This Privacy Policy explains how [BUSINESS LEGAL NAME] ("we", "us") collects, uses, discloses, and protects personal information about visitors, customers, and account holders of The AI Creator Lab ("Service"). It is written to satisfy the disclosure requirements of the California Consumer Privacy Act as amended ("CCPA/CPRA") and the EU/UK General Data Protection Regulation ("GDPR") to the extent applicable. For questions or to exercise your rights, contact hello@aicreatorlab.com.
1. Data controller
The data controller is [BUSINESS LEGAL NAME], [BUSINESS ADDRESS]. If you are in the EEA or UK and require an Article 27 representative, contact us and we will provide the current designee.
2. Information we collect
- Account data: email address, display name, hashed authentication credentials, and OAuth identifiers when you sign in with Google.
- Purchase data: Stripe customer ID, order and subscription history, entitlements, refund history, and billing metadata. Stripe collects the payment card itself; we never see or store full card numbers.
- Content you submit: community posts, comments, feedback, event RSVPs, marketplace listings, and support messages.
- Usage data: pages viewed, features used, AI-assistant messages sent, download events, and standard server logs (IP address, user agent, timestamps, referrer).
- Cookies and similar technologies: session cookies for login, and preference cookies (e.g., dismissed banners). See Section 8.
- Device and diagnostic data: browser errors, performance metrics, and crash reports when analytics or error monitoring are enabled.
3. How we use information
- Deliver purchased products, generate signed download links, and grant entitlements.
- Provide, secure, and improve the Service, including debugging and abuse prevention.
- Process payments and prevent fraud (jointly with Stripe).
- Send transactional email (order confirmations, receipts, security alerts, plan changes).
- Send marketing email only after you opt in, with a working unsubscribe link in every message.
- Comply with legal obligations and enforce our Terms.
4. Legal bases (GDPR)
Where GDPR applies, we rely on: contract (to deliver purchased products and account services), legitimate interests (security, fraud prevention, product improvement), consent (marketing email, non-essential cookies, analytics), and legal obligation (tax and accounting records).
5. Subprocessors and third parties
- Stripe, Inc. (US) — payment processing, tax calculation, invoicing, subscription billing, and fraud prevention. Stripe receives your name, email, billing address, IP address, device fingerprint, and payment card details directly at checkout. Governed by Stripe's Privacy Policy.
- Lovable Cloud (backed by Supabase, Inc. and Amazon Web Services) (US/EU) — hosting, database, authentication, file storage.
- [EMAIL PROVIDER — e.g., Resend or Postmark] — transactional and marketing email delivery.
- Sentry (Functional Software, Inc., US) — application error monitoring and performance tracing (when enabled). See Section 8A.
- PostHog (PostHog Inc., US or EU region) — product analytics, session-level event tracking, and feature-flag evaluation (when enabled). See Section 8B.
- Google LLC — Google Sign-In (if used).
Each subprocessor is bound by a data processing agreement and processes personal data only on our documented instructions. A current list is available on request.
6. Data retention
- Account data: retained while your account is active and for up to 24 months after closure, unless a longer period is required for legal or accounting reasons.
- Purchase and tax records: retained for at least 7 years to satisfy US tax and accounting requirements.
- Server logs: retained for up to 90 days.
- Support correspondence: retained for up to 24 months.
- Sentry error events: retained for up to 90 days, then automatically purged.
- PostHog analytics events: retained for up to 12 months at event-level, then aggregated or deleted. Session recordings, if enabled, are retained for up to 30 days.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal information; the right to object to processing based on legitimate interests; and the right to withdraw consent. California residents have the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell personal information and do not knowingly share it for cross-context behavioral advertising. To exercise rights, email hello@aicreatorlab.com. We will respond within the timeframe required by applicable law.
8. Cookies and tracking
We use strictly necessary cookies for authentication (Supabase session token) and preference persistence (e.g., dismissed banners, saved filters). If analytics or advertising cookies are enabled in your region, we present a consent banner before setting them and you may withdraw consent at any time. You can clear cookies via your browser settings; doing so will sign you out.
