requested by Fraw. We do not authorize providers to use Face-Containing Images for unrelated advertising, resale, independent profiling, facial recognition, biometric identification, or unrelated model training. Where supported by the applicable provider terms or service configuration, we require or configure providers to delete or de-identify input images and related Face-Containing Images after processing or after any limited technical, safety, security, abuse-prevention, service-reliability, or legal retention period.
  • Backups: Deleted Face-Containing Images may remain in encrypted backups for a limited period until those backups are overwritten or deleted according to our backup retention schedule. Backup copies are not used for active processing except where restoration is necessary for security, disaster recovery, legal compliance, or service continuity.

3.7 Face-Containing Images Security

We apply reasonable technical, administrative, and organizational safeguards designed to protect Face-Containing Images from unauthorized access, loss, misuse, alteration, or disclosure, including encryption in transit and at rest, access controls, and regular security reviews.

4. How We Use Information

We may use personal information for the following purposes.

4.1 To Provide and Operate the Service

We use information to:

  • create and manage accounts;
  • authenticate users;
  • provide subscriptions, credits, top-ups, and official functions;
  • enable private and published extensions;
  • process creator participation and reward eligibility;
  • operate referral, promotional, and reward programs;
  • provide generated outputs and related features.

4.2 To Process Payments and Transactions

We use information to:

  • process subscriptions, renewals, top-up purchases, and related transactions;
  • verify purchases;
  • detect and resolve payment issues;
  • manage refunds, cancellations, chargebacks, and billing disputes.

4.3 To Improve and Maintain the Service

We use information to improve, maintain, secure, and support the Service. This may include using information to:

  • analyze feature usage, engagement, performance, and service reliability;
  • monitor crashes, errors, latency, system health, and technical performance;
  • debug technical issues and improve product quality, usability, safety, and stability;
  • develop, test, and improve new or existing features and services;
  • detect, investigate, and prevent fraud, abuse, spam, security incidents, policy violations, and misuse of the Service;
  • evaluate and improve internal safety, reliability, performance, fraud-prevention, abuse-prevention, moderation, and service-quality systems using aggregated, de-identified, anonymized, or non-face operational data where appropriate.

We do not use Face-Containing Images, uploaded face images, original input images containing faces, or generated face-containing outputs to train general-purpose artificial intelligence or machine-learning models, including facial-recognition, identity-matching, biometric-identification, or general-purpose image-generation models, unless we obtain your separate consent where required by applicable law.

We may use aggregated, de-identified, or anonymized information to understand service usage, improve system performance, enhance safety controls, and develop or improve features, provided that such information is not reasonably capable of identifying you.

4.4 To Enforce Rules and Protect the Platform

We use information to:

  • detect fraud, abuse, spam, and suspicious activity;
  • investigate self-dealing, manipulation, referral abuse, or creator misuse;
  • enforce our Terms, policies, and community rules;
  • protect the security, integrity, and reliability of the Service.

4.5 To Communicate With You

We may use information to:

  • send account, billing, subscription, or transactional notices;
  • respond to support requests;
  • provide service updates, security notices, or legal notices;
  • send marketing or promotional communications where permitted by law.

4.6 To Comply With Legal Obligations

We may use information to:

  • comply with laws, regulations, court orders, and lawful requests;
  • maintain tax, accounting, fraud, or audit records;
  • protect our legal rights and interests.

5. Legal Bases for Processing

Where required by applicable law, we process personal information on one or more of the following legal bases:

  • performance of a contract with you;
  • legitimate interests, such as operating, securing, improving, and enforcing the Service;
  • compliance with legal obligations;
  • your consent, where required;
  • other lawful bases permitted by applicable law.

6. How We Share Information

We do not sell your personal information. We also do not share personal information for cross-context behavioral advertising unless we provide any legally required notice and opt-out rights.

6.1 Service Providers

We may share information with vendors and service providers that perform services on our behalf, such as:

  • hosting and cloud providers;
  • analytics providers;
  • payment processors;
  • customer support providers;
  • security and fraud-prevention providers;
  • infrastructure and communications providers.

