Content source of truth for
/privacy(src/pages/privacy.astro). Snapshot from commiteaeba13, live 2026-07-10. See README.
Page title: Privacy | fiuto.ai Meta description: How Fiuto handles account, study, respondent, billing, analytics, and AI data.
How Fiuto handles product data
Fiuto is a study authoring, launch, and results product. Accordingly, we hold account data for people who create studies, and respondent data from people who answer those studies.
At a glance
- Creators: Accounts, studies, launches, results, billing, connected apps, agent memories, and support messages.
- Respondents: Anonymous sessions, answers, timing, click data, intake fields, and recordings where a study asks for them.
- Website visitors: Page views, referrer, campaign parameters, and signals such as which call to action was clicked, counted without storing anything on your device.
- No recruitment: We do not recruit respondents. Study owners choose what they ask and who receives the study link.
Scope
This policy covers the Fiuto product at app.fiuto.ai, Fiuto’s hosted MCP surface at mcp.fiuto.ai, and this public website. Fiuto Ltd is registered in England & Wales, company number 17212337, with its registered office at Impact Brixton, 17A Electric Lane, London SW9 8LA, United Kingdom.
Controller and processor roles
Fiuto acts in two capacities, depending on whose data is involved.
- For account users and website visitors, Fiuto Ltd is the data controller. We decide how and why personal data about creators, collaborators, and visitors is processed.
- For study respondents, Fiuto acts as a data processor on the study owner’s instructions. The study owner is the controller for respondent data: they decide what to ask, how to describe the study, who receives the link, the lawful basis for collecting responses, and how long they need the results. Fiuto provides the product surface, storage, and processing needed to run the study, and processes respondent data only to deliver the product to the study owner and to secure and operate the product.
- For a limited set of respondent-data processing that Fiuto determines itself (in particular securing the product and preventing abuse, such as the salted hashing of IP address and user agent), Fiuto acts as a controller on the basis of its own legitimate interests, separate from its processor role for the study content it handles on the study owner’s instructions.
What we collect
Account users
- Account identity: email address, password or OAuth identity through Supabase Auth, login events, and profile settings.
- Plan and billing data: tier, credit allowance and usage, launch counters, Stripe customer and subscription identifiers, billing address collected by Stripe, and subscription metadata.
- Study content: titles, plans, blocks, media, launch snapshots, share links, results, exports, reports, and settings you create or edit.
- Agent and integration data: messages you send to Fiuto’s agent, generated plans, analysis runs, memories or preferences you save, API/MCP tokens, and connector secrets. Connector secrets are encrypted at rest before they are stored.
- Feedback and support data: messages you send from in-app feedback or by email, plus the route and account context needed to help.
Study respondents
- Session data: a random session identifier, referrer, path through the study, completion state, and salted hashes of IP address and user agent. Fiuto does not store raw respondent IP addresses or user agents in the response tables.
- Responses: choices, ratings, rankings, card sorts, tree-test paths, click coordinates, free-text answers, intake fields, timing, and other block-specific answers.
- Recordings: prototype and live-website tasks can ask the respondent to share a screen, microphone, or camera recording. Those files are stored in Cloudflare R2 and are private to the study owner.
- Free-text risk: respondents can type personal data into intake fields, survey text fields, and “why” answers. Fiuto stores those answers as submitted. We do not automatically scrub names, emails, opinions, or other personal details from free text.
Website visitors
When you use the public website, we collect analytics data: the pages you visit, where you arrived from, any UTM campaign parameters, and our own signals such as which call to action was clicked. This analytics measurement uses no cookies and stores no analytics data in local or session storage, so there is no analytics consent banner. Visits are linked to one another only within a single day, and only through a hash that PostHog computes on its own servers. We do not learn your country, region, or city, and we derive no browser or device details from what your browser sends. The Cookies and analytics section below describes the mechanism in full. The marketing site does not ask for your email or other account details. Signing up happens in the product at app.fiuto.ai.
How we use it
- To create accounts, authenticate users, and keep studies private to the right owner or collaborator.
- To let creators build, launch, pause, stop, delete, export, and analyse studies.
- To collect respondent answers and show aggregated or per-launch results to the study owner.
- To run AI features, including study-plan generation, agent assistance, and analysis of study responses. AI prompts can include study content, connector context the user asked Fiuto to fetch, and respondent free-text answers when the owner asks Fiuto to analyse results.
- To meter usage, enforce plan limits, provide paid plans and credit packs, prevent abuse, debug reliability issues, and understand which product surfaces are working.
