Privacy Policy

Last updated: February 2026

1. Introduction

KREAVO LLC ("KREAVO", "we", "us", "our"), a Wyoming Limited Liability Company, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered creative platform (the "Service"). By using the Service, you consent to the data practices described in this policy. This policy applies to all users of the Service, regardless of location. We comply with applicable privacy laws including GDPR, CCPA/CPRA, and other US state privacy laws.

2. Information We Collect

a) Information You Provide: • Account information: email address, display name, profile picture • Payment information: processed and stored exclusively by Stripe, Inc.; we do not store, access, or process full payment card details at any time • Uploaded content: product photos, brand assets, reference images, videos, audio files • User inputs: text prompts, generation parameters, preferences, feedback • Communications: emails, support tickets, and messages you send to us b) Automatically Collected Information: • Device information: browser type and version, operating system, device identifiers, screen resolution • Usage data: pages visited, features used, credits consumed, models selected, generation parameters, timestamps • Log data: IP address, access times, referring URLs, error logs, request identifiers • Cookies and similar technologies: session cookies, authentication tokens, local storage (see our Cookie Notice for details) c) Information We Do NOT Collect: • We do not collect biometric data for identification purposes • We do not collect financial account numbers (handled solely by Stripe) • We do not engage in cross-site tracking or behavioral advertising profiling

3. Legal Basis for Processing (GDPR)

For users in the EU/EEA/UK, we process your personal data under the following legal bases: • Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Service, manage your account, process payments, and deliver AI-generated content • Legitimate Interest (Art. 6(1)(f)): Analytics, fraud prevention, security monitoring, and service improvement — balanced against your rights and freedoms • Consent (Art. 6(1)(a)): Optional analytics cookies, marketing communications (where applicable) • Legal Obligation (Art. 6(1)(c)): Tax compliance, responding to legal requests, data breach notifications You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

4. How We Use Your Information

We use your information to: • Provide, maintain, and improve the Service • Process your AI generations by transmitting inputs to third-party AI model providers • Manage your account, subscriptions, and billing • Send transactional communications (welcome emails, billing receipts, security alerts, service updates) • Analyze usage patterns to improve AI model selection, performance, and credit pricing • Detect and prevent fraud, abuse, platform manipulation, and security incidents • Enforce our Terms of Service and Acceptable Use Policy • Comply with legal obligations and respond to lawful requests • Provide customer support and resolve disputes We do NOT: • Sell your personal data to third parties — EVER • Use your uploaded content to train our own AI models without explicit opt-in consent • Share your content with other users unless you voluntarily use community features • Use your data for targeted advertising or advertising profiling • Make automated decisions with legal or similarly significant effects without human oversight

5. AI Model Processing & Third-Party Providers

When you generate content, your inputs (text prompts, uploaded images, video, audio) are transmitted to carefully selected third-party AI model providers for processing. We work with leading AI infrastructure providers based in the United States and internationally. The specific providers and models we use may change at any time without notice as we continuously optimize our platform. IMPORTANT DISCLOSURES: • Your inputs are transmitted to these providers solely for the purpose of generating the requested output • We select providers that maintain high standards of data protection under our agreements • Providers are contractually prohibited from retaining your data for their own training purposes under our agreements • However, KREAVO cannot guarantee the data practices of third-party providers beyond our contractual agreements • Third-party providers have their own privacy policies that may apply to the processing of your data • The list of providers may change at any time as we add, modify, or remove AI model integrations • For specific inquiries about our data sub-processors, you may contact us at [email protected]

6. Data Storage & Security

• All data is stored on secure, encrypted cloud infrastructure hosted in the United States • Encryption at rest: AES-256 • Encryption in transit: TLS 1.3 • Database access: Row-Level Security (RLS) ensures data isolation per user account • Access control: production data access is limited to authorized personnel with multi-factor authentication • File storage: uploaded and generated assets are stored in isolated, access-controlled storage buckets • We conduct regular security reviews and vulnerability assessments • We maintain incident response procedures for data breach scenarios WHILE WE IMPLEMENT INDUSTRY-STANDARD SECURITY MEASURES, NO METHOD OF TRANSMISSION OVER THE INTERNET OR ELECTRONIC STORAGE IS 100% SECURE. WE CANNOT GUARANTEE ABSOLUTE SECURITY OF YOUR DATA. You use the Service and transmit data at your own risk.