These parties may process personal information only as necessary to provide services to us, subject to contractual, platform, technical, organizational, or legal safeguards. Depending on the service, these providers may process information for hosting, storage, image generation, safety review, payment processing, analytics, fraud prevention, customer support, infrastructure, communications, or compliance purposes.

6.2 App Stores and Payment Platforms

Transactions made through Apple App Store, Google Play, or other platforms may involve data sharing with those platforms as necessary for billing, subscription management, verification, refunds, and compliance.

6.3 Other Users

If you publish an extension or otherwise use public-facing creator features, certain information may be visible to other users, such as:

  • your display name or creator name;
  • extension title, description, and related public metadata;
  • content you choose to make public through the Service.

6.4 Legal and Safety Reasons

We may disclose information where reasonably necessary to:

  • comply with law, regulation, or legal process;
  • respond to lawful requests by public authorities;
  • enforce our Terms and policies;
  • detect or prevent fraud, abuse, or security incidents;
  • protect the rights, safety, and property of Fraw, our users, or others.

6.5 Corporate Transactions

We may share information in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, subject to applicable confidentiality and legal protections.

7. Official Functions, Extensions, and Creator Data

Because Fraw includes official functions, private extensions, and published extensions, we may process information related to:

  • official function usage;
  • extension creation and editing;
  • extension publication and moderation;
  • creator eligibility review;
  • creator rewards, Diamonds, or withdrawal processing;
  • anti-fraud and anti-self-reward enforcement;
  • user interaction with published extensions.

Where extensions are published for other users, we may collect and use usage data relating to those extensions for moderation, analytics, fraud prevention, feature improvement, and creator-program administration.

7.1 Creator Payout and Withdrawal Records

If you apply for or use creator withdrawal, payout, or monetization features, we may collect and process information necessary to administer creator rewards or Diamonds, verify withdrawal eligibility, prevent fraud or misuse, process withdrawal requests, maintain transaction records, comply with applicable legal obligations, and enforce our Terms and creator policies.

For the global version of the Service, Fraw does not directly collect government identification documents, tax identification numbers, tax forms, or other formal identity-verification or tax records from users as part of the standard account signup, login, creator participation, or withdrawal flow. Account signup and login may be supported through third-party authentication providers, such as Apple ID or Google login.

Creator payouts may be processed through third-party payout providers, such as PayPal, where available. When you use a third-party payout provider, you may be required to provide payout account information, identity information, tax information, or other compliance-related information directly to that provider. That provider's collection, use, retention, and disclosure of such information are governed by its own terms, privacy policy, and legal obligations.

Fraw may receive or retain limited information from or about the payout process, such as your Fraw account identifier, creator account status, withdrawal eligibility, withdrawal requests, payout status, payout amount, transaction reference, payout provider identifier, fraud-prevention signals, and related creator-program records.

We use this information to administer creator rewards or Diamonds, process and track withdrawal requests, prevent misuse of creator programs, maintain accurate records, resolve disputes, comply with applicable law, and enforce our Terms and creator policies.

Creator-program, withdrawal, payout-status, transaction, fraud-prevention, accounting, audit, and compliance records may be retained for the period required or permitted by applicable law, even after you delete your account, archive an extension, unpublish an extension, or stop participating in creator features.

8. Referral, Rewards, and Fraud Prevention

If you participate in referral, rewards, or promotional programs, we may collect and use data relating to:

  • invitations sent or accepted;
  • referral attribution;
  • signup and conversion events;
  • account relationships;
  • device, payment, and account signals;
  • suspected abuse or manipulation.

We use this information to operate referral programs, determine eligibility, prevent fraud, enforce program rules, and protect platform integrity.

9. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law. Retention periods may vary depending on the type of information, the purpose of processing, account status, user choices, legal requirements, security needs, fraud-prevention needs, creator-program administration, dispute-resolution needs, backup-retention practices, and operational requirements.

