Legal

Privacy policy

Last updated July 22, 2026

This is the current, effective version of this document and governs your use of Creataly's website and platform. When we make material changes, we update the date shown above and, where appropriate, notify you.

1. Who we are

Creataly is a creator-business operating system for creator agencies, brands, and creators, operated by Creataly, Inc., a company incorporated in the State of Delaware, USA. Creataly is the business responsible for personal data collected through this website and the Creataly platform. For visitors and customers in the United Kingdom and European Economic Area, Creataly acts as the “data controller” under UK GDPR and the EU GDPR; for residents of US states that have consumer privacy laws, Creataly is the “business” that determines how your personal data is handled.

If you have a question about this policy or how we handle your data, contact us at hello@creataly.com or by post at Creataly, Inc., 16192 Coastal Highway, Lewes, Delaware 19958, USA.

2. What data we collect

Information you provide

  • Account information: name, email, password, and authentication identifiers handled by Clerk.
  • Workspace information: agency or brand name, role, team size, roster details, deal records, campaign briefs, payout preferences, and any content uploaded into Roster, Deals, Campaigns, Scheduler, Pay, and Insights.
  • Demo, contact, and waitlist submissions: name, email, company, role, team size, current tools, and the message or workflow notes you share with us.
  • Billing information: company name, billing address, and tax identifiers (such as sales-tax or VAT registration numbers). Payment card details are collected and processed directly by Stripe. Creataly does not store full card numbers on its servers.

Information collected automatically

  • Product and analytics data: pages visited, modules used, session duration, referring source, and feature interactions.
  • Advertising data: campaign source, conversion events, and remarketing identifiers from Google Ads.
  • Device and connection information: IP address, browser type, operating system, device type, language, and approximate location.
  • Cookies and local storage: authentication sessions, preference flags, and analytics identifiers. See our Cookie Notice for details.

Data from connected social accounts

Creators can optionally connect their social media accounts, currently Instagram, TikTok, YouTube, and Twitch, so Creataly can display their audience metrics. Depending on the platform, we receive and store profile details (such as user ID, username or handle, account type, and profile picture), audience metrics (such as follower or subscriber count, average views, reach, and engagement), recent post data (such as post type, caption, link, thumbnail, and like, comment, and view counts), and, for Instagram and YouTube, aggregated audience demographics (such as age range, gender, and country distribution), along with an access token that we keep encrypted at rest. See the “Connected social accounts and platform data” section below for how this data is used and deleted.

Data from a connected WhatsApp Business number

Agencies and brands can optionally connect their own WhatsApp Business number through the WhatsApp Business Platform (Cloud API) so they can read and reply to customer conversations inside Creataly. When you connect a number, we receive and store the business phone number and its display name, and — for people who message that number — their WhatsApp ID (phone number), WhatsApp profile name, and the content and timestamps of the messages exchanged. We also store the access token issued for your WhatsApp Business Account, which we keep encrypted at rest. See the “WhatsApp Business messaging” section below for how this data is used and deleted.

Data from connected email and calendar accounts

You can optionally connect a Gmail (Google) or Outlook (Microsoft) mailbox and calendar so you can read, organise, and send email and sync events inside Creataly. When you connect a mailbox, Creataly accesses the email you open on demand, including subjects, message bodies, attachments, and sender and recipient addresses, and can send email on your behalf. We do not store the contents of your emails on our servers; they are fetched from Google or Microsoft each time you view them, and we retain only the encrypted access token and basic account details such as the connected address. To help you address messages, we also access the contacts in the connected account. Calendar events you sync, such as title, notes, and times, are stored so we can display and two-way sync your calendar. See the “Connected email and calendar accounts” section below, including our limited-use commitment, for how this data is used and deleted.

Identity and verification data

Creators may be asked to verify their identity. Verification is performed by Stripe using Stripe Identity: you provide a government-issued identity document and a matching selfie directly to Stripe, which checks them and returns a result. Creataly does not store your identity document images or your selfie; we store only the verification session reference, its status and expiry, and the derived trust and risk signals. Where we handle identity or biometric information we treat it as sensitive personal data and use it only to confirm identity and support payout readiness. Some creator profiles may also include optional details such as gender, age range, or ethnicity that a creator or agency chooses to add.

Data you process through Creataly

When you use Creataly to manage creators, brands, deals, campaigns, or payouts, you may upload personal data about other people such as creator contact details, brand contacts, contract counterparties, or payee information. For that data, you are the controller and Creataly acts as your processor under a data processing addendum.

Messages, notes, and assistant memory

Creataly stores content you create inside the platform, including internal chat and direct messages and their attachments, notes you add to creators, contacts, or deals, and files you upload. When you use our AI assistant we store your conversations and may keep short durable summaries, which we call memories, that the assistant distils from them to give more relevant help over time. You can review and manage assistant memory in your settings.

