Privacy Policy

Last updated: February 3, 2026

1. Information We Collect

Personal Information: - Email address (required for account creation) - Name (optional) - Payment information (processed securely by Stripe; we do not store card numbers)

Usage Data: - Pages visited and features used - Brand URLs submitted for extraction - Generated assets and campaigns - Device type, browser, and operating system - IP address and approximate location (country level)

Cookies: - Authentication cookies (required for the Service to function) - Analytics cookies (optional, can be declined) - Session cookies (temporary, deleted when you close your browser)

2. How We Use Your Information

We use your information to: - Provide, maintain, and improve the Service - Process payments and manage subscriptions - Send transactional emails (receipts, password resets, important notifications) - Respond to your support requests and inquiries - Detect, prevent, and address fraud and security issues - Analyze usage patterns to improve our AI models (anonymized data only)

We do NOT: - Sell your personal information to third parties - Share your data with third parties for their marketing purposes - Use your brand assets for our own marketing without explicit permission - Send unsolicited marketing emails (unless you opt-in)

3. Data Sharing

We share data with the following service providers who help us operate the Service:

ProviderPurposeData Shared
StripePayment processingEmail, payment details
SupabaseDatabase & authAccount data, usage data
VercelHostingAccess logs, IP addresses
Google Cloud RunAI computeBrand URLs, prompts, generated content
Google AI (Gemini)Brand analysisWebsite screenshots, brand data
ReplicateImage generationPrompts, generated images
AnthropicAI text generationBrand data, prompts
UnsplashStock photographySearch queries
SentryError monitoringError logs, device info (anonymized)
SendGridTransactional emailEmail address, email content

All providers are bound by data processing agreements and maintain appropriate security measures. We only share the minimum data necessary for each service.

4. Data Retention

We retain your data for the following periods:

  • Account data: Retained while your account is active, deleted within 30 days of account deletion
  • Generated assets: Retained for 90 days after account deletion
  • Payment records: Retained for 7 years (required by tax and financial regulations)
  • Analytics data: Retained for 26 months
  • Server logs: Retained for 30 days

You can request earlier deletion of your data by contacting us at privacy@fresqo.xyz.

5. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and associated data
  • Portability: Request your data in a machine-readable format
  • Object: Object to certain processing activities
  • Withdraw consent: Withdraw consent for optional data processing

To exercise these rights: Email privacy@fresqo.xyz with your request. We will respond within 30 days.

We may need to verify your identity before processing requests.

6. Data Security

We protect your data with industry-standard security measures:

  • Encryption in transit: All data transmitted using TLS 1.3
  • Encryption at rest: Data encrypted using AES-256
  • Access controls: Role-based access, multi-factor authentication for staff
  • Regular audits: Periodic security assessments and penetration testing
  • Secure infrastructure: SOC 2 compliant data centers

While we implement strong security measures, no system is 100% secure. Please use a strong password and protect your account credentials.

7. Children's Privacy

The Service is not intended for users under the age of 18.

We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will delete it promptly.

If you believe a child has provided us with personal information, please contact us at privacy@fresqo.xyz.

8. International Data Transfers

Your data may be transferred to and processed in the United States, where our servers and service providers are located.

For EU/EEA users: We ensure appropriate safeguards for international transfers through: - Standard Contractual Clauses (SCCs) approved by the European Commission - Adequacy decisions where applicable - Binding corporate rules with our service providers

By using the Service, you consent to the transfer of your data to the United States.

9. California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act:

  • Right to Know: Request what personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information, so this right does not apply
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

To exercise these rights, email privacy@fresqo.xyz.

We will respond to verifiable consumer requests within 45 days.

10. GDPR Compliance (EU Users)

For users in the European Union, our legal bases for processing your data are:

  • Contract: Processing necessary to provide the Service you requested
  • Consent: For optional analytics and marketing communications
  • Legitimate Interest: For security, fraud prevention, and service improvement

Your additional GDPR rights: - Right to lodge a complaint with a supervisory authority - Right to restrict processing in certain circumstances - Right to object to processing based on legitimate interests

Data Protection Officer: For GDPR-related inquiries, contact our DPO at privacy@fresqo.xyz.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the new policy on this page
  • Updating the "Last updated" date
  • Sending an email notification for significant changes

We encourage you to review this policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

For questions or concerns about this Privacy Policy or our data practices:

Email: privacy@fresqo.xyz

Response Time: We will respond to all inquiries within 5 business days.

For EU-specific inquiries, you may also contact our Data Protection Officer at the same email address.

Questions about this policy? Contact us at legal@fresqo.xyz