The following table describes our general retention practices:

Category of InformationGeneral Retention Period
Account informationRetained while your account is active. After account deletion, account information is deleted or de-identified from active systems within a reasonable period, unless retention is required or permitted for legal, security, fraud-prevention, dispute-resolution, tax, accounting, audit, enforcement, creator-program, payout, or backup purposes.
Contact and communication informationRetained while needed to communicate with you, provide support, maintain records, resolve disputes, comply with law, enforce our Terms, or protect our rights, users, and Service.
Device, technical, diagnostic, and usage informationRetained for the period reasonably necessary to operate, secure, debug, analyze, improve, and protect the Service, and to detect fraud, abuse, spam, security incidents, technical issues, or policy violations.
Transaction, subscription, top-up, and purchase recordsRetained for the period required or permitted for billing, refund handling, chargeback management, accounting, tax, audit, fraud-prevention, legal compliance, and dispute-resolution purposes.
Temporary processing imagesImages uploaded for AI processing that are not saved to your account gallery, associated with a saved extension, or otherwise retained as part of an account feature are deleted from active systems within 48 hours after generation is complete, unless a longer period is necessary for security, abuse prevention, legal compliance, dispute resolution, technical troubleshooting, enforcement of our Terms, or protection of legal rights.
Saved gallery images and generated contentRetained while your account is active, or until you delete them through available in-app controls, subject to legal, security, fraud-prevention, dispute-resolution, enforcement, creator-program, payout, tax, accounting, audit, and backup-retention requirements.
Original input imagesRetained only where saved to your account, gallery, extension, project, history, or other account feature at your request or as part of a feature you use. Such images are retained while needed to provide the relevant feature, or until you delete the relevant image, gallery item, project, account content, or account, subject to the exceptions described in this Privacy Policy.
Face-Containing ImagesRetained as described in Section 3.6, Retention of Face-Containing Images.
Draft, temporary, or unsaved extension assetsRetained while the draft, temporary, or unsaved extension remains available in your account or in the relevant creation flow. Draft, temporary, or unsaved extensions may be deleted individually through available controls where such controls are provided. If associated assets are deleted, they are deleted, removed, or de-identified from active systems within a reasonable period, subject to legal, security, fraud-prevention, dispute-resolution, enforcement, and backup-retention requirements.
Saved private extension assetsRetained while the private extension remains active, archived, visible in your account, or otherwise available through the Service. Archiving does not delete the extension or its associated assets. Individual deletion may not be available. If assets are deleted through available controls or account deletion, they are deleted, removed, or de-identified from active systems within a reasonable period, subject to applicable exceptions.
Published or public extension assetsRetained while the extension remains published, active, archived, visible in your account, previously used by a user, or otherwise available through the Service. Individual deletion may not be available. If assets are deleted through available controls or account deletion, they are deleted, removed, or de-identified from active systems within a reasonable period, subject to applicable exceptions.
Archived extension assetsArchiving does not delete the extension or its associated assets. Archived extensions and related assets may remain stored and visible where needed to support account history, prior-use records, creator-program administration, fraud prevention, dispute resolution, audit, security, legal compliance, enforcement of our Terms, and backup-retention purposes.
Archived public extension assetsWhen a public extension is archived, it is no longer made available for new public use, and users cannot initiate new generation or active extension-based image-processing functions from it. Users who previously used it may still be able to open limited general information, history, or record views, including related before-and-after images or generated results. Assets may be retained for account history, prior-use records, creator-program administration, fraud prevention, dispute resolution, audit, security, legal compliance, enforcement, and backup-retention purposes.
Unpublished public extension assetsIf you unpublish a public extension without deleting it, we remove it from public availability but may retain it and associated assets in your account or internal systems. Users cannot initiate new public use unless it is republished or otherwise made available again.
Extension assets deleted through available controls or account deletionWe delete, remove, or de-identify associated extension assets from active systems within a reasonable period, subject to legal, security, fraud-prevention, creator-program, payout, tax, accounting, audit, dispute-resolution, enforcement, and backup-retention requirements.
Referral, rewards, and fraud-prevention recordsRetained for the period reasonably necessary to operate referral or reward programs, determine eligibility, prevent abuse, investigate manipulation, enforce program rules, resolve disputes, and protect platform integrity.
Creator-program, withdrawal, payout-status, transaction, fraud-prevention, accounting, audit, and compliance recordsRetained for the period required or permitted for creator-program administration, withdrawal processing, payout tracking, accounting, audit, fraud-prevention, legal, and compliance obligations, even after you delete your account, archive or unpublish an extension, or stop participating in creator features.
Support requests, reports, complaints, and moderation recordsRetained for the period reasonably necessary to respond to requests, investigate reports, moderate content, resolve disputes, enforce our Terms, comply with law, protect rights and safety, and maintain appropriate business records.
Security logs and abuse-prevention recordsRetained for the period reasonably necessary to protect the Service, detect and prevent fraud, abuse, spam, security incidents, policy violations, or misuse, and to support investigations, enforcement, legal compliance, or dispute resolution.
De-identified, aggregated, or anonymized informationMay be retained for longer where permitted by law, provided that the information is not reasonably capable of identifying you.
BackupsDeleted information may remain in encrypted backups for a limited period until those backups are overwritten or deleted according to our backup retention schedule. Backup copies are not used for active processing except where restoration is necessary for security, disaster recovery, legal compliance, or service continuity.

