How we handle your data and outputs

Legal - Data, Security & IP

This section summarises how CreativeArc handles your data, protects your account, and who owns the content you create. For the full legal text, see our Privacy Policy and Terms of Service.

Data & privacy

What we collect
CreativeArc collects the information needed to run your account and deliver the service: your name and email address (via Clerk authentication), billing information (processed by Stripe - CreativeArc never sees raw card details), usage logs (credits spent, generation counts), and the images and prompts you submit for generation.
Image storage
Generated images and any source images you upload are stored in Cloudflare R2 object storage, encrypted at rest. Files are linked to your account and are not publicly accessible without a time-limited signed URL. You can delete your images at any time from the session history panel or by contacting support.
Prompt & usage data
Prompts and generation metadata (tab used, resolution, credit cost, timestamp) are stored to power your session history, usage dashboard, and support queries. This data is not sold or shared with third parties for advertising purposes.
Third-party AI providers
When you generate, your prompt and source image are sent to the AI provider that powers the relevant feature. Providers used are: Google (image generation, video-Nano Banana Pro/2, Veo 3.1, Gemini Omni Flash), OpenAI (image generation, prompt enhancement-GPT-Image 2, GPT-5.6 Terra), Anthropic (the Interactive assistant-Claude Sonnet 5), Black Forest Labs (image and video generation, upscaling, object removal-Flux-2 Pro/Max, Flux 3, Flux Erase, Flux Deblur), BytePlus (image and video generation-Dola Seedream 5.0 Pro, Dreamina Seedance 2.5), Kling (video generation), Recraft (vector artwork, vectorizing, background removal), Magnific and Topaz Labs (upscaling), Replicate (some upscaling and background removal), Tripo3D and Meshy (3D generation), and World Labs (immersive world generation-Marble-1.1/1.1-plus). Transmissions are encrypted in transit over HTTPS. CreativeArc does not store your data with these providers beyond what they require to return a result. Review each provider's privacy policy for their own handling terms. On the API Plan, data is sent to whichever provider your key belongs to.
API Plan key handling
If you connect your own Gemini or OpenAI API key, it is encrypted at rest in the CreativeArc database and is only decrypted server-side at the moment of a generation request. Your key is never returned to the client or logged in plaintext.
Error monitoring
CreativeArc uses Sentry to capture crash reports and error diagnostics from the app. This can include technical context (URL, browser, stack trace) but not your generated images or prompts.
Data retention
Account data is retained for the lifetime of your account. Session images are retained for a minimum of 12 months. If you close your account, all personal data and stored images are deleted within 30 days. Credit transaction records may be retained for up to 7 years for financial compliance.
Your rights
You have the right to access, correct, export, or delete your personal data at any time. You can permanently delete your account from Settings → Security-no email required. To request a copy of your data or make any other request, contact support@creativearc.ai. CreativeArc is GDPR-compliant and supports data subject requests for users in the UK and EU. For US users, CreativeArc complies with applicable state privacy laws including CCPA.

Security

Encryption in transit
All connections between your browser and CreativeArc's servers are encrypted using TLS 1.2 or higher. HTTP requests are automatically redirected to HTTPS. API calls to third-party AI providers are also made exclusively over HTTPS.
Encryption at rest
Images and files are stored in Cloudflare R2 with server-side encryption. Database records containing sensitive fields (API keys, tokens) are additionally encrypted at the application layer before storage.
Authentication
CreativeArc uses Clerk for authentication. Passwords are never stored by CreativeArc - Clerk handles hashing, salting, and secure credential storage. Sessions are protected with short-lived JWTs and refresh token rotation. Social login (Google) uses OAuth 2.0 via Clerk's verified integrations.
Access control
All API endpoints require a valid authenticated session. Session data is scoped to the authenticated user - you cannot access another user's images, sessions, or billing data. Database queries are parameterised to prevent injection attacks.
Infrastructure
CreativeArc's API server runs on isolated cloud infrastructure. File storage is served through Cloudflare's global CDN with signed, time-limited URLs - direct file paths are not publicly enumerable. Cloudflare's network provides DDoS mitigation and WAF protection on all traffic.
Vulnerability disclosure
If you discover a security vulnerability, please report it responsibly to support@creativearc.ai with the subject line Security report. We aim to acknowledge reports within 48 hours and resolve critical issues within 14 days.

Intellectual property

Ownership of outputs
You own the images CreativeArc generates for you. CreativeArc does not claim any intellectual property rights over the outputs produced in your sessions. You are free to use, publish, sell, or license generated images as you see fit, subject to the terms of the underlying AI provider and applicable law.
Commercial use
Commercial use of generated images is permitted on paid plans (Pro, Studio, API Plan) and any credit pack purchase. The Free plan is for personal, non-commercial evaluation only. Commercial use includes client work, publication, merchandise, marketing materials, and any other income-generating use.
Your uploaded content
You retain full ownership of any images, textures, or reference files you upload to CreativeArc. By uploading, you grant CreativeArc a limited licence to process and transmit those files to the AI provider solely for the purpose of completing your generation request. CreativeArc does not use your uploads for any other purpose.
No training on your data
CreativeArc does not use your prompts, uploaded images, or generated outputs to train or fine-tune any AI model. Your creative work stays yours and is not incorporated into CreativeArc's or any third party's model training pipeline.
CreativeArc's platform IP
The CreativeArc platform - including its interface, codebase, brand, and documentation - is the intellectual property of CreativeArc Ltd. You may not copy, reverse-engineer, or redistribute the CreativeArc platform without written permission.
Third-party model terms
Outputs generated via Google Gemini or Veo are additionally subject to Google's Gemini API terms regarding AI-generated content. If you use the API Plan with your own key, outputs are governed by the terms of the key provider you choose. CreativeArc recommends reviewing those terms for any specific restrictions on generated content.
Questions about legal matters?

For privacy requests, data deletion, security reports, or licensing queries, reach out to us directly.

support@creativearc.ai →