7. Data Retention

• Account data: retained as long as your account is active • Uploaded content: retained as long as your account is active; deleted within 30 days of account deletion • Generated content: retained as long as your account is active; available for download for 30 days after account deletion, after which it is permanently deleted • Usage logs: retained for up to 24 months for billing, analytics, fraud prevention, and legal compliance • Payment records: retained as required by tax and financial regulations (typically 7 years per IRS requirements) • Support correspondence: retained for up to 36 months for quality assurance and legal compliance • Anonymized and aggregated analytics data: may be retained indefinitely for statistical and service improvement purposes (this data cannot identify you) We may retain data longer if required by law, ongoing legal proceedings, or to enforce our Terms of Service.

8. Your Rights

Depending on your jurisdiction, you may have the following rights: a) Under GDPR (EU/EEA/UK residents): • Right to access your personal data • Right to rectification of inaccurate data • Right to erasure ("right to be forgotten") • Right to restriction of processing • Right to data portability • Right to object to processing based on legitimate interests • Right to withdraw consent at any time • Right to lodge a complaint with your local supervisory authority b) Under CCPA/CPRA (California residents): • Right to know what personal information is collected, used, and disclosed • Right to delete personal information • Right to opt-out of sale/sharing of personal information (Note: KREAVO does NOT sell personal information) • Right to non-discrimination for exercising privacy rights • Right to correct inaccurate personal information • Right to limit use of sensitive personal information c) Under other US state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, and others): We comply with applicable state privacy laws providing similar rights to access, delete, correct, and opt-out. d) California "Shine the Light" Law (Civil Code § 1798.83): California residents may request information about personal data disclosed to third parties for direct marketing purposes. KREAVO does not disclose personal data to third parties for their direct marketing purposes. To exercise any of these rights, contact us at [email protected] with your specific request. We will verify your identity and respond within 30 days (or sooner if required by applicable law). We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.

9. Do Not Track Disclosure

Some browsers transmit a "Do Not Track" (DNT) signal. There is currently no universally accepted standard for how companies should respond to DNT signals. At this time, KREAVO does not respond to DNT signals. However, we do not engage in cross-site tracking or serve targeted advertisements, so our data practices are functionally consistent with DNT preferences.

10. Cookies & Tracking Technologies

We use the following types of cookies: • Essential cookies: required for authentication, session management, and security (cannot be disabled) • Functional cookies: remember your preferences and settings (can be disabled) • Analytics cookies: help us understand how the Service is used (can be disabled) We do NOT use: • Advertising, retargeting, or marketing cookies • Third-party tracking pixels (Facebook Pixel, Google Ads, etc.) • Cross-site tracking cookies • Browser fingerprinting technologies For complete details, please review our Cookie Notice at /cookie-policy.

11. International Data Transfers

Your data is primarily stored and processed in the United States. If you are located outside the US, your data will be transferred to and processed in the US. For transfers from the EU/EEA/UK: • We rely on Standard Contractual Clauses (SCCs) approved by the European Commission • We implement supplementary measures where required by applicable law • We ensure that all international transfers are protected by appropriate safeguards By using the Service from outside the United States, you expressly consent to the transfer of your data to the US, where privacy laws may differ from those in your jurisdiction.

12. Children's Privacy

The Service is NOT intended for users under 18 years of age. We do not knowingly collect personal data from minors under 18 (or under 16 in jurisdictions where GDPR applies with a lower age threshold for consent). If we become aware that we have inadvertently collected data from a minor, we will take immediate steps to: (a) delete all associated personal data, (b) terminate the associated account, and (c) notify the minor's parent or guardian if contact information is available. If you believe a minor has provided us with personal data, please contact us immediately at [email protected].

13. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will: • Notify affected users without undue delay and, where feasible, within 72 hours of becoming aware of the breach • Notify relevant supervisory authorities as required by applicable law (GDPR, state breach notification laws, etc.) • Provide details of the breach, categories of data affected, potential consequences, and measures taken • Take immediate steps to contain, investigate, and mitigate the impact • Implement measures to prevent recurrence • Maintain a documented record of all breaches for compliance purposes

14. Third-Party Links & Services

The Service may contain links to third-party websites or services (e.g., Stripe for payments). We are not responsible for the privacy practices, content, or security of third-party services. We encourage you to review the privacy policies of any third-party service you access through or in connection with the Service.

15. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be notified via email or in-app notification at least 30 days before they take effect. The "Last updated" date at the top will be revised accordingly. We encourage you to review this policy regularly. Continued use of the Service after changes constitutes acceptance of the updated policy. If you do not agree to the changes, your sole remedy is to discontinue use of the Service and delete your account.

16. Data Protection Contact

For privacy-related inquiries, data subject requests, or to exercise your data rights: KREAVO LLC Attn: Privacy Team 1021 E Lincolnway, Cheyenne, WY 82001 United States Email: [email protected] General support: [email protected] We aim to resolve all privacy-related requests within 30 days (or sooner if required by applicable law). If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.