Fenra Privacy Policy
Last updated: 17.12.2025
This Privacy Policy explains how Fenra collects, uses, shares, and protects personal information when you access or use Fenra at fenra.io, app.fenra.io, and any related Fenra subdomains (the "Service").
The Service is provided by O.D. Hechim ("Company," "we," "us," or "our").
This Privacy Policy describes two roles.
- Controller activities: We are the data controller for personal information we collect and use to operate Fenra, such as account administration, billing, security, and communications.
- Processor activities: When an organization uses Fenra and submits Customer Data, we typically process that Customer Data on behalf of that organization. In that context, the customer organization acts as the controller and we act as a processor.
If you do not agree with this Privacy Policy, do not use the Service.
1. Scope
This Privacy Policy is intended to support compliance with applicable data protection laws, including Bosnia and Herzegovina personal data protection requirements, and where applicable the EU General Data Protection Regulation (GDPR).
This Privacy Policy applies to:
- Visitors to fenra.io and app.fenra.io (and any related Fenra subdomains)
- Registered users of Fenra (including users who access Fenra via app.fenra.io)
- People who receive emails from us related to Fenra, such as invitations, alerts, product announcements, release notes, new feature updates, security notices, billing notices, and notices about changes to our Terms of Service or Privacy Policy.
This Privacy Policy does not cover third-party websites, services, or applications that you may access through Fenra.
2. Contact
O.D. Hechim
Sarajevo 71000, Bosnia and Herzegovina
Email: support@fenra.io
3. Personal Information We Collect
We collect information in the following categories.
3.1 Account and Organization Information
- Email address
- First name and last name
- Organization name
- Role within an organization (OWNER, ADMIN, VIEWER)
- Authentication related identifiers (for example user IDs, session tokens)
Passwords are handled by our authentication provider and are not stored by Fenra in plaintext.
3.2 Service Usage and Administrative Data
- API key records (API keys are stored as hashes and key prefixes for identification)
- API key usage timestamps (such as last used time)
- Team invitations (invitee email, inviter identity, role, token, expiration, status)
- Notification settings (thresholds, filters, recipients, throttling)
- Notification history (trigger events, delivery status, errors)
- Metadata registry (unique metadata keys and values observed within an organization)
3.3 LLM Transaction Data and Metadata Submitted by Customers
Fenra may process Customer submitted transaction information to calculate estimated usage and costs and to provide dashboards, analytics, reports, and alerts. Transaction information may include:
- Provider and model information
- Usage metrics (token counts and modality related usage such as text, image, audio, video)
- Customer defined metadata (key value pairs such as environment, project, internal user IDs, and feature names)
- Pricing configuration references and cost calculation results
Fenra is designed to track usage and costs. Customers control what they submit.
Important: You should avoid submitting personal data within transaction payloads or metadata unless it is necessary and you have a lawful basis to do so.
Prompts and Model Outputs
Fenra does not collect or store prompts or model outputs as a product feature.
However, Customers may choose to include prompt text, model outputs, or other content inside metadata fields or payloads. If they do, Fenra will process and store that content as Customer Data under the Customer’s instructions, subject to the Customer’s configured retention and deletion actions.
3.4 Technical and Log Data
When you use the Service, we may collect:
- IP address
- Device and browser information (for example user agent)
- Request timestamps and request identifiers
- Basic security and operational logs
3.5 Billing and Subscription Information
If you purchase a paid plan, we and our payment processor may process billing and subscription information such as:
- Plan selection, subscription status, and renewal dates
- Invoice and payment status
- Billing contact details provided by you (for example name, email, company name, address)
Payment card details are handled by our payment processor. We do not store full payment card numbers.
3.6 Cookies and Similar Technologies
Fenra may use cookies or similar technologies (such as local storage) to:
- Keep you signed in
- Maintain session state and security protections
- Remember preferences
You can control cookies through your browser settings. Disabling certain cookies may cause the Service to not function properly.
