Privacy Policy
Last updated 28 September 2026
This policy says what Kresso collects when you visit kresso.ai, request access, sign in or connect a Google Ads account; why; how long it is kept; and who else handles it. It describes the product as it works today and is updated when that changes.
Who we are
The site and the service are operated by Kresso, a business to be incorporated in England and Wales. For the personal data whose purposes we decide — visitor, access-request and account data — we are the controller under the UK GDPR and, for people in the European Economic Area, the EU GDPR. Questions and requests go to legal@kresso.ai.
We have not yet appointed a representative in the European Union under Article 27 of the EU GDPR. Anything you would raise with one, raise with us at the address above.
What we collect, and why
Visiting the site. No analytics cookies, no advertising pixels, no fingerprinting. Cloudflare serves the site and protects it from abuse, and three of its services see your visit:
- Cloudflare Web Analytics counts page views. Cloudflare describes it as working without cookies or other client-side state.
- Bot Fight Mode sets one cookie,
__cf_bm, to tell browsers from bots. It expires after 30 minutes of inactivity, and Cloudflare classes it as strictly necessary. - Turnstile checks that the request-access and login forms are submitted by a person. It runs under Cloudflare's Turnstile Privacy Addendum.
Our servers and Cloudflare's keep ordinary request logs — the address you connect from, the page requested, the browser's description of itself — for security and debugging.
Requesting access. The form asks for your name, work email, company, a monthly ad-spend band and an optional note about what you want to fix. We use it to decide whether to invite you and to reply, on the basis of our legitimate interest in answering a request you made. Each submission also records your email and IP address for one day, to rate-limit the form.
Signing in. Kresso has no passwords. Signing in sends a one-time code and a link to your work email; Supabase, our authentication provider, issues them and Resend delivers the email. Each attempt records your email and IP address for one day, to rate-limit the login. Staying signed in uses one first-party cookie holding a refresh token, set by our API alone and unreadable to scripts; the short-lived access token stays in your browser's memory. Two conveniences also live in your browser and never leave it: a cookie that remembers whether you collapsed the sidebar, kept for seven days, and, in the admin console, the companies you opened last.
Holding an account. Your profile is your email, name, company and role. Actions that change who has access — creating a company, inviting or updating a person, granting or removing access — are written to an audit ledger with the name and email of the person who acted, whether Kresso staff in the admin console or your company's owners on the Team page, so those changes can be traced.
Google user data
When you connect a Google Ads account, Google asks you to grant Kresso three OAuth scopes: openid and email, which identify the Google account you connected so that the same account is not linked twice and its address can be shown to your team; and https://www.googleapis.com/auth/adwords, the Google Ads API scope.
The Google Ads scope permits both reading and changing an account; Google offers no read-only variant. Today Kresso only reads: the accounts your Google identity can reach, and for each its id, name, whether it is a manager account, its currency and its time zone. It makes no change to any account. Should Kresso ever make changes on your behalf, that will be a separate permission you grant explicitly, and every change will need approval from a person on your team before it reaches an account.
The refresh token Google issues is encrypted before it is stored, with a key held in AWS Key Management Service, and is used only to obtain the short-lived access tokens the reads above need. Disconnecting an account revokes the token at Google, as far as Google lets us, clears the stored token at once and marks the connection revoked. The record of which Google account was linked, by whom and when is kept until your account is deleted; the app no longer shows it once it is revoked.
Google user data is stored for us by Supabase, which runs the database, and encrypted with keys that Amazon Web Services holds; on its way to your browser it passes through Cloudflare, the network in front of our API. Each of them acts only on our instructions. Nobody else receives it: no advertiser, no data broker and no AI model provider.
Kresso's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising or credit decisions, and do not use it to train or improve general-purpose artificial-intelligence or machine-learning models.
Who processes it for us
These providers process data on our behalf, under contracts with us, and for no purpose of their own:
- Amazon Web Services (us-east-1, United States) runs the API, holds the encryption keys and keeps the application logs.
- Supabase (us-east-1, United States) provides authentication and the database.
- Cloudflare is the network in front of the site and the API, and provides Turnstile, Web Analytics and bot protection.
- Resend delivers the sign-in and notification emails.
- Google provides the sign-in for connections and the Google Ads API.
No AI model provider receives your data today. Before one does, this policy will name it and say what it receives and for what.
Where your data lives
Our servers and database are in the United States. If you are in the United Kingdom or the European Economic Area, that is an international transfer of your data. Where a provider is certified under the EU–US Data Privacy Framework and its UK Extension we rely on that; otherwise we rely on the standard contractual clauses, with the UK International Data Transfer Addendum where the UK GDPR applies.
How long we keep it
- Rate-limit records for logins and access requests: 24 hours.
- Access requests we decline: deleted 30 days after the decision, or 30 days after your last submission if you send the form again. Requests we accept become your account. Requests we have not decided on yet are kept while we consider them; ask us to delete one at any time.
- Account data: for as long as the account exists, then deleted on request.
- Google tokens: until you disconnect the account, when the stored token is cleared at once. The record of the connection itself: until your account is deleted.
- Application logs: 30 days.
- Audit ledger entries: two years.
Your rights
Under the UK GDPR and the EU GDPR you can ask to access, correct, delete or export your personal data, to restrict or object to how we use it, and to withdraw a consent you gave. Send the request to legal@kresso.ai from the address on your account; we answer within 30 days. Deleting an account removes the profile, its Google connections and the accounts linked through them. Audit ledger entries are kept for the two years above: they name the person who acted, and an entry about you — the invitation that created your account, a change to your role — keeps the email and name it recorded at the time.
You can also complain to the Information Commissioner's Office in the United Kingdom, or to the supervisory authority of the EEA country you live in.
Security
Everything travels over TLS. Sign-in uses one-time codes, never passwords. Google tokens are encrypted at rest with keys the application does not hold. Access inside Kresso is by role, and administrative actions are logged.
Changes to this policy
We update this policy when the product changes what it collects or who handles it. The date at the top says when it last changed. Account holders are told by email about changes that matter to them.