Creatozen
← Back to home

Privacy Policy

Last updated: 10 September 2026

This Privacy Policy explains how Creatozen (“Creatozen”, “we”, “us”) collects, uses, stores, shares, and deletes information when you use our website at creatozen.com and our application at app.creatozen.com (together, the “Service”). It also explains how we handle data accessed through the Instagram Platform and the Meta Graph API on your instruction.

If you do not agree with this policy, please do not use the Service.

1. Who this policy is for

The Service is a business tool used by creators, coaches, and their teams (“Customers”). This policy covers:

  • Customers and their team members who create an account and operate a workspace.
  • End users — the people who message or comment on a Customer's connected Instagram account and whose interactions are processed by the Service on that Customer's behalf.
  • Visitors to creatozen.com.

For end-user data processed on a Customer's behalf, the Customer is the data controller and Creatozen is the data processor. We act on the Customer's documented instructions.

2. Information we collect

2.1 Account and workspace information

  • Name, email address, and (optionally) phone number.
  • Password, stored only as a salted hash (Argon2id). We never store it in plain text.
  • Workspace settings you configure: your offer details, tone and messaging rules, automations, tags, pipeline stages, saved views, and team members and their roles.
  • Billing information if you subscribe to a paid plan. Card details are handled by our payment processor and are never stored on our servers.

2.2 Instagram and Meta Platform data

When you connect an Instagram professional account, you authorise Creatozen through Meta's official login. With your authorisation and the permissions you grant, we access and process:

  • Account profile — the connected account's ID, username, name, profile picture, follower and media counts, and the linked Facebook Page where applicable.
  • Direct messages — the content, sender, timestamp, and delivery status of messages in conversations the connected account is part of, and messages the Service sends on your instruction.
  • Comments — the text, author, and timestamp of comments on the connected account's media, and replies the Service posts on your instruction.
  • Media metadata — captions, media type, permalink, and timestamps of the connected account's posts and reels.
  • Insights — reach, impressions, engagement, and similar metrics for the connected account and its media, where the metric is exposed by the Meta API.
  • Access tokens issued by Meta so the Service can act on your behalf until you disconnect.

We request only the Instagram permissions that the capabilities you enable require. If you do not enable a capability, we do not request its permission.

2.3 Data we derive

  • Contact records and conversation summaries built from the interactions above.
  • Lead scores and stages computed from qualifying signals in a conversation.
  • Content ideas, hooks, captions, and trend analysis generated from your inputs and your account's performance.

2.4 Technical and usage data

  • IP address, browser and device type, and pages or actions within the Service, used for security, debugging, and product analytics.
  • Server logs and error reports.
  • A session cookie to keep you signed in. We do not use third-party advertising or cross-site tracking cookies.

3. How we use information

PurposeExamples
Provide the ServiceReply to and qualify DMs, post comment replies, build the CRM, plan content, and report analytics — all as configured by you.
Account & securityAuthenticate you, prevent abuse, enforce rate limits, and keep audit logs.
SupportRespond to your requests and diagnose issues.
BillingProcess subscriptions and meter usage against your plan.
Improve the ServiceUnderstand which features are used, in aggregate. We do not use the content of end-user messages to train third-party AI models.
LegalComply with applicable law and enforce our Terms.

4. Legal bases

Where the GDPR or similar laws apply, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (security, product improvement, and running our business); consent (where required, such as the Instagram connection you authorise); and legal obligation. For end-user data, the relevant lawful basis is determined by the Customer as controller.

5. Meta Platform data — specific commitments

Our use of information received from the Instagram and Meta APIs follows the Meta Platform Terms and Developer Policies. In particular:

  • We use Platform Data only to provide or improve the features you enabled.
  • We do not sell Platform Data, and we do not use it for advertising or to build user profiles for purposes unrelated to the Service.
  • We do not transfer Platform Data to data brokers, ad networks, or monetisation partners.
  • We retain Platform Data only as long as needed for the purpose above, and we delete it on request or when you disconnect (see sections 7 and 8).

6. How we share information

We do not sell your personal information. We share it only with:

  • Infrastructure providers that host and run the Service under contract: Railway (application and database hosting) and Cloudflare (content delivery, DNS, and security). Data is processed in their data centres, primarily in the United States.
  • Payment processors — Stripe and/or Razorpay — to take payment if you subscribe.
  • AI processing provider — Anthropic — when you use AI features, to generate replies, summaries, or content from the inputs you provide. Content sent for processing is not used to train their models.
  • Meta Platforms — to send and receive the messages, comments, and requests you instruct.
  • Professional advisers and authorities where required by law, or to protect rights and safety.
  • A successor entity in the event of a merger, acquisition, or sale of assets, under equivalent protections.

7. Retention

  • Account and workspace data is kept while your account is active.
  • When you disconnect an Instagram account, the stored access token is revoked and deleted, and synced Instagram content for that connection is deleted or de-identified.
  • When you delete a workspace or your account, data enters a short grace period (during which it can be restored on request) and is then permanently purged from production systems. Encrypted backups are overwritten on their normal rotation, no later than 30 days after purge.
  • We may retain minimal records required for legal, tax, or security purposes for as long as the law requires.

8. Your rights and choices

  • Access, correction, export, deletion — you can access and edit most data in the app, export your workspace data, and delete your workspace or account from Settings. See Data Deletion for the full process, or email creatozen@gmail.com.
  • Disconnect Instagram — remove the connection in the app, or revoke Creatozen's access from your Instagram settings at any time.
  • Objection and restriction — where applicable law provides these rights, contact us to exercise them.
  • Complaint — you may lodge a complaint with your local data protection authority.
  • End users: to exercise rights over data processed by a Customer, contact that Customer; we will assist them as their processor.

9. Security

  • Encryption in transit (TLS) for all traffic, and encryption at rest for the database and for integration credentials such as access tokens.
  • Per-workspace data isolation enforced in the application and, on the database, with row-level security.
  • Role-based access control, scoped API keys, rate limiting, and audit logging.
  • Least-privilege access for our team, and prompt revocation when access is no longer needed.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any regulator as required by law.

10. International transfers

We and our providers may process data in countries other than yours, including the United States. Where required, we use appropriate safeguards such as Standard Contractual Clauses for such transfers.

11. Children

The Service is for people aged 18 or older and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact creatozen@gmail.com and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will post the new version here with an updated date and, for material changes, notify you in the app or by email. Continued use of the Service after a change means you accept the updated policy.

13. Contact

For privacy questions, data requests, or anything else about the Service, email creatozen@gmail.com.