Content source of truth for
/privacy(src/pages/privacy.astro). Snapshot from commiteaeba13, live 2026-07-10. See README.
Page title: Privacy | fiuto.ai Meta description: How Fiuto handles account, study, respondent, billing, analytics, and AI data.
How Fiuto handles product data
Fiuto is a study authoring, launch, and results product. Accordingly, we hold account data for people who create studies, and respondent data from people who answer those studies.
At a glance
- Creators: Accounts, studies, launches, results, billing, connected apps, agent memories, communication preferences, and support messages.
- Respondents: Anonymous sessions, answers, timing, click data, intake fields, and recordings where a study asks for them.
- Website visitors: Page views, referrer, campaign parameters, and signals such as which call to action was clicked, counted without storing anything on your device.
- Recruitment only when you order it: Study owners choose what they ask and who receives the study link. If a study owner places a panel order, Fiuto recruits participants for it through Prolific, and Fiuto receives only each participant’s Prolific ID and submission status.
Scope
This policy covers the Fiuto product at app.fiuto.ai, Fiuto’s hosted MCP surface at mcp.fiuto.ai, and this public website. Fiuto Ltd is registered in England & Wales, company number 17212337, with its registered office at Impact Brixton, 17A Electric Lane, London SW9 8LA, United Kingdom.
Controller and processor roles
Fiuto acts in two capacities, depending on whose data is involved.
- For account users and website visitors, Fiuto Ltd is the data controller. We decide how and why personal data about creators, collaborators, and visitors is processed.
- For study respondents, Fiuto acts as a data processor on the study owner’s instructions. The study owner is the controller for respondent data: they decide what to ask, how to describe the study, who receives the link, the lawful basis for collecting responses, and how long they need the results. Fiuto provides the product surface, storage, and processing needed to run the study, and processes respondent data only to deliver the product to the study owner and to secure and operate the product.
- For a limited set of respondent-data processing that Fiuto determines itself (securing the product and preventing abuse, such as the salted hashing of IP address and user agent, and counting visits to study pages anonymously to improve the product), Fiuto acts as a controller on the basis of its own legitimate interests, separate from its processor role for the study content it handles on the study owner’s instructions.
What we collect
Account users
- Account identity: email address, password or OAuth identity through Supabase Auth, login events, and profile settings.
- Plan and billing data: tier, credit allowance and usage, launch counters, Stripe customer and subscription identifiers, billing address collected by Stripe, and subscription metadata.
- Study content: titles, plans, blocks, media, launch snapshots, share links, results, exports, reports, and settings you create or edit.
- Agent and integration data: messages you send to Fiuto’s agent, generated plans, analysis runs, memories or preferences you save, API/MCP tokens, and connector secrets. Connector secrets are encrypted at rest before they are stored.
- Communication preferences: whether you have agreed to receive marketing email from Fiuto, when you agreed, and which part of the product asked you. Fiuto holds this record in its own database, against your account. Agreeing does not add your address to a mailing tool’s audience. Fiuto does not yet send marketing email on this permission.
- Feedback and support data: messages you send from in-app feedback or by email, plus the route and account context needed to help.
Study respondents
- Session data: a random session identifier, referrer, path through the study, completion state, and salted hashes of IP address and user agent. Fiuto does not store raw respondent IP addresses or user agents in the response tables.
- Responses: choices, ratings, rankings, card sorts, tree-test paths, click coordinates, free-text answers, intake fields, timing, and other block-specific answers.
- Recordings: prototype and live-website tasks can ask the respondent to share a screen, microphone, or camera recording. Those files are stored in Cloudflare R2 and are private to the study owner.
- Free-text risk: respondents can type personal data into intake fields, survey text fields, and “why” answers. Fiuto stores those answers as submitted. We do not automatically scrub names, emails, opinions, or other personal details from free text.
- Anonymous counting: study pages use the same anonymous counting as the rest of app.fiuto.ai, described under Cookies and analytics.
Website visitors
When you use the public website, we collect analytics data: the pages you visit, where you arrived from, any UTM campaign parameters, and our own signals such as which call to action was clicked. This analytics measurement uses no cookies and stores no analytics data in local or session storage, so there is no analytics consent banner. Visits are linked to one another only within a single day, and only through a hash that PostHog computes on its own servers. We do not learn your country, region, or city, and we derive no browser or device details from what your browser sends. The Cookies and analytics section below describes the mechanism in full. The marketing site does not ask for your email or other account details. Signing up happens in the product at app.fiuto.ai.
