← Creira

Privacy Policy

Last updated: 23 August 2026

1. Who controls your data

Creira is operated by Dani Mas in Spain. Creira is the data controller for personal data processed through creira.com and app.creira.com. Questions or privacy requests can be sent to contact@danimas.dev.

2. Data we collect

Depending on how you use Creira, we process:

  • Account data, such as your name, email address, language, timezone, and authentication records.
  • Workspace and brand data, including brand identity, guidelines, assets, content, and collaborators.
  • Content and publishing data, including drafts, captions, media, schedules, destinations, and results.
  • Connected-account data supplied by social platforms, such as account identifiers, display name, avatar, granted permissions, access tokens, and publishing status.
  • Technical and security data, such as IP address, browser, device, request logs, and error records.
  • Billing and support data when you purchase a plan or contact us.

We receive data directly from you, from members of your workspace, from connected social platforms, and automatically from your use of the service. We never ask for or store your social-platform password.

3. Social-platform data and permissions

If you connect TikTok, Creira requests only the permissions needed for the feature you choose:

  • user.info.basic to display and identify the TikTok account you choose to connect.
  • video.upload to send media to your TikTok inbox as a draft that only you can finish and publish in TikTok.
  • video.publish to submit content to that account only after you review the destination, privacy settings, disclosures, and content and explicitly confirm publication.

Creira does not publish silently. You can revoke access in TikTok or disconnect the account in Creira at any time. We do not sell TikTok data or use it for advertising profiles.

TikTok profile identifiers, display name, avatar, granted scopes, encrypted access and refresh tokens, publication identifiers, and delivery status are used only to provide the connection and publishing features you request. Creira does not request your TikTok password, read private messages, or access data outside the scopes shown during authorisation.

If you connect Facebook or Instagram, Creira uses the permissions you approve to list the Pages or professional accounts you manage, display the selected account, read the minimum account and publication metadata needed to operate the connection, and publish content only when you request it. Depending on the connection, these permissions include pages_show_list, pages_read_engagement, pages_manage_posts, instagram_business_basic, and instagram_business_content_publish. Creira stores the selected Page or account identifier, display name, avatar where supplied, encrypted OAuth credentials, granted permissions, publication identifiers, and delivery status. We do not use this data to build advertising profiles or sell it.

If you connect LinkedIn, Creira uses openid and profile for a member connection, or rw_organization_admin and w_organization_social for a LinkedIn Page connection. These permissions identify the account or Pages you administer and allow the publication you expressly request. Creira stores the selected member or organisation identifier, display name, avatar where supplied, encrypted OAuth credentials, granted permissions, publication identifiers, and delivery status.

A complete, plain-language description of each connection and its user-controlled flow is available on our integrations page.

4. Why we use personal data

  • To provide accounts, workspaces, content creation, scheduling, and publishing services.
  • To process user-authorised social-platform connections and publication requests.
  • To secure the service, prevent abuse, investigate incidents, and maintain audit records.
  • To provide support, service notices, and requested communications.
  • To improve reliability and usability using aggregated or appropriately minimised data.
  • To meet legal, accounting, and regulatory obligations.

Our legal bases under the GDPR are performance of our contract with you, our legitimate interests in operating and securing Creira, compliance with law, and consent where the law requires it. You may withdraw consent without affecting earlier lawful processing.

5. Service providers and transfers

We use service providers only where needed to operate Creira. Current core providers include Contabo for EU-based hosting infrastructure, OpenAI for AI generation requested by the user. Background and scheduled workflows run on our own infrastructure. OpenAI receives the prompts, brand context, text, and images needed for the generation request, but Creira does not send social-platform passwords or OAuth access tokens to OpenAI. Our live subprocessor list explains purposes, locations, and data categories. Connected platforms such as TikTok, Meta, and LinkedIn process data under their own policies.

Some providers operate outside the European Economic Area. Where required, we use adequacy decisions, Standard Contractual Clauses, and supplementary safeguards for international transfers.

6. Retention and deletion

We keep account and workspace data while your account is active. Connected-account tokens are retained only while the connection is active and are removed or invalidated when you disconnect it. Operational logs are normally kept for up to 12 months; billing and legally required records may be kept for the statutory period. Backups expire on a rolling schedule.

You can disconnect a social account from Creira at any time. Disconnecting stops future access and removes the stored connection credentials. TikTok also lets you revoke Creira from its own security settings. Publication receipts and security logs are normally retained for up to 12 months; content stays in your workspace until you delete it or close the account.

To request deletion of your Creira account and associated data, follow our data deletion instructions or email contact@danimas.dev. We verify the request and normally complete it within 30 days. Residual encrypted backups expire within 90 days unless retention is required by law, needed for security, or necessary to resolve a dispute.

7. Cookies, security, and official requests

Creira uses essential cookies and similar storage for authentication, security, language, and session continuity. Optional analytics are used only where permitted. We apply encryption in transit, access controls, token protection, logging, and operational safeguards. No online service can guarantee absolute security, so please use a strong password and protect access to your devices.

Requests from public authorities are handled under our Government Requests Policy, which requires validation of legal authority, review of scope, data minimisation, challenge of invalid or overbroad demands where legally permitted, and documented handling.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. Contact us at contact@danimas.dev. We may need to verify your identity. You may also complain to the Spanish Data Protection Agency (AEPD) or your local supervisory authority.

9. Children and changes

Creira is a professional service and is not intended for anyone under 18. We may update this policy when the service or law changes. Material changes will be communicated in the service or by email, and the date above will be updated.