← Back to home

Privacy Policy

Last updated 2026-10-08

This policy explains what data Creo (https://contentfai.xyz) collects, why, and who it is shared with. The data controller is [ ЮРЛИЦО ], [ ЮРИДИЧЕСКИЙ АДРЕС ].

The service is available to users in multiple countries, so this policy is written to meet the EU General Data Protection Regulation (GDPR) and the data-protection law of the controller's place of registration.

1. Data we process

  • Account data: email address, name, and the identifier supplied by your sign-in provider.
  • Generated content: your prompts, scripts, images, videos and voiceovers created in the service, plus any reference links you provide.
  • Payment data: the fact and amount of payment, plan, and subscription status. Card details are handled by the payment provider — the service never receives or stores them.
  • Your third-party API keys (BYOK mode), if you add them. Keys are stored encrypted (AES-256-GCM) and used only for calls made on your behalf.
  • Technical data: IP address, browser type, event timestamps, error and API logs — limited to what is needed to run and protect the service.

2. Purposes and legal bases

  • Providing the service and performing our contract: account creation, content generation, storing results, deducting credits. Basis — performance of a contract (Art. 6(1)(b) GDPR).
  • Taking payment and keeping accounting records. Basis — contract and legal obligation (Art. 6(1)(b), 6(1)(c) GDPR).
  • Security, abuse prevention, rate limiting, incident investigation. Basis — legitimate interests (Art. 6(1)(f) GDPR).
  • Responding to support requests. Basis — contract and legitimate interests.
  • Service emails (email confirmation, password reset, welcome, account and billing notices). Basis — contract. News and offers are sent only with your separate consent; unsubscribe via the link in any email.

We do not sell personal data and do not use it for advertising profiling.

3. Who we share data with

To operate the service, data is shared with processors strictly as needed for a given operation — for example, your prompt is sent to a generation provider to produce the result.

Current list of processors:

ProcessorPurposeRegion
Supabaseauthentication, database, account storageEU / US
Resendemail delivery: confirmation, password reset, notices and opt-in newslettersUS
S3-совместимое хранилищеgenerated media storageEU
Stripeinternational payment processing (card details never reach the service)US / EU
Plategapayment processing in RUB — SBP, cards, SberPay (card details never reach the service)RU
OpenRoutertext generation (LLM)US
HeyGenAI avatar video generationUS
KIE.aivideo and image generationUS / APAC
ElevenLabsspeech synthesis (voiceover)US
Cloudflarebot protection on sign-in (Turnstile)US / EU
Fish Audiospeech synthesis (voiceover)US
ZapCapautomatic subtitlesEU
Apifypublic data scraping for reference linksEU / US
OmniSocialspublishing content to social networks on your behalfUS
BytePlustext generation (alternative LLM provider, when enabled)Singapore

4. International transfers

Some processors are located outside the controller's country of registration and outside the European Economic Area, including in the United States and Singapore. For such transfers we rely on legally recognised safeguards: standard contractual clauses and the data-processing terms included in our agreements with providers.

By submitting content for generation you instruct us to transfer it to the provider you selected. Do not include data in prompts if you are not prepared to authorise its transfer abroad.

5. Retention

  • Account data — while the account exists, and up to 30 days after deletion (technical backups).
  • Generated content and media — until you delete it, or for the retention period of your plan.
  • Payment records — for the period required by accounting and tax law.
  • Security logs — normally no longer than 12 months.

6. Your rights

You have the right to: access your data and receive a copy; correct inaccurate data; erase data (the 'right to be forgotten'); restrict processing; object to processing based on legitimate interests; receive your data in a portable format; and withdraw consent where processing relies on it.

To exercise these rights, write to [ EMAIL ]. We reply within the period set by applicable law (under GDPR, within one month).

If you believe your rights have been infringed, you may lodge a complaint with the data-protection supervisory authority where you live.

7. Security

Access to data is restricted and segregated at the database level, connections are protected with TLS, and user API keys are encrypted before storage. No protection is absolute: if a breach occurs that poses a high risk to your rights, we will notify you and the supervisory authority within the required timeframes.

8. Children

The service is not intended for anyone under 16. We do not knowingly collect children's data. If such data has reached us, contact us and we will delete it.

9. Changes to this policy

We may update this policy. We announce material changes in advance — by a notice in the interface or by email. The date of the latest revision is shown at the top of the document.

10. Contact

Data protection enquiries: [ EMAIL ]. Controller: [ ЮРЛИЦО ], [ ЮРИДИЧЕСКИЙ АДРЕС ].