LAST UPDATED · 12 SEPTEMBER 2026
Data Collection Policy
A practical account of the information handled by CreatorTech.io. Read the Privacy Policy for lawful bases, rights and how to raise a complaint.
On this page
1. Scope and collection methods
We collect information through forms, email verification, uploads, tool requests, saved projects, comments and support messages. Sign-in services supply limited identity information for the features using them. Hosting providers receive the technical information needed to deliver web requests, such as an IP address and request headers.
Data collection is not the same as permission to send marketing. The service records successful and failed generation events to operate its allowances and understand usage, even when you reject optional browser storage. Optional saved entries are a separate device feature. We do not treat hashed identifiers as anonymous where they can still relate to an individual.
2. Records we collect
- Account and access records
- Email address, first and latest access, age-confirmation time, hashed verification/session tokens, challenge expiry and attempts, and the resource associated with a request where applicable. Email verification confirms access to an inbox, not legal identity or age.
- Prompts and tool briefs
- Audience, industry, topic, content goal, offer, context, selected hooks, scripts, pasted transcripts, factual notes, reference URLs and brand instructions you provide. The assembled lead magnet prompt and generated outputs can be saved with the account email.
- Projects and versions
- Project titles, content, brand settings, revisions, generation status, approval choices, slide layouts, motion choices and export-related settings. A saved approval records your choice; it is not independent verification that the content is accurate or legally cleared.
- Uploads and asset metadata
- Uploaded logos, images, screenshots and videos, labels and descriptions, media type, file size, dimensions, aspect ratio, ownership/scope, dates, expiry and project-use metadata. Files can contain embedded metadata or visible personal information; remove information you do not want to share before uploading. We do not promise to strip all embedded metadata.
- Usage and quality records
- Tool, action, account email, brief, result, timestamps, outcome, cache/live source, feedback, model, available input/output token counts, request duration and estimated provider cost. Quality reports may include flagged hooks and context. Owner reports distinguish estimated cost from actual provider billing reports.
- Quotas and security
- Daily usage keys derived from identity and IP/network information, request counts, expiry and security outcomes. The application uses hashes for network quota records and does not write raw IP addresses into its generation-history reports. Hosting security logs are separate.
- Library and public discussions
- Guide requests/download events; for discussions, site-specific sign-in identifiers, name, email supplied by the sign-in service, comment/reply content, dates and individual voting records. Readers see the display name, content, dates and totals, not the list of voters or account emails. A download event records a request, not proof that you read the file.
- Consent and enquiries
- Selected marketing list, submitted email, consent wording/version where recorded, signup time, and messages sent to us. Optional browser-storage preference and its expiry are stored on your device. Contact messages and their reply email are recorded in the private administration area.
Connected projects also store customer personas, products, brand fonts and visual preferences; research notes and source links; content and campaign records; selected context; posted/rejected/successful labels; and manually entered performance counts and notes. These are member-provided records, not automatically collected social analytics. They are included in project exports and version history. Removing a content record from the current draft does not erase earlier versions; deleting the project removes its versions. Relevant material may also remain in service generation history under the schedule below.
3. What goes to AI providers
| Action | Information sent | Processing |
|---|---|---|
| Lead Magnet Prompt Builder | The audience/offer brief goes to CreatorTech's server. | Prompt assembly without an AI call. You decide whether to paste it into another service. |
| Topics and hooks | Relevant brief, topic, audience and hook context. | OpenAI generates and may review or revise results. Account email is not deliberately included. |
| Scripts, carousels and articles | Relevant project content, brand brief, selected source text and asset descriptions. Selected image references may also be included. | OpenAI generation and input/output safety checks. The brief can contain personal information you supplied. |
| Uploaded video / reference links | Stored file or URL and associated labels. | No automatic video AI analysis or fetching of reference pages in the current member workflow. |
| Browser export | Selected project content and assets used in the browser. | Local rendering and download. Browser export does not itself call an AI model. |
Generated results are stored on the site independently of the AI provider's own retention. Some AI requests disable response storage; not all generation paths currently do. We therefore do not promise that provider-side content is deleted immediately. OpenAI's API data controls describe provider logs and application-state retention; the effective settings and any exceptions depend on the endpoint and account. See OpenAI's data-controls documentation.
Do not enter personal details merely because a tool accepts free text. If you use someone else's information, make sure you have an appropriate lawful basis and authority. Ask us before using this public service for confidential, regulated or large-scale client data.
Connected generation uses the current project only: its brand and brief, up to six selected non-rejected text records (up to 4,000 characters per record), and up to twelve recent posted, rejected or successful summaries. Summary notes are limited to 300 characters each. Selected material and summaries are processed by OpenAI for requested generation and safety checks. We do not automatically send every saved content record or numerical performance metric. Generation records retain the submitted project brief for service history and reporting.
