Fresko

Privacy Policy

Last updated: 4 August 2026

This Privacy Policy explains how Fresko ("Fresko", "we", "us") collects, uses, shares and protects personal data when you visit fresko.ai, use the Fresko application at app.fresko.ai, or otherwise interact with us (together, the "Service").

1. Who we are

Fresko is the data controller for the personal data described in this policy. You can reach us about anything in this document at [email protected].

Registered entity name, registered address and, where applicable, EU representative and Data Protection Officer details are available on request and will be published here once confirmed by our legal team.

2. What we collect

2.1 Data you give us

2.2 Data we collect automatically

2.3 Data we collect from third parties

3. Why we use it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Providing the Service: analysing your site, generating strategy, ideas, copy and visuals, publishing posts you approvePerformance of a contract
Creating and securing your account, authentication, fraud and abuse preventionPerformance of a contract; legitimate interests
Billing, invoicing and tax recordsPerformance of a contract; legal obligation
Product analytics, debugging, quality monitoring and improving output qualityLegitimate interests
Service emails (transactional, security, account notices)Performance of a contract
Marketing emails and non-essential cookiesConsent (withdrawable at any time)
Responding to legal requests and defending legal claimsLegal obligation; legitimate interests

4. AI processing

Fresko uses large language models and generative image models to produce marketing strategy, copy and visuals. Content you submit — your website content, brand inputs and briefs — is sent to our model providers to generate that output.

5. Who we share it with

We do not sell personal data. We share it only with:

All processors act on our documented instructions under a data processing agreement. An up-to-date list of subprocessors is available at [email protected].

6. International transfers

Some of our providers are located outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses, an adequacy decision, or another lawful transfer mechanism, together with additional technical safeguards such as encryption in transit and at rest.

7. Cookies

We use:

Non-essential cookies are set only with your consent, which you can change or withdraw at any time via your browser settings or the cookie controls on our site.

8. How long we keep it

9. Your rights

If you are in the EEA or the UK, you have the right to:

To exercise any of these, email [email protected]. We respond within one month. Depending on where you live, other local privacy rights may also apply to you.

10. Security

We protect personal data with encryption in transit and at rest, row-level access controls in our database, short-lived access tokens, least-privilege access for staff, and regular dependency and infrastructure review. No system is perfectly secure, but we will notify you and the relevant authority of a personal data breach where the law requires it.

11. Children

The Service is intended for business use and is not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will update the "Last updated" date above and, for material changes, notify you by email or in the Service before the change takes effect.

13. Contact

Privacy questions and requests: [email protected]
General enquiries: [email protected]