Privacy Policy
How Gray Matter Labs, Inc. collects, uses, and protects your personal information.
Introduction
Gray Matter Labs, Inc. (“Company”, “we”, “us”, or “our”) operates Frugal, an AI API cost management service (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service or visit our website.
Gray Matter Labs, Inc. is incorporated in the State of Delaware, United States. By using the Service, you agree to the practices described in this Privacy Policy.
Information Collection
Information You Provide
- Email address — when you join our waitlist, create an account, or contact us.
- API keys — provided to connect your AI provider accounts. Encrypted with AES-256 before storage and never appear in plaintext in our systems.
- Payment information — processed by Stripe. We do not store card numbers or payment credentials on our servers.
- Profile information — name and any other details you provide when creating an account.
Information Collected Automatically
- Usage data — pages visited, features used, timestamps of actions.
- Log data — IP address, browser type, referring URLs, and other technical identifiers.
- Cookies and local storage — session tokens and user preferences. See our Cookie Policy for details.
AI Provider Usage Data
How We Use Your Data
- To provide, operate, and improve the Service.
- To send transactional communications: account confirmations, budget alert notifications, and billing receipts.
- To send waitlist and launch updates (you can unsubscribe at any time).
- To respond to support requests and communications.
- To comply with legal obligations and enforce our Terms of Service.
- To detect and prevent fraud, abuse, and security incidents.
- To analyze usage patterns and improve product features.
We do not sell your personal information to third parties. We do not use your data to train AI or machine learning models.
Data Sharing
We may share your information with:
- Service providers — Vercel (hosting), Supabase (database), Upstash (caching), Stripe (payments), Resend (email delivery). These providers process data only as necessary to provide their services to us.
- Legal requirements — when required by law, court order, or governmental authority.
- Business transfers — in connection with a merger, acquisition, or sale of assets, with advance notice to you.
Data Security
We implement industry-standard security measures including:
- AES-256 encryption for all stored API keys
- TLS/HTTPS encryption for all data in transit
- Row-level security (RLS) on all database tables — no row accessible without authenticated user context
- Strict access controls and authentication requirements
No method of internet transmission is 100% secure. We take commercially reasonable precautions to protect your data, but cannot guarantee absolute security.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated data at any time by contacting us. We will delete or anonymize your data within 30 days, except where retention is required by law.
Waitlist email addresses are retained until you unsubscribe or request deletion.
Your Rights
General Rights
- Access the personal information we hold about you
- Correct inaccurate personal information
- Request deletion of your personal information
- Object to or restrict processing of your personal information
- Receive your data in a machine-readable format (data portability)
- Withdraw consent at any time where processing is based on consent
GDPR Rights
CCPA Rights
Additional Information
Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us immediately.
International Transfers
Your information may be transferred to and processed in the United States and other countries where our service providers operate. When transferring data from the EEA or UK, we rely on Standard Contractual Clauses or other appropriate safeguards as required by applicable law.
Contact Us
Gray Matter Labs, Inc.
Registered Agent in the State of Delaware, USA
Privacy inquiries: privacy@getfrugal.dev
General: hello@getfrugal.dev