Privacy

What I read, and what I forget

I read your numbers so you don’t have to. That’s a lot of trust for nineteen dollars, so here is the whole arrangement in plain English rather than eleven pages of it.

What I read

Only the sources you connect, and only ever read-only. From your revenue tools I read subscription, payment and refund events. From analytics I read session, pageview and channel totals. From search I read impressions, clicks and query-level performance for your own site. From product analytics I read event counts and funnel steps. From error tracking I read error volumes and their types.

I work in aggregates. I don't need your customers' names, email addresses, card details or support tickets, so I don't pull them, and there's nowhere in my database for them to sit. Where a source hands me a customer identifier as part of a payment event, it is counted and dropped, not stored against a person.

What I store about you

Your email address, your timezone, your preferred send day and hour, your display currency, and your billing status. That's the account.

Alongside it sit the weekly and daily aggregates I compute from your sources, the briefs I've written you, the questions you've asked me by reply, and whether you told me a recommendation worked.

Credentials

API keys and OAuth tokens you give me are encrypted before they're written down and are only ever decrypted inside the job that talks to that source. Nobody at Freddy reads them, they're never logged, and they're never sent anywhere except the source they belong to.

Disconnect a source and its credential is deleted immediately, not marked inactive.

How long I keep it

Aggregates: twelve rolling months, because a year is what it takes to tell a seasonal dip from a real one. Anything older is deleted.

Briefs and the questions you asked about them: kept while your account is open, so the archive stays readable.

Close your account and everything is deleted within thirty days. Ask me to delete it sooner and I'll do it that day.

Who else sees it

Nobody buys it, because it isn't for sale, and I don't run advertising. Three kinds of company touch it in order to do their job: the hosting and database platform this runs on, the email service that delivers your brief, and the AI provider that writes the narrative.

The AI provider receives the numbers and comparisons for the week being written about, so it can turn them into sentences. It does not receive your credentials, your customer data, or your other accounts, and your data is not used to train models.

Email

Your brief is transactional: it's the product you hired me for. There's an unsubscribe link on every one, and using it stops briefs entirely rather than nudging you into a marketing list, because there isn't one.

I record that a brief was sent, and whether it bounced or was marked as spam, so I can tell you when your inbox has stopped accepting me. I don't track opens or clicks inside the brief. The only thing I record from the email itself is which of the two feedback buttons you pressed.

Your rights

You can ask me for a copy of everything I hold on you, ask me to correct it, or ask me to delete it. One email does all three: freddy@hirefreddy.com. No form, no ticket queue — I'll reply and get on with it.

This site is run from the United Kingdom. Data is processed on infrastructure in the EU and the United States under standard contractual clauses.

Cookies

One cookie, and only once you sign in: the one that remembers you're signed in. No analytics on this site, no advertising pixels, and therefore no cookie banner to click away — which is a small piece of judgment I'd rather apply to my own site before selling it to yours.

Last updated 2026. If this ever changes in a way that matters, I’ll tell you in a brief rather than quietly reposting the page.