Privacy Policy
Last updated: August 10, 2026
1. Data controller
KARA, trading as Studio Creativariant, is the controller of your personal data under GDPR rules. Its registered office is Route de Palavas, Chemin Saint-Hubert, 34970 Lattes, France. To contact us, use the Contact page.
2. Data collected
| Data type | Examples |
|---|---|
| Account data | Email, password hash, language and service preferences |
| Project data | Source images, generated images and texts, product listings, metadata |
| Transaction data | Payments, invoices, credits, refunds and dates |
| Technical data | IP address, device information, sessions, security and audit logs |
| Contact requests | Email address, subject and message |
| Client review data | Client email and answers submitted through a shared preview |
3. Purposes and legal bases
- Contract performance: service delivery, listing generation, balance management.
- Pre-contractual steps: answering contact and service requests.
- Legal obligation: retaining accounting and tax records.
- Legitimate interest: securing the service, preventing abuse and producing anonymized statistics.
4. Data sharing
Your data may be shared with our technical processors only when needed to provide the service:
- Hostinger: application and API hosting.
- OVHcloud: object storage for source and generated files, exports and the separate legal archive.
- OpenAI: processing user-provided images and texts and generating content.
- Stripe: payment and billing processing.
- Brevo or the configured SMTP provider: transactional emails.
We never sell your data to third parties.
5. Data retention
| Data type | Retention |
|---|---|
| Account, projects and products | While the account or project is active; operational data is deleted when the verified deletion completes |
| Source and generated files | Unattached uploads: 30 days. Files attached to an active project: until the project or account is deleted |
| Client validation and shared preview data | While the related project is active, then deleted with the project or account |
| Contact messages | Not stored in the application database; sent to the email provider. The provider retention period remains to be verified and configured |
| Copies held by processors | Depends on the service, account configuration and current contract. By default, OpenAI API abuse-monitoring logs may contain customer content for up to 30 days; Stripe and email-provider periods still need confirmation in active contracts and settings |
| Export files | 7 days |
| Accounting records | Up to 10 years after the close of the fiscal year |
| Stripe webhook events stored by the application | The raw payload is scrubbed immediately after processing. An unprocessed event is retained for no more than 30 days. The complete record, its identifier and the technical tombstone are deleted no later than 30 days after the event is received |
| Authentication sessions | 1 day, or 30 days when “Keep me signed in” is selected; revoked or deleted sooner when required |
| AI detection cache (when enabled) | 30 days maximum and purged when the account is deleted |
| Security audit logs | 90 days |
| Billing dispute evidence | Up to 5 years when needed to establish, exercise or defend legal claims |
| Backups and pseudonymous deletion ledger | Deletion is blocked if the maximum backup retention is not configured. The deletion ledger is kept for that configured duration plus 30 days and replayed before a restore is reopened |
6. Your rights
Under GDPR, you have the following rights:
- Access: obtain a copy of your data.
- Correction: correct inaccurate data.
- Deletion: request deletion of your data.
- Portability: receive your data in a structured format.
- Objection: object to processing.
- Restriction: restrict the processing of your data.
You can exercise these rights from My account → Settings → Personal data or by contacting us through the Contact page.
7. Essential cookies and browser storage
The current website and application use only storage needed to provide and secure the service:
- NEXT_LOCALE: language preference cookie, kept for 1 year.
- refresh_token: HttpOnly authentication cookie, kept for 1 day or 30 days when “Keep me signed in” is selected.
- csrf_token: security cookie used to prevent forged requests, kept for 24 hours.
- cv_wizard_v1 and onboarding status: browser session or local storage used to resume the creation flow and avoid replaying onboarding.
No analytics or marketing tracker is currently installed. A consent banner is therefore not required for these essential uses.
8. International transfers
Some processors, including OpenAI and Stripe, may process data in the United States. The safeguard applicable to each provider and transfer depends on the current arrangement and must be documented in KARA’s processing register and current contracts. You can contact KARA for details.
9. Complaint
If you believe your rights are not respected, you can submit a complaint to the CNIL, the French data protection authority.
10. Contact
For any question about your personal data, contact us through the Contact page.