Legal · Privacy

Privacy Policy

Last updated 2026-05-25

Creativity is operated by Optima IA (Tunis, Tunisia). We process your brand's ad and commerce data to compute money-truth metrics and generate creative briefs. This page explains what we collect, where it lives, and how to control it.

What we collect

Plain language

Your ad and order data from the connectors you link (Meta, Converty, Shopify, Woo, Judge.me, TikTok, Trustpilot), plus your account email and locale preference. We don't collect your customers' personal data beyond what those connectors already store on your behalf.

Read the legal-grade detail

Account data: email, name, password hash (bcrypt), locale cookie, theme preference.

Brand operational data: ad events (spend, impressions, clicks, ROAS), order events (value, status, refusal, delivery), product financials (COGS, packaging, return cost), reviews, brief approvals, Friday conversations.

Derived data: embeddings, AI Tags, Performance Memory verdicts, anomaly traces.

Not collected: we do not collect end-customer payment details, government IDs, or device fingerprints.

Meta Platform Data

Plain language

When you connect your Meta (Facebook) ad account, we request three read-only permissions — ads_read, read_insights, and business_management — solely to show you your own advertising performance inside your private workspace.

Read the legal-grade detail

What we collect: your ad account identifiers, ad and creative metadata, and ad performance metrics (spend, impressions, clicks, conversions) via ads_read and read_insights; and which ad accounts you can choose to sync via business_management (read-only — we never modify your Business Manager settings, pages, or any other asset).

Why: to compute and display your own advertising analytics back to you, inside your own workspace. This data is never shown to other Creativity customers, never used to advertise to you, and never sold.

How it's deleted: disconnect at any time from Settings → Integrations — see Data Deletion Instructions for the full process.

Where your data lives

Plain language

Everything is stored in the EU. Supabase EU region for the database and storage. LangSmith EU workspace for AI traces. Google AI Studio EU billing for Gemini. Anthropic Claude calls use the EU inference region where supported. Vercel serves the app from EU edge locations.

Read the legal-grade detail

Primary data store: Supabase (PostgreSQL + Storage), EU region. Row-Level Security scopes every read and write by `brand_id`.

AI processors: Anthropic Claude (`inference_geo=eu`), Google AI Studio (Gemini, EU billing on paid tier — your data is not used to train Google models), OpenAI for `gpt-image-2` (image generation only, no training).

Observability: LangSmith EU workspace for LLM call traces and evals.

Hosting: Vercel for the web app, Render (EU region) for the agent service.

AI training-data posture

Plain language

Your data is never used to train third-party AI models. We pay for Google AI Studio's paid tier specifically so that Gemini calls aren't used to improve Google's models. Anthropic and OpenAI's API tiers carry the same no-training guarantee. You can also disable derived embeddings on the per- brand Privacy page inside the app.

Read the legal-grade detail

Creativity does not train models on customer data. We use third-party AI providers strictly via paid API tiers that contractually prohibit training on inputs and outputs:

Anthropic Claude: Commercial API — no training on customer prompts or completions.

Google AI Studio (Gemini): Paid tier — no training on customer inputs (the free tier's training-on-inputs default is the reason we never operate customer-touching traffic on free).

OpenAI (gpt-image-2): API tier — no training on customer inputs or generated outputs.

Your rights

Plain language

You can export your data, delete a brand, or close your account at any time from Settings → Privacy. We honor GDPR-style rights (access, rectification, erasure, portability, objection) regardless of where you're based.

Read the legal-grade detail

Access: request a JSON export of every row tied to your brand from Settings → Privacy. Delivered within 7 days.

Erasure: deleting a brand soft-deletes all rows (`is_deleted = true`); a hard purge runs 30 days later unless you reactivate.

Portability: exports include connector tokens (encrypted at rest), brand knowledge, performance memory, and raw events.

Objection / withdrawal of consent: email aziz@optimaia.pro. We respond within 30 days.

Retention

Plain language

Active brand data is kept as long as your subscription is active. Soft-deleted rows are purged 30 days after deletion. LangSmith traces auto-expire after 90 days. Backups roll over 35 days.

Read the legal-grade detail

Operational data: retained for the lifetime of the active subscription. On cancellation, you have 60 days to export before soft-deletion.

LangSmith traces: auto-deleted after 90 days per workspace policy.

Backups: Supabase PITR window is 35 days. Backups containing deleted data roll out of the window automatically.

Sub-processors

Plain language

We share data only with the processors required to operate Creativity: Supabase (hosting), Vercel (web app), Render (agent service), Anthropic + Google AI Studio + OpenAI (AI), LangSmith (observability), Konnect (payments), Resend (email).

Read the legal-grade detail

Full sub-processor list with purpose and data category:

  • Supabase — primary database + storage (EU region).
  • Vercel — web app hosting + edge middleware (EU).
  • Render — agent service hosting (EU).
  • Anthropic — Claude API (Research, Ideation, Hypothesis).
  • Google AI Studio — Gemini 3 Flash (Briefing, Friday chat) and Gemini Embedding 001 (multimodal embeddings).
  • OpenAI — gpt-image-2 (image generation, Premium only).
  • LangSmith — LLM trace observability (EU workspace).
  • Konnect — subscription billing (TN).
  • Resend — transactional email.

The Data Processing Addendum (DPA) on /legal/dpa reflects this list verbatim.

Questions? Reach us at aziz@optimaia.pro.