Security and compliance

Security and data handling

How Kresso handles your ad accounts, tokens and conversations, for you and for your security or legal reviewer. Statements marked “Coming with agents” describe the product once its agents start making changes; everything else is how it works today.

Last updated 8 October 2026Private beta
Principles

What Kresso does with your data, in six lines

Nothing changes without a person

Until Kresso’s agents start making changes, it changes nothing at all. When they do, every change waits for a named person on your team to approve it.

Never sold or shared

Your account data is never sold, licensed or handed to advertisers or data brokers. It is processed for your business and no one else.

Never used to train AI

Kresso trains no models on your data, and allows no AI provider to train on it either.

Tokens sealed with keys in AWS

Each Google refresh token is encrypted with its own key, and that key is wrapped by one that never leaves AWS Key Management Service.

No passwords to leak

Sign-in is a one-time code or link sent to your work email. Kresso never sets or stores a password.

Disconnect at any time

Disconnect an account in Kresso and its stored token is cleared at once. You can also remove Kresso from your Google Account.
Data classification

Every kind of data, where it lives and how long it stays

The periods are the privacy policy’s, row for row.

DataWhat it holdsWhere it is storedHow long it is kept
AccountYour email, name, company and roleSupabase Postgres in us-east-1, encrypted at restfor as long as the account exists, then deleted on request.
Access requestsName, work email, company, ad-spend band and an optional noteSupabase Postgres in us-east-1, encrypted at restdeleted 30 days after the decision. Requests we accept become your account. Requests we have not decided on yet are kept while we consider them; ask us to delete one at any time.
Google connectionThe Google account id and email, the granted scopes, the refresh tokenSupabase Postgres in us-east-1, encrypted at rest; the token sealed with its own key, wrapped by AWS KMS, before it is storeduntil you disconnect the account, when the stored token is cleared at once. The record of the connection itself: until your account is deleted.
Rate-limit recordsThe email and IP address of a login or access requestSupabase Postgres in us-east-1, encrypted at rest24 hours.
Invitation recordsThe invited address, the company and the person who invitedSupabase Postgres in us-east-1, encrypted at rest48 hours.
Sign-in link recordsYour email and a hash of a value only your browser holdsSupabase Postgres in us-east-1, encrypted at restuntil the link is used or expires.
Connection requestsYour profile id and company, and hashes that tie the request to your browserSupabase Postgres in us-east-1, encrypted at restuntil the connection completes or the request expires.
Application logsPath, method, status, client IP and company id of each request; never an emailAWS CloudWatch in us-east-130 days.
Audit ledgerWho changed access, and when, with their name and emailSupabase Postgres in us-east-1, encrypted at resttwo years.
ConversationsComing with agents: arrives when Kresso's agents start making changesYour messages, the agents' replies and the data fetched to answerSupabase Postgres in us-east-1, encrypted at restuntil you delete the chat or the account.
Agent workComing with agents: arrives when Kresso's agents start making changesProposals, approvals with the approver's name, reverse changes, notes, managed campaign objects, report snapshotsSupabase Postgres in us-east-1, encrypted at restfor as long as the account exists.
How changes work

How a change reaches your account

Kresso reads before it does anything else. Making changes is a separate step you take, and every change has a named approver.

  1. 1

    You connect a Google Ads account. Google asks for its full Ads scope, because it offers no read-only one.

  2. 2

    Kresso reads which ad accounts you can reach and, for each, its id, name, manager flag, currency and time zone.

  3. 3

    The refresh token Google returns is sealed with its own key, wrapped by AWS KMS, before it is stored. Access tokens stay in our API’s memory.

  4. 4

    You grant the separate permission to make changes, per platform, inside Kresso. You can withdraw it at any time.Coming with agents: arrives when Kresso's agents start making changes

  5. 5

    An agent proposes a change with its reason. It waits until a named person on your team approves it.Coming with agents: arrives when Kresso's agents start making changes

  6. 6

    Kresso makes exactly the approved change, checks that it landed and keeps the reverse change on file.Coming with agents: arrives when Kresso's agents start making changes

  7. 7

    Disconnect at any time: the stored token is cleared at once and the grant is revoked at Google, unless another Kresso workspace still uses the same Google account.