8A. Error monitoring — Sentry
When Sentry is enabled, we use it to detect and diagnose application crashes, JavaScript exceptions, failed API calls, and slow requests so we can fix bugs.
- What Sentry collects: error stack traces, breadcrumbs (recent user actions leading up to the error such as clicks and navigations, without input values), browser type and version, operating system, viewport size, page URL and route, timestamp, a random session identifier, your authenticated user ID (to correlate errors across sessions), truncated IP address (for geographic aggregation), and, for server errors, the request method and path.
- What Sentry does not collect: form field values, passwords, payment details, download tokens, message bodies, or the contents of API request/response payloads. We scrub sensitive fields before sending.
- Purpose and legal basis: legitimate interest in maintaining a secure and reliable service, and legal obligation to safeguard user data.
- Retention: up to 90 days, then automatically purged from Sentry.
- Safeguards: transmitted over TLS; access restricted to project maintainers via SSO; Sentry is bound by a data processing agreement and Standard Contractual Clauses for EU transfers.
- Opt-out: use a browser-level ad/tracker blocker (Sentry's SDK is blocked by common blocklists), or email us to opt out; opting out disables our ability to diagnose crashes that affect your account.
8B. Product analytics — PostHog
When PostHog is enabled, we use it to understand which features are used, where users drop off in the purchase funnel, and how to prioritize improvements.
- What PostHog collects: page views (URL, referrer, title), custom product events (e.g. checkout_started, download_clicked, subscription_upgraded), click and form-submission events on tagged elements, device and browser metadata, viewport size, session identifier, and — for signed-in users — your authenticated user ID, email, tier, and country. Approximate location is derived from IP address; the raw IP is not stored beyond geo-lookup.
- Session recordings (if enabled): masked replays of your interaction with the site. All text inputs, passwords, and payment fields are masked before capture (we use PostHog's default masking plus
data-ph-no-captureon sensitive elements). Recordings are stored for up to 30 days. - What PostHog does not collect: full card numbers, CVCs, passwords, download tokens, message bodies of AI conversations, or personal content you have not chosen to share.
- Purpose and legal basis: legitimate interest (or your consent where required by local law) in improving the Service and the checkout experience.
- Retention: event-level data up to 12 months; session recordings up to 30 days; aggregated/anonymized metrics may be retained longer.
- Safeguards: transmitted over TLS; hosted in [US or EU] region; RBAC on the PostHog project; bound by a data processing agreement.
- Opt-out: enable "Do Not Track" or Global Privacy Control in your browser, use a tracker blocker, or email us. We honor GPC signals as opt-outs of analytics for California residents.
No cross-context behavioral advertising. We do not use Sentry or PostHog data — or any other data — to serve targeted advertising, and we do not share it with ad networks.
9. International transfers
We are based in the United States and our subprocessors operate in the United States and the European Union. When personal data is transferred outside your country, we rely on Standard Contractual Clauses or an equivalent transfer mechanism.
10. Security
We use TLS in transit, encryption at rest for storage buckets, row-level security in the database, role-based admin access, HMAC-signed download URLs with short expiries, and audit logging for privileged actions. No system is perfectly secure; if we become aware of a data breach affecting your personal information, we will notify you as required by applicable law.
11. Children
The Service is not directed to children under 16 (or under 13 in the United States). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes
We may update this Policy. Material changes will be posted here and, for account holders, sent by email at least 14 days before taking effect.
13. Contact and complaints
[BUSINESS LEGAL NAME], [BUSINESS ADDRESS] — hello@aicreatorlab.com. EEA/UK residents may lodge a complaint with their local supervisory authority.
This document is a draft prepared for attorney review. It has not been reviewed by counsel and does not constitute legal advice. Confirm applicability to your jurisdiction, business structure, and enabled subprocessors before publishing.