Shell

Privacy policy

Effective date: September 8, 2026
Last updated: September 28, 2026

1. What this covers

This policy describes what Fresh Start collects, why, who can see it, how long it's kept, and what you can do about it. It's written to be read, not skimmed past — if anything here is unclear, that's on us to fix, not you to decode.

The short version of what Fresh Start is: a coaching and companionship product for people navigating job loss — not therapy, not a medical device, not a crisis service — designed so that the moment you need more than it can give, it hands you to real human help, for free, without ever having monetized the moment that got you there. The full description of what that means in practice is in the Terms of Service.

2. What we collect

  • What you tell us at signup and in daily check-ins: how long you've been out of work, your CV/role/company/industry, where you are in your search, and — once you choose to share it — more personal information: the reason your job ended, your family situation and financial runway (as ranges, not exact figures), how you're feeling, and, directly, whether you're having thoughts of harming yourself.
  • What you say in conversation with Fresh Start, including anything you disclose about your emotional state, relationships, or situation.
  • What the product infers from that — patterns it notices across weeks (for example, "this keeps coming up"), used to make its coaching more useful to you.
  • Anything you choose to import — a CV, a spreadsheet of applications, or similar.
  • Ordinary account and usage information — that you signed up, when you used the product, and (once payment exists) that you paid or cancelled.

3. How we use it

  • To have the coaching conversation itself, and to remember your situation across sessions so you don't have to re-explain it.
  • To notice patterns in what you've told us over time, so the coaching adapts to you specifically.
  • To detect and respond to safety concerns — see Section 6.
  • To run the product: keep your account working, respond to support requests, and process payment once a paid tier exists.
  • To meet legal obligations, including California's SB 243, which will require us to report annually (starting July 2027) an aggregate count of how many crisis referrals we issue — a number only, never your identity or content — and to defend against a payment dispute using only account and billing metadata (see Section 8) — never your conversation content.

What we never do with it: your emotional or situation data is never used for advertising, never sold or shared with data brokers, and never repurposed under an "anonymized" label as a workaround. This isn't just policy — it's enforced in how the product is built, not left to a promise alone.

4. Your consent

Using Fresh Start beyond the free preview requires one consent, given once, covering everything in this policy together — there is no version where you consent to some of this and not the rest. The consent screen states it in these words:

Withdrawing consent means deleting your account — stated on the same screen as: "Withdrawing this means deleting your account." There is no partial-withdrawal mode. If you decline consent at signup, you're offered a choice: leave and keep your account as-is (your answers so far are retained on the normal 90-day schedule described below, and you can come back and consent later), or leave and delete everything gathered so far immediately. Nothing is deleted automatically just because you declined — deleting is something you choose.

5. You're talking to an AI

Fresh Start tells you plainly, before you can interact with it, and as a standing line under the input afterward: "I'm an AI, not a person." This is not buried in this policy — it's in the product itself, because it matters in the moment, not just on paper.

6. Crisis detection, and what happens when it activates

The automated system — separate from the coaching conversation itself — checks what you write for signs of self-harm, an intent or plan, hopelessness with risk markers, harm toward another person, or an acute crisis. It's deliberately tuned to flag even when it isn't certain, because missing a real crisis matters more than a false alarm. It can also miss a real one, or respond late — it's automated, not a guarantee. If you're in immediate danger, please contact emergency services directly rather than relying on this system to notice.

When it flags something: Fresh Start checks in with you directly, and — regardless of how you answer — shows you a real, human-staffed resource list (in the US: 988 and the Crisis Text Line; everywhere else: the worldwide directory at findahelpline.com; always: local emergency numbers for immediate danger). This never requires a login, is never limited by your payment status, and is always available at /help even if you're not signed in.

What that page does and doesn't do: it doesn't check who you are, and nothing you read or tap on it is tracked by us. It is *not* invisible to everyone — like any page on the internet, the request to load it passes through our hosting provider's ordinary infrastructure and may appear in their standard request logs. We don't read those logs to find out who visited, and nothing about your visit is recorded in your Fresh Start account or conversation history.

When a human reads your words, and when they don't. A flag from the automated system is what leads the founder to read conversation content — specifically the flagged message and enough of the surrounding conversation to understand the situation, not your full history by default. Ordinary account support (billing questions, login trouble) never involves reading your conversation content — only account-level information like whether you're signed up or subscribed. This is logged internally as an access event, but you will not receive a real-time notification each time it happens. There's no guaranteed response time, and Fresh Start doesn't collect your phone number or address — so even after a human reads what you wrote, reaching you outside the product may not be possible on that alone.

We do not promise absolute confidentiality. If what you write leads a reasonable person to believe there's an imminent threat of serious physical harm to you or to an identifiable other person, the founder may — after reviewing it himself, not automatically — contact emergency services or law enforcement.

If you think a safety flag on your account was handled badly, or missed something, tell us — see Section 15 for how to reach us.

7. Retention — how long we keep things

We keep your conversation, situation, and emotional-disclosure data for 90 days after your last activity, then it's automatically removed. The minimal record of a crisis flag (when it happened, its severity tier, what happened next — not a transcript) currently rides this same 90-day window as our working default, and is used only to avoid over-messaging you, for internal safety review, and for the aggregate legal report in Section 3 — never for anything else.

(Note on the alpha specifically: the automated 90-day purge is built but not yet live within the alpha's timeframe — manual deletion, described below, is the working path for now.)

