This Privacy Policy explains how CreatorsForge.io ("CreatorsForge", "we") collects, uses, and protects personal data when you use our platform.
1. Data we collect
- Account data: email address, name (if provided), authentication identifiers (including Google sign-in identifiers), and hashed credentials.
- Content data: prompts, projects, uploads, generated outputs, brand kits, and connected-account metadata you create in the service.
- Usage & billing data: credit balances and usage records, subscription/plan status, payment transaction references (we do not store card numbers — payments are handled by our payment processors), and audit/security logs.
- Technical data: IP address, browser/device information, and cookies strictly needed for authentication and session management.
2. How we use data
- To provide the service: generate content, store projects, meter credits, deliver emails (password resets, notifications, reports).
- To secure the service: rate limiting, fraud and abuse prevention, audit logging, error monitoring.
- To improve the service: aggregate, de-identified usage analysis.
- We do not sell your personal data.
3. AI processing
Your prompts and relevant project context are sent to third-party AI providers (for example Anthropic for text, fal.ai for images/video, ElevenLabs for voice) to generate the outputs you request. We send only what is needed to fulfil your request. These providers process data under their own terms and privacy policies and, per their standard API terms, do not use API data to train their models.
4. Google user data (Gmail) and Limited Use
If you choose to connect a Google account (Gmail or Google Workspace) to the CreatorsForge AI Email Assistant, you authorize us, through Google’s OAuth consent screen, to access specific Google user data. This section describes that access and applies in addition to the rest of this policy.
Scopes we request and why:
- View your email messages and settings (
gmail.readonly): to read the messages in your inbox so the Email Assistant can classify them, surface what needs your attention, summarize them, and prepare draft replies for you. - Send email on your behalf (
gmail.send): to send a reply onlyafter you review and explicitly approve it. Nothing is sent automatically by default.
How we handle this data:
- We access the minimum data needed to provide the features you request, and only while your account is connected.
- Message content and metadata are used solely to power the user-facing Email Assistant features described above. We do not use Gmail data for advertising, and we do not sell it.
- We do not use Gmail data to develop, improve, or train generalized artificial-intelligence or machine-learning models. Where AI classifies or drafts, it operates only on your data to produce your result, under provider terms that prohibit training on that data.
- OAuth tokens are encrypted at rest (AES-256-GCM) and are never exposed to other users. Message headers and snippets we cache to run the assistant are protected by row-level access controls and are deleted when you disconnect the account or delete your data.
- Humans do not read your Gmail data except (a) with your explicit consent, (b) where necessary for security purposes (such as investigating abuse), or (c) to comply with applicable law.
- Administrators of CreatorsForge can see only aggregate counts (for example, the number of messages processed) and can never read your email content.
Limited Use. CreatorsForge’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke our access at any time from the Email Assistant settings (Disconnect), by deleting your data in-app, or via your Google Account permissions page. On disconnect we delete the stored tokens immediately and remove cached message data.
5. Service providers (sub-processors)
We use trusted providers to run CreatorsForge, including:
- Supabase (database, authentication, file storage)
- Vercel (hosting and content delivery)
- Anthropic, fal.ai, ElevenLabs, Shotstack, HeyGen, OpenAI (AI generation and media rendering)
- Brevo and Resend (transactional email)
- Payment processors (e.g. NOWPayments for cryptocurrency; card processors when enabled)
- Sentry (error monitoring) and Upstash (rate limiting)
6. Cookies
We use essential cookies for sign-in sessions and security. We do not use third-party advertising cookies. Optional analytics, if enabled, are privacy-respecting and aggregate.
7. Data retention
Account and content data are retained while your account is active. When you delete content or your account, we delete or de-identify associated personal data within a reasonable period, except where we must retain records for legal, billing, or security purposes.
8. Your rights
Depending on your location (including under GDPR and CCPA), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can delete projects and content in-app, or contact us to exercise any right. We will respond within the timeframes required by law.
9. Security
We use industry-standard measures: encrypted connections (TLS), encryption at rest for sensitive tokens, row-level access controls on all user data, audit logging, and least-privilege access. No system is 100% secure; report concerns to hello@creatorsforge.io.
10. International transfers
Our providers may process data in other countries, including the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses offered by our sub-processors.
11. Children
The service is not directed to children under 18 and we do not knowingly collect their data.
12. Changes & contact
We may update this policy; material changes will be announced in the app or by email. Contact us at hello@creatorsforge.io.