Legal

Privacy Policy

Last updated: 29 August 2026

1. Who we are

CreativeArc ("we", "our", "us") operates the CreativeArc platform available at creativearc.ai and app.creativearc.ai-an AI-powered design suite for architects, designers, and creative studios.

For data protection purposes, CreativeArc is the data controller. You can reach us at support@creativearc.ai.

2. What data we collect

Account information-your name, email address, and profile details provided when signing up via Clerk. If you sign in with Google or another OAuth provider, we receive basic profile data from that provider.

Generated content-images, 3D files, videos, and immersive world scenes (gaussian splat data, panoramas) you produce using CreativeArc tools. These are stored in Cloudflare R2 object storage, linked to your account.

Prompts and inputs-text prompts you type to guide AI generation, and any uploaded reference images or source images you provide. These are transmitted to the relevant AI provider to fulfil your request and are also stored as part of your generation history. Prompts may incidentally contain personal information; we treat them accordingly and do not use them to train AI models.

Session and usage data-design sessions, generation history, credit balance and transaction records, and tool preferences (e.g. selected models, canvas settings).

Payment information-billing details are processed and stored by Stripe. We do not store card numbers or payment credentials directly.

Technical data-IP address, browser type, device type, and access logs, retained for security monitoring and debugging.

Cookies and local storage-arc_cookie_consent (a functional HTTP cookie set on .creativearc.ai, valid for 1 year) to remember that you have acknowledged this notice. sidebar_state is stored in your browser's local storage, not as a cookie. We do not use advertising or tracking cookies. See our Cookie Policy for details.

3. How we use your data

  • To provide, operate, and improve the CreativeArc platform.
  • To authenticate your identity and manage your account (via Clerk).
  • To process payments and manage credit subscriptions (via Stripe).
  • To send AI generation requests to our model providers (Google, OpenAI, Black Forest Labs, BytePlus, Kling, Dreamina, Replicate, Tripo3D, Meshy, World Labs) on your behalf.
  • To store and serve your generated images and files (Cloudflare R2).
  • To calculate and deduct credits for each generation.
  • To respond to support requests and communications.
  • To detect and prevent fraud, abuse, or unauthorised access.
  • To comply with legal obligations.

We do not sell your personal data. We do not use your generated content to train AI models.

Legal basis for processing (GDPR / UK GDPR) — Where data protection law requires us to identify a legal basis, we rely on the following:

  • Contract performance (Article 6(1)(b)) — processing necessary to provide the CreativeArc service you have signed up for: account management, generation requests, credit billing, and storing your files.
  • Legitimate interests (Article 6(1)(f)) — security monitoring, fraud prevention, abuse detection, error diagnostics, and platform improvement, where our interests do not override your rights.
  • Legal obligation (Article 6(1)(c)) — retaining financial records for the period required by applicable tax and accounting law.
  • Consent (Article 6(1)(a)) — marketing communications, where required. You may withdraw consent at any time.

4. Third-party services

CreativeArc works with the following third-party processors, which are contractually obligated to protect your data in accordance with applicable data protection law:

  • Clerk — user authentication and account management (clerk.com)
  • Stripe — payment processing and billing (stripe.com)
  • Neon — managed Postgres database hosting user account, session, and credit data (neon.tech)
  • Cloudflare R2 — object storage for uploaded and generated images (cloudflare.com)
  • Railway — backend server hosting and infrastructure (railway.app)
  • Vercel — frontend hosting and edge delivery (vercel.com)
  • Sentry — error monitoring and crash diagnostics; may receive anonymised stack traces (sentry.io)
  • Google — AI image and video generation and editing, e.g. Nano Banana Pro/2, Veo 3.1, Gemini Omni Flash (ai.google.dev)
  • OpenAI — AI image generation and prompt enhancement, e.g. GPT-Image 2, GPT-5.6 Terra (openai.com)
  • Black Forest Labs — AI image and video generation, upscaling, and object removal, e.g. Flux-2 Pro/Max, Flux-3, Flux Erase, Flux Deblur (bfl.ai)
  • BytePlus — AI image generation, e.g. Dola Seedream 5.0 Pro (byteplus.com)
  • Recraft — AI vector and raster image generation (recraft.ai)
  • Magnific — AI image upscaling (magnific.ai)
  • Replicate — AI model inference for upscaling, background removal, and video, including Kling and Dreamina models (replicate.com)
  • Tripo3D — AI 3D model generation (tripo3d.ai)
  • Meshy — AI 3D model generation and retexturing (meshy.ai)
  • World Labs — AI world generation via the Marble API (worldlabs.ai)

