Franko Go to app

Privacy Policy

Last updated: 20 May 2026

This Privacy Policy explains what personal data we collect when you use Franko (the “Service”), how we use it, with whom we share it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act.

1. Who is responsible

The data controller is:

Useful Systems OÜ Tornimäe tn 5 10145 Tallinn Estonia Registry code: 17370540 (https://ariregister.rik.ee/eng/company/17370540) Contact: contact@tellfranko.com

You can reach us about any privacy matter at the contact above. The supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), https://www.aki.ee/en.

2. Whose data we process

We process data about two kinds of people:

  • Creators: people who sign up for an account and create surveys.
  • Respondents: people who answer a survey at a link a Creator has shared with them.

We treat Respondent answers as Creator Content for the Creator; we act as data controller for the Respondent personal data we collect directly for the operation of the Service (cookies, technical logs).

3. What we collect and why

We process the data below to provide the Service to you (performance of our contract), to comply with our legal obligations such as accounting and tax, and for our legitimate interests in keeping the Service secure and understanding how it is used.

3.1 Creator account data

When you sign up we collect:

  • Email address, name, and (if you sign in with Google or LinkedIn) a profile picture URL.
  • Preferred language (en / it) and preferred pronouns if you provide them during onboarding.
  • An encrypted password if you sign up with email + password. Passwords are stored only as a salted hash; we never see your password in clear text.
  • Session metadata: IP address, user agent, and session token, used to keep you signed in and to prevent fraud.
  • OAuth tokens when you sign in with Google or LinkedIn (access and refresh tokens, kept only as long as needed to keep you signed in).

3.2 Survey content and onboarding answers

When you build or run a survey we store:

  • The survey definition (title, description, questions, language, context).
  • Your onboarding answers (Franko Personal asks a short set of meta-questions).
  • The chat history of any wizard or onboarding conversation.
  • AI-generated material linked to your survey (briefs, analyses, Personal Wrapped cards).

3.3 Respondent answers

When a Respondent opens a survey link we store:

  • The interview session: which survey, language, current position, the answers given, and the AI conversation that accompanies each answer.
  • A completed submission: when an interview is finished, we extract structured observations from the conversation and store them for the Creator’s report.
  • A short-lived cookie (franko_interview) that lets the Respondent resume an in-progress interview from the same browser, and a second short-lived cookie (franko_deletable) that lets them request deletion of their just-submitted response.

We do not ask Respondents for their name or email. However, answers and conversations are free text, so they may contain information that identifies a Respondent if the Respondent chooses to provide it. The underlying interview conversation may be retained so the Creator’s report can be generated, regenerated, or re-analysed (see §6).

3.4 Payments

If you subscribe to a paid plan we store the Stripe customer ID linked to your organisation. The actual payment (card details, billing address, VAT identifier) is handled by Stripe. We never see your full card number.

3.5 Error reports and observability

When something breaks, we capture an error report that may include the stack trace, the URL that was loaded, the user agent and IP address. We use this only to diagnose bugs. We also capture LLM traces (the prompt and the model’s response) for the same purpose; trace data is kept in a separate observability tool with a short retention.

3.6 Analytics

We use a self-hosted instance of Umami for product analytics. Umami is configured to be cookieless and to collect only aggregated, anonymous usage data (which page was viewed, country, browser type, referrer). It does not store an identifier in your browser and is not used to track you across sites. No data goes to Google Analytics or any third-party analytics provider.

4. Cookies

We use a small number of first-party cookies, all strictly necessary:

CookiePurposeLifetime
Session cookieKeeps you signed inSession / up to 7 days
franko_langRemembers your language preference1 year
franko_interviewLets a Respondent resume an interview24 hours
franko_deletableLets a Respondent request deletion of a fresh submissionA few minutes

We do not use advertising, third-party tracking, or third-party analytics cookies. Our Umami analytics is cookieless.

5. Who we share data with (sub-processors)

We use the following sub-processors. Each is bound by a data-processing agreement. Transfers to the United States rely on the EU-US Data Privacy Framework where the recipient is certified, and on Standard Contractual Clauses otherwise.

Sub-processorPurposeRegion
OpenRouter, Inc.Routes our requests to LLM providersUSA
Google LLC (Gemini, via OpenRouter)Generates AI interview follow-ups, summaries and reportsEU / USA
Google LLC (Sign-in with Google)Authenticates you if you choose Google as a sign-in methodEU / USA
LinkedIn Corporation (Sign-in with LinkedIn)Authenticates you if you choose LinkedIn as a sign-in methodEU / USA
Stripe Payments Europe Ltd / Stripe, Inc.Processes paid-plan paymentsIreland / USA
Resend, Inc.Sends transactional emails (verification, magic link, password reset)USA
Deepgram, Inc.Real-time speech-to-text when voice mode is usedUSA
OpenAI, L.L.C.Fallback speech-to-text (Whisper) when voice mode is usedUSA
Functional Software, Inc. (Sentry)Error monitoring (stack traces, user agent, IP address)USA
Langfuse GmbHLLM observability (prompt + response text), only when enabledGermany
Our VPS hosting providerRuns the app server and databaseEU

Our self-hosted Umami analytics instance runs on infrastructure operated by Useful Systems OÜ; it is not a third party.

6. How long we keep data

  • Active account data: for as long as your account is active.
  • Closed accounts: we delete personal data within 90 days of account deletion, except where retention is required for legal, accounting (typically 7 years under Estonian law) or security reasons.
  • Interview sessions and the conversations within them: retained while the related survey is active, so the Creator’s report can be generated, regenerated, or re-analysed. The Creator can delete a survey (and its responses) at any time, and a Respondent can request deletion of a response they have just submitted.
  • Extracted submission observations: kept for as long as the Creator’s account is active.
  • Error reports: typically 90 days.
  • LLM observability traces: short retention (on the order of weeks).
  • Backups: rolling, with retention not exceeding 30 days.

7. Your rights

Subject to the conditions in applicable data-protection law, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate data;
  • Erase your data (“right to be forgotten”);
  • Restrict how we process your data;
  • Data portability to receive your data in a structured, machine-readable format;
  • Object to processing based on our legitimate interests;
  • Withdraw consent at any time where consent is the legal basis;
  • Lodge a complaint with the Estonian Data Protection Inspectorate or with your local supervisory authority.

To exercise any of these rights, email contact@tellfranko.com. We will respond within the period required by law. There is no charge for reasonable requests.

8. International transfers

Several of the sub-processors above are based in the United States. We rely on the EU-US Data Privacy Framework where the recipient is certified, and on the European Commission’s Standard Contractual Clauses supplemented with additional safeguards where it is not. You can request details of the transfer mechanism that applies to a specific sub-processor by emailing us.

9. Children

The Service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

10. Security

We use industry-standard measures to protect your data: TLS in transit, hashed passwords, role-based access controls, encryption at rest for backups, and rate-limited authentication. No system is perfectly secure; we will notify affected users and the relevant authority of a personal-data breach where required by law.

11. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date at the top reflects the latest revision. We will notify active users by email or an in-app notice when changes are material.

12. Contact

For any privacy question or to exercise your rights: contact@tellfranko.com.

© Useful Systems OÜ Home