▌ LEGAL · PRIVACY

Privacy Policy.

EFFECTIVE · 2026-07-06

This Privacy Policy explains how StakLabs LLC (the "Company", "we", "us"), a limited liability company organized under the laws of the United States and acting as the business and data controller, collects, uses, shares and protects personal data when you use the Creou website, application or API (the "Service").

For users in the United States we describe rights available under the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) and other applicable U.S. state privacy laws. For users in the European Economic Area and the United Kingdom, we also process personal data in accordance with the EU/UK General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), and the GDPR rights described below apply to you.

1. Data controller

The business and data controller is StakLabs LLC, registered in the United States. You can reach us at hello@creou.app. If we appoint a Data Protection Officer ("DPO") or an EU/UK representative, their contact information will be set out here.

2. Categories of personal data we process

  • Account data — name, email address, password hash, authentication identifiers (e.g. Google sign-in subject).
  • Profile data — display name, optional avatar image, role, team membership.
  • User Content — files (images, video, audio) you upload as references; prompts and parameters you submit; outputs generated by the Service. These may contain personal data of you or others.
  • Connected social accounts — platform account identifiers, usernames, display names, avatar images, and OAuth access/refresh tokens for social media accounts you choose to connect (currently TikTok and Instagram), together with engagement metrics for posts published through the Service. See Section 6 below.
  • Usage data — generation logs, credit ledger entries, error events, IP address, user agent, device hints, coarse location derived from IP.
  • Payment data — billing history, transaction identifiers, receipts. Card data is processed directly by Stripe; we do not receive or store full card numbers.
  • Communications — emails or support messages you send us, takedown / DMCA notices.

3. Purposes of processing and legal bases

  • Provide the Service (account, generations, billing, support) — performance of a contract (GDPR Art. 6(1)(b)).
  • Security, fraud prevention, abuse detection — legitimate interests in keeping the Service secure and lawful (GDPR Art. 6(1)(f)).
  • Compliance with legal obligations (tax, accounting, response to lawful authority requests, takedown laws including the U.S. TAKE IT DOWN Act) — Art. 6(1)(c).
  • Service improvement and analytics — legitimate interests, balanced against your rights; we minimise the data used and avoid using sensitive content for analytics.
  • Marketing communications, if any — your consent (Art. 6(1)(a)), which you can withdraw at any time.

4. AI processing of User Content

When you submit a prompt or reference asset, we transmit it to the relevant generative-AI provider so it can return an output. Reference assets that contain images of people are personal data and may, in some cases, contain biometric information. By submitting such content, you confirm under our Terms of Service that you have the legal right to do so. We do not use your User Content to train our own foundation models without your separate opt-in.

5. Recipients and processors

We share personal data with the following categories of recipients, each under a written data-processing agreement where required:

  • Anthropic, OpenAI and Google (United States), which provide the underlying generative-AI models. Prompts and reference assets you submit (which may include images of real people) are transmitted to the relevant provider to generate your output. Each provider's terms apply to its processing.
  • Supabase Inc. for authentication, database and object storage (EU region where available).
  • Stripe, Inc. for payment processing.
  • Resend for transactional email.
  • Sentry / Functional Software, Inc. for error monitoring.
  • Cloud hosting (e.g. Vercel) for application delivery.
  • TikTok and Meta Platforms (Instagram) — when you publish or schedule content to a connected social account, the content, caption and scheduling metadata are transmitted to the respective platform through its official APIs. Each platform's own terms and privacy policy apply to its processing.
  • Government and law-enforcement bodies, where legally required.

6. Social platform integrations (TikTok, Instagram)

The Service lets you connect your own social media accounts so that we can publish content you have approved and retrieve performance metrics for that content. We only access platform data through each platform's official APIs, with your explicit authorization, and only to the extent needed to provide these features.

  • TikTok. When you connect a TikTok account through TikTok's Login Kit (OAuth), we receive and store your TikTok user identifier (open id), username and display name, avatar image, and the access and refresh tokens needed to act on your behalf. When you schedule or publish a post, we transmit your content and caption to TikTok's Content Posting API, and we retrieve engagement metrics (such as views, likes, comments and shares) for posts made through the Service. We use TikTok data solely to provide these features. We do not sell TikTok user data, do not use it for advertising, and do not share it with third parties other than the hosting and database processors listed in Section 5.
  • Instagram. When you connect an Instagram professional account through Meta's Graph API, we likewise receive your account identifier, username, avatar and tokens, publish content you have approved, and retrieve engagement metrics for posts made through the Service.
  • Retention, disconnection and deletion. Platform tokens and connected-account metadata are stored only while the connection is active. You can disconnect a platform account at any time from the Connections page in your dashboard, which deletes the stored tokens. You can also revoke the Service's access from within the platform itself (in TikTok: Settings and privacy → Security → Apps and services; in Meta: account security settings). Deleting your account, or contacting us at the address in Section 14, removes all connected-account data we hold. Engagement metrics retrieved from the platforms are otherwise retained and deleted in line with Section 8.

7. International data transfers

Some recipients are located outside the European Economic Area, including in the United States (Anthropic, OpenAI, Google, Stripe, Resend, Sentry, Vercel) and other jurisdictions. Where required, transfers are protected by appropriate safeguards, including the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and supplementary technical and organisational measures. You can request a copy of the safeguards applicable to a specific transfer by contacting us.

8. Retention

We retain personal data only as long as necessary for the purposes described above:

  • Account & profile — until you delete your account, plus a short reconciliation window for backups.
  • User Content — until you delete it from the Service or delete your account.
  • Billing records — for the period required by applicable U.S. federal and state tax and accounting law (generally up to seven years).
  • Logs and security data — typically up to 12 months, longer where needed to investigate incidents or comply with legal obligations.

9. Your rights

If you are in the EEA or the UK, you have the right under GDPR to (a) access your personal data, (b) rectify inaccurate data, (c) erase data ("right to be forgotten"), (d) restrict or object to processing, (e) data portability, (f) withdraw consent at any time where processing is based on consent, and (g) lodge a complaint with your local data protection supervisory authority (in the EEA, your national data protection authority; in the UK, the Information Commissioner's Office).

You can exercise most of these rights directly from your account settings (data export and account deletion). For any other request, contact us using the contact details on our website. We respond within 30 days or as required by law.

U.S. residents. Depending on your state, you may have rights to know, access, delete, correct, opt out of "sale" or "sharing" of personal information, limit use of sensitive personal information, and to be free from discrimination for exercising those rights. We do not "sell" personal information for monetary consideration. To exercise these rights, use the same in-product controls or contact us.

10. Children

The Service is not directed to children under 18. We do not knowingly process personal data of children under 13 in violation of applicable law. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Cookies

We use a small number of strictly-necessary cookies (e.g. authentication and CSRF). We do not use advertising cookies. Where additional cookies become necessary, we will request your consent in line with the EU ePrivacy rules and applicable U.S. state privacy law.

12. Security

We implement industry-standard technical and organisational measures to protect personal data, including encryption in transit, access controls, audit logging and isolation of administrator surfaces. No system is perfectly secure; we cannot guarantee absolute security.

13. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email.

14. Contact

Questions or requests can be sent to StakLabs LLC at hello@creou.app.


© 2026 StakLabs LLC. All rights reserved.

TermsPrivacyAcceptable useDMCATakedownCookiesRefundsContact