Legal
Privacy Policy
This policy explains what information CreateForge AI handles, why we use it, and the choices available to you.
Last updated: August 18, 2026
Account and activity information
When you sign in with Google through Supabase Auth, we receive account details made available for authentication, such as your name, email address, account identifier, and profile image. We do not receive your Google password.
When you use the service, we process prompts, uploaded reference images, video or audio, generation settings, quoted credits, job status, generated assets, usage records, support communications, and technical logs such as IP address, browser information, timestamps, request identifiers, and security events.
Billing, subscription, and credit records
Payments are processed by Stripe. CreateForge stores the Stripe customer, Checkout, PaymentIntent, subscription, price, and invoice identifiers needed to reconcile a transaction, together with the selected offer, amount, currency, payment or subscription status, paid period, cancellation state, and relevant timestamps. We do not store complete card numbers.
We maintain balances for permanent and subscription credits, active reservations, subscription expiry, billing debt, and an auditable credit ledger. That ledger records grants, reservations, successful generation charges, failed-output releases, subscription expiry, refunds, disputes, and manual corrections so we can operate the account and investigate billing questions.
How we use information
- Provide, secure, troubleshoot, measure, and improve CreateForge AI.
- Authenticate accounts, process generation jobs, store results, and maintain credit balances.
- Process purchases, subscriptions, refunds, disputes, and required financial records.
- Prevent fraud, abuse, unauthorized access, and violations of our terms.
- Comply with legal obligations and respond to valid requests.
AI generation content
CreateForge sends the prompt, selected settings, and eligible reference inputs to Kie and the selected underlying model provider to perform the generation you request. Requests or outputs may be evaluated by automated safety systems operated by CreateForge or its providers. We may retain limited, sanitized records of blocked or failed requests for security, abuse prevention, provider reconciliation, and audit.
CreateForge does not currently operate a model-training program that uses your private prompts, reference inputs, or Library outputs. Third-party providers process submitted content under their own terms and privacy practices; their independent retention or model-improvement rules may differ, and this policy does not make a promise on their behalf.
Service providers and other disclosures
We use Vercel for web delivery, Cloudflare for API infrastructure and private R2 media storage, Supabase for Google authentication and database services, Stripe for payments, and Kie plus the selected underlying AI model providers for uploads and generation. We disclose only the information reasonably needed for those services to perform the requested function, secure the platform, or satisfy legal obligations.
We may also disclose relevant information when you direct us to do so; to investigate fraud, abuse, security incidents, or rights claims; to comply with a valid legal request; or in connection with a merger, financing, acquisition, reorganization, or sale of all or part of the business. We do not disclose private generation content to unrelated advertisers or make it public through CreateForge.
These recipients may process information in countries other than your own under their applicable terms, security controls, and transfer safeguards. Their independent retention or legal obligations may differ from CreateForge controls.
Reference inputs and generated media
Reference inputs are private, authenticated uploads. Current generation workflows stream eligible inputs to Kie temporary file storage so the selected model can access them. CreateForge records the temporary provider reference and an expiry time; the CreateForge upload record expires after 24 hours and scheduled retention removes the stored reference. Kie and an underlying model provider may keep data for a different period under their own operational or legal requirements.
Successful generated images and videos are copied from temporary provider links into a private Cloudflare R2 bucket and associated with your Library. They are delivered through authenticated access rather than a public storage URL. Job, asset, credit, and security records remain in Supabase for account operation, billing integrity, troubleshooting, and abuse prevention.
Cookies, browser storage, and analytics
Supabase uses essential authentication cookies and related security storage to keep signed-in sessions working and protect requests. You can block or clear them in your browser, but signed-in features may stop working.
CreateForge uses browser session storage for Create composer and sign-in drafts, including the prompt and selected settings. Files are not saved in those drafts, and drafts older than 24 hours are rejected. Local storage remembers limited interface preferences such as the collapsed navigation and studio theme. Clearing site data removes these browser-only values.
Public pages use a privacy-focused Plausible analytics script served through stat.re to measure aggregated visits and page performance. We do not run third-party behavioral advertising, sell personal information, or use analytics to build advertising profiles.
Retention and security
Temporary reference-upload records expire after 24 hours. Failed intermediate media is scheduled for cleanup after 7 days, and sanitized provider-event payloads are scheduled for removal after 30 days. Event hashes, status, cost, and timing metadata may be retained longer as an audit record. Generated Library media and account records are retained for as long as reasonably needed to provide the service, maintain billing and security integrity, resolve disputes, and meet legal obligations. Financial, fraud, chargeback, or compliance records may be retained longer where required.
We use authenticated access, encryption in transit, private object storage, signed webhooks, upload tokens, and least-privilege credentials. No online service can guarantee absolute security.
Your choices and rights
Depending on where you live, you may request access, correction, deletion, restriction, objection, or a portable copy of eligible personal information. You may also ask us to close your account. We will verify requests as appropriate and may retain records required for security, fraud prevention, billing, dispute resolution, or legal compliance.
Children and external links
CreateForge AI is not directed to children under 18. The service may link to external websites that have their own privacy practices; review their policies before providing information to them.
Policy changes
We may update this policy as the service or legal requirements change. We will post the new version and revise the date above. For material changes, we will make reasonable efforts to provide additional notice through the service or an account communication when practicable.
Contact
For privacy or support requests, use the contact page or email contactus@createforgeai.com. Please include enough information for us to identify the relevant account without sending passwords or complete payment-card details. Use of CreateForge is also governed by the Terms of Service.