Privacy policy
This policy explains how SafeCreators processes personal data when you visit the site, create an account, request a scan, claim an outreach report, purchase a plan, or ask us to support a removal request.
Effective 14 August 2026
1. Controller and contact
Smart Solutions Jacques, a French micro-entreprise, 340 rue de Nancy, 54690 Eulmont, France, is the data controller. SIREN/SIRET and VAT registration numbers are pending.
For privacy questions, access requests, objections or deletion requests, contact support@safecreators.io. You may also use the deletion request in your account.
2. Who this service is for
SafeCreators is strictly for adults aged 18 or older. Do not create an account, submit a profile, or upload verification material if you are under 18.
3. Data we process
- Account and contact data, including email address, authentication records and support communications.
- Creator profile data, handles, aliases, platform URLs, verification status and bio verification codes.
- Your consent choices, plan, subscription status, invoices and limited payment metadata. Full card details are handled by Stripe and are not stored by us.
- Scan and evidence data: matched threads and posts, reactions, host references, URLs, timestamps, counts, censored thumbnails, hashes, removal status and audit records.
- Outreach conversion events linked to a private report, such as link opened, claim page viewed, account or magic-link action, sign-in, verification, checkout and payment status. We do not store the magic-link token, an IP address or a browser fingerprint in this funnel.
- Technical and security data such as IP address, device/browser information, request logs and necessary browser storage.
- For Growth Shield only, facial images and visual-match results used for open-web facial-recognition search. This feature is activated only after explicit consent.
Evidence may concern adult content and may reveal sensitive information. We minimise access, show creators only censored evidence, and restrict exact source data to authorised removal work.
4. How and why we use data
- Contract: create and secure your account, run requested scans, provide reports, manage subscriptions, and prepare agreed removal work.
- Consent: scan closed communities, store censored evidence, act as a takedown agent, and perform Growth Shield facial-recognition searches. You can withdraw consent in your account; withdrawal does not affect earlier lawful processing.
- Legitimate interests: prevent fraud and abuse, protect the service, maintain audit trails, improve match quality, and establish or defend legal claims, balanced against individual rights.
- Legal obligations: accounting, tax, regulatory requests and responding to valid legal process.
We do not sell personal data. We do not use creator evidence for advertising or train general-purpose AI models on it.
5. Sources of data and outreach
We receive data from you, from the creator profile you identify, from the supported communities and file-hosting pages covered by a requested scan, and from service providers used to complete the service. An outreach recipient initially sees only a source-neutral summary. The private claim link provides first-party attribution so we can understand whether the report was opened and which onboarding stage was reached. The underlying report is linked to an account only after claim, profile verification and consent.
6. Service providers and transfers
Lovable and Supabase provide EU-hosted website, authentication, database and storage infrastructure. Stripe processes payments. Growth Shield may use PimEyes for facial-recognition-based open-web search. We may also disclose limited evidence to a forum, search engine, hosting provider or its takedown processor when you authorise removal work.
Some providers or recipients may process data outside the EEA. Where required, we rely on an adequacy decision, approved contractual safeguards, or another lawful transfer mechanism. Contact us for current transfer information.
7. Retention
- Account data: until account deletion, then normally removed within 30 days.
- Censored evidence: for the subscription period and up to 90 days afterwards, unless you request earlier deletion or preservation is legally required.
- Scan and takedown metadata: up to 24 months.
- Security and audit logs: up to 12 months.
- Unclaimed outreach data: 30 days; expired outreach-link records: up to 30 days after expiry.
- Outreach funnel timestamps: up to 12 months, or earlier when the related outreach and account data is deleted.
- Invoices and legally required accounting records: for the period required by French law.
Backups may persist for a limited recovery cycle before secure overwrite. We may retain narrowly necessary records longer for disputes, fraud prevention or legal obligations.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time and lodge a complaint with the CNIL or your local supervisory authority. In France, visit cnil.fr.
We may need to verify your identity before fulfilling a request. We normally respond within one month, subject to lawful extensions.
9. Security, automated matching and accuracy
We use access controls, private storage, signed short-lived links, censored previews and audit logging. No online service is risk-free. Scan and facial-match results are leads for human review, not definitive statements about identity or wrongdoing. Material decisions and removal requests remain subject to review.
10. Cookies and changes
See our Cookie policy for browser storage details and controls. We may update this policy when the service or law changes. Material changes will be highlighted in the service or sent by email where appropriate.