Legal
Privacy Policy
Last updated 30 June 2026
This policy explains what data frutti.ai collects, why, and your rights over it. frutti.ai is operated by Fast AI Labs, the data controller for your information.
1. Who we are
frutti.ai (the "Service") is operated by Fast AI Labs ("we", "us"), the controller of personal data processed through the Service. Contact us about privacy at [email protected].
2. Data we collect
- Account data — your email and authentication identifiers, handled via our auth provider (Clerk).
- Content data — the fruit-video prompts you submit, any reference asset you choose to upload, and the videos we generate for you.
- Billing data — plan, credit balance, and subscription identifiers. Web card payments are processed by Stripe and iOS purchases are processed by Apple; we do not store full card numbers.
- Usage & device data — log data, approximate location from IP, and analytics events (via Google Analytics and Cloudflare Web Analytics) to keep the Service secure and improve it.
- Cookies — strictly-necessary cookies for sign-in and security, plus analytics cookies/identifiers as above.
3. How we use your data
- to provide the Service — authenticate you and generate the talking-fruit videos you request;
- to process payments, manage subscriptions and credits, and prevent fraud and abuse;
- to secure, debug, monitor, and improve the Service;
- to communicate with you about your account, support, and material changes;
- to comply with legal obligations.
4. Legal bases (UK/EU GDPR)
We process data to perform our contract with you (providing the Service and billing), on the basis of our legitimate interests (security, fraud prevention, analytics, and product improvement, balanced against your rights), to comply with legal obligations, and on the basis of your consent where required (e.g. certain cookies), which you may withdraw at any time.
5. AI processing & sub-processors
To generate a fruit video, your prompt and any reference asset you choose to upload are sent to third-party AI model providers (such as OpenRouter and the models routed through it). We share data only with providers that help us run the Service, including:
- Clerk — authentication;
- Stripe — payments and subscriptions;
- Supabase — database and storage;
- AI model providers (e.g. via OpenRouter) — content generation;
- Cloudflare and our hosting provider — delivery, security, and infrastructure;
- Google Analytics & Cloudflare Web Analytics — usage measurement.
We do not sell your personal data.
6. International transfers
Some providers process data outside your country, including outside the UK/EEA. Where they do, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision.
7. Retention
We keep personal data for as long as your account is active and as needed to provide the Service, then for as long as necessary to meet legal, tax, accounting, and security obligations or to resolve disputes. You can delete content from within the Service, revoke AI-processing consent in the iOS app (which stops new AI processing until you consent again), and delete your account from the app or by contacting us.
8. Your rights
Subject to law, you have the right to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. To exercise any of these, email [email protected]. You also have the right to complain to your local data protection authority (in the UK, the ICO).
9. Security
We use technical and organisational measures appropriate to the risk, including access controls and reputable infrastructure providers. No system is perfectly secure, so we cannot guarantee absolute security.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect their data.
11. Changes & contact
We may update this policy; the "last updated" date shows the current version. Questions or requests: [email protected].