How we use it
- To create accounts, authenticate users, and keep studies private to the right owner or collaborator.
- To let creators build, launch, pause, stop, delete, export, and analyse studies.
- To collect respondent answers and show aggregated or per-launch results to the study owner.
- To run AI features, including study-plan generation, agent assistance, and analysis of study responses. AI prompts can include study content, connector context the user asked Fiuto to fetch, and respondent free-text answers when the owner asks Fiuto to analyse results.
- To meter usage, enforce plan limits, provide paid plans and credit packs, prevent abuse, debug reliability issues, and understand which product surfaces are working.
- To send transactional messages such as account, invite, billing, and study-related emails.
Lawful bases
Where Fiuto is the controller, we rely on the following lawful bases under UK GDPR.
- Performance of a contract: to create and operate your account, provide the product and its features, and deliver the paid plan you have chosen.
- Legitimate interests: to secure the product, prevent and investigate abuse, debug reliability issues, and understand which product surfaces are working, balanced against your rights.
- Legitimate interests: to measure how our public websites, fiuto.ai and help.fiuto.ai, are used, without storing anything on your device, balanced against your rights. This measurement stops when a browser sends a Do Not Track or Global Privacy Control signal.
- Legitimate interests: to count visits to app.fiuto.ai anonymously before you answer our analytics question, and to keep the small items listed under Cookies and analytics that show where sign-ups come from, so we can improve the product. UK law allows this without asking first, as long as we tell you and you can object. Saying no thanks, or a Global Privacy Control or Do Not Track signal, stops both.
- Consent: to send you marketing email, and, in the product at app.fiuto.ai, to use analytics cookies, which link your activity across visits and to your account. These are two separate permissions, asked separately: agreeing to one does not give the other. Both permissions are recorded against your account, and the analytics permission also against the browser you answer in, because it governs what is stored there. You can change either at any time in Settings, under Privacy, and withdrawing does not affect processing that already happened while the permission was in place.
- Legal obligation: where we must retain or disclose data to comply with the law.
For respondent data, the study owner is the controller and determines the lawful basis for collecting and using responses. Fiuto processes that data on the study owner’s instructions.
Processors and connected services
Fiuto uses a small set of infrastructure and product processors to run the product.
- Supabase provides database, authentication, edge functions, and storage for account, study, launch, response, token, and media data. Fiuto’s Supabase database is hosted in EU West.
- Cloudflare provides Pages, CDN, Workers, Turnstile, the MCP proxy, and R2 storage for recordings. Cloudflare operates a global edge network. Recordings are stored in Cloudflare R2 in the EU.
- Stripe processes checkout, subscriptions, billing address, and payment data when paid billing is enabled. Card numbers do not pass through Fiuto’s servers.
- PostHog EU receives product analytics events, selected person traits, and LLM metadata such as model, token count, and latency. Fiuto’s code does not send LLM prompt or completion content to PostHog. Session replay is enabled for product diagnostics in the product at app.fiuto.ai, and is switched off on the public website. Input fields are masked by default, so values typed into forms are not captured, and replay data is retained in PostHog’s EU region under access controls.
- Prolific recruits participants when you place a panel order. Fiuto sends Prolific the study link and the audience filters you chose, and receives each participant’s Prolific ID and submission status to run and settle the order. Prolific is the controller for its own participants’ accounts, screening profiles, and payments; Fiuto does not receive their names or contact details. Prolific is a company registered in England and Wales, and where it processes participant data is set out in its own privacy notice.
- Anthropic provides Fiuto’s AI features through its commercial API, under Anthropic’s standard commercial terms and Data Processing Addendum. Prompts can include user messages, study content, connector context, and respondent answers when analysis is requested. Under Anthropic’s commercial terms, API inputs and outputs are not used to train Anthropic’s models by default, and are retained only for a limited period, generally up to 30 days, before deletion, subject to standard exceptions such as trust and safety review, abuse prevention, and legal requirements. Fiuto does not hold a zero-retention or other special model arrangement with Anthropic.
- Resend sends transactional invite notifications for people who already have confirmed Fiuto accounts. New-account collaborator invites go through Supabase Auth email instead. Pending invite email addresses are stored on Fiuto’s grant and invite-token records so the invited person can accept the share.
- Figma is used through the Embed Kit for Figma prototype blocks. Fiuto uses a public client id to load Figma-hosted embeds in the respondent’s browser. Fiuto does not exchange a Figma client secret or store Figma OAuth tokens for this block.
