What Kresso does with your data, in six lines
Nothing changes without a person
Never sold or shared
Never used to train AI
Tokens sealed with keys in AWS
No passwords to leak
Disconnect at any time
Every kind of data, where it lives and how long it stays
The periods are the privacy policy’s, row for row.
| Data | What it holds | Where it is stored | How long it is kept |
|---|---|---|---|
| Account | Your email, name, company and role | Supabase Postgres in us-east-1, encrypted at rest | for as long as the account exists, then deleted on request. |
| Access requests | Name, work email, company, ad-spend band and an optional note | Supabase Postgres in us-east-1, encrypted at rest | deleted 30 days after the decision. Requests we accept become your account. Requests we have not decided on yet are kept while we consider them; ask us to delete one at any time. |
| Google connection | The Google account id and email, the granted scopes, the refresh token | Supabase Postgres in us-east-1, encrypted at rest; the token sealed with its own key, wrapped by AWS KMS, before it is stored | until you disconnect the account, when the stored token is cleared at once. The record of the connection itself: until your account is deleted. |
| Rate-limit records | The email and IP address of a login or access request | Supabase Postgres in us-east-1, encrypted at rest | 24 hours. |
| Invitation records | The invited address, the company and the person who invited | Supabase Postgres in us-east-1, encrypted at rest | 48 hours. |
| Sign-in link records | Your email and a hash of a value only your browser holds | Supabase Postgres in us-east-1, encrypted at rest | until the link is used or expires. |
| Connection requests | Your profile id and company, and hashes that tie the request to your browser | Supabase Postgres in us-east-1, encrypted at rest | until the connection completes or the request expires. |
| Application logs | Path, method, status, client IP and company id of each request; never an email | AWS CloudWatch in us-east-1 | 30 days. |
| Audit ledger | Who changed access, and when, with their name and email | Supabase Postgres in us-east-1, encrypted at rest | two years. |
| ConversationsComing with agents: arrives when Kresso's agents start making changes | Your messages, the agents' replies and the data fetched to answer | Supabase Postgres in us-east-1, encrypted at rest | until you delete the chat or the account. |
| Agent workComing with agents: arrives when Kresso's agents start making changes | Proposals, approvals with the approver's name, reverse changes, notes, managed campaign objects, report snapshots | Supabase Postgres in us-east-1, encrypted at rest | for as long as the account exists. |
How a change reaches your account
Kresso reads before it does anything else. Making changes is a separate step you take, and every change has a named approver.
- 1
You connect a Google Ads account. Google asks for its full Ads scope, because it offers no read-only one.
- 2
Kresso reads which ad accounts you can reach and, for each, its id, name, manager flag, currency and time zone.
- 3
The refresh token Google returns is sealed with its own key, wrapped by AWS KMS, before it is stored. Access tokens stay in our API’s memory.
- 4
You grant the separate permission to make changes, per platform, inside Kresso. You can withdraw it at any time.Coming with agents: arrives when Kresso's agents start making changes
- 5
An agent proposes a change with its reason. It waits until a named person on your team approves it.Coming with agents: arrives when Kresso's agents start making changes
- 6
Kresso makes exactly the approved change, checks that it landed and keeps the reverse change on file.Coming with agents: arrives when Kresso's agents start making changes
- 7
Disconnect at any time: the stored token is cleared at once and the grant is revoked at Google, unless another Kresso workspace still uses the same Google account.
Key properties
- Google's scope alone changes nothing
- Refresh tokens are sealed before they reach the database, and access tokens never do
- Every customer-facing request is checked against your company and your role before any data is read
- No email address or token is written to the application logs
What is stored, and what never is
Stored
- The Google account you connected, the scopes it granted and its sealed refresh token
- The ad accounts you can reach: their id, name and whether each is a manager account
- Conversations with the agents, proposals with their reasons, approvals with the approver’s name and the reverse changesComing with agents: arrives when Kresso's agents start making changes
Never stored
- Your Google password: Google’s own sign-in never shows it to Kresso
- Google access tokens: they live in our API’s memory for at most the hour Google gives them
- Payment card details: Kresso takes no payments in the private beta
Hosted in the United States, isolated by company
Kresso runs on AWS and Supabase in us-east-1, with Cloudflare at the edge and no public address of its own.
Compute
Database
Secrets
Edge
Tenant isolation
- Every customer-facing request is checked against your company and your role before any data is read
- Every customer-facing read and change touches only your company’s rows
- Tables holding personal data show a signed-in person only their own rows
- Every account with production access (AWS, Supabase, Cloudflare, GitHub) has multi-factor authentication on
- The API logs no email address or user agent, redacts tokens and keeps its logs 30 days
Your rights over your data
Under the UK GDPR and the EU GDPR, for the data whose purposes Kresso decides.
Access
Correction
Erasure
Export
Restriction and objection
Complaint
Send a request to legal@kresso.ai from the address on your account; we answer within 30 days.
Where your data lives
Kresso's servers and database are in the United States, in AWS us-east-1. For anyone in the United Kingdom or the European Economic Area that is an international transfer. Where a provider is certified under the EU–US Data Privacy Framework and its UK Extension we rely on that; otherwise on the standard contractual clauses, with the UK International Data Transfer Addendum where the UK GDPR applies.
Kresso has not yet appointed a representative in the European Union under Article 27 of the EU GDPR; anything you would raise with one, raise with us.
Who processes data for Kresso
Each acts only on Kresso’s instructions and for no purpose of its own.
- Amazon Web Services (us-east-1, United States) runs the API, holds the encryption keys and keeps the application logs.
- Supabase (us-east-1, United States) provides authentication and the database.
- Cloudflare hosts the site, is the network in front of it and the API, and provides Turnstile, Web Analytics and bot protection.
- Resend delivers the sign-in, invitation and notification emails.
- Google provides the sign-in for connections and the Google Ads API.
- Anthropic, OpenAI, Google (Gemini) and OpenRouter provide the AI models behind Kresso's agents. Each receives only what a request needs, keeps it for its standard API retention period, and may not train on it.Coming with agents: arrives when Kresso's agents start making changes
Data handling at a glance
| Component | Stored by Kresso | Where it lives | Encryption |
|---|---|---|---|
| Ad account list | Yes | Supabase Postgres, us-east-1 | At rest and in transit (TLS 1.2 or later) |
| Campaign data the agents readComing with agents: arrives when Kresso's agents start making changes | Snapshots behind reports | Supabase Postgres, us-east-1 | At rest and in transit (TLS 1.2 or later) |
| Google refresh tokens | Yes, sealed | Supabase Postgres, us-east-1 | Its own AES-GCM key, wrapped by AWS KMS; at rest and in transit |
| Google access tokens | No | Our API’s memory only | In transit (TLS 1.2 or later) |
| ConversationsComing with agents: arrives when Kresso's agents start making changes | Yes | Supabase Postgres, us-east-1 | At rest and in transit (TLS 1.2 or later) |
| Account details | Yes | Supabase Postgres, us-east-1 | At rest and in transit (TLS 1.2 or later) |
| Data sold to anyone | Never | — | — |
Questions for your security review?
Write to us for an audit question, a security report or a deletion request. The binding texts are the Privacy Policy and the Terms of Service; this page summarises them.
security@kresso.ai