What we do with your data.

Including the parts that are not finished. There are no audit badges on this page because there are no audits, and a badge for one that never happened is not a marketing decision.

How the product is built

Access rules live in the database

Workspace separation is enforced by row-level security in Postgres, not only by application code. A query for another workspace's data is refused at the database, even if a bug in the app asks for it.

Your API keys are encrypted

Provider keys you add in Settings are encrypted before they are stored, and the product uses them server-side. The browser only ever gets a masked preview, the first and last few characters, so you can tell which key is saved without the key itself coming back.

Scheduled and automated work runs without you

When you schedule a campaign, queue a social post, enroll a contact in a journey or set an automation rule, a background job carries it out at its time. It does not check with you first, and if a channel has no draft ready it writes one and sends that. Publishing to your own website is the exception: a page goes live only if the piece was approved first.

Analytics and error reporting are off until you say yes

Sentry and Google Analytics do not load until you accept them. Declining is a real decline, not a delayed prompt.

Unsubscribes are enforced, not suggested

Contacts who unsubscribe are filtered out of sends at the query that builds the audience, so an opt-out cannot be bypassed by picking a different segment.

Your contacts are yours

We do not sell, rent or share your contact data, and we do not use your content to train models.

Every company that touches your data

This is the complete list. Where it says you bring your own account, that vendor relationship is yours: you hold the account, you pay them directly, and their agreement with you governs that data.

CompanyWhat it doesWhat reaches themAccount
SupabaseDatabase, authentication and server functions. This is where your workspace lives.Your account, workspace, content, contacts and settings. Everything the product stores.Ours
CloudflareServes the website and application to your browser.Standard web request data, including IP address, as any website receives.Ours
SentryError reporting, so a crash can be diagnosed.Technical error details. Text is hidden, media is blocked, and emails and phone numbers are stripped before anything leaves the browser. It does not load at all until you accept it.Ours
OpenRouter, OpenAI, Anthropic, Google and MistralThe AI models that generate and analyze content.The prompt and the context it needs, which can include your brand voice, your content and your keywords.Yours
SerpApi and SerpstackLive search results for keyword research and rank tracking.The keywords and domains you ask about.Yours
PicaRoutes some search-result lookups on our own account.The keywords and domains you ask about, sent under a Creaiter account rather than one of yours.Ours
ResendDelivers your email campaigns.The recipients and content of emails you choose to send.Yours
TwilioDelivers your SMS messages.The phone numbers and message text of texts you choose to send.Yours
Google (Analytics and Search Console)Reads your own performance data for the dashboards.A read request against the properties you connect. Creaiter reads from Google here rather than sending your data to it.Yours
WordPress and WixPublishing finished content to your own site.The posts you choose to publish, to the site you connected.Yours
VercelPublishing finished content to a site you host on Vercel.The Vercel token you paste, so Creaiter can list your projects. On the project you pick it then writes three environment variables — a generated publish secret, your Supabase URL, and your Supabase service-role key when you supply one — and triggers a redeploy. After that, the posts you choose to publish.Yours
GitHubInstalling the site publisher, and committing content into your own repository.The access token for the repository you install into, and the posts and glossary entries you publish, written as commits to that repository.Yours
X, LinkedIn, Facebook, Instagram and PostPeerPublishing the social posts you schedule or send.The post text and any media, relayed through PostPeer or Bundle.social to the networks you linked inside that account.Yours
Bundle.socialRelays the social posts you schedule to the networks you linked in Bundle.social.The post text and any media.Yours
Microsoft ClarityReads your own session and heatmap data for the page-health views.A read request naming the project you connect and a date range. Creaiter reads from Clarity here rather than sending your data to it.Yours
Replicate, Runway, HeyGen and Kling AIImage and video generation, when you use those features.The prompt and any source media you provide for that generation.Yours

Questions a security review asks

Do you have SOC 2 or ISO 27001?

No. Creaiter is pre-launch and has completed no third-party security audit or penetration test. If your procurement process requires one, we are not ready for you yet, and we would rather say that here than in month three of a trial.

Do you train AI models on my content?

No. Your content is sent to the AI provider you connect in order to do the work you asked for, and that provider's own terms govern what they do with it. We do not train anything on your data.

Can you sign a data processing agreement?

Email us. We are a small pre-launch team and we are not going to publish a template DPA that looks binding without a lawyer having read it.

How do I export or delete my data?

You do it yourself, immediately. Settings → Profile has Export JSON for your account data and Delete account for the whole thing. Contacts has its own Export and Delete all. Nothing here needs a support ticket, and we do not hold a queue between you and your own data.

Found a security problem? Email support@creaiter-in.me and we will treat it as the priority. Please do not test against other people's workspaces.