Fresia Privacy Policy
Effective date: September 18, 2026
Last updated: September 18, 2026
This policy explains what Fresia collects, why, who else touches it, and what you can do about it. It describes the product as it actually works today.
Fresia is operated by Cupsa Technologies Inc., a Canadian corporation ("Fresia", "we", "us"), which is the controller of the personal data described here. Contact: swerikcode@gmail.com.
The short version
- We store the goals you set, the work your agents produce, and a profile of your business, because that is the product.
- We do not run analytics, advertising, or tracking scripts. The only cookies we set keep you signed in.
- We never sell your data and we never share it for advertising.
- Your connected accounts (Gmail, Stripe, GitHub and the rest) are held by Composio, our OAuth provider. Fresia does not store those access tokens.
- Payments are handled by Stripe. We never see your card number.
- Your content is sent to Anthropic so the AI models can do the work you asked for.
- Anything your agents do that leaves your workspace is gated behind your approval, unless you explicitly relax that setting.
- You can delete your workspace and everything in it yourself, from inside the app, at any time. See section 6.
1. Information we collect
1.1 Account information
When you create an account, our authentication provider, Clerk, collects your email address and your sign in credential: a password, which Clerk stores only as a hash, or a sign in through Google or GitHub. We store Clerk's identifier for you, your workspace name, and your role in that workspace.
1.1a Billing information
When you start the trial, Stripe collects your card and billing details directly, including a billing address where that is needed to work out sales tax. We store Stripe's identifiers for you and your subscription, the plan, and its status. We do not receive or store your card number.
1.2 Your business profile
During onboarding you provide, or let us read from your website, a description of your business: its name, website URL, one line summary, longer description, target audience, primary goal, and stage. This profile is attached to every instruction your agents receive, so it shapes all of their work.
1.3 Work you create and the work agents produce
We store:
- the goals and instructions you type,
- the schedules you set (the instruction, its cron expression, and its timezone),
- the results your agents produce, including full result text, structured results, and summaries,
- your conversation threads with individual agents,
- every approval request, including the arguments of the action awaiting your decision, your decision, and your reason if you give one,
- an audit log entry for each action taken, including which agent, which tool, the decision, and whether it was reversible,
- your permission settings and which agents you have enabled,
- the cost of each run and a ledger of the credits your workspace has used,
- whether and when the workspace owner accepted the email sending terms,
- images, designs and video your agents generate, held in file storage under your workspace.
1.4 Connected account data
When you connect a third party account, Fresia can read from it and, subject to your approval, act on it. The accounts you can connect are listed on the Connections page, and today include Gmail, Stripe, GitHub, Google Search Console, Google Analytics, Google Drive, Notion, X, LinkedIn and Reddit.
Fresia does not store your access tokens. The OAuth authorization happens with Composio, which custodies the tokens and executes calls on your behalf. We store only a record that a connection exists: the service name, Composio's account identifier, the connection status, and the scopes granted.
Data returned from those accounts (an email thread, a revenue figure, a search query report) passes through Fresia to your agents and may be stored in the run results and audit log described above.
1.5 Technical information
Our hosting and infrastructure providers process standard server request data, including IP address, browser user agent, and timestamps, for security and reliability. Clerk sets the cookies that keep you signed in. That is the extent of our cookie use.
1.6 What we do not collect
We do not run analytics, product telemetry, session recording, advertising, or third party tracking scripts in the application. We do not set advertising or analytics cookies. We do not buy personal data about you from data brokers.
2. How we use your information
We use the information above to:
- run the agents and produce the work you asked for,
- keep a record of what was done, which is the point of the audit log,
- ask you to approve actions before they take effect,
- notify you by email that something is waiting for your approval, and send you a summary of work your agents did while you were away, both through your own connected mailbox,
- authenticate you and protect the service from abuse,
- measure your usage against your plan's credits, and bill your subscription,
- diagnose failures and improve the product.
We do not use your content for advertising, and we do not sell or rent it.
3. AI processing
Fresia is built on Anthropic's Claude models. To do the work you request, we send Anthropic the content it needs: your instruction, your business profile, relevant results from your connected accounts, and the intermediate output of the agents.
Anthropic processes this content to generate a response and returns it to us. Under Anthropic's commercial API terms, inputs and outputs submitted through the API are not used to train their models. Anthropic's own terms and privacy policy govern their handling of that data.
Do not put information into Fresia that you are not permitted to disclose to a third party processor.
