Fresko

Fresko Privacy Policy

Fresko is an AI-powered marketing assistant operated by Fresko AI Ltd, registered in England and Wales (company no. 17324246), 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We are the controller of the personal data described here under UK and EU data protection law (GDPR).

Contact for anything in this policy: legal@fresko.ai

This policy covers fresko.ai, app.fresko.ai, and emails we send. We never sell personal data.

1. What we collect

From you: email, name, password (stored hashed), language, invite code; your business website URL and social handles; briefs, onboarding answers and edits; documents and images you upload; waitlist sign-ups (email, website, page, language); messages you send us. You need an email address (or Google sign-in) to create an account — without it we cannot provide the Service; everything else you provide is optional. If you sign in with Google, we receive only your Google email, name and account ID. If you connect social accounts for publishing (e.g. Instagram, Facebook, LinkedIn, X), we store the access tokens and account details needed to post on your behalf, and the performance of content published through Fresko (views, likes, comments and similar metrics).

Automatically: product usage events, device and browser type, IP address (and the approximate location derived from it), referral source; technical logs for security and debugging; cookies and similar storage (see §9). Session recordings of how you interact with our pages may be collected for usability improvement — typed text is masked in recordings.

From public sources: to analyse your business we collect publicly available content from the website and social profiles you point us at (page text, images, brand assets, public posts and profile data), and — for inspiration features — from other public social accounts and news sources in your industry.

2. Data about other people

Scraped public content can include personal data about people we have no relationship with — for example team bios or customer testimonials on your website, or public posts by other accounts. We collect only what is publicly posted (never private messages, non-public follower lists or comment threads), we don't use it to contact or profile private individuals, and we delete it on the schedule in §8. Legal basis: legitimate interests (Art. 6(1)(f)). If you are one of these people, you can ask what we hold, object, or have it deleted: legal@fresko.ai — actioned within one month (extendable for complex requests, as the GDPR permits — we will tell you if so).

If content you upload contains personal data about your staff or customers, you are the controller of that data and we process it as your processor under the Data Processing Annex in our Terms. Where we use such content to improve Fresko (§3), we act as a controller and only with aggregated or de-identified data.

3. Why we process data (legal bases)

PurposeBasis (Art. 6(1))
Providing the Service: accounts, sign-in, analysing your business, generating strategies and content, transactional emailsContract (b)
Waitlist and product updates you requestConsent (a)
Marketing emails to existing customers about our similar services (opt-out at sign-up and in every email)Legitimate interests (f), relying on the UK e-privacy "soft opt-in"
Product analytics and session recordingsConsent (a), collected via the consent tool in §9
Improving Fresko: learning which content and strategies perform well, refining our prompts, templates and features, and producing aggregated, anonymised industry benchmarks — where content includes personal data about people other than you, only in aggregated or de-identified formLegitimate interests (f)
Security, abuse prevention, enforcing our Terms, defending legal claimsLegitimate interests (f)
Tax and accounting recordsLegal obligation (c)

We make no automated decisions with legal or similarly significant effects about you.

4. AI processing

To analyse your business and generate content we send relevant data (scraped content, briefs, uploads) to the AI providers listed below. They process it only to return results and are contractually restricted from using your personal data in identifiable form to train their models. We do, however, use your content and its performance to improve Fresko itself (see §3) — that learning stays with us, not with the model providers. We keep AI usage records (token counts and costs) that contain no content.

5. Who we share data with

Service providers processing data on our instructions under data-processing agreements:

ProviderPurposeLocation
Google CloudHosting, loggingEU
NeonDatabaseEU (Frankfurt)
CloudflareSite hosting, storage (EU jurisdiction), deliveryEU storage, global edge
UpstashJob queue and temporary authentication stateUnited States
Google (Gemini), AnthropicAI analysis and generationUS
fal.aiAI image and video generationUS
LangfuseAI quality telemetryEU
AmplitudeProduct analyticsEU
BrevoEmailEU (France); some of its sub-processors are in the US
ApifyPublic social data collectionEU (Czechia) and US
Sentry, Better Stack, UptraceErrors and monitoringUS
Google Tag ManagerMarketing-site measurement tagsUS

If a paid plan is offered through Stripe Managed Payments, Link will act as merchant of record for that payment. Stripe and Link will handle payment and card details under their applicable privacy policies; Fresko will not see full card details. Independent controllers: the social platforms you connect and publish to (Meta, LinkedIn, X — under their own terms and privacy policies), Google (if you sign in with Google), our professional advisers, and authorities where legally required. In a merger or sale, data may transfer under confidentiality; we'd notify you.

6. Government and law enforcement requests

If a public authority asks us for personal data, we treat the request as contested until we're satisfied it's lawful. A designated member of our team reviews every request before any data leaves our systems — checking that it comes from an authority with jurisdiction over us, that it's properly served under a valid legal instrument, and that its scope is lawful — and we take external legal advice where a request is unclear, broad or significant. We refuse or challenge requests that are unlawful, overbroad, vague or unaccompanied by the legal process the law requires, and we never disclose personal data voluntarily in the absence of a binding obligation.

Where we must comply, we disclose only the narrowest set of data that satisfies the request; we don't provide bulk exports, and no authority gets direct, standing or automated access to our systems. We log every request, the authority making it, the legal basis cited, our assessment, what was disclosed and who authorised it. We'll tell you about a request affecting your data wherever we're legally permitted to, so you have the chance to seek your own remedy first.

7. International transfers

Some providers process data in the US, and content delivery may transit Cloudflare's global network in encrypted form. We rely on the UK–US Data Privacy Framework extension where the provider is certified, and otherwise on the UK International Data Transfer Addendum / EU Standard Contractual Clauses. Copies available via legal@fresko.ai.

8. Retention

DataKept for
Account, business and generated contentUntil you delete your account (or after 24 months of inactivity, following notice from us), + 30 days
Waitlist24 months
Analytics and recordings12 months
Public data collected under §212 months rolling, or until account deletion if sooner
Logs90 days
Support correspondence24 months after the matter closes
Billing, usage and refund-verification records6 years (UK law)

When you delete your account (Settings → Delete account, or email us), we also instruct our processors to delete your personal data within the same 30-day window.

9. Cookies and analytics

We use: strictly necessary storage (sign-in tokens, session context, language — no consent needed); analytics (Amplitude — usage events and session recordings); and measurement tags on the marketing site (Google Tag Manager).

When you first visit, a consent banner lets you accept or reject the non-essential categories — rejecting is as easy as accepting, and non-essential technologies do not run until you consent. Change your choice at any time via the "Cookie settings" link in the footer, or block cookies in your browser settings (essential sign-in storage excepted).

10. Your rights

You can access, correct, delete, export, or restrict your data, object to processing (including direct marketing — always honoured), and withdraw consent at any time. Email legal@fresko.ai; we respond within one month. You can also complain to the UK ICO (ico.org.uk) or, in the EU, your local data protection authority — though we'd appreciate the chance to fix it first.

11. Security, children, changes

We protect data with encryption in transit and at rest, hashed credentials, access controls and monitoring; if a breach risks your rights we'll notify the regulator and, where required, you. The Service is for businesses and not directed at anyone under 18. We'll post changes here and notify you by email or in-app before material changes take effect.