Privacy Policy
Last updated: August 11, 2026 · Effective immediately
FUSS Studio LLC ("FUSS Studio," "we," "us," or "our") operates the Frestly mobile application and frestly.com website (collectively, the "Service"). This Privacy Policy explains what information we collect, why we collect it, who we share it with, and what you can do about it. We have written it to be read, not to be skimmed past.
Frestly is available in the United States, the United Kingdom, Ireland, Canada, Australia, New Zealand, and The Bahamas. Your country's privacy law applies to you and gives you rights that this policy cannot take away. Section 16 sets out those rights country by country, including how to complain to your own regulator. Section 11 explains our advertising and measurement in full, because that is the part most people want to know about.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: When you create an account, we collect your name, email address, and authentication credentials. If you sign in with Apple or Google, we receive your name and email (or a private relay email in the case of Hide My Email) from those providers.
- Profile & Preferences: Dietary preferences, allergies, intolerances, taste profiles, household size, and notification preferences you configure within the Service.
- Kitchen & Inventory Data: Food items, quantities, expiry dates, storage locations, categories, prices, recipes, meal plans, shopping lists, and household membership data you enter, scan, or upload. For products you add by barcode, we also store product attributes derived from third-party databases, including a calculated health score and rating, nutrition information, additive information, and declared allergens, on the item so it can be displayed to your household without re-querying.
- AI Chat Data: Conversations with Chefly (our AI chef assistant) including prompts, responses, recipe requests, and conversation history, stored in your account for continuity.
- Photo & Scan Data: Photos you submit for AI-powered features, namely grocery receipts, fridge photos, and expiry-date labels, are sent to our AI processing providers for item and text extraction. These images are processed to produce structured results and are not stored by us after extraction is complete. Barcode scans query the Open Food Facts product database and local PLU produce mappings; resolved product data (including nutrition, additives, and allergens used to calculate health scores) is cached in a shared product index keyed by barcode, not by user.
- Support Communications: Emails, feedback, bug reports, and other communications you send to us.
1.2 Information Collected Automatically
- Usage & Product Analytics: We record how the Service is used so we can improve it. This includes screens visited, session duration, and specific in-app actions: creating an account, completing onboarding steps, adding an item (and the method used, such as receipt scan, barcode, or manual entry), marking an item as used or wasted, scanning a barcode (including whether the product was found), opening Chefly, viewing the paywall (and which screen you came from), and starting a trial or subscription. This is collected through Firebase Analytics, together with crash and error reports through Firebase Crashlytics.
Please note: although this data does not include your name or email, it is linked to a persistent identifier assigned to your app installation and to your account. It is therefore pseudonymous rather than anonymous, and we treat it as personal data under GDPR, UK GDPR, and comparable laws. - Device Information: Device model, operating system version, app version, unique installation identifiers, language, timezone, and coarse location inferred from IP address (country or region level only, never GPS).
- Advertising & Attribution Identifiers: We work with advertising and measurement partners so we can tell which advertisements bring people to Frestly. Depending on your choices, this may involve the device advertising identifier (IDFA on iOS), a vendor identifier, IP address, and event data. On iOS, the advertising identifier is collected only if you allow it through Apple's App Tracking Transparency prompt. Our partners for this are AppsFlyer (attribution measurement), Meta Platforms (advertising on Facebook and Instagram), and AppLovin (an advertising network). See Section 11 for the full description and your controls.
- Log Data: IP address, access times, pages viewed, app crashes, and system activity logs. IP addresses are not stored long-term and are used solely for security and abuse prevention.
- Push Notification Tokens: Device tokens used to deliver push notifications for food expiry alerts and kitchen summaries. You can disable notifications at any time.
1.3 Information We Do NOT Collect
- We do not collect or store payment card numbers, bank account information, or financial data. All payments are processed by Apple App Store or Google Play Store.
- We do not collect precise location data (GPS).
- We do not access your camera roll, contacts, or other device data beyond what is explicitly needed for features you initiate (e.g., receipt scanning uses the camera only when you tap "Scan Receipt").
