This privacy policy covers the Creator app ("the app") for Android — and for iOS, when released — made and operated by CREOVIA PRO LLP, a limited liability partnership incorporated under the (Indian) Limited Liability Partnership Act, 2008 (LLPIN: ADA-3738)("we", "us", "our"), registered office: No. 33, 4th Floor, 1st Main, HMT Layout, CBI Road, Ganganagar, R T Nagar, Bengaluru – 560032, Karnataka, India. Privacy contact: [email protected]. We are the data controller — and, for India, the data fiduciary under the Digital Personal Data Protection Act, 2023 — for the personal data described here. The Creovia Pro website has its own policy at creoviapro.com/privacy.
The short version: your footage is processed on your phone, not on our servers. Accounts are optional, we cannot see your content, and backups go to your own cloud storage — not ours. The data the app does collect is the standard operational kind — account basics if you sign in, analytics, crash reports, advertising, and purchase state — and every category is listed below, along with who processes it and how to exercise your rights.
1. Your videos, photos, and audio stay on your device
- Editing — including every AI feature (background replacement, face redaction, captions, auto-reframe, stabilization, and the rest) — runs entirely on your device. Your media is never uploaded to us or to any server for processing.
- Speech-to-text for captions, silence detection, and all detection and tracking models run on-device.
- The app accesses only the photos and videos you explicitly pick, via the system photo picker or scoped storage access. Voice-over recordings are stored locally with your project.
- Projects, drafts, and exports are stored locally on your device. We cannot access, view, scan, or moderate your content — signed in or not.
- Backups are yours too. If you connect a cloud drive, project backups are written to your own Google Drive (Android) or iCloud Drive (iOS), under scoped access that only reaches files the app itself created. We run no content servers and hold no copy.
- We do not use your content to train AI models — ours or anyone else's.
2. Data we collect, and why
At a glance — each category maps to the disclosures in Google Play's Data safety section and Apple's App Privacy label, and is explained in full below the table.
| Category | Examples | Purpose | Legal basis | Shared with | Retention |
|---|---|---|---|---|---|
| Account info (optional) | Email, name, profile photo | Account, purchases, backup | Contract | Google (Firebase Auth) | Until account deletion |
| App interactions | Features used, screen flows | Product improvement | Consent / legitimate interests | Google (Firebase), Mixpanel | 14 months (Firebase) / 12 months (Mixpanel) |
| Crash & diagnostics | Stack traces, device model | Stability | Legitimate interests | Google (Crashlytics) | 90 days |
| Device & ad identifiers | Advertising ID, app-instance IDs, push token | Ads, analytics, notifications | Consent | Ad partners (below) | Until reset / deletion |
| Purchase state | Active subscription / purchase | Delivering what you bought | Contract | Google Play Billing | While entitlement active |
| Sticker searches | Search terms | Returning results | Legitimate interests | Klipy | Not stored by us |
| Support mail | Your email + message | Responding to you | Legitimate interests | — | Up to 24 months after resolution |
- Account information (only if you sign in). Creator works fully without an account — you can continue as a guest. If you choose to sign in (Google or email & password, via Firebase Authentication), we receive your email address and, with Google sign-in, your basic profile (name, profile photo). Purpose: keeping your purchases and settings attached to you, and enabling cloud-drive backup. Passwords are handled by Firebase Authentication; we never see them.
- App interactions (usage analytics). Which features are used and how often, screen flows, and feature performance, under pseudonymous identifiers (app-instance and device-scoped IDs). Processed by Google Firebase Analytics and Mixpanel. Purpose: understanding what to improve.
- Crash logs and diagnostics. Stack traces, device model, OS version, and performance timings when something breaks. Processed by Firebase Crashlytics and Firebase Performance. Purpose: app functionality and stability.
- Device and other identifiers. The advertising identifier (Android Advertising ID; on iOS only with your App Tracking Transparency permission), Firebase app-instance IDs, and a push-notification token if notifications are enabled.
- Purchase state. Which subscription or one-time purchase is active, via Google Play Billing (or Apple In-App Purchase on iOS). Payments are processed entirely by the app store; we never receive your card or bank details.
- Search queries (sticker & GIF library).When you search the sticker library, the search term is sent to our sticker-library provider to return results. We don't attach your identity to these queries.
- Support correspondence. If you email us, we receive your email address and whatever you include, used solely to respond.
We do notcollect: your location, contacts, messages, browsing history, health or financial information, or the content of your media — and unless you sign in, we don't hold your name or email either. We do not sell personal data, and we do not use your data for third-party marketing.
3. Advertising and consent
- The free tier shows ads served through Google AdMob and AppLovin MAX, our ad-mediation platform. Through mediation, an ad may be filled by one of our advertising partners: Google, AppLovin, or Meta Audience Network. These partners may receive your device's advertising identifier and coarse, non-identifying device information to serve, frequency-cap, and measure ads. Paid tiers remove ads.
