Fresko Privacy Policy
Last updated: 13 September 2026
Fresko is an AI-powered marketing assistant operated by Fresko AI Ltd, registered in England and Wales (company no. 17324246), 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We are the controller of the personal data described here under UK and EU data protection law (GDPR).
Contact for anything in this policy: legal@fresko.ai
This policy covers fresko.ai, app.fresko.ai, and emails we send. We never sell personal data.
1. What we collect
From you: email, name, password (stored hashed), language, invite code; your business website URL and social handles; briefs, onboarding answers and edits; documents and images you upload; waitlist sign-ups (email, website, page, language); messages you send us. You need an email address (or Google sign-in) to create an account — without it we cannot provide the Service; everything else you provide is optional. If you sign in with Google, we receive only your Google email, name and account ID. If you connect social accounts for publishing (e.g. Instagram, Facebook, LinkedIn, X), we store the access tokens and account details needed to post on your behalf, and the performance of content published through Fresko (views, likes, comments and similar metrics).
Automatically: product usage events, device and browser type, IP address (and the approximate location derived from it), referral source; technical logs for security and debugging; cookies and similar storage (see §9). Session recordings of how you interact with our pages may be collected for usability improvement — typed text is masked in recordings.
From public sources: to analyse your business we collect publicly available content from the website and social profiles you point us at (page text, images, brand assets, public posts and profile data), and — for inspiration features — from other public social accounts and news sources in your industry.
2. Data about other people
Scraped public content can include personal data about people we have no relationship with — for example team bios or customer testimonials on your website, or public posts by other accounts. We collect only what is publicly posted (never private messages, non-public follower lists or comment threads), we don't use it to contact or profile private individuals, and we delete it on the schedule in §8. Legal basis: legitimate interests (Art. 6(1)(f)). If you are one of these people, you can ask what we hold, object, or have it deleted: legal@fresko.ai — actioned within one month (extendable for complex requests, as the GDPR permits — we will tell you if so).
If content you upload contains personal data about your staff or customers, you are the controller of that data and we process it as your processor under the Data Processing Annex in our Terms. Where we use such content to improve Fresko (§3), we act as a controller and only with aggregated or de-identified data.
3. Why we process data (legal bases)
| Purpose | Basis (Art. 6(1)) |
|---|---|
| Providing the Service: accounts, sign-in, analysing your business, generating strategies and content, transactional emails | Contract (b) |
| Waitlist and product updates you request | Consent (a) |
| Marketing emails to existing customers about our similar services (opt-out at sign-up and in every email) | Legitimate interests (f), relying on the UK e-privacy "soft opt-in" |
| Product analytics and session recordings | Consent (a), collected via the consent tool in §9 |
| Improving Fresko: learning which content and strategies perform well, refining our prompts, templates and features, and producing aggregated, anonymised industry benchmarks — where content includes personal data about people other than you, only in aggregated or de-identified form | Legitimate interests (f) |
| Security, abuse prevention, enforcing our Terms, defending legal claims | Legitimate interests (f) |
| Tax and accounting records | Legal obligation (c) |
We make no automated decisions with legal or similarly significant effects about you.
4. AI processing
To analyse your business and generate content we send relevant data (scraped content, briefs, uploads) to the AI providers listed below. They process it only to return results and are contractually restricted from using your personal data in identifiable form to train their models. We do, however, use your content and its performance to improve Fresko itself (see §3) — that learning stays with us, not with the model providers. We keep AI usage records (token counts and costs) that contain no content.
5. Who we share data with
Service providers processing data on our instructions under data-processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud | Hosting, logging | EU |
| Neon | Database | EU (Frankfurt) |
| Cloudflare | Site hosting, storage (EU jurisdiction), delivery | EU storage, global edge |
| Upstash | Job queue and temporary authentication state | United States |
| Google (Gemini), Anthropic | AI analysis and generation | US |
| fal.ai | AI image and video generation | US |
| Langfuse | AI quality telemetry | EU |
| Amplitude | Product analytics | EU |
| Brevo | EU (France); some of its sub-processors are in the US | |
| Apify | Public social data collection | EU (Czechia) and US |
| Sentry, Better Stack, Uptrace | Errors and monitoring | US |
| Google Tag Manager | Marketing-site measurement tags | US |
If a paid plan is offered through Stripe Managed Payments, Link will act as merchant of record for that payment. Stripe and Link will handle payment and card details under their applicable privacy policies; Fresko will not see full card details. Independent controllers: the social platforms you connect and publish to (Meta, LinkedIn, X — under their own terms and privacy policies), Google (if you sign in with Google), our professional advisers, and authorities where legally required. In a merger or sale, data may transfer under confidentiality; we'd notify you.
6. Government and law enforcement requests
If a public authority asks us for personal data, we treat the request as contested until we're satisfied it's lawful. A designated member of our team reviews every request before any data leaves our systems — checking that it comes from an authority with jurisdiction over us, that it's properly served under a valid legal instrument, and that its scope is lawful — and we take external legal advice where a request is unclear, broad or significant. We refuse or challenge requests that are unlawful, overbroad, vague or unaccompanied by the legal process the law requires, and we never disclose personal data voluntarily in the absence of a binding obligation.
Where we must comply, we disclose only the narrowest set of data that satisfies the request; we don't provide bulk exports, and no authority gets direct, standing or automated access to our systems. We log every request, the authority making it, the legal basis cited, our assessment, what was disclosed and who authorised it. We'll tell you about a request affecting your data wherever we're legally permitted to, so you have the chance to seek your own remedy first.
7. International transfers
Some providers process data in the US, and content delivery may transit Cloudflare's global network in encrypted form. We rely on the UK–US Data Privacy Framework extension where the provider is certified, and otherwise on the UK International Data Transfer Addendum / EU Standard Contractual Clauses. Copies available via legal@fresko.ai.
8. Retention
| Data | Kept for |
|---|---|
| Account, business and generated content | Until you delete your account (or after 24 months of inactivity, following notice from us), + 30 days |
| Waitlist | 24 months |
| Analytics and recordings | 12 months |
| Public data collected under §2 | 12 months rolling, or until account deletion if sooner |
| Logs | 90 days |
| Support correspondence | 24 months after the matter closes |
| Billing, usage and refund-verification records | 6 years (UK law) |
When you delete your account (Settings → Delete account, or email us), we also instruct our processors to delete your personal data within the same 30-day window.
9. Cookies and analytics
We use: strictly necessary storage (sign-in tokens, session context, language — no consent needed); analytics (Amplitude — usage events and session recordings); and measurement tags on the marketing site (Google Tag Manager).
When you first visit, a consent banner lets you accept or reject the non-essential categories — rejecting is as easy as accepting, and non-essential technologies do not run until you consent. Change your choice at any time via the "Cookie settings" link in the footer, or block cookies in your browser settings (essential sign-in storage excepted).
10. Your rights
You can access, correct, delete, export, or restrict your data, object to processing (including direct marketing — always honoured), and withdraw consent at any time. Email legal@fresko.ai; we respond within one month. You can also complain to the UK ICO (ico.org.uk) or, in the EU, your local data protection authority — though we'd appreciate the chance to fix it first.
11. Security, children, changes
We protect data with encryption in transit and at rest, hashed credentials, access controls and monitoring; if a breach risks your rights we'll notify the regulator and, where required, you. The Service is for businesses and not directed at anyone under 18. We'll post changes here and notify you by email or in-app before material changes take effect.