- We do not sell your personal information, and we do not display third-party advertising inside the Frestly app.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, maintain, and improve the Service's features and functionality
- To track food freshness, calculate shelf life, and send expiry notifications
- To power AI-generated recipe suggestions, meal plans, and cooking advice personalized to your kitchen inventory and dietary preferences
- To enable household sharing and collaborative inventory management among household members
- To process subscription management through Apple App Store or Google Play Store via RevenuCat
- To send push notifications about expiring items, weekly kitchen summaries, and food recall alerts (with your opt-in permission)
- To detect, prevent, and address technical issues, bugs, and security threats
- To analyze aggregated, anonymized usage patterns to improve the Service
- To measure the effectiveness of our advertising, attribute app installs and subscriptions to the campaigns that drove them, and reach potential new users, using advertising identifiers only where you have consented (see Section 11)
- To respond to your support requests and communications
- To comply with legal obligations and enforce our Terms of Service
3. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your personal data include:
- Contract Performance: Processing necessary to provide the Service you signed up for (account management, inventory tracking, AI features).
- Legitimate Interests: Product analytics and crash reporting to fix and improve the Service, install attribution to check our advertising is not wasted, security monitoring, and fraud prevention. We have weighed these against your rights, and you may object at any time as described in Section 11.4.
- Consent: Push notifications, marketing communications, advertising and measurement identifiers (collected via Apple's App Tracking Transparency prompt or website cookies), and other optional data processing features. You may withdraw consent at any time.
- Legal Obligation: Processing required to comply with applicable laws, regulations, or legal processes.
4. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We share information only as follows:
4.1 Household Members
If you join or create a household, other members can see shared inventory data, meal plans, shopping lists, activity logs, and household settings. You control household membership and may leave at any time.
4.2 Service Providers (Data Processors)
We use the following third-party services to operate the Service. Each processes data on our behalf under data processing agreements and their respective privacy policies:
- Firebase (Google LLC): Authentication, Firestore database, Cloud Functions, Cloud Storage, Analytics, Crashlytics, and Cloud Messaging (push notifications).
- RevenueCat: Subscription and in-app purchase management. RevenueCat receives anonymous subscriber IDs and purchase receipts, not your name or email.
- OpenRouter: Our primary AI gateway. Requests for Chefly chat, food lookup and name normalization, receipt and photo processing, food-image generation, and food-recall relevance filtering are routed through OpenRouter to the underlying model providers described below. Prompts, images, and responses are processed in real time to return a result and are not used to train models.
- Anthropic (Claude) and OpenAI: The AI model providers reached through OpenRouter (and, for some features, directly) that generate Chefly's responses, interpret your photos and receipts, and produce food images. Content is processed in real time and is not used to train their models.
- Google (Gemini API): AI processing for image-based features including receipt scanning, fridge-photo recognition, and expiry-date extraction. Submitted images and text are processed in real time and are not used to train Google's models.
- Google Cloud Storage: Storage of AI-generated food images (non-personal data).
- Open Food Facts, USDA FoodData Central, UPCitemdb, and Spoonacular: Third-party food and product databases queried to resolve a scanned barcode or food name into product details, nutrition, additives, and declared allergens. Only the barcode or food term is sent to these services. No account identifier, device identifier, or other personal data is transmitted.
- U.S. Food and Drug Administration (openFDA) and USDA FSIS: Public government sources we query for food recall notices. These are outbound lookups only; no personal data is sent.
- AppsFlyer: Our mobile measurement partner. AppsFlyer receives device and installation identifiers, IP address, and a defined set of pre-purchase events (account created, onboarding completed, paywall reached) so we can determine which advertisement led to an install. Our subscription provider additionally reports trial starts and purchases to AppsFlyer. On iOS, the advertising identifier is included only where you have permitted tracking. See Section 11.
- AppLovin: An advertising network we buy app-install advertising through. AppLovin receives measurement postbacks (forwarded by AppsFlyer) confirming that an install or conversion occurred, so it can optimize which people are shown our advertisements. Where you have not permitted tracking, this is limited to Apple's privacy-preserving SKAdNetwork reporting, which does not identify you.
- Meta Platforms, Inc. (Facebook/Instagram): Advertising measurement and attribution. Where you consent (via Apple's App Tracking Transparency prompt on iOS) or visit our website, we share advertising and device identifiers, a hashed subscriber identifier, and conversion events (such as app installs, sign-ups, and subscription starts) with Meta so we can measure and improve our own advertising campaigns. This occurs through the Meta SDK in the app, the Meta Pixel on frestly.com, and Meta's Conversions API (sent on our behalf by RevenueCat). See Section 11.
