Privacy Policy

Last updated: August 19, 2026

1. Information We Collect

Account information: Email address, name, and profile data you provide during registration.

Content data: Articles, keywords, email templates, contact lists, and other content you create or upload.

Usage data: Feature usage patterns, analytics interactions, and AI chat conversations to improve the Service.

API keys: Third-party API keys you provide, stored encrypted using AES-256-GCM.

Technical data: Browser type, IP address, and device information for security and diagnostics.

2. How We Use Your Information

We use your data to: provide and improve the Service; generate AI-powered content and recommendations; personalize your experience through user intelligence profiles; send transactional emails (account verification, password resets); and comply with legal obligations.

3. Data Storage & Security

Data is stored on Supabase (PostgreSQL) with row-level security policies. API keys are encrypted at rest. Edge functions process data in Deno isolates. We implement authentication on all API endpoints and use HTTPS for all data transmission.

4. Third-Party Sub-Processors

The Service integrates with the following sub-processors. When you use these integrations, your data is sent under their respective privacy policies and our Data Processing Agreements. We do not sell your data to third parties.

  • AI / LLM: OpenAI, Anthropic, Google AI, OpenRouter — chat content, brand voice, generated text
  • SEO data: SerpAPI, Pica — search-result fetches you trigger
  • Email delivery: Resend — subject + body + recipient address; webhook receipts
  • SMS delivery: Twilio (when configured) — phone number + message body
  • Image generation: OpenAI (DALL-E), Google Gemini — image prompts you submit
  • Video generation: Runway, Replicate, Kling — video prompts and reference media
  • Error monitoring & session replay: Sentry — error reports and Session Replay recordings of your visit (only after you accept the cookie banner; all text masked, all media blocked, PII scrubbed) — see section 8
  • Audience measurement: Google Analytics 4 — page addresses visited, approximate location derived from IP, device and browser type (only after you accept the cookie banner) — see section 8
  • Hosting / infrastructure: Supabase (PostgreSQL + Edge Functions), Lovable (preview environments)

Data residency: Production data is stored in the Supabase project's primary region. International transfers, where applicable, rely on EU Standard Contractual Clauses or equivalent safeguards. Contact support@creaiter-in.me for the current sub-processor list and DPA references.

Children's privacy (COPPA): The Service is not directed at users under 13. By signing up, you confirm you are 13 years of age or older. If we discover an account belongs to a child under 13, we will delete it.

5. Your Rights (GDPR/CCPA)

Right to access: You can export all your data at any time from Settings.

Right to rectification: You can update your profile and content at any time.

Right to deletion: You can permanently delete your account and all associated data from Settings.

Right to data portability: You can download your data in a machine-readable format (JSON).

Right to object: You can opt out of user intelligence profiling by contacting support.

To exercise any of these rights, use the Settings page or contact us at support@creaiter-in.me.

6. Email Marketing (CAN-SPAM / GDPR)

If you use the Engage email module, you are responsible for compliance with CAN-SPAM, GDPR, and other applicable email marketing laws. All marketing emails must include an unsubscribe link. The Service enforces this requirement before sending.

7. Data Retention

We retain your data for as long as your account is active. When you delete your account, all personal data is permanently removed within 30 days. Anonymized usage analytics may be retained for product improvement.

8. Cookies & Browser Storage

Essential — always on. Signing in stores an authentication cookie and a session token in your browser's local storage. Without these you cannot stay signed in, so they are not optional and we do not ask consent for them. We run no advertising cookies and no ad-network trackers, and we sell no data.

Consent-gated — off until you accept the banner. Sentry, our error-monitoring sub-processor, records Session Replay: a replay of your visit covering clicks, navigation and page structure. It samples 10% of sessions, plus every session in which an error occurs. All text is masked and all media is blocked in your browser before anything is sent, so the recording does not capture what you typed or the content you were working on. Sentry keeps its session identifier in browser session storage rather than in a cookie — the law treats browser storage and cookies alike, and so do we: none of it starts before you accept.

Consent-gated — off until you accept the banner. Google Analytics 4 counts visits so we can see which parts of the product get used. It sets a _ga cookie holding a random identifier, and records the page addresses you visit, your device and browser type, and an approximate location derived from your IP address. It does not receive your name, your email address, or anything you type or generate in the product. The Google tag is not present in the page until you accept — the script is requested from Google only at that moment, so declining means no request to Google is ever made and no _ga cookie is ever set.

Withdrawing consent. You can withdraw at any time. Clearing this site's data in your browser erases the stored choice and the banner asks again; Session Replay and Google Analytics stay off unless and until you accept a second time. You can also email support@creaiter-in.me and we will confirm removal.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification.

10. Contact

For privacy-related inquiries, contact us at support@creaiter-in.me.