When the purpose of collection or processing has been fulfilled, the applicable retention period has expired, or deletion is required by applicable law, we will delete, de-identify, anonymize, or otherwise securely dispose of personal information, unless retention is required or permitted for legal, tax, accounting, audit, security, fraud-prevention, dispute-resolution, enforcement, creator-program, payout, backup, or other legitimate purposes described in this Privacy Policy.

If you delete your account, or if saved content, images, draft or temporary extensions, extension assets, or other account materials are deleted through available controls, we will delete, remove, or de-identify the relevant information from active systems within a reasonable period, subject to the exceptions described in this Privacy Policy.

We may retain certain records where necessary to comply with law, process transactions, handle refunds or chargebacks, administer creator payouts, maintain tax or accounting records, investigate fraud or abuse, enforce our Terms, resolve disputes, protect legal rights, or comply with court orders, governmental requests, or regulatory obligations.

10. International Data Transfers

We operate the Service using cloud infrastructure, service providers, and technical systems that may be located in countries or regions other than where you live. As a result, your personal information may be processed, stored, accessed, or transferred outside your country or region of residence.

This may include account information, device and usage information, transaction records, support information, creator-program, withdrawal, or payout-status information where applicable, user content, uploaded images, generated content, extension assets, and Face-Containing Images where such information is processed as part of the Service.

We transfer personal information only where reasonably necessary to provide, operate, secure, support, analyze, improve, or legally administer the Service. This may include transfers to cloud hosting providers, storage providers, AI image-generation or image-processing providers, analytics providers, payment platforms, payout providers, customer support providers, security providers, fraud-prevention providers, and other service providers described in this Privacy Policy.

Where required by applicable law, we take appropriate steps to protect personal information transferred across borders. These steps may include contractual safeguards, data-processing agreements, provider due diligence, access controls, encryption in transit, encryption at rest where supported by the applicable storage system, technical and organizational security measures, and other recognized transfer mechanisms.

For transfers involving Face-Containing Images or face-containing content, we use safeguards designed to limit processing to the purposes described in this Privacy Policy, including providing the requested image-processing feature, supporting service reliability, performing safety or abuse-prevention checks, securing the Service, complying with legal obligations, and enforcing our Terms.

Some jurisdictions may require additional disclosures, consents, transfer mechanisms, or user rights for international transfers of personal information. Where required, we may provide supplemental regional notices or addenda that describe additional transfer-related information, such as the categories of information transferred, the recipients or types of recipients, the destination countries or regions, the purposes of transfer, the transfer methods, retention periods, and applicable user rights.

By using the Service, you acknowledge that your personal information may be processed and transferred as described in this Privacy Policy and any applicable regional notice or addendum.

11. Your Rights and Choices

Depending on where you live, you may have rights regarding your personal information. These rights may include the right to:

  • access personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion of certain personal information;
  • request restriction of processing;
  • object to certain processing;
  • withdraw consent where processing is based on consent;
  • request portability of certain information;
  • opt out of certain marketing communications;
  • appeal or challenge a decision relating to your privacy request where required by applicable law.