- Klaviyo: Email marketing and website analytics. When you create an account, we send your email address and account creation date to Klaviyo so we can send you onboarding and product emails. Klaviyo's on-site script also runs on frestly.com (including the kitchen quiz) to measure engagement. Every marketing email contains a one-click unsubscribe link, and unsubscribing stops all marketing email immediately.
Each of the above processes data on our behalf under its own terms and privacy policy. We do not authorize any of them to use your personal data for their own independent purposes, except that Meta and AppLovin act as independent controllers of the advertising data they receive, as described in Section 11.
4.3 Legal Requirements
We may disclose your data if required to do so by law, court order, subpoena, or government request, or if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation; (b) protect and defend our rights or property; (c) prevent fraud or address security issues; or (d) protect the personal safety of users or the public.
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service before your data is subject to a different privacy policy.
5. Data Storage, Security & Infrastructure
Your data is stored in Google Cloud Firestore servers located in the United States. We implement industry-standard security measures including:
- Firebase Authentication with secure token-based access control
- Firestore Security Rules ensuring users can only access their own data and their household's shared data
- All data transmitted over HTTPS/TLS encryption in transit
- Encryption at rest provided by Google Cloud infrastructure
- Regular security audits of Firestore Security Rules and Cloud Function access controls
- Principle of least privilege for all service account access
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
- Active Accounts: We retain your data for as long as your account is active and as needed to provide the Service.
- Account Deletion: Upon account deletion (available in Settings > Delete Account), we permanently delete all personal data, inventory items, chat history, household data, and preferences from our servers within 30 days. Some anonymized, aggregated analytics data may be retained indefinitely as it cannot be linked back to you.
- Inactive Accounts: Accounts inactive for more than 24 months may be flagged for deletion. We will attempt to notify you via email before deletion.
- Backup Retention: Automated database backups may retain deleted data for up to 30 additional days before permanent destruction.
- Legal Holds: We may retain data beyond normal retention periods if required by law, court order, or ongoing investigation.
7. Your Rights & Choices
Depending on your location and applicable law, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and all associated data. You can delete your account directly in the app (Settings > Delete Account) or by contacting us.
- Data Portability: Request your data in a structured, commonly used, machine-readable format.
- Restriction: Request restriction of processing in certain circumstances.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Opt Out of Analytics: You may opt out of Firebase Analytics data collection by contacting us.
- Notification Preferences: Manage push notification preferences in Settings within the app or disable them via your device's system settings.
To exercise any of these rights, contact us at Phillip@frestly.com. We will respond within 30 days (or as required by applicable law). We will not discriminate against you for exercising your rights.
8. International Data Transfers
Frestly is operated from the United States, and your personal data is stored and processed in the United States. If you are located anywhere else, including the United Kingdom, Canada, Australia, New Zealand, or The Bahamas, using the Service necessarily involves your data being transferred to the United States, where privacy laws differ from those in your country and where you may have fewer or different legal remedies.
8.1 Where your data goes
Our service providers are located in the following countries. We list these so you can make an informed decision before signing up.
- United States: Google/Firebase (database, authentication, analytics, crash reporting, push notifications, file storage), RevenueCat, Anthropic, OpenAI, OpenRouter, Klaviyo, Meta Platforms, AppLovin.
- Israel and the United States: AppsFlyer.
- Ireland and the United States: Meta Platforms, for users outside North America.
- France: Open Food Facts (barcode lookups only, no personal data).
Providers may also operate support or infrastructure facilities in other countries. A current list is available on request at Phillip@frestly.com.
8.2 Safeguards
Where we transfer personal data out of a country whose law restricts such transfers, we rely on the mechanisms that law provides. For the United Kingdom and the European Economic Area, this means Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by our providers' own transfer frameworks. For Australia, Canada, New Zealand, and The Bahamas, we remain accountable for the data we hand to overseas providers and require each of them by contract to protect it to a standard comparable to the one that applies to us.
You may request a copy of the relevant safeguards by contacting Phillip@frestly.com.
9. Children's Privacy
Frestly is a household kitchen tool intended for adults. The Service is not directed at children, and we do not knowingly collect personal information from a child below the minimum age in their country.
The minimum age to hold a Frestly account is 13, or higher where local law requires it:
- United States: 13 (Children's Online Privacy Protection Act).
- United Kingdom: 13.