Your prompt and any uploaded images are transmitted to the relevant AI provider solely to fulfil your generation request, in accordance with each provider's published data handling terms. We do not permit providers to use your content for their own model training.

5. Data retention

  • Account data-retained for the lifetime of your account.
  • Generated images and session files-retained for a minimum of 12 months from creation.
  • Credit transaction records-retained for up to 7 years for financial compliance purposes.
  • Technical logs-retained for up to 90 days.
  • On account deletion-removal of all personal data and stored files is initiated immediately upon your request and completes as part of that process in most cases. In rare circumstances where a step cannot complete immediately (for example, due to a temporary issue with a storage provider), any remaining data will be fully removed within 30 days. Financial records may be retained longer as required by law.

6. Your rights

Depending on your location, you have the following rights regarding your personal data:

  • Access-request a copy of the data we hold about you.
  • Correction-request that inaccurate data be corrected.
  • Erasure-request deletion of your account and associated data.
  • Portability-request your data in a machine-readable format.
  • Restriction-request that we limit how we process your data.
  • Objection-object to processing based on legitimate interests.

To exercise any of these rights, email support@creativearc.ai with the subject line Data Request. We respond within 30 days.

EU and UK users are protected under the GDPR. California users are protected under the CCPA. We honour data subject requests regardless of location.

7. Account deletion

You may request permanent deletion of your account and all associated data at any time by emailing support@creativearc.ai with the subject line Account deletion request.

Deletion is initiated immediately upon your request. All personal data, sessions, and stored images are removed as part of that process; in rare cases where a step cannot complete immediately (e.g. a temporary issue with a storage provider), any remaining data will be fully removed within 30 days. Credit transaction records required for financial compliance may be retained in anonymised form for up to 7 years. This action is irreversible.

8. Data security

We implement the following technical and organisational measures to protect your data:

  • All data transmitted over HTTPS/TLS.
  • Bring-your-own-key (BYOK) API keys are AES-256 encrypted at rest.
  • Images in Cloudflare R2 are encrypted at rest and served via time-limited signed URLs.
  • Authentication session cookies are HttpOnly and set on your account domain.
  • Access to production databases is restricted to authenticated services.
  • Sensitive values (API keys, payment secrets) are never logged.

9. Cookies

CreativeArc primarily uses first-party browser local storage rather than cookies:

  • sidebar_state-stores your sidebar open/closed preference. Category: functional.
  • arc_cookie_consent-stores your cookie consent choice. Category: functional.

We do not use advertising, analytics, or cross-site tracking cookies. Authentication session cookies are managed by Clerk and are set on your account subdomain only. See our Cookie Policy for the full breakdown.

10. International transfers

CreativeArc is operated from the European Union. Some of our third-party processors — including Stripe, Cloudflare, Neon, Google, OpenAI, Black Forest Labs, Replicate, Recraft, Magnific, Tripo3D, Meshy, World Labs, Railway, and Vercel — may process data in the United States or other countries outside the EU/EEA. Where this occurs, transfers are covered by appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism recognised under applicable data protection law. You may request a copy of the relevant safeguards by contacting us at support@creativearc.ai.

11. Children

CreativeArc is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, please contact us immediately at support@creativearc.ai.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or via an in-app notice at least 14 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.

Where a change affects processing that requires your consent under applicable law, we will ask for your explicit acknowledgment before it takes effect. For other changes, continuing to use CreativeArc after the effective date indicates you have read and understood the updated policy.

13. Contact

For privacy questions, data requests, or to report a concern:

  • Email: support@creativearc.ai
  • Subject line for data requests: Data Request
  • Subject line for account deletion: Account deletion request