3. How we use your data

  • Provide the service: account creation, workspace setup, module access, scheduling, payments, and customer support.
  • Communicate with you: respond to demo and contact requests, send service notices, security alerts, and product updates.
  • Improve the platform: analyse usage patterns to refine modules, performance, and onboarding.
  • Marketing and growth: with consent where required, send relevant updates about Creataly modules, events, and case studies.
  • Protect the service: detect fraud, abuse, and security incidents, and meet our legal and tax obligations.

Creataly does not sell your personal data for money. Where we use advertising cookies such as Google Ads remarketing, our sharing of online identifiers with those providers may be treated as a “sale” or “sharing” for cross-context behavioural advertising under some US state privacy laws, and you can opt out at any time through our cookie controls and as described in “Your privacy rights” below. To provide AI features, we send the content you choose to use them on to our AI processors, who process it only to generate the response and, under our agreements with them, do not use it to train their own models; we do not otherwise train external AI models on your customer or workspace content. We do not use your data for automated decision-making that produces legal or similarly significant effects without a lawful basis or, where required, your consent.

4. Legal basis for processing

Where UK or EU data protection law applies to our handling of your personal data, we rely on one or more of the following legal bases:

  • Contract: providing the platform and services you have signed up for.
  • Legitimate interests: maintaining a secure, reliable, and improving service, and pursuing limited, relevant marketing.
  • Consent: optional analytics, advertising cookies, and marketing emails where consent is required.
  • Legal obligation: tax, accounting, anti-fraud, and other regulatory requirements.

5. Who we share your data with

We share personal data only with the processors that operate the service on our behalf. Each provider is bound by a written agreement with appropriate confidentiality and security obligations.

  • Clerk: authentication, session management, and user identity.
  • Stripe: subscription billing, checkout, and payment processing, and identity verification through Stripe Identity.
  • Supabase: database hosting and file storage for workspace data.
  • Vercel: application hosting, deployment, and edge delivery.
  • Vercel AI Gateway: routes AI requests to model providers, which may include OpenAI, Anthropic, and Google, that process the content you use our AI features on in order to generate responses.
  • Google: when you connect a Google account, access to Gmail, Google contacts, and Google Calendar to power your inbox and calendar; and, where you consent, Google Analytics and Google Ads for website analytics and marketing.
  • Microsoft: when you connect an Outlook account, access to Outlook mail and calendar through Microsoft Graph to power your inbox and calendar.
  • Meta Platforms and other social platforms (Instagram, TikTok, YouTube, and Twitch): audience metrics from the accounts creators choose to connect, and, when the WhatsApp Business feature is enabled, delivery of WhatsApp messages.
  • Sentry: error and crash monitoring to keep the service reliable and secure.
  • PostHog: product and website analytics, including how visitors use our site and how brands interact with public creator media kits.
  • Upstash: caching and rate limiting, which may process technical identifiers such as IP addresses.
  • Brevo: sending transactional email and managing our contact, waitlist, and lifecycle marketing lists.
  • Calendly: scheduling for demo bookings made from our website.

Creataly is based in the United States, and the providers listed above may store or process your personal data in the United States and other countries. When we transfer personal data from the United Kingdom or European Economic Area to a country without an equivalent adequacy decision, we rely on approved safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

6. How long we keep your data

  • Account and workspace data: for the lifetime of your subscription, plus 30 days after cancellation to allow recovery.
  • Connected social account data and access tokens: kept until you disconnect the account or delete your workspace, and removed immediately when you disconnect (posts you have chosen to feature on your media kit remain part of the kit until you remove them).
  • WhatsApp conversations, messages, and access tokens: retained while your WhatsApp Business number is connected, and deleted when you disconnect the number or delete your workspace.
  • Billing and tax records: up to 7 years, in line with applicable tax, accounting, and audit requirements.
  • Demo, contact, and waitlist submissions: up to 24 months from the last interaction.
  • Analytics and advertising data: in line with the relevant provider retention windows described in our Cookie Notice.
  • Backups: rolling backups for disaster recovery, deleted on a regular cycle.

Where we are required by law to keep records for longer, or where data is necessary to defend a legal claim, we will retain it only for as long as that purpose requires.

7. Cookies and tracking technologies

Creataly uses essential cookies for authentication, session security, and basic site function, and uses analytics and advertising cookies where you have given consent. Our Cookie Notice explains each cookie, the provider, and how long it lasts, and how you can change your choices.

8. Your privacy rights

You can exercise the rights below by emailing hello@creataly.com. We will verify your identity where required and respond within the time the applicable law allows. You will not be discriminated or retaliated against for exercising your rights, and you may use an authorised agent to submit a request on your behalf.

