Privacy
This page says what Kreashot collects, which companies process it on our behalf, how long it is kept and how to have it deleted. No defined terms, no cross references, nothing written to be skipped.
Last updated 9 August 2026
Kreashot is built and operated by Raygency. For anything you upload or create in the product, Raygency is the data controller under the GDPR.
Questions, requests and complaints go to privacy@kreashot.com. A person reads that address, and we answer within 30 days as the GDPR requires, usually a great deal sooner.
We do not buy data about you, and we do not run advertising or tracking pixels of our own on this site.
Kreashot is assembled from services that specialise in one job each. Every company below has a data processing agreement with us and works only on our instructions. Transfers to the United States rely on the EU standard contractual clauses.
| Company | What it does | What it sees | Where |
|---|---|---|---|
| Railway | Hosting and the application database | Account records, project data, everything the app stores | EU and United States |
| Google Cloud Storage | Storing the images you upload and the assets we generate | Product photographs, backgrounds, composites, finished ads | European Union |
| OpenAI | Writing ad copy, headlines and creative briefs | Your brand voice notes and product descriptions, as prompt text | United States |
| Google (Gemini) | Generating and editing images | Product photographs and the prompts describing them | United States |
| Replicate | Some background generation | Prompt text and, for some jobs, a source image | United States |
| Stripe | Subscriptions and payments | Billing details and card data, which Stripe holds and we never see | European Union and United States |
| Resend | Sign in links, verification and account email | Email address and message content | United States |
| PostHog | Product analytics, which features get used | Page views, feature events, a pseudonymous id | European Union |
| Sentry | Error monitoring, so crashes get fixed | Stack traces, browser details, the user id involved | European Union and United States |
| Meta | Publishing ads, only if you connect a Meta account yourself | The ad images and copy you choose to publish | United States |
Your product photographs are sent to the image and text providers listed above only to produce the asset you asked for, under their paid API terms, which exclude that content from being used to train their models. We do not build models of our own, and we do not sell, license or share your images with anyone else.
Generated assets belong to you. We keep them only so they appear in your account.
Connecting Meta is optional and entirely your decision. When you do, we store the access token you provide, encrypted with AES-256-GCM, along with the ad account, Page and Instagram account you selected. The token is decrypted only at the moment you press publish.
We use it for nothing else. Everything Kreashot creates in your Meta account is created paused, so nothing spends money until you switch it on yourself. Disconnect in Settings and the token is deleted from our database immediately.
If you are in the EU or the UK, the GDPR gives you the right to get a copy of your data, correct it, have it deleted, take it elsewhere in a portable format, restrict what we do with it, and object to processing based on legitimate interest. There is no charge and no form to fill in. Email privacy@kreashot.com and say what you want.
If we handle it badly you can complain to your national data protection authority. In Germany that is the supervisory authority for the state you live in.
Two kinds, and no banner farm. A session cookie keeps you signed in and cannot be turned off without breaking sign in. PostHog sets a pseudonymous analytics id so we can count how features get used. No advertising cookies, no third party trackers, nothing sold to a data broker.
Traffic runs over TLS. Passwords are hashed with bcrypt. Meta access tokens are encrypted at rest with AES-256-GCM under a key held outside the database. Access to production is limited to the two people who run Raygency.
If a breach ever affects your data, we will tell the supervisory authority within 72 hours and tell you without undue delay.
Kreashot is a tool for businesses and is not intended for anyone under 16. We do not knowingly collect data from children.
When this policy changes we update the date at the top. If a change actually affects you, such as a new processor or a new purpose, we email you before it takes effect rather than hoping you reread the page.
Raygency, for Kreashot