1. Scope
This Policy applies to creatu.io, the app.creatu.io workspace and Creatu features used to prepare and publish social-media content. A user instructs Creatu to interact only with the platforms the user selects.
2. Data we process
- Creatu account email, name, organization and sign-in data;
- connected profile, Page, group and channel identifiers;
- OAuth tokens and granted-permission records;
- text, images, video, schedules and publication settings;
- publication identifiers, delivery results and API errors;
- IP address, request time, browser and security logs;
- support requests.
Creatu does not ask for or store social-platform passwords. A password is entered only on the platform's own authorization page.
3. Purposes
- operate accounts and sessions;
- connect a user-selected platform;
- create, store, schedule and send user-created publications;
- show results, diagnose errors and provide support;
- protect the service, maintain backups and comply with law;
- demonstrate requested functionality to a platform reviewer.
4. Legal bases
Processing is based on the service agreement, the user's instruction and consent to connect an external platform, legitimate interests in service security, and the operator's legal obligations.
5. Social platforms
When connecting Meta, Google/YouTube, VK, TikTok, LinkedIn or another selected platform, that platform's own terms and privacy policy also apply. Creatu sends only the data needed to carry out the user's instruction.
When enabled, Creatu uses YouTube API Services. Use is subject to the YouTube Terms of Service and the Google Privacy Policy. Google access can be revoked on the Google security permissions page.
6. Sharing and service providers
Data may be shared with the user-selected social platform, hosting infrastructure and the support email provider only to the extent needed for the feature. Creatu does not sell personal data or share it with advertising data brokers.
7. Retention
Account and content data is retained while the account is active or as needed for the task and legal obligations. An OAuth token is removed from the active connection after the user deletes that connection. YouTube data is deleted within 7 calendar days of a verified request. Other active data is deleted or anonymized within 30 calendar days unless law requires longer retention. See the Data Deletion Instructions.
8. User rights
Users may request access, correction, restriction, withdrawal of consent or deletion by emailing info@lemon-media.ru from the Creatu account email. The operator may verify control of the email to prevent deletion of another person's account.
9. Security
Creatu uses HTTPS, server-side secret storage, restricted external network access, backups and health checks. No system is absolutely secure; suspected incidents should be reported to the support address.
10. Children
Creatu is intended for adults and organization representatives and is not directed to children.
11. Changes
A new version is published with its effective date. Material changes affecting user rights are announced before they apply when required by law.
12. Contact
Ivan Tumakov, Individual Entrepreneur, Tax ID 262811988477, OGRNIP 320265100009043, Kislovodsk, Stavropol Krai, Russian Federation. Email: info@lemon-media.ru. This is the active operator email for lemonmedia and Creatu.