What we do with your data.
Including the parts that are not finished. There are no audit badges on this page because there are no audits, and a badge for one that never happened is not a marketing decision.
How the product is built
Access rules live in the database
Workspace separation is enforced by row-level security in Postgres, not only by application code. A query for another workspace's data is refused at the database, even if a bug in the app asks for it.
Your API keys are encrypted
Provider keys you add in Settings are encrypted before they are stored, and the product uses them server-side. The browser only ever gets a masked preview, the first and last few characters, so you can tell which key is saved without the key itself coming back.
Scheduled and automated work runs without you
When you schedule a campaign, queue a social post, enroll a contact in a journey or set an automation rule, a background job carries it out at its time. It does not check with you first, and if a channel has no draft ready it writes one and sends that. Publishing to your own website is the exception: a page goes live only if the piece was approved first.
Analytics and error reporting are off until you say yes
Sentry and Google Analytics do not load until you accept them. Declining is a real decline, not a delayed prompt.
Unsubscribes are enforced, not suggested
Contacts who unsubscribe are filtered out of sends at the query that builds the audience, so an opt-out cannot be bypassed by picking a different segment.
Your contacts are yours
We do not sell, rent or share your contact data, and we do not use your content to train models.
Every company that touches your data
This is the complete list. Where it says you bring your own account, that vendor relationship is yours: you hold the account, you pay them directly, and their agreement with you governs that data.
| Company | What it does | What reaches them | Account |
|---|---|---|---|
| Supabase | Database, authentication and server functions. This is where your workspace lives. | Your account, workspace, content, contacts and settings. Everything the product stores. | Ours |
| Cloudflare | Serves the website and application to your browser. | Standard web request data, including IP address, as any website receives. | Ours |
| Sentry | Error reporting, so a crash can be diagnosed. | Technical error details. Text is hidden, media is blocked, and emails and phone numbers are stripped before anything leaves the browser. It does not load at all until you accept it. | Ours |
| OpenRouter, OpenAI, Anthropic, Google and Mistral | The AI models that generate and analyze content. | The prompt and the context it needs, which can include your brand voice, your content and your keywords. | Yours |
| SerpApi and Serpstack | Live search results for keyword research and rank tracking. | The keywords and domains you ask about. | Yours |
| Pica | Routes some search-result lookups on our own account. | The keywords and domains you ask about, sent under a Creaiter account rather than one of yours. | Ours |
| Resend | Delivers your email campaigns. | The recipients and content of emails you choose to send. | Yours |
| Twilio | Delivers your SMS messages. | The phone numbers and message text of texts you choose to send. | Yours |
| Google (Analytics and Search Console) | Reads your own performance data for the dashboards. | A read request against the properties you connect. Creaiter reads from Google here rather than sending your data to it. | Yours |
| WordPress and Wix | Publishing finished content to your own site. | The posts you choose to publish, to the site you connected. | Yours |
| Vercel | Publishing finished content to a site you host on Vercel. | The Vercel token you paste, so Creaiter can list your projects. On the project you pick it then writes three environment variables — a generated publish secret, your Supabase URL, and your Supabase service-role key when you supply one — and triggers a redeploy. After that, the posts you choose to publish. | Yours |
| GitHub | Installing the site publisher, and committing content into your own repository. | The access token for the repository you install into, and the posts and glossary entries you publish, written as commits to that repository. | Yours |
| X, LinkedIn, Facebook, Instagram and PostPeer | Publishing the social posts you schedule or send. | The post text and any media, relayed through PostPeer or Bundle.social to the networks you linked inside that account. | Yours |
| Bundle.social | Relays the social posts you schedule to the networks you linked in Bundle.social. | The post text and any media. | Yours |
| Microsoft Clarity | Reads your own session and heatmap data for the page-health views. | A read request naming the project you connect and a date range. Creaiter reads from Clarity here rather than sending your data to it. | Yours |
| Replicate, Runway, HeyGen and Kling AI | Image and video generation, when you use those features. | The prompt and any source media you provide for that generation. | Yours |
Questions a security review asks
Do you have SOC 2 or ISO 27001?
No. Creaiter is pre-launch and has completed no third-party security audit or penetration test. If your procurement process requires one, we are not ready for you yet, and we would rather say that here than in month three of a trial.
Do you train AI models on my content?
No. Your content is sent to the AI provider you connect in order to do the work you asked for, and that provider's own terms govern what they do with it. We do not train anything on your data.
Can you sign a data processing agreement?
Email us. We are a small pre-launch team and we are not going to publish a template DPA that looks binding without a lawyer having read it.
How do I export or delete my data?
You do it yourself, immediately. Settings → Profile has Export JSON for your account data and Delete account for the whole thing. Contacts has its own Export and Delete all. Nothing here needs a support ticket, and we do not hold a queue between you and your own data.
Found a security problem? Email support@creaiter-in.me and we will treat it as the priority. Please do not test against other people's workspaces.