Privacy Policy
Last updated: 31 August 2026
Creo Systems ("Creo", "we", "us", "our") operates Creo Access, a subscription workspace for recruitment professionals, accessible at access.creosystems.io. This policy explains what information we collect, how we use it, and the choices you have.
Creo Access is organised around the Role: the assignment you are working on. It helps you structure role information, work through recruiting conversations, organise candidate evidence, prepare candidate submissions and produce recruiter working material with AI assistance. It is not a candidate database, candidate marketplace or sourcing search tool, and it works only with information you choose to supply.
For information you enter about other people, such as candidates, clients and hiring managers, you decide what to collect and why. In data protection terms you are the controller of that information and we process it on your behalf to provide the service.
1. Information we collect
Account information. To create and manage your account, authenticate you and keep you signed in, we collect your name and email address, and, if you sign in with Google, the basic profile information Google shares with us. Authentication is handled by our authentication provider: passwords are stored by that provider as salted hashes, never in readable form, and we never see your password. This also covers invitations, password setup and password reset, and the session information needed to keep you signed in.
Payment information. If and when you subscribe, payment is processed by Stripe. We do not store your card details; Stripe handles them in line with its own security standards. We retain a record of your subscription status, billing history, and transaction dates.
Content you submit. Depending on how you use the service, this may include your recruiter and company information, client and hiring-manager information, Role briefs and job descriptions, requirements, outcomes and unresolved items, your own edits and Role history, recruiter notes, call and interview notes, transcripts and audio files, candidate names and details, CVs and other candidate materials, optional candidate context you type into the Prompt Generator, prompts you generate or refine and their versions, generated outputs and your edits to them, feedback submitted through a shared Role link, the actions you keep in Creo Actions together with any AI-drafted message saved against them, and support or feedback submissions. Not every user provides every category: what we hold is what you choose to enter or upload.
Recent and pinned work. To help you return to what you were doing, we store references to your own recent and pinned items, such as which Role, conversation or candidate case you last opened. This is a productivity feature visible only to you. It is not used for advertising or behavioural profiling.
Preferences. We store your appearance preference for the app (System, Light or Dark), your email preference, and onboarding or product-tour state such as which step you reached and whether you completed, skipped or reopened it. On our public website, a Light or Dark preference is stored in a cookie shared across our public Creo subdomains so the site looks consistent. These are functional preferences, not tracking.
Operational usage information. We record the usage needed to run the service and enforce your allowance: which feature ran, when, whether it succeeded, the AI generation activity counted against your allowance, transcription minutes used, your usage period, and your entitlement or subscription state. These records support fair use, reliability, troubleshooting and billing. We do not use them for advertising.
Saved prompts and version history. Prompts you generate are saved to your private prompt library. When you edit a prompt or refine it with AI, we keep every earlier version alongside the new one, together with the instruction you gave, so you can compare versions and restore an older one. Only you can see your saved prompts and their version history. Deleting a saved prompt deletes all of its versions permanently.
Technical information. Standard technical data such as IP address, browser type, and device information, collected automatically for security and to keep the service running properly.
Early-access requests. If you submit the early-access form, we collect your first name, email address, recruitment role or recruitment type, and, where you supply them, your company and the recruitment challenge you describe, together with any campaign or source information carried in the link you arrived through. We use this to assess and manage access requests and to contact you about access. Submitting the form does not create an account. The marketing checkbox is optional: we only send general product updates and launch news if you tick it, and you can unsubscribe at any time. You will still receive the confirmation and access-related messages needed to handle your request.
2. How AI features process your information
Several features are AI-assisted, and running them sends the relevant information you supplied to an AI service so it can generate the output you asked for. This happens when you use Creo Align, process a conversation in Capture, run audio transcription, generate or refresh an Evidence view, prepare a Candidate Submission, ask Creo a question, ask Creo to draft the message for an action in Creo Actions, or generate or refine a prompt.
