Creatorfield AICreatorfield AI

Legal Document

Privacy Policy

Last updated: June 5, 2025

Applies to: creatorfield.org and all related services operated by Creatorfield AI

This Privacy Policy explains how Creatorfield AI ("we", "us", "our") collects, uses, stores, and protects your personal information when you use our platform at creatorfield.org and any associated services (collectively, the "Service").

1

Information We Collect

1.1Account data full name, email address, username, and profile photo provided upon registration through our authentication provider (Supabase).
1.2Usage data pages visited, features used, actions taken, session duration, and timestamps of interactions with the Service.
1.3Technical data IP address, browser type and version, operating system, device identifiers, time zone, and referring URLs.
1.4Content data videos, scripts, captions, prompts, and any other content you upload, create, or generate using the Service.
1.5Payment data billing name, address, and payment method details, processed securely by our payment provider. We do not store full card numbers.
1.6Connected accounts data when you connect a third-party social media account, we collect and store OAuth tokens, account ID, display name, and profile image provided by that platform.
2

How We Use Your Information

2.1To provide, operate, and maintain the Creatorfield AI platform and all its features.
2.2To process payments and manage your subscription plan.
2.3To send transactional communications: account confirmations, password resets, and billing receipts.
2.4To send product updates, feature announcements, and marketing communications. You may opt out at any time.
2.5To analyse aggregated usage data for the purpose of improving performance and user experience.
2.6To detect, investigate, and prevent fraudulent activity, abuse, and security incidents.
2.7To comply with applicable laws, regulations, legal process, and governmental requests.

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

3

How We Share Information

We share data with the following trusted service providers solely to operate the Service:

3.1Supabase (supabase.com) authentication, session management, user identity, and database storage.
3.2Vercel (vercel.com) cloud hosting, edge network, and deployment infrastructure.
3.3Google Gemini (ai.google.dev) AI content generation.
3.4Supabase Postgres (supabase.com) database storage for connected accounts and application data.
3.5Polar.sh (polar.sh) subscription billing and payment processing.

All providers are bound by data processing agreements and applicable data protection laws.

4

Cookies and Tracking

4.1We use strictly necessary cookies required for authentication, session management, and core functionality.
4.2We do not use advertising cookies, tracking pixels, or third-party analytics that share data with advertisers.
4.3You may disable cookies through your browser settings. Disabling essential cookies may prevent you from accessing certain features of the Service.
5

Data Retention

5.1Account data is retained for as long as your account remains active.
5.2Upon account deletion, personal data is permanently deleted within 30 days, except where retention is required by law.
5.3Billing records are retained for 7 years in compliance with tax and accounting regulations.
5.4Anonymised and aggregated analytics data may be retained indefinitely as it cannot be linked to individual users.
6

Your Rights

Depending on your jurisdiction (including GDPR for EU residents and CCPA for California residents), you have the following rights:

6.1Right of access request a copy of the personal data we hold about you.
6.2Right to rectification request correction of inaccurate or incomplete data.
6.3Right to erasure request deletion of your personal data ("right to be forgotten").
6.4Right to data portability receive your data in a structured, machine-readable format.
6.5Right to object object to processing based on legitimate interests or for direct marketing.
6.6Right to withdraw consent where processing is based on consent, withdraw it at any time.

To exercise any of these rights, contact us at azaamat.se@gmail.com. We will respond within 30 calendar days.

7

Data Security

7.1All data in transit is encrypted using TLS 1.2 or higher.
7.2Data at rest is encrypted using AES-256 encryption.
7.3Access to personal data is restricted to authorised personnel on a need-to-know basis.
7.4We conduct regular security reviews and follow responsible disclosure practices.
7.5In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users within 72 hours of becoming aware of the breach, as required by GDPR.
8

Children's Privacy

8.1The Service is not directed to individuals under the age of 16.
8.2We do not knowingly collect personal data from children under 16.
8.3If we become aware that we have collected data from a child under 16 without parental consent, we will delete it promptly. Contact us at azaamat.se@gmail.com if you believe this has occurred.
9

International Transfers

9.1Our primary servers are located in the United States. By using the Service, you consent to your data being transferred to and processed in the US.
9.2For transfers of personal data from the European Economic Area (EEA) to the US, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or other lawful transfer mechanisms.
10

Changes to This Policy

10.1We may update this Privacy Policy periodically to reflect changes in our practices or applicable law.
10.2We will notify you of material changes by email and/or in-app notification at least 14 days before the changes take effect.
10.3Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
11

Contact

For questions or notices regarding this document:

Creatorfield AI

Email: azaamat.se@gmail.com

Website: creatorfield.org