Privacy · last updated 19 September 2026
What we hold, and why.
This is the whole of it, in the order a person actually wants it: what we have about you, how we got it, who else sees it, how long it stays, and how to make it stop.
Who this covers
Two different people read this page, and the law treats them differently, so the answers are kept separate rather than averaged.
- You are not a customer — we wrote to you about your own public posting numbers and you never asked us to. Start at the next section.
- You are a customer, or you asked for a free report. Start at “If you asked us for a report”.
If we wrote to you and you are not a customer
How we got your address. From the contact field on your own public creator profile — the one you fill in when you switch to a professional or business account, and that the platform publishes. We reach it through a creator data provider that licenses that information. We did not take it from your messages and we did not buy a leaked list.
What we measured before writing. Counts that are visible on your public profile — views, likes, comments and shares on recent posts — compared against a published benchmark for your platform. We did not need an account, a login or your permission to read them, because they are the numbers anyone visiting your profile can see.
What the link in the email records. If you open it, we store that the page was opened, the public handle it was for, a timestamp, and the browser’s user-agent string — the line your browser sends to every site naming itself and your operating system. We keep that last one so we can tell a real visit from an automated one. We deliberately do not store the link itself: it is a credential that opens your page, and keeping a credential in order to count a page view is a cost with nothing on the other side of it.
How to be removed. Reply to the message and say so, or use whatever unsubscribe option your mail app offers on it. We honour that within ten business days, which is the maximum US law allows us. You do not have to give a reason.
How long we keep it if you never reply. Until you ask us to stop, or until the campaign it belongs to ends, whichever comes first. If you do ask us to stop, we keep your email address on a suppression list and nothing else — because deleting it outright is how you end up being written to again.
There is more about the email itself, including who sends it, on the verification page.
If you asked us for a report, or you are a customer
From the report form: your email address, a display name if you give one, your content vertical, a stated goal, a stated challenge, and which platforms you say you post on. If you reached the form from an automated Instagram reply, the identifier that reply carried comes with you, so that the report reaches the right person.
When you connect a platform: the grant itself, and the posts, engagement metrics and message interactions that grant exposes. The grant is what decides the scope — we cannot read anything you did not allow.
From billing: whatever Stripe needs to take a payment. We never receive or store your card number.
From ordinary use of the site: standard server logs, and — if you arrived from a link we published — which link it was, so we can tell which of our own channels works.
To keep the form from being abused: your IP address, stored against a short rolling window so that one machine cannot request an unlimited number of reports or key re-issues. This is a row in our database rather than a line in a log, which is why it is named here separately from the server logs above.
What we do with it
Produce your analytics and your Content DNA report; schedule and publish the content you ask us to publish; run the message automations you configure; bill you; and send you transactional email about your own account. Nothing here is sold, and nothing here is handed to an advertiser.
One more use, and it is switched on unless you ask us to switch it off. A connected account contributes to the model for its niche, and what it contributes is patterns, never posts — hook type, format, structure, length, posting window, and how each of those related to performance. Those relationships are pooled at the category level across many accounts, and you receive the same model back. Your posts, your transcripts, your numbers and your report stay in your workspace: nothing you published is reproduced, quoted or shown to another creator. You can have contributing turned off for your workspace by asking, and your own analysis and report are the same either way.
How your content is analysed
Plainly, because it is the paragraph most worth reading closely: the content of your posts is sent to third-party AI services for analysis, and the labels and scores that come back are what your report is made of. Those services are named in the list below. Your posts are sent so that they can be analysed for you, and for nothing else: we do not sell your content and we do not use it to train a model of our own.
Who else receives it
Everyone who touches creator or prospect data, and what each one gets. Nobody else receives it — the niche model described above travels as patterns, and never as anything of yours.
- Neon · Postgres database
- All application data — every record described above is stored here.
- Render · Application hosting
- Requests and server logs for both the website and the analysis service.
- Resend · Transactional email
- Your email address and the contents of the messages we send you.
- Loops · Contact record
- Your email address, upserted as a contact when you submit the report form. It sends you nothing.
- Stripe · Payments
- Name, email, payment details, and your subscription and invoice records. We never see or store your card number.
- Cloudflare · Bot challenge
- Signals used to tell a person from a script when you submit a form.
- Zernio · Platform connection broker
- The access token for any account you connect, and the posts and post analytics that token exposes.
- InsightIQ · Alternative platform connection provider
- The same as Zernio, on the same terms, whenever it is the provider in use — one of the two is, never both. Which one is a setting on our side rather than yours, so we name both instead of letting the answer depend on a switch you cannot see.
- Anthropic, Google · AI analysis
- The content of posts we analyse for you, in order to label and score them. See “How your content is analysed” above.
- Instagram, Facebook, TikTok, YouTube, LinkedIn · The platforms themselves
- Whatever your own grant to them permits, and nothing beyond it.
How long we keep it
If you asked for a free report and never connected an account, the workspace created for you in our analysis service is deleted automatically after 14 days, along with anything held inside it. That is not a policy we intend to follow — it is a job that runs and deletes it, and we send reminders beforehand so the deletion is never a surprise.
The record of your original request — the email address and the answers you gave on the form — is kept separately and is not covered by that job. We keep it until you ask us to delete it, and we will when you do.
For a paying account we keep your data for as long as the account is open, and for records we are legally required to hold — invoices, chiefly — after it closes. Prospect records are covered above.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask for it in a portable form, or withdraw a consent you gave. Today every one of those is a human answering an email, not a button in the product. We would rather tell you that than imply a self-serve flow that does not exist. Write to hello@crezio.ai and it reaches a person.
Disconnecting is the exception: you can remove a connected platform inside the product at any time, which stops further collection from it and reduces your bill accordingly. You can also revoke the grant from the platform’s own settings, which we cannot override.
Turning off the niche model is one of those requests too, and the one worth naming separately because it is on unless you ask. Write to the same address and your workspace stops contributing patterns to its category. Your own report and analysis do not change.
Children
Crezio is not directed at children under 13 and we do not knowingly collect their personal information. If you believe a child has given us data, write to the address above and we will delete it.
Where your data is processed
Most of the vendors listed above are hosted in the United States, and that is where the data we hold is processed and stored. Two entries are not covered by that sentence, and both are named below rather than left to the word “most”.
Cloudflare is the first. It runs the check that tells a person from a script when you submit a form, and it runs on a global edge network — so if you are in Frankfurt, that check happens in Frankfurt, and the signal it uses is processed there rather than in the United States. Nothing else we hold about you is sent to it.
The platforms are the second, and not an exception we can fix: what you grant to Instagram, Facebook, TikTok, YouTube or LinkedIn is processed wherever that platform’s own terms say, in whichever countries it operates. That is outside our control — as is every other thing a platform decides, which the terms say in the same words rather than different ones.
The other policy you may have seen
Crezio’s analysis service publishes a narrower notice at its own /api/v1/legal/privacy address, written for the Instagram and Facebook connection and declared to Meta. It remains correct about what it covers. This page is the canonical one, and it governs wherever the two differ.
Changes
Posted here, with the date at the top of the page moved. If a change is material to you we will say so in an email rather than rely on you re-reading this.
Questions, or any of the requests above: hello@crezio.ai. The terms of service cover the other half.