- Where required (for example the EEA, UK, and Switzerland), you'll see a consent dialog (Google's UMP framework) before any personalised advertising, and you can choose non-personalised ads or decline. You can change your choice any time from the app's settings.
- On Android you can reset or delete your Advertising ID in system settings (Settings → Google → Ads). On iOS, ads would only ever track across apps if you allow the App Tracking Transparency prompt; declining it is fully supported.
- Ad partners process data under their own policies: Google advertising, AppLovin privacy policy, Meta privacy policy.
4. Who processes data on our behalf
- Google LLC — Firebase Authentication (accounts), Firebase Analytics, Crashlytics, Performance, Cloud Messaging, Remote Config; AdMob; Google Play Billing; Google Drive (as your chosen backup destination). Privacy policy.
- Mixpanel, Inc. — product analytics. Privacy policy.
- AppLovin Corporation — ad mediation and ad serving. Privacy policy.
- Meta Platforms, Inc. — Audience Network ads via mediation. Privacy policy.
- Klipy (klipy.com) — sticker & GIF search results.
- Apple Inc. (on iOS) — App Store distribution, In-App Purchase, and iCloud Drive as your chosen backup destination.
These providers act as our processors or as independent controllers for their platform services, under contracts and terms that require protection at least equivalent to this policy. Beyond them, we share data only if the law requires it (a valid legal request), to protect rights and safety, or — should CREOVIA PRO LLP ever be part of a merger or acquisition — with the successor entity under this same policy.
5. Legal bases (EEA/UK users)
- Consent— personalised advertising, push notifications, and analytics where consent is required. You can withdraw consent at any time without affecting the app's core function.
- Contract — operating your account if you create one, and processing purchase state to deliver what you bought.
- Legitimate interests — crash diagnostics, security, fraud prevention, and non-identifying usage measurement, balanced against your rights.
6. Retention and deletion
- Analytics and diagnostics are retained for defined windows and then deleted or irreversibly aggregated: Firebase Analytics user-level data for 14 months; Crashlytics crash records for 90 days; Mixpanel events for our configured project window of 12 months. Push tokens persist until refresh or account deletion.
- Your projects and media live only on your device: deleting a draft (and its trash entry), clearing the app's storage, or uninstalling the app deletes them. We hold no copy.
- Delete your account in the app:Settings → Account → Delete account. This deletes your Firebase Authentication account, unlinks your identity from analytics, revokes the app's cloud-drive access, and clears the app's data on the device. Backups already in your own Google Drive or iCloud remain yours to keep or delete there.
- No longer have the app installed? Use the data-deletion request page or email [email protected]— we'll delete your account and the analytics or diagnostics data tied to your identifiers with our providers, and confirm within 30 days.
- Support emails are kept only as long as needed to resolve your request.
7. Security
All data in transit between the app and our service providers is encrypted (TLS). Because content processing is on-device and we run no content servers, the most sensitive data — your media — never crosses the network at all. Access to provider dashboards is restricted and protected with strong authentication.
8. International transfers
Our providers may process the limited data above on servers outside your country, including the United States. Where data leaves the EEA/UK, transfers rely on adequacy decisions or Standard Contractual Clauses; equivalent safeguards apply for other regions with transfer rules.
9. Your rights
- EEA/UK (GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent — plus the right to complain to your supervisory authority.
- California (CCPA/CPRA):the rights to know, delete, and correct; we do not "sell" personal information. If serving personalised ads constitutes "sharing", you can opt out via the in-app ad-consent controls or your device's ad settings, and we honour opt-out preference signals where technically applicable. We don't discriminate for exercising rights.
- India (DPDP Act 2023): as data principals you have the rights to access, correction and erasure, grievance redressal, and to nominate. Our grievance contact is below. If you are not satisfied with our resolution, you have the right to complain to the Data Protection Board of India.
- Exercise any of these by emailing [email protected]. We may need to verify the request came from the affected device, since we hold no identity data to match against.
10. Children
Creator is not directed at children under 13 (or the higher minimum age your jurisdiction sets for consent), and we do not knowingly collect personal data from them. The app is not enrolled in child-directed programs, and ads are not targeted at children. If you believe a child has used the app in a way that gave us personal data, contact us and we'll delete it.
11. Changes to this policy
We'll update this policy as the app evolves. New versions are published at this URL with an updated effective date; material changes are additionally noted in the app's release notes and, where consent is the legal basis, re-consented in the app.
12. Contact & grievance
Data controller / data fiduciary: CREOVIA PRO LLP, registered office: No. 33, 4th Floor, 1st Main, HMT Layout, CBI Road, Ganganagar, R T Nagar, Bengaluru – 560032, Karnataka, India. Grievance redressal (India — DPDP Act, 2023): the Grievance Officer, CREOVIA PRO LLP, [email protected]. We acknowledge grievances within 48 hours and resolve them within the timelines applicable law prescribes. General support: [email protected].