Which service. AI requests are sent through the Lovable AI Gateway, the AI platform our application runs on, which routes them to the underlying model providers it uses, currently including OpenAI models for text generation and for audio transcription. Requests are made server-side and only include the information needed for the feature you ran, for example the Role context and the material you supplied.
What we do not claim. We do not control the logging or retention practices of the AI platform or its underlying providers, and we do not claim your content is anonymous to them, that it is never retained, or that it is never used to improve their services. Treat anything you enter as information sent to a third-party AI service, and supply only what is necessary for the assignment.
Automated decisions. These features organise, summarize and draft information. They do not make recruitment decisions, rank or score candidates, or decide suitability, and no decision about a candidate is made automatically by Creo Access. Output can be incomplete or wrong, and you remain responsible for reviewing it before relying on or sending it.
Not everything uses AI. Structural prompt checks, Role history, recent and pinned work, and your preferences are handled entirely within Creo Access and send no content to an AI service.
Everything you create is private to you. Your Roles, conversations, candidate cases, submissions, prompts and their versions are stored against your account only, and access is enforced in the database as well as in the interface. Other users cannot read, edit or delete your workspace.
3. Audio and transcription
If you create a conversation from audio, the file is uploaded to a private storage area only your account can reach, and it is sent for transcription through the AI platform described above so the conversation can be processed from the transcript.
By default the original recording is deleted as soon as transcription completes, and only the transcript and the working material produced from it are kept. If you choose to keep the recording, it stays in your private storage until you delete it, and you can delete a recording at any time from the conversation without losing the transcript or your edits. Once a recording is deleted it cannot be transcribed again. Transcription minutes are counted against your allowance.
4. CVs and Evidence materials
CVs and other candidate documents you upload are stored in a private storage area scoped to your account and are used to provide the Evidence and Candidate Submission functionality you have asked for: organising the supplied material against the Role, showing what it evidences and what it does not establish, citing its source, and helping you prepare a submission you own and edit. Their text is sent to the AI service when you run those features.
We do not add candidate documents to any shared, searchable or sourcing database, we do not make them available to other users, and we do not use them to build a candidate marketplace. Deleting a candidate case or your workspace removes the documents you uploaded to it.
6. How we use your information
We use your information to:
- Provide and maintain your account, workspace and subscription
- Generate the AI-assisted outputs you request
- Enforce fair-use allowances, entitlements and service reliability
- Process payments and send billing communications
- Improve Creo Access based on how it is actually used
- Respond to support requests and content suggestions
- Send service and account messages, and optional product updates where you have opted in
- Meet our legal and accounting obligations
We do not sell your personal information to third parties.
8. Where your data is stored
Your data is stored using our infrastructure providers (including Supabase and associated cloud hosting), which may process data in regions outside your own country. Where this involves transferring data outside the UK or European Economic Area, we take reasonable steps to ensure an adequate level of protection is in place, in line with applicable data protection law.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Request a copy of your data in a portable format
- Withdraw consent where processing is based on consent
- Complain to your local data protection authority
These rights are handled by contacting us at the email below; we do not currently provide a self-service account export tool, and the submission export in the product is a document feature rather than a complete export of your account data. We will respond within the timeframe required by applicable law (for example, one month under UK/EU GDPR).
If you are in the UK or EEA, we process your data on the basis of contract necessity (to provide the service you have signed up for), legitimate interests (to improve and secure the platform), and consent (for optional marketing communications). Where you enter information about candidates, clients or other people, you are the controller of that information and requests from those individuals should be directed to you; we will support you in responding to them.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.
10. Data retention, account closure and deletion
We keep your workspace for as long as your account is active. When access ends, your workspace follows a defined lifecycle: it stays available to you in read-only form for 30 days, is then retained but no longer accessible, and is deleted 90 days after access ended. Restoring access during the read-only period returns your workspace to normal use.
