Last updated: July 8, 2026
This Privacy Policy explains how AILuminary Intelligence Private Limited (incorporated in India, doing business as "Cretos") collects, uses, shares, and protects personal data when you use our AI-native platform, accessible from cretos.ai. We are built to operate globally — this policy is written to give you real rights, not boilerplate.
| Category | Examples | Why We Collect It |
|---|---|---|
| Account | Name, email, phone, password (hashed) | Create and secure your account |
| AI Memory | Context built from your interactions, brand, goals | Personalize agent behavior over time |
| Content | Files, links, connected-account data | Power agent search & retrieval |
| Billing | Plan, payment references (via Stripe/Razorpay) | Process payments and subscriptions |
| Usage | Credits, agent runs, feature activity | Operate your plan, prevent abuse |
| Device & Log | IP address, browser, timestamps | Security, debugging, fraud prevention |
| Brand Registration | Company details, contact person’s name/email/job title, business profile, uploaded documents (logo, brand guidelines, media kit) | Review and verify your brand profile, match you with creators, AI-assisted enrichment (never applied without confirmation) |
| Enterprise Inquiries | Name, work email, phone, job title, company, website, industry, team size, and business goals you share with us | Evaluate your inquiry, prepare a proposal, and contact you about our Enterprise offering — not used for any other marketing purpose |
Where GDPR or a similar law applies to you, here's the legal basis for each purpose:
We currently use only strictly-necessary cookies to keep you signed in. See our full Cookie Policy.
We share data only with the infrastructure and service providers needed to run Cretos — never for advertising or resale. See our full Subprocessors list for exactly who, what, and why.
Some of our infrastructure providers (including our database/auth provider and AI inference provider) process data outside of India, including in the United States. Where we transfer personal data internationally — including from the EEA/UK — we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or an equivalent legally recognized transfer mechanism with those providers.
We keep your personal data for as long as your account is active, plus a reasonable period afterward to handle disputes, comply with legal obligations (e.g. billing records for tax purposes), and prevent fraud. When you request deletion, your account is deactivated immediately and your data is retained for 7 days in case you change your mind — after that window, it is permanently deleted, except billing/transaction records we're required to keep for tax and accounting law.
As our home jurisdiction, every Cretos user has these rights under India's Digital Personal Data Protection Act:
If GDPR or UK GDPR applies to you, you additionally have the right to:
If you're a resident of California, Virginia, Colorado, Connecticut, Utah, or another state with a comprehensive privacy law, you have the right to:
Sign in and go to Settings → Privacy & Data to request a copy of your data or delete your account — or use our dedicated Request My Data and Delete My Account pages. We verify every request against your authenticated account before acting on it. Data export requests are reviewed and compiled by our team, typically ready within a few hours — we'll email you when it's downloadable. Account deletion is immediate: your account is deactivated and signed out right away, with a 7-day window to restore it before your data is permanently deleted. If you can't sign in, email privacy@cretos.ai and we'll verify your identity manually.
In accordance with India's DPDP Act, our Grievance Officer can be reached at: complain@cretos.ai
Cretos is not directed at children, and you must be at least 18 (or the age of legal majority in your jurisdiction) to create an account. We don't knowingly collect personal data from children. If you believe a child has provided us data, contact us and we'll delete it.
We use industry-standard measures including encrypted connections, database-level access isolation, and authenticated access controls to protect your data. See our Security page for more detail. No system is 100% secure, and we encourage you to use a strong, unique password.
We may update this policy as our practices evolve. We'll update the date at the top of this page, and for material changes, we'll notify you directly (e.g. by email or in-app notice) before they take effect.
Questions about this policy? Reach us at privacy@cretos.ai. For a formal privacy concern, contact our Grievance Officer using the email above. For more on how we approach security, compliance, and AI governance, visit our Trust Center.