Privacy Policy

How Creates Growth OS protects business data

Creates Growth OS helps businesses analyze their brand, generate AI marketing assets, and prepare campaigns. This policy explains what data we collect, how we use it, and how users can control it.

Data We Collect

We collect account information such as name, email address, authentication identifiers, workspace membership, and basic business profile details.

Users may provide business information including website URLs, social media links, WhatsApp details, business type, growth goals, campaigns, content plans, customer pipeline notes, and AI memory context.

Authentication

Authentication is handled through Supabase Auth. Session cookies and secure tokens are used to keep users signed in and protect access to private workspace areas.

Users are responsible for keeping login credentials secure and for notifying us if they believe account access has been compromised.

Supabase

Creates Growth OS uses Supabase to store user accounts, workspaces, onboarding information, saved AI outputs, campaign records, integration status, and activity logs.

Supabase security features such as row level security, server-side service role usage, and protected environment variables are used to limit unauthorized access.

OpenAI

When AI generation is requested, relevant business context may be sent to OpenAI to generate analysis, campaign strategies, content plans, WhatsApp sales scripts, and pipeline recommendations.

We do not send secret API keys or private integration tokens to OpenAI prompts. Users should avoid submitting sensitive personal data that is not needed for marketing strategy.

Meta Account Data

When an authorized workspace owner or administrator connects Meta, we receive the Meta user identity, granted permission status, accessible Business Portfolios, Ad Accounts, Facebook Pages, and an optional Instagram professional account linked to a selected Page.

Meta access tokens and Page tokens are encrypted and stored server-side. Meta-derived asset data is used for connection validation, explicit asset selection, and manually approved creation of advertising objects in PAUSED status. It is not included in OpenAI prompts.

Connection records are retained while the integration remains connected. Users can disconnect Meta to request remote permission revocation and irreversible local credential deletion, or use the verified data-deletion workflow.

Cookies

We use essential cookies and local browser storage for authentication, language preferences, and core application functionality.

If analytics are enabled in the future, they will be used to understand product usage and improve reliability, not to sell personal information.

Analytics

Creates Growth OS may collect operational analytics such as page usage, error states, feature usage, and performance signals.

Analytics are used to improve the product experience, diagnose issues, and understand which workflows help users create business outcomes.

User Rights

Users may request access, correction, export, or deletion of account and workspace data.

Requests can be submitted through the Data Deletion page or by contacting the email listed in this policy.

Data Retention

We retain account, workspace, campaign, AI memory, and activity data while an account remains active or as needed to provide the service.

When deletion is requested and verified, we will delete or anonymize eligible data unless retention is required for security, legal, billing, or abuse-prevention reasons.

Security

Secrets and integration tokens are stored server-side only and are never intentionally exposed to the frontend.

We use environment variables, encrypted token storage patterns, access controls, and audit logs to reduce the risk of unauthorized access.