- To send transactional messages such as account, invite, billing, and study-related emails.
Lawful bases
Where Fiuto is the controller, we rely on the following lawful bases under UK GDPR.
- Performance of a contract: to create and operate your account, provide the product and its features, and deliver the paid plan you have chosen.
- Legitimate interests: to secure the product, prevent and investigate abuse, debug reliability issues, and understand which product surfaces are working, balanced against your rights.
- Legitimate interests: to measure how the public website is used, without storing anything on your device, balanced against your rights. This cookieless measurement also applies when a browser sends a Do Not Track or Global Privacy Control signal.
- Consent: for optional communications. You can withdraw it at any time.
- Legal obligation: where we must retain or disclose data to comply with the law.
For respondent data, the study owner is the controller and determines the lawful basis for collecting and using responses. Fiuto processes that data on the study owner’s instructions.
Processors and connected services
Fiuto uses a small set of infrastructure and product processors to run the product.
- Supabase provides database, authentication, edge functions, and storage for account, study, launch, response, token, and media data. Fiuto’s Supabase database is hosted in EU West.
- Cloudflare provides Pages, CDN, Workers, Turnstile, the MCP proxy, and R2 storage for recordings. Cloudflare operates a global edge network. Recordings are stored in Cloudflare R2 in the EU.
- Stripe processes checkout, subscriptions, billing address, and payment data when paid billing is enabled. Card numbers do not pass through Fiuto’s servers.
- PostHog EU receives product analytics events, selected person traits, and LLM metadata such as model, token count, and latency. Fiuto’s code does not send LLM prompt or completion content to PostHog. Session replay is enabled for product diagnostics in the product at app.fiuto.ai, and is switched off on the public website. Input fields are masked by default, so values typed into forms are not captured, and replay data is retained in PostHog’s EU region under access controls.
- Anthropic provides Fiuto’s AI features through its commercial API, under Anthropic’s standard commercial terms and Data Processing Addendum. Prompts can include user messages, study content, connector context, and respondent answers when analysis is requested. Under Anthropic’s commercial terms, API inputs and outputs are not used to train Anthropic’s models by default, and are retained only for a limited period, generally up to 30 days, before deletion, subject to standard exceptions such as trust and safety review, abuse prevention, and legal requirements. Fiuto does not hold a zero-retention or other special model arrangement with Anthropic.
- Resend sends transactional invite notifications for people who already have confirmed Fiuto accounts. New-account collaborator invites go through Supabase Auth email instead. Pending invite email addresses are stored on Fiuto’s grant and invite-token records so the invited person can accept the share.
- Figma is used through the Embed Kit for Figma prototype blocks. Fiuto uses a public client id to load Figma-hosted embeds in the respondent’s browser. Fiuto does not exchange a Figma client secret or store Figma OAuth tokens for this block.
Fiuto processes personal data with these providers under their standard data processing agreements, which include GDPR-compliant terms and, where relevant, each provider’s own security and sub-processing commitments.
User-directed integrations, such as Notion, Slack, GitHub, Linear, Amplitude, or PostHog as a source, are different. If you connect one, Fiuto reads from it at your direction. Those connected services remain your third-party accounts.
International transfers
Some of these providers process personal data outside the UK and the EEA, in particular Anthropic and Resend, which are based in the United States. Where personal data is transferred outside the UK or the EEA, those transfers are covered by appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses, as provided under each provider’s standard terms.
Cookies and analytics
Fiuto’s analytics uses no analytics cookies on the public website and stores no analytics data in local or session storage. Storing or reading information on your device is what triggers a consent requirement under the UK’s Privacy and Electronic Communications Regulations. Our analytics does neither, so there is no analytics consent banner to answer. We measure the public website on the basis of our legitimate interests under UK GDPR.
PostHog’s analytics library is not loaded and no PostHog code runs in your browser. A small piece of our own code sends events directly to PostHog’s collection endpoint: the page you viewed, the address you arrived from, any UTM campaign parameters, and our own signals such as which call to action was clicked.
Visitors are counted on PostHog’s servers rather than in your browser. PostHog computes a hash from a salt that rotates daily, together with your IP address, your user agent, and this website’s hostname. In PostHog’s own words, the salt “changes daily which we delete once that day’s events have been processed”. Page loads that produce the same hash are linked as one anonymous visitor, so visits within a single day are linked to each other. Because the salt is deleted, that linkage does not survive the day: afterwards the hash cannot be worked back to your IP address or your browser, it cannot follow you from one day to the next, and a visit on another day counts as a new visitor. PostHog strips your IP address before any location lookup runs, so we do not learn your country, region, or city, and no device or browser details are derived from your user agent. Session replay is switched off on this website.