8. Sharing your information

We share information only as needed to run the product, never to monetize it:

  • The AI model that powers coaching, the separate safety-classifier system, and the database host that stores your account's information each process what's needed to do their specific job. Each is contractually held to: no retention beyond what's needed to provide the service, no use of your data to train their own models, a signed data-processing agreement, and no secondary use.
  • Model provider: OpenRouter, Inc. receives each request and forwards it to Relace, the company whose servers run the model (DeepSeek V4.1 Flash, an open-weights model made by DeepSeek). We pin every request to Relace, so no other company on OpenRouter's network receives your words; DeepSeek the company does not receive them. Every request carries OpenRouter's zero-data-retention flag: OpenRouter routes it only to an endpoint it classifies as storing nothing, and refuses the request rather than route elsewhere. OpenRouter itself keeps no prompts or replies unless an account opts into logging, which ours does not. What we rely on: OpenRouter's published terms and privacy policy, and that enforced routing. What we do not have: a separately signed data-processing agreement, which OpenRouter offers only to enterprise customers.
  • Safety-classifier provider: the same two companies, the same model, the same enforced zero-retention routing — OpenRouter forwards the safety check to Relace under the same flag.
  • Database host: pending — not yet under contract. This section will name the vendor once a signed agreement is in place.
  • Payment processor (once a paid tier exists): Stripe, for billing and subscription management.
  • Payment-dispute processing: if you dispute a charge, we may share limited account metadata (login history, session counts, feature use, billing correspondence) with our payment processor to respond — never conversation content, emotional disclosures, or crisis-flag information, without exception.
  • Emergency and safety exceptions: see Section 6.
  • Legal requirement: if we're required by law to disclose something, we will, and we'll tell you unless the law prohibits it.

We do not sell your information, and we do not share it for advertising purposes, under any circumstance.

9. Your rights and controls

  • Download your data. Email hello@myfreshst.art from the address you sign in with, and we'll send you a copy of everything you've told Fresh Start — your check-ins, remarks, conversation content, and anything you imported — within 30 days. An in-app control is coming. (This does not include Fresh Start's internal pattern insights, since those are derived, not something you gave us.)
  • Delete your account. Email hello@myfreshst.art from the address you sign in with and ask us to delete it. We'll offer you a copy of your data first, and confirm when deletion is done, within 30 days. An in-app control is coming. Deleting removes your situation record, conversation history, insights, and activity log; backup copies are purged within 30 days. Deletion is never delayed or interrupted by an active safety conversation.
  • What deletion doesn't remove: the bare fact that an account existed and, once payment exists, that it paid or cancelled — a business record that never contained anything you told the product about how you're doing.

10. Where this applies

Fresh Start is available globally from day one. If you're in the US, the crisis resources above are written for you directly; if you're elsewhere, the worldwide directory at findahelpline.com is provided because we haven't yet verified country-specific numbers against their operators — we'd rather send you somewhere reliable than guess.

No EU (GDPR Art. 27) or UK representative has been appointed as of this policy's last update. This gap is being closed with counsel before wider launch.

If you're a California resident, state law (the CCPA/CPRA) gives you the right to know what we collect about you, to delete it, to correct it, and to not be discriminated against for exercising any of these rights — all of which you can already do through the download and delete controls in Section 9. Some of what you tell Fresh Start about your health and emotional state is treated as sensitive personal information under that law; consistent with everything else in this policy, we don't sell it and don't use it for cross-context advertising. (This paragraph states our practice; whether Fresh Start meets the statutory size/revenue thresholds that trigger CCPA's formal notice requirements hasn't been confirmed with counsel yet.)

11. Consumer health data (Washington and similar laws)

Because information about your emotional and mental state may count as "consumer health data" under laws like Washington's My Health My Data Act, that data gets its own, separate policy — see the Washington Consumer Health Data Policy — in addition to everything above.

12. Age

Fresh Start is for adults, 18 and older. We don't currently verify age at signup. If it becomes clear an account belongs to someone under 18, Fresh Start stops processing new information, says plainly that it's built for adults, and gives that person the same export-or-delete choice described in Section 9 — the same as any user.

13. Security

We take reasonable technical and organizational steps to protect your information, but no system is perfectly secure, and we can't promise otherwise. If a breach affecting your information occurs, we will tell affected users what happened without unreasonable delay.

14. Changes to this policy

If we change what we collect, how we use it, or who can see it, we'll tell you before the change takes effect — not just update the date at the top of this page.

15. Contact

Fresh Start is operated by Tzvika Besor. You can reach us by mail at: 62 Krinitzi St., Ramat Gan, Israel.

16. The waiting list and our website

If you join the Fresh Start waiting list at myfreshst.art, we keep your email address and the time you joined. If you choose to answer, we also keep when you were laid off, what kind of work you did, and whether you're open to a short conversation. We use this only to tell you when Fresh Start is live and, if you said yes to a conversation, to ask for one. We don't sell it, and we don't share it for advertising. It's stored in a database hosted by Neon, separate from the product's own data, and the website runs on Vercel. To stop abuse, we keep a scrambled (hashed) form of your internet address for up to one day. To know whether people visit, the site counts page loads: the day, whether you arrived from a search engine or another site, and whether you're on a phone or a computer. It also uses Vercel Web Analytics, which counts visits without cookies and without identifying you. To come off the list, reply to any email from us or write to hello@myfreshst.art, and we'll delete your entry.