- European Economic Area: 16, or the lower age set by your member state, which may be 13, 14, or 15.
- Quebec, Canada: 14. Elsewhere in Canada, a parent or guardian must consent on behalf of a child who cannot meaningfully consent for themselves.
- Australia, New Zealand, and The Bahamas: 13, and in any case only where the person is capable of understanding what they are agreeing to.
We never knowingly use a child's data for advertising or attribution. If we learn that we have collected personal data from someone under the applicable age without proper consent, we will delete it and close the account promptly. If you believe a child has given us personal data, contact us at Phillip@frestly.com and we will act on it without delay.
10. Push Notifications
With your permission, we send push notifications for:
- Food expiry alerts (customizable lead time in Settings)
- Weekly kitchen summaries and waste reports
- FDA/USDA food recall alerts matching items in your inventory
You can manage notification categories within the app's Settings, or disable all notifications through your device's system settings at any time.
11. Advertising, Measurement & Cookies
We buy advertising to bring people to Frestly, and we use measurement tools to understand which advertisements actually work so we do not waste money on the ones that do not. We do not show third-party advertisements inside the Frestly app, and we do not sell your personal information. This section explains exactly who receives what.
11.1 In the app
- AppsFlyer is our measurement partner. Its software is included in the app and records your installation, a device identifier, your IP address, and a limited set of events: when you create an account, when you finish onboarding, and when you reach the paywall. Our subscription provider separately reports trial starts and purchases. AppsFlyer matches these against advertising clicks so we can tell which campaign brought you to Frestly.
- Meta receives app events through the Meta SDK, and receives subscription events through Meta's Conversions API (sent on our behalf by RevenueCat), matched using device or hashed account identifiers.
- AppLovin receives confirmation from AppsFlyer that an install or conversion happened, so its system can learn who to show our advertisements to. AppLovin does not receive your inventory data, chat history, email, or name.
- Apple's App Tracking Transparency: on iOS, the device advertising identifier (IDFA) is collected and shared only if you tap "Allow" on Apple's tracking prompt. If you decline, no IDFA is collected, and measurement falls back to Apple's SKAdNetwork and AdAttributionKit, which report campaign performance in aggregate and do not identify you.
11.2 On our website
frestly.com, including the kitchen quiz, uses the Meta Pixel and Klaviyo's on-site script to measure visits and actions such as starting or completing the quiz. These set cookies or use similar technologies when you visit the site. You can block or delete them at any time using your browser's privacy settings, and you can control how Meta uses the data in your Meta account's Ad Preferences. The Frestly mobile app itself does not use cookies.
11.3 What advertising partners do with the data
For the data described in this section, Meta and AppLovin act as independent controllers, meaning they also use it under their own privacy policies, including to improve their own advertising systems. We are not able to control that downstream use. If you would rather they did not receive anything, decline Apple's tracking prompt and decline cookies on our website; both are honored.
11.4 Our legal basis, and how to opt out
Where GDPR, UK GDPR, or an equivalent law applies to you, we want to be exact about what runs on what basis:
- Advertising identifiers (the IDFA) and cross-app tracking: consent. These are collected only if you tap "Allow" on Apple's tracking prompt. Declining costs you nothing and locks you out of nothing. You can change your answer at any time in iOS Settings, and we honor the change immediately.
- Product analytics, crash reporting, and install attribution: legitimate interests. We use these to find bugs, understand which features are worth building, and check that our advertising spend is not being wasted. This telemetry is tied to an installation identifier, not to your name or email. You have the right to object to it. Email Phillip@frestly.com with the subject "Opt out of analytics" and we will exclude you and delete the telemetry already associated with your installation. We will confirm when it is done.
- Marketing email: consent. Every message has a one-click unsubscribe, which takes effect immediately.
Withdrawing any of these does not reduce your access to any feature of the Service.
Your choices: On iOS, you control this at any time under Settings → Privacy & Security → Tracking, and you can reset or limit ad tracking under Settings → Privacy & Security → Apple Advertising. You can adjust how Meta uses your data in your Meta account's Ad Preferences. On the website, you can use browser controls to block cookies. The Frestly mobile app itself does not use cookies; frestly.com uses essential first-party cookies plus the advertising/measurement technologies described above.
