Privacy Policy
Last updated 2026-10-08
This policy explains what data Creo (https://contentfai.xyz) collects, why, and who it is shared with. The data controller is [ ЮРЛИЦО ], [ ЮРИДИЧЕСКИЙ АДРЕС ].
The service is available to users in multiple countries, so this policy is written to meet the EU General Data Protection Regulation (GDPR) and the data-protection law of the controller's place of registration.
1. Data we process
- Account data: email address, name, and the identifier supplied by your sign-in provider.
- Generated content: your prompts, scripts, images, videos and voiceovers created in the service, plus any reference links you provide.
- Payment data: the fact and amount of payment, plan, and subscription status. Card details are handled by the payment provider — the service never receives or stores them.
- Your third-party API keys (BYOK mode), if you add them. Keys are stored encrypted (AES-256-GCM) and used only for calls made on your behalf.
- Technical data: IP address, browser type, event timestamps, error and API logs — limited to what is needed to run and protect the service.
2. Purposes and legal bases
- Providing the service and performing our contract: account creation, content generation, storing results, deducting credits. Basis — performance of a contract (Art. 6(1)(b) GDPR).
- Taking payment and keeping accounting records. Basis — contract and legal obligation (Art. 6(1)(b), 6(1)(c) GDPR).
- Security, abuse prevention, rate limiting, incident investigation. Basis — legitimate interests (Art. 6(1)(f) GDPR).
- Responding to support requests. Basis — contract and legitimate interests.
- Service emails (email confirmation, password reset, welcome, account and billing notices). Basis — contract. News and offers are sent only with your separate consent; unsubscribe via the link in any email.
We do not sell personal data and do not use it for advertising profiling.
3. Who we share data with
To operate the service, data is shared with processors strictly as needed for a given operation — for example, your prompt is sent to a generation provider to produce the result.
Current list of processors:
| Processor | Purpose | Region |
|---|---|---|
| Supabase | authentication, database, account storage | EU / US |
| Resend | email delivery: confirmation, password reset, notices and opt-in newsletters | US |
| S3-совместимое хранилище | generated media storage | EU |
| Stripe | international payment processing (card details never reach the service) | US / EU |
| Platega | payment processing in RUB — SBP, cards, SberPay (card details never reach the service) | RU |
| OpenRouter | text generation (LLM) | US |
| HeyGen | AI avatar video generation | US |
| KIE.ai | video and image generation | US / APAC |
| ElevenLabs | speech synthesis (voiceover) | US |
| Cloudflare | bot protection on sign-in (Turnstile) | US / EU |
| Fish Audio | speech synthesis (voiceover) | US |
| ZapCap | automatic subtitles | EU |
| Apify | public data scraping for reference links | EU / US |
| OmniSocials | publishing content to social networks on your behalf | US |
| BytePlus | text generation (alternative LLM provider, when enabled) | Singapore |
4. International transfers
Some processors are located outside the controller's country of registration and outside the European Economic Area, including in the United States and Singapore. For such transfers we rely on legally recognised safeguards: standard contractual clauses and the data-processing terms included in our agreements with providers.
By submitting content for generation you instruct us to transfer it to the provider you selected. Do not include data in prompts if you are not prepared to authorise its transfer abroad.
5. Retention
- Account data — while the account exists, and up to 30 days after deletion (technical backups).
- Generated content and media — until you delete it, or for the retention period of your plan.
- Payment records — for the period required by accounting and tax law.
- Security logs — normally no longer than 12 months.
6. Your rights
You have the right to: access your data and receive a copy; correct inaccurate data; erase data (the 'right to be forgotten'); restrict processing; object to processing based on legitimate interests; receive your data in a portable format; and withdraw consent where processing relies on it.
To exercise these rights, write to [ EMAIL ]. We reply within the period set by applicable law (under GDPR, within one month).
If you believe your rights have been infringed, you may lodge a complaint with the data-protection supervisory authority where you live.
7. Security
Access to data is restricted and segregated at the database level, connections are protected with TLS, and user API keys are encrypted before storage. No protection is absolute: if a breach occurs that poses a high risk to your rights, we will notify you and the supervisory authority within the required timeframes.
8. Children
The service is not intended for anyone under 16. We do not knowingly collect children's data. If such data has reached us, contact us and we will delete it.
9. Changes to this policy
We may update this policy. We announce material changes in advance — by a notice in the interface or by email. The date of the latest revision is shown at the top of the document.
10. Contact
Data protection enquiries: [ EMAIL ]. Controller: [ ЮРЛИЦО ], [ ЮРИДИЧЕСКИЙ АДРЕС ].