Privacy Policy — Friends & Robots
Last updated: 2 July 2026
1. Who we are (data controller)
Friends & Robots FZCO ("Friends & Robots", "we", "us", "our"), a company registered in the United Arab Emirates with registered address at Unit No: UT-12-CO-53 DMCC Business Centre Level No 12 Uptown Tower, Dubai, UAE, is the controller of personal data processed through our websites, desktop application, agents, hosted media operations, support services, and related features (together, the "Service").
For questions about this policy or your data, contact privacy@fnrb.com.
2. What personal data we collect
We collect the following categories of personal data, depending on how you use the Service:
- Account and identity data — your name, email address, account identifier, profile information, and sign-in provider received from Google or Apple.
- Service content — prompts, instructions, conversations, session names, files, images, video, audio, text, URLs, generated outputs, and associated metadata that you submit to or create with hosted features.
- Billing and transaction data — subscription, credit balance, purchases, invoices, billing status, payment method type, card brand, last four digits, expiry, and transaction identifiers. Stripe processes complete payment-card details; we do not store them.
- Support data — support-agent conversations, tickets, emails, attachments, diagnostic information, and records of how an issue was resolved.
- Usage and device data — IP address, device and application identifiers, operating system, browser and application version, language, referring URL, pages and features used, interactions, timestamps, credit usage, operation status, crash data, diagnostics, and security logs.
- Communications and marketing data — email address, subscription preferences, and engagement with service or marketing messages.
- Information you provide about other people — for example, personal data contained in uploaded media, prompts, or support requests.
Please do not submit special-category, highly sensitive, confidential, or legally protected information unless it is necessary for your requested use and you have the right and a lawful basis to provide it.
3. Local and hosted processing
Sessions are stored in folders on your Mac. Bundled media-processing tools run locally in the session folder and are designed to operate without internet access. We do not automatically receive every file stored in a session folder merely because it exists there.
Account functions, agent conversations, support, billing, and some media operations use hosted services. When you request or approve a hosted operation, the Service may transmit the relevant prompt, instructions, media, and metadata to our servers and the third-party provider needed to perform it. The result is returned to the application and may be saved in your local session folder.
4. Why we use personal data and our legal bases
| Purpose | Personal data | Legal basis |
|---|---|---|
| Create and manage accounts; authenticate users; provide conversations, media operations, credits, subscriptions, billing, and support | Account, identity, Service content, transaction, support, usage, and device data | Contract — to provide the Service you request. |
| Process payments, maintain financial records, prevent fraud, and enforce our Terms | Account, identity, transaction, usage, device, and support data | Contract, legal obligation, and our legitimate interests in protecting the Service and recovering valid amounts. |
| Secure, troubleshoot, monitor, analyze, and improve the Service | Usage, device, diagnostic, security, support, and de-identified information | Our legitimate interests in maintaining a secure, reliable, and effective Service. |
| Send transactional and service communications | Account, transaction, support, and communications data | Contract and our legitimate interests in communicating about the Service. |
| Send marketing messages and manage marketing preferences | Email address and communications data | Consent where required; otherwise our legitimate interests, subject to your right to opt out. |
| Comply with law, lawful requests, and protect legal rights and safety | As required | Legal obligation, legitimate interests, or protection of vital interests, as applicable. |
Where we rely on legitimate interests, we balance those interests against your rights and reasonable expectations. We do not use your Input or Output to train general-purpose generative models, and we do not authorize model providers to do so, unless you affirmatively opt in through a training-data control that describes the use. Participation is optional and is not required to use the Service. You may withdraw your consent at any time for future use; withdrawal does not affect processing that occurred before it.
We do not sell personal data, share it for cross-context behavioural advertising, or use it to make solely automated decisions that produce legal or similarly significant effects.
5. Who we share personal data with
We share personal data only as reasonably necessary with:
- Authentication providers — Google and Apple, when you choose to sign in through them.
- Payment provider — Stripe, which processes payments and operates the billing portal.
- Model and media providers — providers that perform requested image, video, audio, transcription, enhancement, and stock-media operations. The current providers are described in our documentation and may change as the Service evolves.
- Hosting, storage, rendering, and infrastructure providers — including Microsoft Azure and providers used to queue, process, deliver, secure, and monitor hosted operations.
- Analytics provider — PostHog, which helps us understand website and Service usage and diagnose problems.
- Email provider — Mailchimp, which stores subscription preferences and sends marketing or update emails.
- Support and professional advisers — providers and advisers who help us deliver support, investigate incidents, comply with law, and protect our rights.