12. Third-Party Links & Services
The Service may contain links to third-party websites, APIs, or services (such as recipe sources, USDA FoodKeeper data, Open Food Facts, or the App Store). We are not responsible for the privacy practices, content, or security of these third parties. We encourage you to review their privacy policies before providing any personal data.
13. Do Not Track Signals
We do not currently respond to "Do Not Track" (DNT) browser signals, as there is no industry-standard interpretation. As described in Section 11, we do use advertising-measurement technologies to attribute and improve our own advertising. You can limit this at any time using the device and browser controls described in Section 11 and Section 14.
14. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
- Right to Know: You may request the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to legal exceptions.
- Right to Correct: You may request correction of inaccurate information.
- Right to Opt Out of Sale/Sharing: We do not sell your personal information for money. However, our sharing of advertising identifiers and conversion events with Meta, AppsFlyer, and AppLovin to measure and target our own advertising (see Section 11) may be considered "sharing" for cross-context behavioral advertising under the CPRA. You may opt out at any time: on iOS, decline or turn off tracking under Settings → Privacy & Security → Tracking; on the web, block cookies in your browser; or email us at Phillip@frestly.com with the subject "Do Not Share" and we will honor your request. We will not discriminate against you for opting out.
- Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To submit a verifiable consumer request, contact us at Phillip@frestly.com.
15. Nevada Privacy Rights
Nevada residents may submit a request directing us not to sell their personal information. We do not sell personal information. To submit such a request, contact us at Phillip@frestly.com.
16. Country-Specific Privacy Rights
Frestly is available in several countries whose privacy laws give you specific rights. Those rights apply to you in addition to everything in Section 7, and nothing in this policy limits them. In every case, you can start by emailing Phillip@frestly.com, and you can always go straight to your regulator if you prefer.
16.1 United Kingdom
We process your data in accordance with the UK GDPR and the Data Protection Act 2018. You have the rights set out in Section 7, including access, rectification, erasure, restriction, portability, and objection, and the right not to be subject to advertising tracking without your consent.
If you believe we have handled your data unlawfully, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, by calling 0303 123 1113, or by writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You do not need to contact us first, although we would like the chance to put things right.
16.2 European Economic Area
If you are in the EEA, the EU GDPR applies and you have the same rights described above. You may lodge a complaint with the supervisory authority in the country where you live, work, or where you believe the problem occurred. If you are in Ireland, that is the Data Protection Commission at dataprotection.ie.
16.3 Canada
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. You may request access to your personal information and challenge its accuracy, and you may challenge our compliance with these principles.
Accountable individual: Phillip Mitchell, FUSS Studio LLC, Phillip@frestly.com, is the individual accountable for our compliance with Canadian privacy law and serves as our Privacy Officer.
You may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376.
If you live in Quebec, Quebec's Law 25 gives you additional rights, including the right to be informed when technology is used to identify, locate, or profile you, the right to have such technology switched off, the right to data portability, and the right to request that we stop disseminating your personal information. Technology of that kind is off by default for Quebec users unless you have separately agreed to it. You may complain to the Commission d'accès à l'information du Québec at cai.gouv.qc.ca. Une version française de la présente politique est disponible sur demande à Phillip@frestly.com.
16.4 Australia
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may request access to the personal information we hold about you and ask us to correct it, and we will respond within a reasonable period and generally within 30 days.
Overseas disclosure (Australian Privacy Principle 8): we disclose personal information to overseas recipients. The countries in which those recipients are located are listed in Section 8.1, and they include the United States, Ireland, and Israel.
If you are not satisfied with how we have handled a privacy issue or a complaint, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992. The OAIC will normally ask you to raise the matter with us first.
16.5 New Zealand
We handle personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles, and we are subject to that Act as an overseas agency carrying on business in New Zealand.
Under Information Privacy Principles 6 and 7 you have the right to ask us what personal information we hold about you, to receive a copy of it, and to request correction. We will respond within 20 working days. If we decline a request we will tell you why, and you may complain about that decision.
Privacy Officer: Phillip Mitchell, Phillip@frestly.com, appointed under section 201 of the Privacy Act 2020.
Information we get about you from others: our advertising measurement partners tell us that an install or subscription came from a particular campaign. Where we receive information about you from a source other than you, we tell you here rather than separately: the categories of information, who it comes from, and why are described in Sections 1.2 and 11.