4. Retention schedule
These are the current application rules and review criteria. “Reviewed” means a necessity review by the operator, not an automated purge. Expiry makes a record or asset unusable for its original purpose; database or file removal may follow on a later request or housekeeping run.
- Verification challenges and access sessions
- Codes expire after 10 minutes and permit no more than five checks. Library/tool sessions last up to 30 days unless revoked earlier by sign-out. Expired challenges and sessions are cleaned on subsequent access requests. The application stores token/code hashes rather than reusable plaintext secrets.
- Free uploads and logos
- Expire 30 days after upload. This covers private images, screenshots, videos and logos. Editing labels, reusing an asset or deleting its originating project does not restart the timer.
- Uploads during paid-tier access
- Active paid-tier uploads have no scheduled expiry while that access continues. Ending paid access gives previously indefinite private uploads a 60-day expiry. New uploads after return to Free receive 30 days. Repeated Free assignment does not extend the grace period. Resuming paid access before expiry can retain remaining files; it does not revive expired or deleted files. These existing access-tier rules do not mean payment collection is live.
- Expired and deleted files
- Expired assets stop being served. Housekeeping deletes stored objects in bounded batches and retries failures. Removal is not guaranteed at the exact expiry minute. Shared CreatorTech and owner assets are exempt from member-tier expiry and remain until withdrawn or no longer needed. Any retained personal information remains subject to privacy rights.
- Projects, versions, account and guide history
- Retained to provide your workspace and resource history until deleted or no longer needed. Account and activity records are reviewed after 24 months; project text has no automatic 30/60-day upload expiry. Ask for remaining linked history to be removed when closing your account.
- Generation, AI request and feedback history
- Reviewed after 24 months and removed when no longer needed or following a valid deletion request, subject to applicable exceptions. These records are separate from caches. Deleting a current project alone does not erase all past usage records. Some recovered legacy results have no recoverable identity or original brief.
- Hook/topic caches and daily counters
- Private cached results are eligible for reuse for up to seven days. Expired cache records are not served and may be cleared on later successful generation. Daily quota and form-limit windows reset at midnight UTC; expired technical records may remain until their cleanup path runs. These are not permanent marketing identifiers.
- Marketing signup records
- Kept until consent is withdrawn or they are no longer needed. Inactive announcement signups and records without an active newsletter programme are reviewed after 24 months. Where necessary, a minimal suppression record may be retained to respect an opt-out; it must not be used for marketing.
- Contact messages and complaints
- Normally retained for 12 months after resolution, with review by the operator. A specific legal claim or obligation may justify longer limited retention. Future financial records will have a documented schedule based on the relevant accounting and legal obligations before paid launch.
- Optional browser entries and downloaded copies
- Saved prompt entries remain until cleared, permission is withdrawn, or the 180-day choice expires and is next checked. Copies you download or export remain under your control. Provider logs and backups are outside these application expiry timers; their exact arrangements still need to be confirmed.
5. Access, reports, exports and deletion
Member projects and uploads are private from other members. Authorised administrators can access account-linked records and reports for support, operation, moderation and product improvement. Shared assets are separately marked and are not created by silently making member uploads public. Reports are not a public directory.
You can edit and export work using the relevant tool and delete your own projects or assets. For a broader access, correction, objection or deletion request, use the privacy contact form. Tell us whether you mean a single file, a project, marketing consent or all account-linked records so we can deal with the right scope.
We may need to verify your request. We will explain any lawful exception to deletion and restrict retained records as appropriate. Provider backups, exported administrator copies and any legal hold must be considered separately; deleting a live record is not a claim that every backup vanished at the same instant. Public copies made by other people and files on your own device cannot necessarily be recalled.
6. Additional records at subscription launch
Before charging for subscriptions, we will disclose the payment processor and relevant retention periods. Expected additional records include plan and price, billing contact, invoice and payment references, entitlement dates, the terms/version accepted, any express request for early supply, trial and renewal dates, reminder and cooling-off notices, cancellation requests and confirmations, refund calculations and payment status.
These records will support fulfilment of the subscription, required notices, consumer remedies, accounting and disputes. They will not create marketing consent. The site does not currently collect card numbers or operate a payment checkout. No payment processor or card-storage certification is claimed here.
7. Limits and your choices
We do not add advertising pixels, sell contact lists or run a hidden demographic questionnaire. We do not infer that you read a guide, achieved a business result or consented to marketing merely because you used a tool. We do not track your browsing across unrelated websites through our application.
Operational reporting is still personal-data processing and includes the content described here. A cookie rejection only controls the optional device storage it describes. Use the Privacy Policy for your other rights, including objection, withdrawal and complaints. See the Cookie Policy for the exact application storage names and durations.
You can save or print this page using your browser. Questions? Contact CreatorTech.io.