You may manage certain information directly in your account settings or through available in-app controls. Account deletion is available in the app. When you initiate account deletion, we will schedule deletion or de-identification of personal information associated with your account from active systems, subject to the limitations and exceptions described in this Privacy Policy.

You may delete individual saved images, generated content, and gallery items through available in-app controls. Gallery content is private to your account unless you choose to share it or use it in a feature that makes it available through the Service.

For extensions saved in your extension library or similar account area, individual deletion may not be available. Instead, you may archive saved extensions through available in-app controls. Archiving an extension does not delete the extension or its associated assets.

Archived extensions and related assets may remain stored and visible where needed to support account history, prior-use records, creator-program administration, fraud prevention, dispute resolution, audit, security, legal compliance, enforcement of our Terms, and backup-retention purposes.

Draft, temporary, or unsaved extensions may be deleted individually through available in-app controls where such deletion controls are provided.

When a public extension is archived, it is no longer made available for new public use, and users cannot initiate new generation or active extension-based image-processing functions from that archived extension. However, users who previously used the public extension may still be able to open limited general information, history, or record views relating to that archived extension, including related before-and-after images or generated results associated with their prior use.

If you unpublish a published extension, we will remove it from public availability, but we may retain the extension and associated assets in your account or internal systems as described in this Privacy Policy.

When you delete your account, we will schedule deletion or de-identification of personal information associated with your account, including account data, saved gallery content, generated content, original input images where stored, draft or unsaved extension data, saved extension records, archived extension records, and related account content, from active systems within a reasonable period, unless retention is required or permitted by applicable law, legal obligations, tax or accounting requirements, payment or payout processing requirements, fraud prevention, security, dispute resolution, enforcement of our Terms, protection of legal rights, creator-program administration, or backup-retention practices described in this Privacy Policy.

Deleted information may remain in encrypted backups for a limited period until those backups are overwritten or deleted according to our backup retention schedule. Backup copies are not used for active processing except where restoration is necessary for security, disaster recovery, legal compliance, or service continuity.

To exercise applicable privacy rights, contact us using the details in the Contact Us section below, or use any in-app privacy or account controls we make available. We may need to verify your identity before fulfilling a request.

You may also request account deletion or data deletion by contacting us at hi@fraw.ai.

We may decline, limit, or delay a request where permitted by law, including where the request is manifestly unfounded or excessive, where we cannot verify your identity, where fulfilling the request would conflict with legal obligations, tax or accounting obligations, payment or payout processing requirements, fraud-prevention needs, security requirements, creator-program administration, dispute-resolution needs, or the rights and freedoms of others.

You may opt out of marketing communications by using the unsubscribe link in the message or by contacting us. Even if you opt out of marketing communications, we may still send service-related, account-related, billing, security, transactional, and legal communications.

12. Marketing Communications

We may send you marketing or promotional communications where permitted by law. You may opt out of marketing communications as described in Section 11. Even if you opt out, we may still send service-related, account-related, billing, security, transactional, and legal communications.

13. Children's Privacy

The Service is not intended for children below the age permitted under applicable law to use the Service without parental consent.

We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided us with personal information unlawfully, please contact us so we can investigate and take appropriate action.

14. Security

We use reasonable technical, administrative, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.

However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

You are responsible for keeping your account credentials secure and for using the Service in a secure manner.

15. Third-Party Services and Links

The Service may contain links to or integrations with third-party websites, products, login systems, payment services, app stores, or tools.

This Privacy Policy does not apply to those third parties. Your interactions with those services are governed by their own terms and privacy policies.

16. Regional Disclosures

Depending on where you live, you may be entitled to additional privacy disclosures, rights, choices, or protections under applicable local privacy laws.

Where required by applicable law, supplemental regional notices or addenda may apply in addition to this Privacy Policy.

If a regional notice or addendum applies to you:

  • it forms part of this Privacy Policy;
  • it should be read together with this Privacy Policy;
  • it may provide additional information about Fraw’s processing practices, legal obligations, international transfers, user rights, complaint procedures, children’s privacy, security, creator data, or regional regulatory requirements; and
  • if there is a conflict between this Privacy Policy and the applicable regional notice or addendum, the regional notice or addendum will apply to the extent required by applicable law.