US state privacy rights

Depending on your state of residence — including California, Virginia, Colorado, Connecticut, Utah, Texas, and other states with consumer privacy laws — you may have the right to:

  • Know and access the categories and specific pieces of personal information we have collected about you.
  • Delete personal information we hold about you.
  • Correct inaccurate personal information.
  • Opt out of the “sale” or “sharing” of your personal information and of targeted or cross-context behavioural advertising. You can do this at any time using our cookie controls.
  • Limit the use of sensitive personal information. Where we process sensitive personal information, such as identity or biometric verification data, we use it only for the purposes described in this policy, such as confirming identity and preventing fraud, and not to infer characteristics about you.
  • Receive a copy of your personal information in a portable format.

For California residents, we respond to verifiable requests within 45 days, extendable by a further 45 days where permitted. California's “Shine the Light” law lets you ask about personal information disclosed to third parties for their own direct marketing — Creataly does not share personal information with third parties for their direct marketing. If we deny a request, you may appeal by replying to our response.

UK and EU rights

If you are in the United Kingdom or European Economic Area, under UK and EU GDPR you have the right to access, rectify, erase, restrict, or object to our processing of your personal data, to receive it in a portable format, and to withdraw consent for marketing or optional cookies at any time. If you are not satisfied with our response, you can complain to the UK Information Commissioner's Office at ico.org.uk or to your local EU supervisory authority.

You can unsubscribe from marketing emails at any time using the link in each email, without affecting the service, billing, and security messages we need to send you.

9. Data security

  • All traffic between your browser and Creataly is encrypted in transit using TLS.
  • Production infrastructure is hosted on Vercel and Supabase with restricted access and audit logging.
  • Payments are handled by Stripe, which is PCI DSS Level 1 certified. Creataly never sees your full card number.
  • Access to production systems is limited to a small number of staff and protected by single sign-on and multi-factor authentication.

10. Children's privacy

Creataly is a business platform intended for users aged 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18, including children under 13 as defined by the US Children's Online Privacy Protection Act (COPPA). If you believe a child has provided us with personal information, contact us and we will delete it.

11. Changes to this policy

We may update this policy as Creataly evolves. Material changes will be communicated by email or by a notice on the website. The last updated date at the top of this page reflects the current version.

12. Connected social accounts and platform data

Creators may connect supported third-party social accounts to Creataly to display their audience metrics. Instagram, TikTok, YouTube, and Twitch are supported today. Connecting is optional and is always initiated by you.

What we access and why

  • We use the Instagram API with Instagram Login and request read-only access through two permissions: instagram_business_basic (your business profile and media) and instagram_business_manage_insights (aggregated audience and media insights).
  • We receive and store your Instagram user ID, username, account type, follower count, and profile picture URL, together with an access token that we hold encrypted at rest.
  • We access up to 12 of your recent Instagram posts, including post type, caption, link, thumbnail, and like, comment, and view counts. We use them to calculate an engagement rate and average views, and, where you choose, to display recent or featured posts on your profile and media kit.
  • We access aggregated Instagram audience insights for the connected account: follower demographics (age range, gender, and country distribution) and 28-day reach split by followers and non-followers. These are aggregated statistics only and never identify individual followers.
  • We use this data only to display your audience metrics, content, and identity inside your Creataly dashboard, profile, and media kit. We do not post on your behalf, send or read messages, write or read the content of comments, or use the data for advertising or to train AI models.
  • For YouTube, we request youtube.readonly and yt-analytics.readonly. These scopes provide read-only access and do not let Creataly upload, edit, delete, like, comment on, or otherwise modify YouTube content.
  • We access the connected YouTube channel's ID, title, handle, subscriber count, and uploads playlist, together with view, like, and comment counts for up to 12 recent uploads. We use those statistics to calculate average views and an engagement rate. We retain the channel identity, subscriber count, and derived metrics, but not the individual upload identifiers or per-video statistics.
  • We access aggregated YouTube Analytics for the preceding 90 days, specifically viewer percentages by age group and gender and views by country. We store normalised audience distributions and the date on which they were sampled so they can be displayed in the creator's dashboard and profile.
  • We use YouTube data only to provide the connected-channel, audience, and analytics features requested by the creator. We do not use it for advertising or to train or improve generalised, foundation, frontier, or shared AI models.

Disconnecting and deleting your platform data

  • You can disconnect a connected account at any time from the “Connect your socials” section of your dashboard. Disconnecting immediately and permanently deletes the stored connection, its cached metrics and recent post data, and the access token.
  • Posts you have chosen to feature on your public media kit are stored as part of the kit (including a copy of the post thumbnail) and are not removed by a disconnect; you can remove them at any time in the kit studio, and they are deleted with your kit or account.
  • Deleting your Creataly workspace or account removes all connected-account data along with it.
  • To request deletion of platform data without using the in-app control, email hello@creataly.com and we will action your request within 30 days.