Fiuto processes personal data with these providers under their standard data processing agreements, which include GDPR-compliant terms and, where relevant, each provider’s own security and sub-processing commitments.
User-directed integrations, such as Notion, Slack, GitHub, Linear, Amplitude, or PostHog as a source, are different. If you connect one, Fiuto reads from it at your direction. Those connected services remain your third-party accounts.
International transfers
Some of these providers process personal data outside the UK and the EEA, in particular Anthropic and Resend, which are based in the United States. PostHog stores Fiuto’s analytics data in Germany. Some of its sub-processors may still process it in the United States: the AI providers behind PostHog’s AI features, when those are switched on, and Cloudflare, which carries data in transit across its worldwide network. Where personal data is transferred outside the UK or the EEA, those transfers are covered by appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses, as provided under each provider’s standard terms.
Cookies and analytics
Fiuto’s analytics uses no analytics cookies on the public website and stores no analytics data in local or session storage. Storing or reading information on your device is what triggers a consent requirement under the UK’s Privacy and Electronic Communications Regulations. Our analytics does neither, so there is no analytics consent banner to answer. We measure the public website on the basis of our legitimate interests under UK GDPR.
PostHog’s analytics library is not loaded and no PostHog code runs in your browser. A small piece of our own code sends events directly to PostHog’s collection endpoint: the page you viewed, the website you arrived from, any UTM campaign parameters, and our own signals such as which call to action was clicked.
Visitors are counted on PostHog’s servers rather than in your browser. PostHog computes a hash from a salt that rotates daily, together with your IP address, your user agent, and this website’s hostname. In PostHog’s own words, the salt “changes daily which we delete once that day’s events have been processed”. Page loads that produce the same hash are linked as one anonymous visitor, so visits within a single day are linked to each other. Because the salt is deleted, that linkage does not survive the day: afterwards the hash cannot be worked back to your IP address or your browser, it cannot follow you from one day to the next, and a visit on another day counts as a new visitor. PostHog strips your IP address before any location lookup runs, so we do not learn your country, region, or city, and no device or browser details are derived from your user agent. Session replay is switched off on this website.
On fiuto.ai and help.fiuto.ai, this cookieless measurement stops when a browser sends a Do Not Track or Global Privacy Control signal. Our code then sends no event to PostHog, so that visit is not counted. Every other visit is measured in the same cookieless way. This website no longer reads the choice left by an earlier consent banner. Nothing writes analytics data to your device, and clearing this site’s data does not change this measurement.
Some pages embed images served by other companies: a preview frame from Loom’s CDN, and a launch-directory badge from nicklaunches.com. Loading an image tells the company serving it your IP address and which browser you are using. Neither sets a cookie. The Loom video player itself loads only when you click to play, and playing a video does set Loom’s own cookies from loom.com. Those are third-party cookies, set by the player rather than by us.
At app.fiuto.ai, cookieless analytics is the baseline. Until you answer our question about analytics cookies, we count visits and product use anonymously, without cookies, in every country. We use these counts as usage analytics to improve the product. Instead of full web addresses, they record only the type of page, the site you came from, and any UTM campaign parameters. They carry no account, study, or share link identifiers. To know which shared study link brought you, we save its referral code to your account when you sign up. On your first visit, a panel at the bottom of the screen asks whether you also accept analytics cookies. It shows Yes and No thanks the same way. It never appears during onboarding or while you answer a study. If you start onboarding without answering, you see it after onboarding ends. If you accept, PostHog EU also uses analytics cookies and local storage to recognise activity across visits and connect it with your account. Because No thanks is also your objection to the anonymous counting, choosing it stops the counting in that browser. It also stops whenever your browser sends a Global Privacy Control or Do Not Track signal.
You can change your answer at any time in Settings, under Privacy. Until you answer, you can also object to the anonymous counting there, with the same No thanks as the panel. So that a no applies on every device you sign in on, we also keep your answer on your account. If you answer before you sign up, we save that answer to your account when you do. Because a yes governs what is stored on a device, it applies only to the device you gave it on. When you say no or turn analytics off, we ask PostHog to delete the analytics data linked to your account, session recordings included. We keep asking until PostHog confirms. To show what you chose, we keep each answer with the time you gave it, the version of the question you saw, and where you gave it, such as in the panel or in Settings.