We use the same cookieless measurement for every visit, including where a browser sends a Do Not Track or Global Privacy Control signal. This website no longer reads the choice left by an earlier consent banner. Nothing writes analytics data to your device, and clearing this site’s data does not change this measurement.
Some pages embed images served by other companies: a preview frame from Loom’s CDN, and a launch-directory badge from nicklaunches.com. Loading an image tells the company serving it your IP address and which browser you are using. Neither sets a cookie. The Loom video player itself loads only when you click to play, and playing a video does set Loom’s own cookies from loom.com. Those are third-party cookies, set by the player rather than by us.
At app.fiuto.ai, cookieless analytics is the baseline. It uses no analytics cookies and stores no analytics data in local or session storage. If you accept analytics cookies, PostHog EU also uses analytics cookies and local storage to recognise activity across visits and connect it with your account. If you reject or dismiss the notice, cookieless analytics continue. Separate cookies and similar storage are essential to sign you in and keep your session secure.
Security
Fiuto uses row-level security on core product tables, owner-scoped access controls, encrypted connector secrets, TLS in transit, hashed respondent IP and user-agent values, short-lived recording upload and playback URLs, rate limits on public edges, and a Content Security Policy with explicit allowlists.
No online product is risk-free. Do not ask respondents for unnecessary special-category data, secrets, passwords, financial details, or other information unsuitable for storage in a research tool.
Retention and deletion
- Account data is kept while the account exists, unless a shorter period applies to a specific operational log.
- Study content is kept until the study owner deletes the study or deletes their account.
- Respondent sessions and their answers (text, choice, and other non-recording responses) are retained for as long as the associated launch, study, or account remains active. Fiuto acts as a data processor for this respondent data and does not apply an independent, fixed expiry to it: the study owner, as data controller, decides how long it is kept and can delete a launch, study, or account at any time to remove it.
- Screen, microphone, and camera recordings have a fixed maximum retention period. Because of their size and sensitivity, Fiuto deletes recording files automatically about 12 months after capture, whether or not the launch or study is still active, unless the study owner has already deleted them. This time limit applies only to the recording media; the text and answer data from the same session is retained under the rule above.
- As the data controller for respondent data, the study owner is responsible for telling respondents how long their data is kept and for deleting it in line with their own privacy notice and any applicable storage-limitation duty. Fiuto supports respondent deletion requests by helping the study owner locate and remove the relevant data from their workspace.
- Abandoned or aborted recording uploads are cleaned up by a 7-day Cloudflare R2 lifecycle rule.
- Prototype tracker events age out after 90 days through a private scheduled database sweep.
- Public-website analytics events are kept for 12 months in PostHog. The daily identifier that links a visit cannot be reconstructed once its salt is deleted, but the events themselves remain for that period.
- The product has a real account deletion path in Settings, under Data & deletion. It deletes the account and cascades through Fiuto-owned study data, storage objects, Stripe customer records, and PostHog person and event data where applicable. Some collaborator grants can block deletion until they are transferred or revoked.
- Anthropic server-side retention is governed by Anthropic’s commercial terms as described above. Fiuto’s account-deletion workflow does not make ad hoc API-deletion requests to Anthropic.
- Where you ask us to delete or erase personal data we hold as controller, we action verified requests without undue delay and within one month, in line with UK GDPR. This sits alongside the self-serve account deletion above and the respondent-data retention rules described above.
Your rights
Under UK GDPR, you may ask us to access, correct, delete, restrict, or export personal data we hold about you. You may also object to certain processing and withdraw consent where processing depends on consent. Fiuto does not make decisions producing legal or similarly significant effects about you based solely on automated processing, including AI features.
Account users can start deletion from the product’s Data & deletion settings. Respondents should usually contact the study owner first because the owner controls the study and the research notice shown to respondents. You can also contact Fiuto at hello@fiuto.ai. If you are unhappy with how we handle your data, you may complain to the UK Information Commissioner’s Office at ico.org.uk.
Children
Fiuto is a tool for business and professional use. It is not directed to children, and account users must be at least 18. Study owners are responsible for ensuring that respondents meet any age requirements their study calls for.
Changes
We may update this policy as the product, processors, billing, and legal posture mature. When the change materially affects how product data is handled, we will update this page and, where appropriate, notify account users.