Last updated: 29 August 2026
CreativeArc ("we", "our", "us") operates the CreativeArc platform available at creativearc.ai and app.creativearc.ai-an AI-powered design suite for architects, designers, and creative studios.
For data protection purposes, CreativeArc is the data controller. You can reach us at support@creativearc.ai.
Account information-your name, email address, and profile details provided when signing up via Clerk. If you sign in with Google or another OAuth provider, we receive basic profile data from that provider.
Generated content-images, 3D files, videos, and immersive world scenes (gaussian splat data, panoramas) you produce using CreativeArc tools. These are stored in Cloudflare R2 object storage, linked to your account.
Prompts and inputs-text prompts you type to guide AI generation, and any uploaded reference images or source images you provide. These are transmitted to the relevant AI provider to fulfil your request and are also stored as part of your generation history. Prompts may incidentally contain personal information; we treat them accordingly and do not use them to train AI models.
Session and usage data-design sessions, generation history, credit balance and transaction records, and tool preferences (e.g. selected models, canvas settings).
Payment information-billing details are processed and stored by Stripe. We do not store card numbers or payment credentials directly.
Technical data-IP address, browser type, device type, and access logs, retained for security monitoring and debugging.
Cookies and local storage-arc_cookie_consent (a functional HTTP cookie set on .creativearc.ai, valid for 1 year) to remember that you have acknowledged this notice. sidebar_state is stored in your browser's local storage, not as a cookie. We do not use advertising or tracking cookies. See our Cookie Policy for details.
We do not sell your personal data. We do not use your generated content to train AI models.
Legal basis for processing (GDPR / UK GDPR) — Where data protection law requires us to identify a legal basis, we rely on the following:
CreativeArc works with the following third-party processors, which are contractually obligated to protect your data in accordance with applicable data protection law:
Your prompt and any uploaded images are transmitted to the relevant AI provider solely to fulfil your generation request, in accordance with each provider's published data handling terms. We do not permit providers to use your content for their own model training.
Depending on your location, you have the following rights regarding your personal data:
To exercise any of these rights, email support@creativearc.ai with the subject line Data Request. We respond within 30 days.
EU and UK users are protected under the GDPR. California users are protected under the CCPA. We honour data subject requests regardless of location.
You may request permanent deletion of your account and all associated data at any time by emailing support@creativearc.ai with the subject line Account deletion request.
Deletion is initiated immediately upon your request. All personal data, sessions, and stored images are removed as part of that process; in rare cases where a step cannot complete immediately (e.g. a temporary issue with a storage provider), any remaining data will be fully removed within 30 days. Credit transaction records required for financial compliance may be retained in anonymised form for up to 7 years. This action is irreversible.
We implement the following technical and organisational measures to protect your data:
CreativeArc primarily uses first-party browser local storage rather than cookies:
We do not use advertising, analytics, or cross-site tracking cookies. Authentication session cookies are managed by Clerk and are set on your account subdomain only. See our Cookie Policy for the full breakdown.
CreativeArc is operated from the European Union. Some of our third-party processors — including Stripe, Cloudflare, Neon, Google, OpenAI, Black Forest Labs, Replicate, Recraft, Magnific, Tripo3D, Meshy, World Labs, Railway, and Vercel — may process data in the United States or other countries outside the EU/EEA. Where this occurs, transfers are covered by appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism recognised under applicable data protection law. You may request a copy of the relevant safeguards by contacting us at support@creativearc.ai.
CreativeArc is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, please contact us immediately at support@creativearc.ai.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or via an in-app notice at least 14 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.
Where a change affects processing that requires your consent under applicable law, we will ask for your explicit acknowledgment before it takes effect. For other changes, continuing to use CreativeArc after the effective date indicates you have read and understood the updated policy.
For privacy questions, data requests, or to report a concern: