CreativeDoctor

Legal

Privacy Policy

Effective 26 September 2026

Your ads and business information are sensitive. This policy explains plainly what we collect, why, who helps us process it, and the control you have over it.

1. Who we are

CreativeDoctor (https://creativedoctor.app) is operated by a sole trader based in New South Wales, Australia (“we”, “us”, “our”). We are responsible for the personal information described in this policy.

You can contact us about privacy at any time at hello@creativedoctor.app.

2. What this policy covers

This policy explains what information we collect when you visit our website, create an account, upload ad creatives, subscribe to a plan or contact us, and how we use, share, store and protect it. It also explains your choices and rights. We aim to handle personal information consistently with the Australian Privacy Principles, and we describe additional rights for people in the European Union, the United Kingdom and California below.

3. Information we collect

Information you give us

  • Account details: your email address, an optional name, and your password. Passwords are stored in hashed form by our authentication provider; we never see them. If you sign in with Google, we receive your email address and name from Google.
  • Content you submit for analysis: ad creatives (images, or still frames extracted from a video), ad copy, product name, description and price, target audience, platform, campaign objective and audience-awareness level, and landing-page URLs.
  • Messages: anything you send us by email, such as support or privacy requests.

Information we create or collect as you use the service

  • Reports: the analyses, scores, recommendations and ideas generated for your creatives.
  • Landing-page content: when you give us a URL, our servers fetch that page and read its publicly visible text (such as the title, headings, prices, buttons and product description). We only fetch public web pages and never sign in to them.
  • Usage and account status: how many analyses you have used, your plan, and the dates of your billing period.
  • Technical and security information: your IP address, browser type and request logs. We use IP addresses to protect the service, for example to limit repeated sign-up attempts and repeated free analyses from one network. Those rate-limit records are kept for about two days.
  • Product analytics: events such as “page viewed”, “analysis started”, “analysis completed”, “pricing viewed” and “checkout started”, together with the page path and either a random identifier stored in your browser or your account ID. We do not send your email address, name, creatives or report content to our analytics provider.

Payment information

Payments are processed by Stripe. We never receive or store your full card number. Stripe tells us your customer ID, which plan you are on, whether your subscription is active, and your billing dates.

4. How video creatives are handled

When you choose a video, your browser extracts a small number of still frames on your own device. Only those frames are uploaded; the video file itself is not sent to our servers. Audio is not analyzed.

5. How we use your information

We use your information to:

  • provide the service, including generating, saving and displaying your analyses;
  • create and secure your account, and sign you in;
  • manage subscriptions, billing and your monthly analysis allowance;
  • prevent fraud and abuse, and keep the service secure and reliable;
  • send essential service emails, such as account confirmation, password resets and a welcome email;
  • respond to your questions and requests;
  • understand, in aggregate, how the product is used so we can improve it; and
  • comply with our legal obligations.

We do not sell your personal information, use it for advertising, or share it with advertisers. We do not send marketing emails unless you have agreed to receive them. We do not train AI models on your creatives or reports.

6. AI processing

To generate a report, we send your creative (or its video frames), the details you entered and the text read from your landing page to Anthropic, which provides the Claude AI models we use. Anthropic processes this content on our behalf to return the analysis. Under its commercial terms, Anthropic does not use this content to train its models, though it may retain it for a limited period for safety and legal purposes as described in its own policies.

Reports are AI-generated opinions about your creative. They are not used to make decisions about you, and they do not affect your account, eligibility or pricing.

7. Who we share information with

We share information only with service providers that help us run CreativeDoctor, and only as needed for the services they provide to us:

  • Supabase: database, authentication and private file storage.
  • Anthropic: AI analysis (see “AI processing” above).
  • Stripe: payments, subscriptions, invoices and the customer billing portal.
  • Resend: sending transactional emails.
  • PostHog: product analytics.
  • Hosting and network providers (such as Vercel and Cloudflare): running the website and delivering pages securely.

We may also disclose information:

  • where required by law, court order or a government authority;
  • to protect the rights, safety or property of our users, the public or us, including to investigate fraud or security issues;
  • to a buyer or successor if the business is sold or transferred, in which case this policy will continue to apply to your information; or
  • with your consent.

8. International transfers

Our service providers are located in, or process data in, countries outside Australia, including the United States. When information is transferred overseas, we take reasonable steps to make sure it is protected, including using providers that commit to appropriate security and data-protection standards in their agreements with us.

9. How we protect your information

  • All traffic to CreativeDoctor is encrypted in transit (HTTPS).
  • Uploaded creatives are kept in private storage. They are only shown to you through temporary links that expire after an hour.
  • Database access rules ensure each account can only read its own analyses and files.
  • Access to production systems is limited to the operator of the service.

No online service is completely secure. If we become aware of a data breach that is likely to cause serious harm, we will notify affected users and the relevant regulator as required by law.

10. How long we keep information

  • Account information: for as long as your account is open.
  • Creatives and reports: until you delete them. Deleting a report also deletes its uploaded files. Reports remain available after you cancel a subscription.
  • After you close your account: we delete your account, creatives and reports within 30 days, except where we must keep records to meet legal obligations. Copies may remain in encrypted backups for a short time until they are overwritten.
  • Billing records: kept for as long as required by tax and accounting laws (in Australia, generally five years). Stripe keeps its own records under its policies.
  • Rate-limit records containing IP addresses: about two days.
  • Analytics events: kept by PostHog under its retention settings, and never linked to your email address.

11. Your choices and rights

You can:

  • access the personal information we hold about you, and receive a copy in a portable format;
  • correct information that is inaccurate or out of date (you can change your name in Settings);
  • delete individual reports yourself at any time, or ask us to delete your account;
  • object to or restrict certain processing, and withdraw any consent you have given; and
  • turn off analytics in your browser from our Cookie & Storage Notice. We also respect the Global Privacy Control and Do Not Track signals.

To make a request, email hello@creativedoctor.app from the address on your account. We will respond within 30 days and may need to confirm your identity first. We do not charge for reasonable requests.

European Union and United Kingdom

If the GDPR or UK GDPR applies to you, we rely on these legal bases: performing our contract with you (providing the service and billing); our legitimate interests (security, fraud prevention, and improving the product in ways that don't override your rights); legal obligations (tax records); and consent where we ask for it. You may also lodge a complaint with your local data-protection authority.

California

We do not sell personal information or share it for cross-context behavioural advertising. You have the right to know, delete and correct your information, and we will not discriminate against you for exercising these rights.

12. Cookies and browser storage

We use a small number of essential cookies to keep you signed in, and browser storage for analytics and for keeping a creative you chose before signing up. We don't use advertising or cross-site tracking cookies. Full details are in our Cookie & Storage Notice.

13. Children

CreativeDoctor is a business tool for people aged 18 and over. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.

14. Complaints

If you have a concern about how we have handled your personal information, please contact us first at hello@creativedoctor.app and we will try to resolve it within 30 days. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or the data-protection authority where you live.

15. Changes to this policy

We may update this policy as the service changes. If we make a material change, we will tell you by email or in the app before it takes effect. The effective date at the top shows when it was last updated.

Questions about this page? Email hello@creativedoctor.app.