Regional notices and addenda do not necessarily mean that every feature, creator function, payment method, payout method, or other part of the Service is available in the relevant country or region.

United States

If you are located in the United States, please review our United States Privacy Addendum.

The United States Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • U.S. state privacy rights;
  • California privacy disclosures;
  • Face-Containing Images;
  • biometric-information clarification;
  • sensitive personal information;
  • sale and sharing disclosures;
  • targeted or cross-context behavioural advertising;
  • retention and deletion;
  • privacy request methods; and
  • other rights available under applicable U.S. state privacy laws.

Canada

If you are located in Canada, including Quebec, please review our Canada Privacy Addendum.

The Canada Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • meaningful consent;
  • cross-border processing;
  • access and correction rights;
  • privacy complaints;
  • safeguards;
  • Quebec-specific privacy requirements;
  • automated processing where applicable; and
  • contact information under applicable Canadian privacy laws.

Australia

If you are located in Australia, please review our Australia Privacy Addendum.

The Australia Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • overseas disclosures;
  • access and correction rights;
  • privacy complaints;
  • sensitive information;
  • security and safeguards;
  • data-breach handling; and
  • how we protect personal information under applicable Australian privacy laws.

Republic of Korea

If you are located in the Republic of Korea, please review our Korea Privacy Addendum.

The Korea Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • collection and use of personal information;
  • legal grounds and consent;
  • outsourcing and service providers;
  • overseas transfers;
  • retention and destruction;
  • data-subject rights;
  • children’s personal information;
  • security safeguards; and
  • protection of personal information under applicable Korean privacy laws.

India

If you are located in India, please review our India Privacy Addendum.

The India Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • processing of digital personal data relating to individuals in India;
  • notices and consent;
  • withdrawal of consent;
  • access, correction, completion, updating, and erasure rights;
  • grievance redressal;
  • nomination rights where applicable;
  • Face-Containing Images and AI processing;
  • processing outside India;
  • data retention and deletion;
  • children’s personal data;
  • security safeguards;
  • personal-data breaches and cybersecurity incidents;
  • creator, Diamond, withdrawal, and payout information; and
  • other rights and obligations under applicable Indian law.

Indonesia

If you are located in Indonesia, please review our Indonesia Privacy Addendum.

The Indonesia Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • Fraw’s role as a Personal Data Controller;
  • categories, sources, purposes, and legal bases for processing personal data;
  • consent and withdrawal of consent;
  • Face-Containing Images and AI processing;
  • personal data relating to other individuals;
  • Personal Data Processors and other recipients;
  • international transfers and processing outside Indonesia;
  • retention, deletion, destruction, and de-identification;
  • personal-data subject rights;
  • privacy requests and complaints;
  • security safeguards;
  • personal-data breaches and cybersecurity incidents;
  • lawful governmental and regulatory requests;
  • user-generated content and content complaints;
  • children’s personal data and child-safety requirements;
  • automated processing and moderation;
  • creator, Diamond, withdrawal, and payout information;
  • electronic-system and regulatory-registration matters where applicable; and
  • other protections and obligations under applicable Indonesian law.

Bangladesh

If you are located in Bangladesh, please review our Bangladesh Privacy Addendum.

The Bangladesh Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • Fraw’s processing of personal data relating to individuals in Bangladesh;
  • the categories, sources, purposes, and legal grounds for processing personal data;
  • notices, consent, and withdrawal of consent;
  • sensitive or specially protected personal data;
  • Face-Containing Images and AI image processing;
  • personal data relating to other individuals;
  • Personal Data Processors, service providers, and other recipients;
  • international transfers and processing outside Bangladesh;
  • data classification, localization, and regulatory-record requirements where applicable;
  • data retention, deletion, destruction, anonymization, and de-identification;
  • personal-data rights and privacy-request procedures;
  • complaints and grievance handling;
  • security safeguards;
  • personal-data breaches and cybersecurity incidents;
  • lawful governmental, regulatory, and law-enforcement requests;
  • user-generated content, Published Extensions, and content complaints;
  • children’s personal data;
  • automated processing and moderation;
  • cookies, mobile SDKs, analytics, and similar technologies;
  • creator, Diamond, withdrawal, and payout information;
  • regulatory registration, local-representative, or responsible-contact requirements where applicable; and
  • other protections, rights, and obligations under applicable Bangladesh law.