You can also delete your data yourself at any time from Settings. That removes the user content stored in your workspace, including Roles and Role history, conversations and their transcripts, candidate cases, uploaded CVs and other Evidence documents, any stored recordings, candidate submissions, prompts and their versions, saved items and share records, which are revoked at the same time.
Some records are kept beyond that point where we are required or permitted to keep them, for example basic account and billing records for accounting and tax purposes, and limited operational records needed for security, fraud prevention, usage accounting and handling disputes. These are kept only for as long as necessary for those purposes and then deleted or anonymised.
11. Security
We take reasonable technical and organisational measures appropriate to the sensitivity of what we hold. In practice that includes encrypted data transmission, per-account access rules enforced in the database rather than only in the interface, private file storage scoped to your own account with time-limited access links, and sensitive commercial operations handled server-side. We do not hold security certifications such as SOC 2 or ISO 27001, and we do not claim to. No system is completely secure and we cannot guarantee absolute security.
13. Support requests
When you contact support we collect what you choose to tell us, the category you pick, your subject, your message and the email address we reply to, together with the reference we generate and the times messages were sent. If you are signed in we record which account the request belongs to, so that you can see it again. We do not ask for, and ask you not to send, candidate CVs, passwords or payment-card details.
We use that information only to answer you and to keep a record of what was asked and what we advised. Support correspondence is readable only by you and by the Creo administrator answering it, enforced in the database and not only in the interface. Nothing from your Roles, Captures, candidate records or evidence appears in a support conversation.
Delivery of support email is handled by Resend, which processes the recipient address, subject and message body in order to deliver it. Support correspondence is kept for 24 months after a request is resolved and then deleted; an open request is kept while it remains open. Deleting your account deletes your support requests with it, except where a record must be kept for legal, billing, fraud-prevention or security reasons.
To ask for a correction to something in a support conversation, or for it to be deleted sooner, write to support@creosystems.io or open a request under “Privacy or data deletion”.
14. Children's privacy
Creo Access is a business tool intended for recruitment professionals and is not directed at children. We do not knowingly collect information from anyone under 16.
15. Role Launch Pack (public tool)
We offer a free public tool at access.creosystems.io/role-launch-pack that turns a job brief into a role launch pack. It works without an account, and it is deliberately separated from Creo Access workspaces: nothing you submit there is added to any workspace, and no workspace information is used to produce it.
It is for role briefs only. Please do not submit a CV, an application or any other document about a named candidate. Input that reads like a candidate document is declined before anything is stored or processed.
- What we process. The role brief text you paste, or the text extracted once from a PDF, Word or plain text file you choose. Uploaded files themselves are never retained.
- Contact details. If we find email addresses, telephone numbers or social profile links in the brief, we pause and tell you before anything is processed or stored. You choose whether we remove them and continue. If you would rather not, you can go back, edit the brief yourself and submit it again. Raw contact details are never stored.
- How it is stored. Once you have chosen to continue, the redacted brief extracts your pack quotes and the pack itself are stored against a random link token. There is no account, name or email address attached to it, and the link is the only way to reach it.
- How long. The redacted brief extracts and the pack are kept for up to 7 days and then deleted. Expired packs are also removed when they are next requested.
- Your network address. We keep only a one-way hash of it, together with privacy-safe operational metadata such as timing, input size and outcome, for up to 30 days, to prevent abuse, apply fair-use limits and control cost. We do not store the address itself.
- AI processing. We use your role brief only to create your temporary Role Launch Pack. Creo Access does not use it to train its own models. The brief is processed through our AI service provider as described in this Privacy Policy, and is subject to that provider's own terms.
Because packs are anonymous, we cannot identify who created one. If you want a pack removed sooner than the 7 days, send us its link and we will delete it.
16. Changes to this policy
We may update this policy as the platform evolves. If we make material changes, we will notify subscribers by email or via a notice on the platform. The "last updated" date at the top reflects the most recent revision.
17. Contact us
If you have questions about this policy or want to exercise your data rights, contact us at:
hello@creosystems.io
Creo Systems
creosystems.io