Privacy Policy

1. Introduction and Scope

This Privacy Policy explains how NOVA BITS STUDIOS LLC, a company incorporated under the laws of Uzbekistan ("Creostar", "we", "us", "our"), collects, uses, shares, and protects personal data in connection with the Creostar platform (the "Service") and our website at creostar.pro.

This Policy applies to three groups of people whose personal data we may process, and is written to be read together with our Terms of Service:

2. Who We Are (Data Controller)

For personal data of website visitors, Customers, and Authorized Users, Creostar acts as the data controller. For personal data about Creators processed through the Service (Section 3.4), Creostar acts as a data processor on behalf of the Customer for the purpose of that Customer's own outreach and negotiation activity — the Customer determines who to search for and contact, and remains responsible, as between Creostar and the Customer, for having a lawful basis for its own outreach.

Contact details: NOVA BITS STUDIOS LLC, 1229-UY, Mustaqillik ko'chasi, Istiqlol MFY, Zafar. Privacy questions: support@creostar.pro.

3. Personal Data We Collect

3.1 Customer Accounts and Authorized Users. When a Customer registers for the Service, we collect the name, work email address, phone number (optional), job title, and company details of its Authorized Users, together with any information exchanged with our support team.

3.2 Data From Our Website. Like most websites, creostar.pro uses cookies and similar technologies to recognize visitors, remember preferences, and understand how the site is used, including for marketing purposes (for example, to measure the performance of a campaign that brought a visitor to our site). See Section 10 for more detail and how to control this.

3.3 Usage and Product Data. When Customers and Authorized Users use the Service, we collect data about that use, including search queries and filters, campaign configuration, in-product actions, log data, device and browser information, and IP address.

3.4 Data About Creators (Third-Party Data). This is the category of personal data most specific to how Creostar works, and we want to be transparent about it. The Service helps Customers find and contact social media creators. To do this, we process personal data about creators that we did not collect directly from them:

3.5 Payment Data. Subscription payments are handled by our payment processors. Creostar does not collect or store full payment card numbers; our payment processors provide us with limited billing information (for example, name, billing address, and the last four digits of a card) needed for invoicing and support.

4. How We Use Personal Data

4.1 Core Purposes. We use personal data described in Section 3 to: provide, operate, and maintain the Service; process payments and manage subscriptions; provide customer support; secure the Service and prevent fraud or abuse; communicate with Customers and Authorized Users about the Service, including service and billing notices; and comply with our legal obligations.

4.2 AI Features. The Service uses artificial intelligence to search for relevant creators and to generate and send outreach messages and negotiation offers, as described in our Terms of Service. To do this, the AI Features process Customer Content (for example, brand and campaign information a Customer provides) together with the creator data described in Section 3.4. We do not use Customer Content or creator personal data to train foundation models operated by third-party AI providers; where any model improvement uses this data, it is limited to Creostar's own models and is described in more detail on request.

4.3 Aggregated and De-Identified Data. We may create aggregated, de-identified statistics from Customer and creator data (for example, typical integration pricing by region and content category) to improve and market the Service. Once data is aggregated and de-identified in this way, it no longer identifies any individual Customer, Authorized User, or creator.

4.4 Marketing. We may use website visitor and Customer contact data to send product updates and marketing communications. Recipients can opt out at any time using the unsubscribe link in any marketing email or by contacting us at the address in Section 15.

5. Legal Bases for Processing (GDPR)

Where the GDPR applies, we rely on the following legal bases:

6. How We Share Personal Data

We do not sell personal data. We share it only as follows:

7. International Data Transfers

Personal data may be transferred to, and processed in, countries outside of Uzbekistan or the European Economic Area (EEA) — for example, where a service provider's infrastructure is located outside the EEA. Where this happens, we use recognized safeguards, such as the European Commission's Standard Contractual Clauses, or rely on an adequacy decision, to ensure the data receives a comparable level of protection to that required under the GDPR.

8. Data Retention

9. Your Rights

Subject to applicable law, Customers, Authorized Users, and website visitors have the right to:

To exercise these rights, contact us at support@creostar.pro. We will respond within the time required by applicable law (generally one month under the GDPR).

10. Cookies and Similar Technologies

We use cookies and similar technologies on creostar.pro and within the Service for: essential functionality (for example, keeping you logged in); analytics (to understand how the site and Service are used); and, on the website, marketing and attribution (to understand which channels bring visitors to our site). Where required by law, we will ask for your consent to non-essential cookies through a cookie banner, and you can change your preferences at any time through that banner or your browser settings.

11. Children's Data

The Service is intended for business use by adults acting on behalf of a company or other organization, and is not directed at, or knowingly used to collect personal data directly from, individuals under 18 in connection with account registration.

12. Data Security

We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit, access controls, and regular review of our security practices. No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting personal data, we will notify affected individuals and any relevant authority as required by applicable law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice by email or through a notice within the Service before the changes take effect. The "Draft prepared" / effective date at the top of this Policy shows when it was last updated. The current version of this Policy is always available at creostar.pro/privacy.

14. Contact Us

Questions about this Privacy Policy, or requests relating to your personal data, can be sent to support@creostar.pro.