Privacy Policy
LAST UPDATED 24 AUGUST 2026
This policy explains what CreatorPlan collects, why, and who it is shared with. The data controller is Vsevolod Korobchenko, Kazakhstan. Contact: justvmaill@gmail.com.
What we collect
- Account data. Your email address, a password stored only as a salted scrypt hash (we never store or see your actual password), whether your email is verified, and your plan status.
- What you submit. The public profile URL you paste, your answers to the intake questions, and any instructions you give while editing.
- What we generate for you. Your plans, content ideas, products, lessons, worksheets and launch plans, saved to your account so you can return to them.
- Publicly available creator data. To research the profile you supply, we retrieve public information about it — such as follower counts, recent video titles, public captions, public comments and transcripts.
- Connected-platform credentials. If you connect a publishing platform, its API key is encrypted at rest (AES-256-GCM) before storage and is never sent back to your browser.
- Payment data. We do not receive or store your card details. Payment is handled entirely by Paddle; we store only your plan status, the renewal date, and the identifiers Paddle gives us to match your subscription to your account.
- Minimal technical data. A signed session cookie to keep you logged in, and standard server logs. We do not run third-party advertising or analytics trackers on the site.
Why we use it
- To provide the Service — researching the profile you gave us and generating your materials.
- To operate your account: sign-in, email verification, password reset, plan entitlements.
- To take payment and manage your subscription.
- To keep the Service secure — for example rate-limiting repeated failed sign-in attempts.
- To comply with legal and tax obligations.
Where the GDPR applies, our lawful bases are performance of a contract (providing the Service), legitimate interests (security and service improvement), consent (where asked), and legal obligation (tax and accounting records).
Who we share it with
We do not sell your personal data. We share only what each provider needs to do its job:
- Anthropic — AI generation. Receives your creator context and the content being generated or revised.
- Web search and social-data providers (such as Tavily, Apify, and the YouTube Data API) — receive the profile URL or search terms used to research it.
- Resend (or an SMTP provider you configure) — receives your email address to deliver verification and password-reset codes.
- Paddle — our Merchant of Record. Handles checkout, payment, tax and billing support, and receives the information needed to process your purchase.
- Whop, or another platform you explicitly connect — receives the course content you choose to publish there.
- Our hosting provider — stores the application and its data.
We may also disclose data where required by law, or to protect our rights, safety, or the integrity of the Service.
How long we keep it
Account and generated content are kept while your account is open. Delete a generation and it is removed from your account; delete your account and we remove your personal data within 30 days, except records we must retain for tax, accounting or legal reasons (typically kept by Paddle for the period required by law). Backups are retained on a short rolling window and overwritten.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. Exercise any of these by emailing justvmaill@gmail.com. You also have the right to complain to your local data-protection authority. California residents may additionally request disclosure of the categories of data collected and opt out of “sale” of personal information — we do not sell personal information.
International transfers
Our providers may process data in countries other than yours, including the United States. Where required, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Security
Passwords are hashed, connected-platform API keys are encrypted at rest, sessions use signed, HTTP-only cookies (marked secure over HTTPS), and repeated failed sign-ins are rate-limited. No system is perfectly secure, but we take reasonable measures to protect your data.
Children
The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
We may update this policy; the “last updated” date above will change, and material changes will be notified by email or in the app.