Cretos
Back to Home

Privacy Policy

Last updated: July 8, 2026

This Privacy Policy explains how AILuminary Intelligence Private Limited (incorporated in India, doing business as "Cretos") collects, uses, shares, and protects personal data when you use our AI-native platform, accessible from cretos.ai. We are built to operate globally — this policy is written to give you real rights, not boilerplate.

1. Data We Collect

CategoryExamplesWhy We Collect It
AccountName, email, phone, password (hashed)Create and secure your account
AI MemoryContext built from your interactions, brand, goalsPersonalize agent behavior over time
ContentFiles, links, connected-account dataPower agent search & retrieval
BillingPlan, payment references (via Stripe/Razorpay)Process payments and subscriptions
UsageCredits, agent runs, feature activityOperate your plan, prevent abuse
Device & LogIP address, browser, timestampsSecurity, debugging, fraud prevention
Brand RegistrationCompany details, contact person’s name/email/job title, business profile, uploaded documents (logo, brand guidelines, media kit)Review and verify your brand profile, match you with creators, AI-assisted enrichment (never applied without confirmation)
Enterprise InquiriesName, work email, phone, job title, company, website, industry, team size, and business goals you share with usEvaluate your inquiry, prepare a proposal, and contact you about our Enterprise offering — not used for any other marketing purpose

2. How We Use Your Data & Our Legal Basis

Where GDPR or a similar law applies to you, here's the legal basis for each purpose:

  • Operating your account and agents — necessary to perform our contract with you
  • Personalizing agent behavior via AI memory — necessary to perform our contract with you, or your consent where required
  • Processing payments — necessary to perform our contract with you, and legal obligation (tax/accounting records)
  • Security and fraud prevention — our legitimate interest in keeping the platform safe
  • Product improvement and analytics — our legitimate interest, balanced against your privacy
  • Marketing communications — your consent, which you can withdraw at any time
  • Reviewing and matching brand registrations with creators — necessary to perform our contract with the registering business, or our legitimate interest in facilitating introductions before a formal relationship exists

3. Cookies

We currently use only strictly-necessary cookies to keep you signed in. See our full Cookie Policy.

4. Who We Share Data With

We share data only with the infrastructure and service providers needed to run Cretos — never for advertising or resale. See our full Subprocessors list for exactly who, what, and why.

5. International Data Transfers

Some of our infrastructure providers (including our database/auth provider and AI inference provider) process data outside of India, including in the United States. Where we transfer personal data internationally — including from the EEA/UK — we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or an equivalent legally recognized transfer mechanism with those providers.

6. Data Retention

We keep your personal data for as long as your account is active, plus a reasonable period afterward to handle disputes, comply with legal obligations (e.g. billing records for tax purposes), and prevent fraud. When you request deletion, your account is deactivated immediately and your data is retained for 7 days in case you change your mind — after that window, it is permanently deleted, except billing/transaction records we're required to keep for tax and accounting law.

7. Your Rights — India (DPDP Act, 2023)

As our home jurisdiction, every Cretos user has these rights under India's Digital Personal Data Protection Act:

  • The right to access a summary of your personal data and how it's processed
  • The right to correction and updating of inaccurate or incomplete data
  • The right to erasure of your personal data once it's no longer needed for the purpose it was collected
  • The right to withdraw consent at any time, as easily as you gave it
  • The right to grievance redressal via our Grievance Officer
  • The right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity

8. Your Rights — European Economic Area & United Kingdom (GDPR)

If GDPR or UK GDPR applies to you, you additionally have the right to:

  • Access — obtain a copy of the personal data we hold about you
  • Rectification — correct inaccurate personal data
  • Erasure ("right to be forgotten") — request deletion of your personal data
  • Restriction of processing — limit how we use your data in certain circumstances
  • Data portability — receive your data in a structured, commonly used, machine-readable format
  • Object — object to processing based on legitimate interest, including profiling
  • Rights related to automated decision-making — we don't currently make decisions that produce legal or similarly significant effects on you using automated means alone without human involvement
  • Lodge a complaint with your local data protection supervisory authority

9. Your Rights — United States (CCPA/CPRA and State Privacy Laws)

If you're a resident of California, Virginia, Colorado, Connecticut, Utah, or another state with a comprehensive privacy law, you have the right to:

  • Know what personal information we collect, use, and disclose about you
  • Delete personal information we've collected from you
  • Correct inaccurate personal information
  • Opt out of sale or sharing — we don't sell or share your personal information for cross-context behavioral advertising, so there's nothing to opt out of today, but this right stands regardless
  • Limit use of sensitive personal information, where applicable
  • Non-discrimination — we won't deny you service, charge you differently, or provide a lower quality of service for exercising any of these rights
  • Designate an authorized agent to submit requests on your behalf

10. How to Exercise Your Rights

Sign in and go to Settings → Privacy & Data to request a copy of your data or delete your account — or use our dedicated Request My Data and Delete My Account pages. We verify every request against your authenticated account before acting on it. Data export requests are reviewed and compiled by our team, typically ready within a few hours — we'll email you when it's downloadable. Account deletion is immediate: your account is deactivated and signed out right away, with a 7-day window to restore it before your data is permanently deleted. If you can't sign in, email privacy@cretos.ai and we'll verify your identity manually.

11. Grievance Officer

In accordance with India's DPDP Act, our Grievance Officer can be reached at: complain@cretos.ai

12. Children's Privacy

Cretos is not directed at children, and you must be at least 18 (or the age of legal majority in your jurisdiction) to create an account. We don't knowingly collect personal data from children. If you believe a child has provided us data, contact us and we'll delete it.

13. Security

We use industry-standard measures including encrypted connections, database-level access isolation, and authenticated access controls to protect your data. See our Security page for more detail. No system is 100% secure, and we encourage you to use a strong, unique password.

14. Changes to This Policy

We may update this policy as our practices evolve. We'll update the date at the top of this page, and for material changes, we'll notify you directly (e.g. by email or in-app notice) before they take effect.

15. Contact Us

Questions about this policy? Reach us at privacy@cretos.ai. For a formal privacy concern, contact our Grievance Officer using the email above. For more on how we approach security, compliance, and AI governance, visit our Trust Center.