4. How We Use Personal Information
We use personal information to:
- Provide, operate, and maintain Fenra
- Create and manage accounts and organizations
- Authenticate users and enforce role based access controls
- Process Customer Data to calculate estimated usage and costs and to provide analytics and reporting
- Send operational emails, including invitations and cost alerts
- Provide customer support and respond to inquiries
- Monitor, prevent, and investigate fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms of Service
5. Legal Bases for Processing
Where required by applicable law, we rely on the following legal bases:
- Contract: to provide Fenra under our Terms of Service
- Legitimate interests: to secure, improve, and operate Fenra, prevent abuse, and support customers
- Consent: where we ask for it, such as for certain optional communications
- Legal obligation: to comply with applicable laws and lawful requests
6. How We Share Personal Information
We may share personal information in the following circumstances.
6.1 Service Providers and Subprocessors
We use third party vendors to help provide the Service, such as:
- Authentication provider: Supabase
- Email delivery: SendGrid
- Infrastructure and hosting: AWS services such as compute, database, and messaging
- Payments and subscription management: a third party payment provider
These vendors process personal information on our behalf to provide their services to us, under contractual obligations.
6.2 LLM Providers
Fenra may store or display transaction records that originate from LLM provider APIs via customer systems.
Fenra does not share your stored Fenra transaction records with LLM providers unless you explicitly configure an integration that requires it.
LLM providers are independent third parties. Your use of those providers is governed by their terms and policies.
6.3 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction.
We may transfer personal information to a successor entity in connection with a corporate reorganization or change of legal entity operating Fenra.
6.4 Legal and Safety
We may disclose personal information if we believe it is necessary to:
- Comply with law, regulation, legal process, or lawful requests
- Protect the rights, property, and safety of the Company, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
6.5 No Sale of Personal Information
We do not sell personal information.
7. International Data Transfers
Your information may be processed in countries other than Bosnia and Herzegovina, depending on where our vendors and infrastructure operate.
When we transfer personal information internationally, we use appropriate safeguards where required, such as contractual protections and vendor transfer mechanisms. Where GDPR applies, these safeguards may include Standard Contractual Clauses and vendor transfer safeguards.
8. Data Retention
We retain personal information for as long as necessary to provide Fenra, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.
8.1 Retention by Plan
Fenra includes plan based data retention periods for LLM transaction data and related analytics:
- Hobby: 30 days retention
- Standard: 1 year retention
- Pro: 3 years retention
- Enterprise: as agreed
Certain operational records may be retained longer where necessary for security, billing, audit, backups, or legal compliance.
Account records may be retained while your account is active and for a reasonable period afterward. Billing and tax records may be retained as required by law. Security logs may be retained for a limited period for fraud prevention and system integrity.
8.2 Deletion
Customers can delete certain records within the Service. Organization deletion may result in cascading deletion of associated data.
Deletion may not immediately remove data from backups, which are retained for limited periods and protected.
9. Security
We implement reasonable administrative, technical, and organizational measures designed to protect personal information.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights and Choices
Depending on your location and applicable law, you may have rights to:
- Access and obtain a copy of personal information
- Correct inaccurate or incomplete information
- Request deletion
- Object to or restrict certain processing
- Data portability where applicable
- Withdraw consent where processing is based on consent
To exercise rights, contact support@fenra.io. We may need to verify your identity. We may deny or limit requests where permitted by law.
We aim to respond within 30 days, subject to extensions permitted by law.
11. Complaints
If you believe your personal information has been processed unlawfully, you may have the right to lodge a complaint with the competent supervisory authority.
In Bosnia and Herzegovina, this is the Personal Data Protection Agency.
12. Children
Fenra is not intended for children under 16.
We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
If changes are material, we will provide notice by posting within Fenra, on fenra.io, or by email. Continued use after the effective date means you accept the updated policy.
14. Customer Content and Use Restrictions
If you use Fenra on behalf of an organization, your organization controls the Customer Data submitted to Fenra.
We process Customer Data only to provide, secure, and support the Service, including cost estimation, analytics, reporting, and alerts, and to comply with law.
We do not use Customer Data to train generalized AI models.
We may use aggregated and de identified information derived from Service usage to operate, protect, and improve Fenra, including for analytics about Service performance and feature usage.
Enterprise customers may request a data processing addendum or other contractual terms.