How Creo handles and deletes data
Last updated: 2 September 2026
This page is the plain-language companion to our Privacy and Data Protection Policy. It lists every category of information Creo Access holds, why it is held, who processes it, how long it lasts, what starts deletion, and what you can delete yourself.
1. The retention table
Every category of information Creo Access holds is listed below, with why it exists, who processes it, how long it lasts, what triggers its removal, and whether you can remove it yourself. Where a period is set by an infrastructure provider rather than by us, the table says so instead of quoting a number we cannot stand behind.
| Category | Why it is held | Where or by whom it is processed | How long it is kept | What starts deletion | Can you delete it yourself? |
|---|---|---|---|---|---|
| Account and profile | To give you an account, identify you in the workspace and address you correctly. | Our database and authentication provider (Supabase), on cloud infrastructure. | For as long as the account exists. | Deleting the account, or the account-closure lifecycle below. | Yes, account deletion in Settings. |
| Authentication and security records | To sign you in, keep the session valid, and detect or investigate abuse of an account. | Our authentication provider (Supabase). Passwords are held by it as salted hashes; we never see them. | Session records last as long as the session. Limited security records are kept while they remain necessary for that purpose. | Session expiry or sign-out; security records when the purpose ends. | You can sign out and end a session. Security records are not user-deletable. |
| Subscription and transaction records | To take payment, apply your entitlement, and meet accounting and tax obligations. | Stripe processes the payment and holds the card details; we hold the subscription state and Stripe identifiers, not your card number. | Subscription state for as long as the account exists. Transaction records are kept for the period required by accounting and tax law, which is longer than the account. | Cancellation ends the subscription; the transaction record is retained for the statutory period. | No. These are records we are required to keep. |
| Roles and Role Memory | This is the working record of the assignment: it is the product. | Our database (Supabase), under per-account access rules enforced in the database. | For as long as the account exists, unless you delete the Role. | Deleting the Role, or deleting the account. | Yes. |
| Uploaded briefs and source documents | To ground the Role blueprint and keep every statement traceable to its source. | Private file storage scoped to your own account (Supabase Storage), reachable only through time-limited links. | For as long as the Role or case they belong to exists. | Deleting the document, the Role, or the account. | Yes. |
| Captures, recordings and transcripts | To turn a conversation into decisions, questions and proposed Role updates you can act on. | Audio is stored privately and scoped to your account; transcription is routed through our AI gateway (Lovable) to the model provider (currently OpenAI). | For as long as the Capture exists. Audio can be removed while keeping the transcript. | Deleting the audio, the Capture, or the account. | Yes. |
| Candidate evidence and submissions | To record which candidate claims are supported by which source, and to prepare a submission. | Our database and private file storage (Supabase). | For as long as the candidate case exists. | Deleting the case, or deleting the account. | Yes. |
| Prompt Generator content | To generate the working prompt you asked for, and to let you reuse it later. | Our database; generation is routed through our AI gateway (Lovable) to the model provider (currently OpenAI). | Saved prompts persist until you delete them. Unsaved input is not retained after the request. | Deleting the saved prompt, or deleting the account. | Yes. |
| Support requests and content suggestions | To answer you, and to fix what you told us was wrong. | Our database, and our operational email provider (Resend) for delivery. | While the request is open and for a reasonable period afterwards so we can follow up. | Closure of the request and the end of that period. | Contact us and we will remove it, unless it relates to a dispute. |
| Marketing consent and email preferences | To send optional product updates only where you asked for them, and to prove you asked. | Our email and subscriber platform (Kit). | Until you unsubscribe. A record that consent was given and withdrawn is kept so we can demonstrate compliance. | Unsubscribing, or asking us to erase the record. | Yes, unsubscribe in any marketing email. |
| Product analytics and error logs | To see which screens are confusing, and to diagnose failures. | Recorded internally as structured events; free text, names, transcripts and generated content are excluded structurally. No third-party analytics service is in use. | Operational logs are kept only as long as they are useful for diagnosis and are then discarded or overwritten by our hosting and database providers. | The rotation of those logs by the provider. | No, but they are designed not to contain your content in the first place. |