If you have not accepted analytics cookies, the app can still keep these small items in your browser:
- A referral code from a shared study link, so we know which link brought you. Lasts 90 days.
- Which study that link was for, read from the same code. Lasts 90 days.
- Where you came from, such as our website, our help centre, or a shared study, so we know what leads people to sign up. Lasts until you close the tab, and 90 days at most.
- The referral code you signed up with, so we can save it to your account. Lasts until it is saved, and 24 hours at most.
- A note that you have seen the analytics question, so we count that once per browser. Lasts 90 days.
- Your answer to the analytics question. Lasts until you change it or clear this site’s data.
We do not keep the first three if you say no. The same applies when your browser sends Global Privacy Control or Do Not Track, unless you have accepted analytics cookies.
Separate cookies and similar storage are essential to sign you in and keep your session secure. When the security check on the sign-up or sign-in page fails, we record why it failed, how long it waited, whether the page was in the background, whether the browser reports that it is under automated control, and the browser family, operating system, and device type, such as Safari, iOS, and phone. We use this to tell automated traffic apart from people the check has blocked. If you have not accepted analytics cookies, nothing more detailed, such as the browser version, is recorded.
Security
Fiuto uses row-level security on core product tables, owner-scoped access controls, encrypted connector secrets, TLS in transit, hashed respondent IP and user-agent values, short-lived recording upload and playback URLs, rate limits on public edges, and a Content Security Policy with explicit allowlists.
No online product is risk-free. Do not ask respondents for unnecessary special-category data, secrets, passwords, financial details, or other information unsuitable for storage in a research tool.
Retention and deletion
- Account data is kept while the account exists, unless a shorter period applies to a specific operational log.
- Study content is kept until the study owner deletes the study or deletes their account.
- Respondent sessions and their answers (text, choice, and other non-recording responses) are retained for as long as the associated launch, study, or account remains active. Fiuto acts as a data processor for this respondent data and does not apply an independent, fixed expiry to it: the study owner, as data controller, decides how long it is kept and can delete a launch, study, or account at any time to remove it.
- Screen, microphone, and camera recordings have a fixed maximum retention period. Because of their size and sensitivity, Fiuto deletes recording files automatically about 12 months after capture, whether or not the launch or study is still active, unless the study owner has already deleted them. This time limit applies only to the recording media; the text and answer data from the same session is retained under the rule above.
- As the data controller for respondent data, the study owner is responsible for telling respondents how long their data is kept and for deleting it in line with their own privacy notice and any applicable storage-limitation duty. Fiuto supports respondent deletion requests by helping the study owner locate and remove the relevant data from their workspace.
- Abandoned or aborted recording uploads are cleaned up by a 7-day Cloudflare R2 lifecycle rule.
- Prototype tracker events age out after 90 days through a private scheduled database sweep.
- Public-website analytics events are kept for 12 months in PostHog. The daily identifier that links a visit cannot be reconstructed once its salt is deleted, but the events themselves remain for that period.
- The product has a real account deletion path in Settings, under Data & deletion. It deletes the account and cascades through Fiuto-owned study data, storage objects, Stripe customer records, and PostHog person and event data where applicable. Some collaborator grants can block deletion until they are transferred or revoked.
- Anthropic server-side retention is governed by Anthropic’s commercial terms as described above. Fiuto’s account-deletion workflow does not make ad hoc API-deletion requests to Anthropic.
- Where you ask us to delete or erase personal data we hold as controller, we action verified requests without undue delay and within one month, in line with UK GDPR. This sits alongside the self-serve account deletion above and the respondent-data retention rules described above.
Your rights
Under UK GDPR, you may ask us to access, correct, delete, restrict, or export personal data we hold about you. You may also object to certain processing and withdraw consent where processing depends on consent. Fiuto does not make decisions producing legal or similarly significant effects about you based solely on automated processing, including AI features.
Account users can start deletion from the product’s Data & deletion settings. Respondents should usually contact the study owner first because the owner controls the study and the research notice shown to respondents. You can also contact Fiuto at [email protected]. If you are unhappy with how we handle your data, you may complain to the UK Information Commissioner’s Office at ico.org.uk.
Children
Fiuto is a tool for business and professional use. It is not directed to children, and account users must be at least 18. Study owners are responsible for ensuring that respondents meet any age requirements their study calls for.
Changes
We may update this policy as the product, processors, billing, and legal posture mature. When the change materially affects how product data is handled, we will update this page and, where appropriate, notify account users.