Creght Legal
Creght Privacy Policy
Last updated: July 22, 2026 · Effective: July 22, 2026
Creght values your privacy and the security of personal information. This Policy explains how we collect, use, store, share, and protect information when you visit, register for, or use Creght, and how you may exercise your rights.
This Policy applies to the Creght website, console, editor, and related services provided directly by Creght. Operators of websites created with Creght are responsible for providing their own privacy notices to visitors.
1. Information We Collect
Account information
Email address, phone number, display name, avatar, login credentials, account ID, team, and permission information. Business users may also provide an organization name, contact person, and verification materials.
Usage and device information
IP address, browser and device type, operating system, login time, access and activity records, error logs, cookie identifiers, and security-risk signals.
Projects and AI interactions
Prompts, uploaded assets, project code, page content, AI output, version history, and publishing configuration. Unless separately and expressly authorized, private projects, form data, Auth data, and website visitor data are not used to train AI models.
Transaction information
Plan, order, amount, payment status, invoice, and refund information. Complete payment-account details are generally handled directly by payment providers.
Support and security information
Support tickets, email and chat records, reports, appeals, attachments, and materials supplied for account verification or security investigations.
Website visitor data
When a customer enables forms, CMS, Auth, Func, analytics, or similar features, Creght may process visitor information on that customer's instructions. The website operator is responsible for required notice and consent.
2. How We Use Information
We process personal information only to the extent reasonably necessary for these purposes.
- Create and manage accounts, teams, and permissions;
- Provide AI website building, editing, hosting, publishing, and backend features;
- Process orders, payments, refunds, and invoices;
- Provide customer and technical support;
- Maintain reliability, security, and abuse prevention;
- Detect phishing, fraud, malware, suspicious login, and other risks;
- Improve product performance and user experience;
- Meet legal obligations and resolve complaints or disputes;
- Send product or marketing communications where lawfully authorized.
3. Cookies and Similar Technologies
We may use cookies, local storage, and similar technologies to maintain sessions, remember settings, measure service performance, and prevent abuse.
Essential cookies support login, security, and core functions. Where consent is required for analytics or marketing cookies, we will provide appropriate notice and choices. Disabling essential cookies may impair the Services.
4. Sharing and Service Providers
We do not sell personal information. We may disclose necessary information only in circumstances such as the following:
- To cloud, payment, email, support, authentication, AI-model, or security providers needed to deliver the Services;
- To third-party integrations that you choose to enable;
- To meet legal obligations, respond to competent authorities, or protect users and the public;
- As lawfully necessary in a merger, acquisition, financing, or asset transfer;
- In other circumstances with your separate authorization.
5. Third Parties, International Processing, and Retention
We intend to identify material providers, service categories, and processing locations in a subprocessor list.
Where personal information is processed across borders, we will use measures required by applicable law, including notice, separate consent, contractual safeguards, or security mechanisms where necessary.
We keep personal information only for as long as reasonably necessary for the relevant purpose or as required by law, after which it is deleted or anonymized unless lawful retention remains necessary.
6. Security
We use technical and organizational measures appropriate to risk, including access controls, encryption in transit, permission management, logging, backups, security monitoring, and confidentiality obligations.
If a personal-data incident may affect your rights, we will take remedial action and provide notifications or reports as required by law.
No internet service is absolutely secure. Use a strong password, protect verification codes and keys, and respond promptly to suspicious-login warnings.
7. Your Rights
Subject to applicable law, you may submit a request through available account settings or by emailing hi@creght.com. We may verify your identity to protect the account.
- Access or obtain a copy of personal information;
- Correct or complete inaccurate information;
- Request deletion where applicable;
- Withdraw consent where processing is based on consent;
- Close your account;
- Request an explanation of our processing practices;
- Submit a privacy complaint.
8. Children
Creght is primarily intended for individuals and organizations with the legal capacity to use the Services. We do not knowingly offer the Services to or collect personal information from children under 14.
If a guardian believes a child submitted personal information without consent, contact hi@creght.com so we can investigate and take appropriate action.
9. Policy Changes and Contact
We may update this Policy to reflect changes in products, law, or processing. Material changes will be communicated by email, in-product notice, or a prominent website notice. We will request renewed authorization where required.
For privacy questions, rights requests, or complaints, contact hi@creght.com.