| Temporary Role Launch Packs | To let anyone try the tool without an account. | Our database, addressed by a random link token with no account, name or email attached. | Up to 7 days, then deleted. See the section below for exactly what is and is not stored. | The seven-day boundary, enforced by a database purge and also applied when a pack is next requested or a new one is built. | Send us the link and we will delete it sooner; packs are anonymous, so we cannot find yours without it. |
| Support correspondence | To answer a support request and to keep a record of what was asked and what we advised. | Our database, and Resend, which delivers the acknowledgement and reply email. | 24 months after a request is resolved, then deleted. An unresolved request is kept while it is open. | The 24-month boundary after resolution, enforced by a scheduled purge; or deleting your account, which removes your support requests with it. | Yes, deleting your account removes them, or ask us and we will delete a request sooner. |
| Backups | To recover the service after a failure or a mistake. | Our database and hosting providers, as part of their managed platform. | Backups are managed by those providers on their own schedule, which is not set by us. We do not claim a specific figure we cannot verify. | The provider's backup rotation. | No, a deletion you make is applied to the live service immediately, but a copy may persist in a backup until it rotates out. |
2. Deleting your account
You can delete your account yourself from Settings. Because it cannot be undone, the flow requires you to be signed in on a current session and to confirm deliberately by typing a confirmation, and it names exactly what will be removed before you can proceed.
Deleting the account cancels any active subscription, ends your sessions, and removes the user content in your workspace: Roles and Role history, Captures with their audio and transcripts, candidate cases, evidence documents and submissions, uploaded briefs and other source documents, generated and saved prompts, saved items, any Role share links, which are revoked at the same time, and your support correspondence with us.
Two things do not disappear at that moment. Transaction and accounting records are retained for the period required by law. And any backup copy taken before the deletion persists until it rotates out on our providers' schedule. We do not describe deletion as instant, because that would not be true of backups.
The deletion itself runs on our servers with privileged access that is never available to the browser, so it cannot be triggered by anyone other than the signed-in account holder.
3. If your access ends without deletion
If a subscription lapses rather than the account being deleted, the workspace follows a defined lifecycle: it stays available to you in read-only form for 30 days, is then retained but no longer accessible, and is deleted 90 days after access ended. Restoring access during the read-only period returns the workspace to normal use.
4. Temporary Role Launch Packs, precisely
The public Role Launch Pack tool is deliberately separate from any workspace. Because the distinction matters, here is exactly what happens to each part of it.
- The file you upload is never retained. Text is extracted once and the file is discarded.
- Contact details found in the brief, email addresses, telephone numbers, social profile links, are never stored. We pause and tell you before anything is processed, and you choose whether we remove them and continue.
- The redacted brief extracts, the quotes and the generated pack are stored against a random link token, with no account, name or email address attached, and are deleted after at most 7 days.
- The raw access token is what appears in your link. We store a hash of it, not the token itself, so possession of the link is the only way to reach a pack, and we cannot reconstruct a link from our records.
- Your network address is kept only as a one-way hash, with privacy-safe operational metadata such as timing, input size and outcome, for up to 30 days, to apply fair-use limits and prevent abuse. The address itself is not stored.
The seven-day boundary is enforced by the database rather than by a single scheduled job: expired packs are purged on a schedule, when a pack is next requested, and again whenever a new pack is built, so the boundary holds even if a scheduler fails.
5. Where processing happens
Our database, authentication, file storage, hosting, AI gateway, email and payment providers may process data in regions outside your own country, including outside the UK and European Economic Area. Where that happens we rely on the safeguards available under applicable data protection law and on those providers' own transfer arrangements. We do not claim that your data is stored in a specific country, because our providers' regional placement is not something we independently guarantee.
6. Asking us instead
If you would rather we handled a deletion, correction or export request for you, or you want something removed sooner than the table above allows, email support@creosystems.io. You can also raise it from the Support screen inside Creo Access, or on the public Support page if you cannot sign in. We respond within the period required by applicable law, one month under UK and EU GDPR.