Our access to and use of Meta and Instagram data complies with the Meta Platform Terms and Developer Policies. Our use of YouTube data complies with the Google API Services User Data Policy, including the Limited Use requirements, and the YouTube API Services Terms of Service. We do not sell connected-platform data, use it for advertising, or share it except with the infrastructure processors listed above that process and store it securely on our behalf.

13. WhatsApp Business messaging

Agencies and brands can connect their own WhatsApp Business number to Creataly through the official WhatsApp Business Platform (Cloud API) to read and reply to customer conversations inside the platform. Connecting is optional, always initiated by you, and each connected number is isolated to your workspace.

What we access and why

  • We use the WhatsApp Business Platform with the whatsapp_business_messaging and whatsapp_business_management permissions to send and receive messages on your number and to read its profile and message templates.
  • We receive and store the business phone number and display name, the WhatsApp ID (phone number), profile name, and the content and timestamps of messages for conversations on that number, together with the access token for your WhatsApp Business Account, which we hold encrypted at rest.
  • We use this data only to show your WhatsApp conversations inside Creataly and to let your team reply to them. We do not use it for advertising or to train AI models.

Customer consent and opt-in

We enable replies to people who have messaged your WhatsApp Business number first, or whom you have added with their consent. Business-initiated messages sent outside WhatsApp's 24-hour customer service window use only message templates approved by WhatsApp. You remain responsible for having a lawful basis and any required consent to message your contacts, in line with WhatsApp's Business Messaging Policy.

Disconnecting and deleting your WhatsApp data

  • You can disconnect your WhatsApp number at any time from Settings → Integrations. Disconnecting removes the stored connection and its encrypted access token.
  • Deleting your Creataly workspace or account removes connected WhatsApp data, including stored conversations and messages.
  • To request deletion of WhatsApp data without using the in-app control, email hello@creataly.com and we will action your request within 30 days.

Our access to and use of WhatsApp and other Meta data complies with the Meta Platform Terms, the WhatsApp Business Messaging Policy, and Meta's Developer Policies. We do not sell platform data, and we share it only with the infrastructure processors listed above that store it securely on our behalf.

14. Connected email and calendar accounts

You can connect a Google (Gmail) or Microsoft (Outlook) account to use Creataly's inbox and calendar. Connecting is optional and always initiated by you.

What we access and why

  • With your permission we access your mailbox so you can read, organise, and send email inside Creataly, and your contacts so we can help you address messages. We read email content only when you open it and do not store the contents of your emails on our servers.
  • We access your calendar to display your events and keep them in two-way sync. The events we sync, such as title, notes, and times, are stored so your calendar works reliably inside Creataly.
  • We keep the account's encrypted access token and basic details, such as the connected email address, until you disconnect.

Limited use

Creataly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and our use of Microsoft data adheres to Microsoft's applicable terms. We do not use Google user data for advertising or sell it. We never use raw or derived Google user data to train or improve any generalized, foundation, or frontier AI model. If you actively invoke an AI feature, such as asking Creataly to draft a reply, we send only the minimum Google user data relevant to generating the output you requested. Our AI providers process that content solely to provide the requested output under terms that prohibit its use for model training or improvement.

Disconnecting and deleting your data

  • You can disconnect a connected mailbox or calendar at any time from Settings, Integrations. Disconnecting removes the stored access token and the calendar events synced from that account.
  • Deleting your Creataly workspace or account removes connected email and calendar data.
  • To request deletion without using the in-app control, email hello@creataly.com and we will action your request within 30 days.

15. AI features and processing

Creataly includes AI features, such as our assistant, AI-assisted email drafts, media-kit copy, and roster insights. When you use these features, the relevant content, for example your prompt, the records you ask about, or the email thread you are replying to, is sent through the Vercel AI Gateway to our AI model providers so a response can be generated. Depending on the feature and the model used, these providers may include OpenAI, Anthropic, and Google.

We send only the minimum content relevant to generating the output you requested. Under our agreements with these providers, your content is used only to produce that output and is not used to train or improve their models. AI output can be inaccurate or incomplete, so you remain responsible for reviewing it before you rely on or send it. You can control certain AI features, including the assistant's long-term memory, in your settings.

16. Contact us

The company responsible for your personal data is Creataly, Inc. Questions, requests, or complaints about this privacy policy can be sent to hello@creataly.com or by post to Creataly, Inc., 16192 Coastal Highway, Lewes, Delaware 19958, USA.