4. Who else processes your data
We use the following subprocessors. Each receives only what it needs for its function.
| Provider | What it does | What it receives |
|---|---|---|
| Clerk | Sign up, sign in and sessions | Your email address and sign in credential |
| Supabase | The primary database, and file storage for generated media | All workspace data described in section 1 |
| Anthropic | The AI models that do the work | Instructions, business profile, and content the agents read or write |
| Composio | Custody of your connected account tokens, and execution of calls against those accounts, including email sent from your own mailbox | Your OAuth tokens, and the requests and responses exchanged with your connected services |
| Stripe | Subscription billing | Your card and billing details, which you give to Stripe directly |
| Trigger.dev | Durable execution of background and scheduled runs | Run instructions, results and identifiers |
| Vercel | Application hosting | Standard server request data |
| fal.ai | Image and video generation | Generation prompts and the resulting media |
| DataForSEO | Keyword, ranking, and search data | The keywords and domains being researched |
| Jina | Reading and searching public web pages your agents need | The URLs and search queries |
| Apify | Finding public creator profiles, when an agent is asked to | The search terms used |
If you connect an advertising account in the future, the relevant advertising platform (Google or Meta) becomes a processor for campaign data. That capability is not enabled today.
We will update this list when it changes.
5. What your agents can do, and your control over it
This section matters more here than in most products, because Fresia can act on your behalf.
Actions that send something outward, spend money, or cannot be undone are held for your approval by default. You review the action and its actual contents before it happens.
In Permissions you can change how much your agents do on their own, per kind of action. Actions classified as spending money or as irreversible can never be set to run without asking you. That restriction is enforced in the system, not just in the interface.
Work your agents do while you are away, overnight or on a schedule, can never send anything. Whatever it prepares is held as a draft until you read it and approve it.
Email goes out from your own connected mailbox. Before the first real send the workspace owner accepts the sending terms shown in the product, and each workspace is limited to 20 real sends a day. Until those terms are accepted, an approved send is a rehearsal and the approval card says so.
Every decision, yours or automatic, is written to the audit log.
6. Retention
We keep your workspace data for as long as your account is open.
While your account is open we keep your runs, results, conversation threads, approvals and audit log, because that history is the product. We do not delete it on a timer. When you delete your workspace it is removed at once, as described below, and nothing of it is kept beyond the backups and financial records described below.
Deleting your data: you can delete everything yourself, from inside the app, without asking us and without waiting for us.
Open Setup and use Delete everything. Only the workspace owner can do this, and you will be asked to type your workspace name to confirm. When you do, we, in this order:
- stop any work still running and settle what it cost,
- remove your schedules,
- cancel your subscription immediately, so nothing further is charged,
- ask Composio to disconnect every account you had connected, which revokes the access tokens it held for Fresia,
- delete every file your agents generated, which also ends any link to them,
- permanently delete, in a single database transaction, your runs and the work your agents produced, your conversation threads, your business profile and settings, your schedules, your approval requests and decisions, your audit log, and your workspace and your membership of it.
If one of the earlier steps cannot be completed, we do not delete your data yet. The screen tells you which step failed and you can run it again, so that nothing of yours is left behind in another service.
What we keep. We keep the financial records we are required to keep: the record of credits used, the billing events received from Stripe, and a record that the deletion happened. None of these contains your content, and the workspace they belonged to no longer exists. Stripe keeps your customer record under its own retention rules. We keep these financial records for seven years and then delete them.
Once it completes, this is not reversible and there is no grace period. We keep no copy of your content and cannot restore any of it for you afterwards. Your sign in is held by Clerk rather than in the workspace, so if you also want that removed, email swerikcode@gmail.com and we will delete it.
Backups are the one place deleted data briefly survives. We keep database backups encrypted and for no longer than 30 days, so deleted data is gone from them within 30 days. We do not restore a backup to recover a deleted workspace.
You can also still delete individual pieces without deleting the account: disconnect any connected account, and delete any schedule, at any time.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data, to receive a copy in a portable format, and to withdraw consent.
If you are in the European Economic Area or the United Kingdom, our legal bases for processing are: performance of our contract with you (to run the service), your consent (to connect an account and to let agents act on it), and our legitimate interests (security, abuse prevention, and improving the product).
If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we do not process it for cross context behavioral advertising.
To exercise any of these rights, email swerikcode@gmail.com. We will respond within the period required by your local law. You also have the right to complain to your local data protection authority.
8. International transfers
Our providers operate in the United States and other countries, so your data will be transferred outside your home country. Where the law requires a safeguard for such a transfer, we rely on the ones our providers offer under their data processing terms, such as the European Commission's Standard Contractual Clauses.
9. Security
Access to your connected accounts is delegated to Composio rather than held by us, which means a compromise of Fresia does not directly expose your account tokens. Card details are held by Stripe and never reach us. Data is encrypted in transit. Every request is tied to the signed in user's workspace on our servers, every query is limited to that workspace, and the database refuses direct access from the browser altogether.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any required regulator within the timeframes the law sets.
10. Children
Fresia is not directed at children and is not intended for anyone under 16. We do not knowingly collect their personal data. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this policy
We will post any change here and update the date at the top. If a change materially affects how we handle your personal data, we will tell you before it takes effect.
12. Contact
Questions, requests, or complaints: swerikcode@gmail.com