Sending information overseas: we are a United States company and our service providers are overseas. Some of them, including Meta and AppLovin, use the information they receive for their own purposes as well as ours. Where we rely on your authorisation for that, you should know that an overseas recipient may not be required to protect your information in a way that provides safeguards comparable to those in the Privacy Act 2020. Section 8 lists the countries involved.
You may complain to the Office of the Privacy Commissioner at privacy.org.nz or 0800 803 909.
16.6 The Bahamas
We handle personal information in accordance with the Data Protection (Privacy of Personal Information) Act (Ch. 324A). You have the right to be informed whether we hold personal data about you, to be given a copy of it, and to have inaccurate data corrected or erased. You may also write to us at any time to tell us to stop using your data for direct marketing, and we will stop and confirm in writing.
For clarity, and as that Act requires: we are FUSS Studio LLC, the data controller; the purposes for which we collect your data are set out in Section 2; and the categories of people and companies your data may be disclosed to are set out in Section 4.
You may complain to the Office of the Data Protection Commissioner, 3rd Floor, Courtesy House, Carmichael Road West, P.O. Box N-3017, Nassau, N.P., The Bahamas. Telephone (242) 604-1001, email dataprotection@bahamas.gov.bs, web dataprotection.gov.bs.
16.7 Response times
We aim to respond to every request within 30 days. Where the law of your country sets a shorter period, that period applies. We do not charge a fee to handle a request unless the law permits it and the request is manifestly excessive or repetitive, in which case we will tell you the cost before doing the work.
17. AI & Automated Decision-Making
Chefly AI provides recipe suggestions and food guidance using AI models. These outputs are informational and do not constitute automated decision-making with legal or significant effects. No decisions about your account access, pricing, or service availability are made solely by automated means.
18. Data Breach Notification
If personal data is lost, stolen, or accessed without authorization in a way that creates a risk to you, we will assess it promptly and tell you what happened, what data was involved, what we have done about it, and what you should do.
We notify the relevant regulator where the law requires it:
- United Kingdom and EEA: the Information Commissioner's Office or the relevant supervisory authority within 72 hours of becoming aware, where the breach poses a risk to your rights and freedoms, and you directly without undue delay where the risk is high.
- Canada: the Office of the Privacy Commissioner and you as soon as feasible, where the breach creates a real risk of significant harm. We keep records of all breaches for at least 24 months, as required.
- Australia: the Office of the Australian Information Commissioner and affected individuals as soon as practicable, where the breach is likely to result in serious harm, under the Notifiable Data Breaches scheme. Where we suspect a breach, we complete our assessment within 30 days.
- New Zealand: the Office of the Privacy Commissioner and affected individuals as soon as practicable, where the breach is likely to cause serious harm.
- United States: affected users and state regulators as required by applicable state breach notification laws.
- The Bahamas: the Data Protection Commissioner and affected individuals as required.
We will not delay telling you because an investigation is incomplete. If we do not yet know the full picture, we will say so and follow up.
19. Changes to This Policy
We reserve the right to update, modify, or replace this Privacy Policy at any time at our sole discretion. Changes will be indicated by updating the "Last updated" date at the top of this page. For material changes, we will provide notice through the app (via in-app notification), by email, or by posting a prominent notice on frestly.com at least 30 days before the changes take effect. Your continued use of the Service after such changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the revised policy, you must stop using the Service and delete your account.
20. Governing Law
This Privacy Policy is governed by the laws of the State of Oregon, United States, without regard to its conflict of law provisions.
This does not take away rights you have where you live. If you are in the United Kingdom, the European Economic Area, Canada, Australia, New Zealand, or The Bahamas, the data protection law of your own country applies to our handling of your personal data, and you keep every right and remedy it gives you, including the right to complain to your own regulator and to bring a claim in your local courts. Where anything in this policy conflicts with that law, that law wins.
21. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, your data, or your rights, contact us at:
FUSS Studio LLC
Privacy Officer: Phillip Mitchell
Prineville, Oregon, United States
Email: Phillip@frestly.com
Website: frestly.com
Phillip Mitchell is the individual accountable for our handling of personal data. That appointment serves as our Privacy Officer under section 201 of New Zealand's Privacy Act 2020, our accountable individual under Canada's PIPEDA, and our contact point for data protection enquiries from the United Kingdom, the European Economic Area, Australia, and The Bahamas.
We aim to respond to every request within 30 days, or 20 working days for requests made under the New Zealand Privacy Act 2020.