PRIVACY POLICY
Effective date: February 15, 2026
Last updated: February 15, 2026
Controller: Creomobile
Website: https://creomobile.com
Authentication Service: https://auth.creomobile.com
Contact: support@creomobile.com
1. Data Controller
Creomobile ("we", "us", "our") operates multiple mobile and web applications (the "Applications").
At the time of publication, the Applications are operated by an individual entrepreneur. If a legal entity is established in the future, it will become the Data Controller, and this Privacy Policy will be updated accordingly.
For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), Creomobile acts as the Data Controller.
Contact: support@creomobile.com
2. Categories of Personal Data
We collect only personal data that is necessary to provide authentication, security, and application functionality.
2.1 Data Received from Google Sign-In
When you authenticate using Google Sign-In, we receive limited information from your Google Account.
Data received:
- Email address (scope: email) – to create and identify your account
- Display name (scope: profile) – to personalize your experience
- Profile picture URL (scope: profile) – to display your avatar
- Google Account ID (scope: openid) – to uniquely identify you across sessions
OAuth scopes requested:
- openid
- profile
We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google services beyond authentication.
We do not read, modify, or access your Google data beyond the information listed above.
We do not store or retain Google OAuth access tokens or refresh tokens beyond the time necessary to complete the authentication process. OAuth tokens are discarded once authentication completes or when you log out.
We never transfer Google OAuth tokens to third parties.
Google API Services User Data Policy Compliance
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google Sign-In data exclusively for:
- User authentication and account creation
- Displaying your name and profile picture in the Applications
- Communication via your registered email address
We explicitly do not:
- Use Google data for serving advertisements
- Sell Google user data
- Use Google data for creditworthiness or lending purposes
We do not allow human access to Google user data except:
- As necessary for security purposes (e.g., investigating abuse or fraud)
- To comply with applicable law
- With your explicit consent
We do not transfer Google user data to third parties except:
- Infrastructure providers (Hetzner Online GmbH, Zitadel) acting as data processors under strict contractual obligations who process data solely on our behalf
- When required by law
For more information about Google's data practices, please see: https://policies.google.com/privacy
Legal basis: Art. 6(1)(b) GDPR – processing is necessary for the performance of a contract (providing user authentication).
2.2 Data Provided Directly by You
Depending on the specific Application you use, we may collect additional data strictly necessary to provide requested functionality.
Examples include:
- Date of birth (for age verification and content personalization)
- User preferences and settings
- Other data required for specific Application features
This data is collected only when necessary to provide the service you request.
Legal basis: Art. 6(1)(b) GDPR – performance of a contract.
2.3 Automatically Collected Data
For security and operational purposes, we may collect:
- IP address
- Browser type and user agent
- Time zone
- Language and locale preferences (e.g., preferred language, regional format settings)
- Basic technical device information (e.g., OS version, device type)
- Login timestamps
This data is used exclusively for:
- Security monitoring and incident response
- Fraud and abuse prevention
- DDoS protection
- System reliability and integrity
- Providing localized content and interface in your preferred language
- Displaying dates, times, numbers, and currency in your regional format
- Compliance with legal obligations
We do not use this data for behavioral profiling, targeted advertising, or cross-site tracking.
Legal basis: Art. 6(1)(f) GDPR – legitimate interest (security and service integrity).
2.4 Cookies and Local Storage
We use strictly necessary cookies and local storage mechanisms provided by our identity provider (Zitadel) solely for:
- Authentication
- Session management
- Security (e.g., CSRF protection and session validation)
These cookies are essential for the operation of the Applications and cannot be disabled without affecting core functionality.
We do not use cookies for analytics, advertising, profiling, or cross-site tracking.
3. Purpose of Processing
We process personal data solely to:
- Provide centralized authentication via auth.creomobile.com
- Maintain user accounts across our Applications
- Deliver specific functionality of the Applications
- Personalize user experience where applicable
- Ensure security and prevent abuse
- Comply with legal obligations
We do not:
- Sell personal data
- Use personal data for advertising or marketing
- Share personal data with third parties for their marketing purposes
- Build advertising profiles
4. Multi-Application Structure
Creomobile operates multiple Applications under a unified authentication system.
Authentication is centralized via auth.creomobile.com.
You may use the same account across multiple Creomobile Applications.
User data is logically separated per Application. Data collected for one Application is not automatically shared with other Applications. Access to your data by another Application requires explicit authorization where applicable. Strict access controls prevent unintended cross-application data mixing.
Your Google Sign-In account identifiers (email and Google Account ID) are used across Applications solely to enable unified authentication. Application-specific data (e.g., preferences, content you create) remains isolated per Application as described above.
5. Data Retention and Deletion
5.1 Data Retention
We retain personal data only as long as necessary to:
- Maintain your active account
- Provide the services you use
- Ensure security and prevent abuse
- Comply with legal obligations
Specific retention periods:
- Account data: retained while your account is active
- Security logs (including IP addresses): typically 30–90 days
5.2 Account Deletion (Right to Erasure)
You have the right to request deletion of your account and associated personal data at any time.
You may request deletion:
Option 1 – In-App: Use the "Delete Account" function (where available).
Option 2 – Email Request: Send a request to support@creomobile.com with the subject line: "Account Deletion Request"
We will process deletion requests without undue delay and within 30 days of receipt. You will receive confirmation once deletion is completed.
Certain data may be retained where legally required (e.g., accounting records or fraud prevention logs).
6. Third-Party Data Sharing and Infrastructure
6.1 Infrastructure Provider
Our infrastructure is hosted by Hetzner Online GmbH (Germany, EU). Hetzner acts as a data processor under GDPR and processes data solely on our behalf.
6.2 Service Providers (Processors)
We use the following service providers who act as data processors:
- Hosting infrastructure: Hetzner Online GmbH (Germany)
- Authentication infrastructure: Zitadel
These service providers:
- Process data only on our documented instructions
- Implement appropriate security measures
- Do not use data for their own purposes
- Comply with GDPR requirements
6.3 Legal Requirements
We may disclose personal data if required by law, court order, or regulatory authority.
6.4 International Transfers
Our primary infrastructure is located within the European Economic Area (EEA).
If personal data is transferred outside the EEA, we implement appropriate safeguards under GDPR Chapter V, such as:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Other legally recognized transfer mechanisms
7. Data Security
We implement appropriate technical and organizational measures, including:
- Encryption in transit (HTTPS/TLS)
- Secure authentication via OAuth 2.0 / OpenID Connect
- Role-based access control (least privilege principle)
- Logical separation of application data
- Restricted access to production systems
8. Data Subject Rights (GDPR)
Under GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
To exercise these rights, contact: support@creomobile.com
We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority in your country of residence.
9. Children's Data
The Applications are not directed to children under 13 years of age (or higher minimum age required by local law, such as 16 in the EU).
We do not knowingly collect personal data from children without appropriate parental consent.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or services.
The updated version will be published on this page with a revised Effective Date.
For material changes affecting your rights, we may notify you via email or in-app notification.
We encourage you to review this Privacy Policy periodically.
11. Contact Information
Creomobile
Email: support@creomobile.com
Website: https://creomobile.com
Authentication Service: https://auth.creomobile.com