Providers may process and temporarily retain prompts, media, and related data under their applicable terms, privacy notices, and agreements with us. Retention and processing locations may differ by provider and operation.
We may also disclose personal data in connection with a merger, financing, reorganization, sale of assets, insolvency, or acquisition; when required by law, court order, or lawful government request; or where reasonably necessary to protect the rights, safety, and security of users, the public, Friends & Robots, or the Service.
6. International data transfers
We are based in the United Arab Emirates and use providers in the United States and other countries. Your personal data may therefore be processed in countries whose privacy laws differ from those where you live.
Where required, we use recognized transfer safeguards, such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate. You may contact us for information about the safeguard relevant to your data.
7. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purposes described above. The period depends on the nature of the data, whether your account remains active, provider processing periods, security and support needs, limitation periods, and legal requirements.
- Account data is generally retained while your account is active and for a limited period after deletion where needed for recovery, security, dispute resolution, or legal compliance.
- Service content and hosted media-job data is retained for as long as needed to provide the requested operation, maintain account functionality, handle support or disputes, and meet security or legal requirements. Third-party provider retention periods may differ.
- Billing, transaction, and invoice records are retained for the period required by tax, accounting, anti-fraud, and other applicable laws.
- Support records are retained for as long as needed to resolve the issue, maintain an appropriate support history, and establish or defend legal claims.
- Security, diagnostic, and analytics data is retained for a limited period appropriate to its operational purpose and may then be aggregated or de-identified.
- Marketing data is retained until you unsubscribe or we determine it is no longer needed. We may retain a minimal suppression record so we do not contact you again.
Deletion from active systems may not immediately remove data from encrypted backups. Backup copies are isolated, retained for a limited period, and deleted or overwritten in the ordinary course. We may retain data longer where required by law, to resolve disputes, enforce agreements, prevent fraud or abuse, or protect legal rights.
8. Your privacy rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate personal data;
- Erase your personal data ("right to be forgotten");
- Restrict or object to our processing;
- Withdraw consent at any time (without affecting the lawfulness of processing before withdrawal);
- Receive a portable copy of the data you provided to us;
- Lodge a complaint with an applicable data-protection authority.
These rights vary by jurisdiction and may be subject to exceptions. California residents may also have rights to know, correct, delete, and obtain a copy of personal information and to limit certain uses of sensitive personal information. We do not sell personal information or share it for cross-context behavioural advertising. We will not discriminate against you for exercising a privacy right.
To exercise a right, request account deletion, or appeal a decision about a request, contact privacy@fnrb.com. We may need to verify your identity and authority before acting. Authorized agents may submit requests where permitted by law. You can opt out of marketing emails using the unsubscribe link in any such message; you may still receive transactional or service communications.
9. Cookies, analytics, and similar technologies
Our websites and Service use cookies, local storage, software development kits, and similar technologies for authentication, security, preferences, analytics, and performance. PostHog may receive page views, interactions, device information, approximate location derived from IP address, and identifiers used to distinguish browsers or sessions.
We do not use third-party advertising cookies. Where law requires consent for non-essential analytics, we request it before enabling those technologies. You can use available cookie controls, browser settings, or device settings to restrict them, although necessary features may not function correctly without essential storage.
10. Children
The Service is intended only for people aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided personal data through the Service, contact us so we can investigate and delete it where appropriate.
11. Security and your responsibilities
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, use, alteration, disclosure, or destruction. These measures include access controls and safeguards appropriate to the nature of the data and processing.
No internet service, provider, sandbox, or device is completely secure. The desktop application can run commands within session folders, and a defect, model error, malicious file, or security failure could cause unintended access or disclosure. Use the command-approval setting when you want to review commands, maintain current backups, secure your sign-in account and device, and do not place secrets or irreplaceable material in a session folder.
If we become aware of a personal-data breach, we will investigate and notify affected people and regulators where required by applicable law.
12. Third-party services and links
The Service may link to or integrate with third-party services. Their handling of personal data for their own purposes is governed by their privacy notices, not this policy. Review those notices before providing data directly to them.
13. Changes to this Privacy Policy
We may update this policy to reflect changes to the Service, providers, law, or our practices. We will post the updated version with a new "Last updated" date. If a change materially affects your rights or how we use personal data, we will provide reasonable notice through the Service, by email, or on our website.
14. Contact
For any privacy question, complaint, or rights request, contact privacy@fnrb.com or write to Unit No: UT-12-CO-53 DMCC Business Centre Level No 12 Uptown Tower, Dubai, UAE.