CREONARA ← Back

Privacy Policy

Last updated: May 23, 2026

At CREONARA, your privacy matters. This policy transparently explains what data we collect, why we collect it, who we share it with, and what rights you have. We comply with the General Data Protection Regulation (GDPR) and Romanian law.

Who is the data controller

The controller of personal data processed through CREONARA is the CREONARA team, reachable at team.creonara@gmail.com. We currently operate as an independent project. We will update this section when we register a legal entity (SRL in Romania or equivalent).

What data we collect

Data you provide directly: email, password (encrypted), display name, username (@), chosen niches, tagline, social links for Bio Link. Data generated automatically during use: IP address (by Firebase Hosting for security), account creation and update timestamps, AI Coach content associated with your profile. We do NOT collect: phone number, precise geolocation, biometric data, or any GDPR special category (ethnicity, religion, orientation, etc.).

Social network data (TikTok, Instagram, etc.)

When you connect a social account via OAuth (e.g., TikTok Login Kit), we receive the following data from the platform: unique identifier (open_id), display name, avatar URL, public username (after TikTok App Review approval), and follower count (after TikTok App Review approval). This data is stored in your CREONARA profile and used for: displaying on your public Bio Link page, calculating your Creator Score, and matching with brand offers via Brand Match. We do NOT receive or store: the content of your posts, your friends/followers list, private messages, or other sensitive data. You can disconnect any social account at any time from the Social Networks screen in the app; associated data is deleted immediately.

How we use the data

Service delivery: account authentication, saving niches for AI Coach personalization, displaying public Bio Link. AI content generation: your niches + name are sent to the Anthropic Claude API to generate personalized insights. Anthropic does NOT retain this data (their API policy). Product improvement: aggregated anonymous usage statistics. Communication: transactional emails (password reset, important notifications). We do NOT use your data for third-party advertising. We do NOT sell data.

Who we share data with

Anthropic (anthropic.com) — for generating AI insights/trends. Data sent: niches, displayName, prompts. Anthropic does not retain data for training. Google Firebase (firebase.google.com) — for authentication, database (Firestore), web hosting. Data stored: email, displayName, niches, bio, links. Firebase complies with GDPR and has EU servers. Cloudflare (cloudflare.com) — for DNS and CDN. Sees only IP and visited URLs, no sensitive content. We do NOT share data with social networks (Meta, TikTok, Google Ads), marketing third parties, or data brokers.

Cookies and tracking

On creonara.app we use 3 categories of cookies/local storage, manageable from the consent banner (appears on first visit and any time via footer → "Cookie Settings"):

Essential (always on): Firebase Auth session, language preference (RO/EN), cookie preference itself. Without these the app does not function. No consent needed under GDPR.

Analytics (optional, off by default): anonymous usage statistics (pages visited, device type, browser) that do NOT identify individuals. Used internally to improve CREONARA. At this time we do NOT have an active analytics platform (e.g., Google Analytics); the toggle is prep for the future. If we ever enable it, you've already consented per your choice.

Marketing (optional, off by default): ad personalization, remarketing, conversion tracking. At this time we do NOT use marketing tracking (no Facebook Pixel, no Google Ads conversion). The toggle exists preemptively for full transparency.

Your choice is saved in localStorage and valid for 6 months, after which we ask for confirmation again. You can change anytime from the site footer. We do NOT share this data with third-party brokers.

Your rights (GDPR)

You have the following rights under GDPR: Access — you may request a copy of your data. Rectification — you can edit your data directly in the app (Profile, Edit Bio). Erasure ("right to be forgotten") — you may request deletion of your account and all associated data. Portability — you may request your data in a structured format (JSON). Restriction of processing — you may ask us to stop certain operations. Objection — you may object to certain processing. Complaint to ANSPDCP — Romanian National Authority for Personal Data Processing Supervision (dataprotection.ro). To exercise any of these rights, write to team.creonara@gmail.com.

Data security

Your data is protected by: encrypted passwords (Firebase Auth uses bcrypt), mandatory HTTPS connections (SSL/TLS), Firestore rules that grant access only to the data owner, hosting on Google Cloud infrastructure with ISO 27001 and SOC 2 certifications. In case of a data breach, we will notify you within 72 hours per GDPR.

How long we keep data

Active account data — kept as long as the account exists. If you delete your account, data is removed within 30 days (note that backups are rotated at 90 days). Data for legal obligations (e.g., Premium subscription invoices) — kept 5 years per Romanian law. Technical logs — kept maximum 90 days.

International transfers

Your data may be processed on servers outside the EU (e.g., Anthropic in the US for AI). These transfers happen under the European Commission's standard contractual clauses. All partners comply with standards equivalent to GDPR.

Minors

CREONARA does not knowingly collect data from people under 13. If you are between 13 and 16, you need parental consent. If we discover an account belongs to a minor under 13, we will delete it immediately. Parents who suspect a child under 13 has an account may contact us for prompt deletion.

Policy changes

We may update this policy. Significant changes (e.g., new data categories collected, new partners) will be announced via email at least 14 days in advance. The current version will always be available in the app and at creonara.app/privacy-en.

For GDPR requests (access, deletion, portability) or any privacy-related question: team.creonara@gmail.com Data Protection Officer: same address for now. Supervisory authority in Romania: ANSPDCP — dataprotection.ro