Key properties

  • Google's scope alone changes nothing
  • Refresh tokens are sealed before they reach the database, and access tokens never do
  • Every customer-facing request is checked against your company and your role before any data is read
  • No email address or token is written to the application logs
Stored and not

What is stored, and what never is

Stored

  • The Google account you connected, the scopes it granted and its sealed refresh token
  • The ad accounts you can reach: their id, name and whether each is a manager account
  • Conversations with the agents, proposals with their reasons, approvals with the approver’s name and the reverse changesComing with agents: arrives when Kresso's agents start making changes

Never stored

  • Your Google password: Google’s own sign-in never shows it to Kresso
  • Google access tokens: they live in our API’s memory for at most the hour Google gives them
  • Payment card details: Kresso takes no payments in the private beta
Infrastructure

Hosted in the United States, isolated by company

Kresso runs on AWS and Supabase in us-east-1, with Cloudflare at the edge and no public address of its own.

Compute

The API runs on AWS in us-east-1, in private subnets with no public address, behind an internal load balancer that only a Cloudflare Tunnel reaches.

Database

Supabase Postgres in us-east-1, encrypted at rest. Row-level security is on for every table, and the backend’s own tables refuse browsers outright.

Secrets

Credentials live in AWS Secrets Manager, the critical ones under a KMS key of their own. Each refresh token is sealed with its own key, wrapped by a KMS key that rotates.

Edge

Cloudflare stands in front of the site and the API: TLS 1.2 or later, HTTPS forced, HSTS on, with rate limiting, Turnstile and bot protection.

Tenant isolation

  • Every customer-facing request is checked against your company and your role before any data is read
  • Every customer-facing read and change touches only your company’s rows
  • Tables holding personal data show a signed-in person only their own rows
  • Every account with production access (AWS, Supabase, Cloudflare, GitHub) has multi-factor authentication on
  • The API logs no email address or user agent, redacts tokens and keeps its logs 30 days
Your rights

Your rights over your data

Under the UK GDPR and the EU GDPR, for the data whose purposes Kresso decides.

Access

Ask for a copy of the personal data Kresso holds about you.

Correction

Ask us to fix anything that is wrong or out of date.

Erasure

Deleting an account removes the profile, its Google connections and the accounts linked through them. Audit entries keep their two years.

Export

Ask for your personal data in a machine-readable form.

Restriction and objection

Ask us to restrict or stop a use of your data, or withdraw a consent you gave.

Complaint

Complain to the Information Commissioner’s Office in the UK, or to the supervisory authority where you live in the EEA.

Send a request to legal@kresso.ai from the address on your account; we answer within 30 days.

Residency

Where your data lives

Kresso's servers and database are in the United States, in AWS us-east-1. For anyone in the United Kingdom or the European Economic Area that is an international transfer. Where a provider is certified under the EU–US Data Privacy Framework and its UK Extension we rely on that; otherwise on the standard contractual clauses, with the UK International Data Transfer Addendum where the UK GDPR applies.

Kresso has not yet appointed a representative in the European Union under Article 27 of the EU GDPR; anything you would raise with one, raise with us.

Who receives data

Who processes data for Kresso

Each acts only on Kresso’s instructions and for no purpose of its own.

  • Amazon Web Services (us-east-1, United States) runs the API, holds the encryption keys and keeps the application logs.
  • Supabase (us-east-1, United States) provides authentication and the database.
  • Cloudflare hosts the site, is the network in front of it and the API, and provides Turnstile, Web Analytics and bot protection.
  • Resend delivers the sign-in, invitation and notification emails.
  • Google provides the sign-in for connections and the Google Ads API.
  • Anthropic, OpenAI, Google (Gemini) and OpenRouter provide the AI models behind Kresso's agents. Each receives only what a request needs, keeps it for its standard API retention period, and may not train on it.Coming with agents: arrives when Kresso's agents start making changes
At a glance

Data handling at a glance

ComponentStored by KressoWhere it livesEncryption
Ad account listYesSupabase Postgres, us-east-1At rest and in transit (TLS 1.2 or later)
Campaign data the agents readComing with agents: arrives when Kresso's agents start making changesSnapshots behind reportsSupabase Postgres, us-east-1At rest and in transit (TLS 1.2 or later)
Google refresh tokensYes, sealedSupabase Postgres, us-east-1Its own AES-GCM key, wrapped by AWS KMS; at rest and in transit
Google access tokensNoOur API’s memory onlyIn transit (TLS 1.2 or later)
ConversationsComing with agents: arrives when Kresso's agents start making changesYesSupabase Postgres, us-east-1At rest and in transit (TLS 1.2 or later)
Account detailsYesSupabase Postgres, us-east-1At rest and in transit (TLS 1.2 or later)
Data sold to anyoneNever——
Contact

Questions for your security review?

Write to us for an audit question, a security report or a deletion request. The binding texts are the Privacy Policy and the Terms of Service; this page summarises them.

security@kresso.ai