Vietnam

If you are located in Vietnam, please review our Vietnam Privacy Addendum.

The Vietnam Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • Fraw’s processing of personal data relating to individuals in Vietnam;
  • the categories, sources, purposes, and legal grounds for processing personal data;
  • basic and sensitive personal data;
  • notices, consent, and withdrawal of consent;
  • Face-Containing Images and AI image processing;
  • personal data relating to other individuals;
  • account authentication and phone-number verification where applicable;
  • Personal Data Processors, service providers, and other recipients;
  • personal-data processing impact assessments;
  • international transfers and processing outside Vietnam;
  • cross-border transfer impact assessments;
  • data localization, local-presence, registration, or representative requirements where applicable;
  • data retention, deletion, destruction, anonymization, and de-identification;
  • data-subject rights, duties, and privacy-request procedures;
  • complaints and grievance handling;
  • security safeguards;
  • personal-data breaches and cybersecurity incidents;
  • lawful governmental, regulatory, and law-enforcement requests;
  • Published Extensions, public information, user-generated content, and content complaints;
  • children’s personal data;
  • automated processing and moderation;
  • cookies, mobile SDKs, analytics, and similar technologies;
  • creator, Diamond, withdrawal, and payout information;
  • consumer transactions;
  • platform-classification and public-content requirements where applicable; and
  • other protections, rights, and obligations under applicable Vietnamese law.

European Economic Area and United Kingdom

If you are located in the European Economic Area or the United Kingdom, please review our European Economic Area and United Kingdom Privacy Addendum.

The European Economic Area and United Kingdom Privacy Addendum supplements this Privacy Policy and provides additional information concerning:

  • Fraw’s role as a controller;
  • the purposes and lawful bases for processing personal data;
  • legitimate interests;
  • consent and withdrawal of consent;
  • special-category and sensitive personal data;
  • Face-Containing Images and AI image processing;
  • processors, service providers, and other recipients;
  • international transfers and applicable transfer safeguards;
  • cookies, mobile SDKs, analytics, and similar technologies;
  • data retention and deletion;
  • automated processing, moderation, and decisions;
  • access, rectification, erasure, restriction, objection, portability, and other data-protection rights;
  • privacy-request procedures;
  • supervisory-authority complaints;
  • children’s personal data;
  • security and personal-data-breach handling;
  • creator, Diamond, withdrawal, and payout information;
  • the current status of Fraw’s EU and UK representative arrangements; and
  • other protections and obligations under applicable European and UK data-protection law.

Other Regional Notices

For users in other countries or regions with specific privacy-law requirements, additional regional notices or addenda may be provided where required or considered appropriate.

Additional regional notices may address matters including:

  • categories and purposes of personal-data processing;
  • legal grounds or consent;
  • sensitive or specially protected information;
  • children’s personal data;
  • international transfers;
  • retention and deletion;
  • data-subject or consumer rights;
  • privacy complaints;
  • data-breach notification;
  • local representatives or privacy contacts;
  • creator, payment, or payout information;
  • automated processing;
  • electronic-system operation; and
  • other country-specific legal requirements.

When we provide an additional regional notice or addendum, we may make it available:

  • through this Privacy Policy;
  • within the Service;
  • on the Fraw website;
  • through an app-store listing;
  • by email;
  • through an account notice; or
  • by another reasonable method.

The availability of a regional privacy addendum does not itself guarantee that the Service or every feature of the Service is available in that country or region.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

If we make material changes, we may provide notice through the Service, by email, or by other reasonable means, as required by law.

Your continued use of the Service after the updated Privacy Policy becomes effective means you acknowledge the revised policy.

18. Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or our privacy practices, please contact us at:

  • Untitled Labs Limited
  • Address: 20/F, Harbourside HQ, 8 Lam Chak Street, Kowloon Bay, Kowloon
  • Support Email: hi@fraw.ai
  • Company Registration: 71095371