Privacy Policy
Effective date: September 10, 2026
1. Introduction and Scope
This Privacy Policy explains how NOVA BITS STUDIOS LLC, a company incorporated under the laws of Uzbekistan ("Creostar", "we", "us", "our"), collects, uses, shares, and protects personal data in connection with the Creostar platform (the "Service") and our website at creostar.pro.
This Policy applies to three groups of people whose personal data we may process, and is written to be read together with our Terms of Service:
- Visitors of our website;
- Customers and their Authorized Users — the businesses that subscribe to the Service and the individuals who use it on their behalf; and
- Creators — the social media creators and influencers that our Customers discover, contact, and negotiate with using the Service. Creators are not our customers and typically do not have an account with us; Section 3.4 describe how we handle their data specifically.
2. Who We Are (Data Controller)
For personal data of website visitors, Customers, and Authorized Users, Creostar acts as the data controller. For personal data about Creators processed through the Service (Section 3.4), Creostar acts as a data processor on behalf of the Customer for the purpose of that Customer's own outreach and negotiation activity — the Customer determines who to search for and contact, and remains responsible, as between Creostar and the Customer, for having a lawful basis for its own outreach.
Contact details: NOVA BITS STUDIOS LLC, 1229-UY, Mustaqillik ko'chasi, Istiqlol MFY, Zafar. Privacy questions: support@creostar.pro.
3. Personal Data We Collect
3.1 Customer Accounts and Authorized Users. When a Customer registers for the Service, we collect the name, work email address, phone number (optional), job title, and company details of its Authorized Users, together with any information exchanged with our support team.
3.2 Data From Our Website. Like most websites, creostar.pro uses cookies and similar technologies to recognize visitors, remember preferences, and understand how the site is used, including for marketing purposes (for example, to measure the performance of a campaign that brought a visitor to our site). See Section 10 for more detail and how to control this.
3.3 Usage and Product Data. When Customers and Authorized Users use the Service, we collect data about that use, including search queries and filters, campaign configuration, in-product actions, log data, device and browser information, and IP address.
3.4 Data About Creators (Third-Party Data). This is the category of personal data most specific to how Creostar works, and we want to be transparent about it. The Service helps Customers find and contact social media creators. To do this, we process personal data about creators that we did not collect directly from them:
- Source: publicly available profile information and engagement data on TikTok (and, in the future, potentially other platforms), obtained through the relevant platform's public API or publicly viewable pages, plus any content of the outreach conversation once a Customer's campaign contacts a creator through the Service.
- Categories: public profile information (username, display name, bio, publicly listed contact details such as a business email), audience and engagement metrics (follower count, average views, engagement rate), publicly posted content used to evaluate fit for a campaign, and the content of messages and negotiated terms exchanged between a Customer and a creator through the Service.
- We do not purchase creator data from third-party data brokers, and we do not use creator data for any purpose other than providing the Service to the Customer that ran the relevant search or campaign, complying with law, and the limited internal purposes described in Section 4 (for example, aggregated, de-identified market benchmarking).
3.5 Payment Data. Subscription payments are handled by our payment processors. Creostar does not collect or store full payment card numbers; our payment processors provide us with limited billing information (for example, name, billing address, and the last four digits of a card) needed for invoicing and support.
4. How We Use Personal Data
4.1 Core Purposes. We use personal data described in Section 3 to: provide, operate, and maintain the Service; process payments and manage subscriptions; provide customer support; secure the Service and prevent fraud or abuse; communicate with Customers and Authorized Users about the Service, including service and billing notices; and comply with our legal obligations.
4.2 AI Features. The Service uses artificial intelligence to search for relevant creators and to generate and send outreach messages and negotiation offers, as described in our Terms of Service. To do this, the AI Features process Customer Content (for example, brand and campaign information a Customer provides) together with the creator data described in Section 3.4. We do not use Customer Content or creator personal data to train foundation models operated by third-party AI providers; where any model improvement uses this data, it is limited to Creostar's own models and is described in more detail on request.
4.3 Aggregated and De-Identified Data. We may create aggregated, de-identified statistics from Customer and creator data (for example, typical integration pricing by region and content category) to improve and market the Service. Once data is aggregated and de-identified in this way, it no longer identifies any individual Customer, Authorized User, or creator.
4.4 Marketing. We may use website visitor and Customer contact data to send product updates and marketing communications. Recipients can opt out at any time using the unsubscribe link in any marketing email or by contacting us at the address in Section 15.
5. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to create and administer Customer accounts, provide the Service, and process payments;
- Legitimate interests — to operate, secure, and improve the Service; to generate aggregated benchmarking data; and, for creator data described in Section 3.4, to enable business-to-business outreach for commercial collaboration opportunities, which we consider a legitimate interest of both Creostar and our Customers, balanced against the creator's interests;
- Consent — for non-essential cookies and, where required by law, for certain marketing communications; consent can be withdrawn at any time; and
- Legal obligation — where we must retain or disclose data to comply with applicable law, a court order, or a competent authority.
6. How We Share Personal Data
We do not sell personal data. We share it only as follows:
- Service providers (processors): cloud hosting and infrastructure, analytics, email delivery, customer support tooling, and our payment processors, each bound by contractual confidentiality and data-protection obligations.
- Third-Party Platforms: to deliver outreach messages and retrieve public profile/engagement data as described in Section 3.4, the Service interacts with TikTok (and, in the future, potentially other platforms) as necessary to provide the Service; those platforms process data under their own privacy policies.
- Professional advisers: lawyers, auditors, and accountants, where necessary and under confidentiality obligations.
- Legal and safety reasons: where required by law, regulation, legal process, or a competent authority, or to protect the rights, property, or safety of Creostar, our Customers, or others.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality safeguards.
7. International Data Transfers
Personal data may be transferred to, and processed in, countries outside of Uzbekistan or the European Economic Area (EEA) — for example, where a service provider's infrastructure is located outside the EEA. Where this happens, we use recognized safeguards, such as the European Commission's Standard Contractual Clauses, or rely on an adequacy decision, to ensure the data receives a comparable level of protection to that required under the GDPR.
8. Data Retention
- Customer account data: retained for as long as the Customer maintains an active subscription, and for 30 days afterward, after which it is deleted or anonymized, except where we must keep it longer to comply with law (for example, billing and tax records) or to resolve disputes.
- Creator data: retained only for as long as reasonably necessary to support the Customer campaign it relates to, and in any event no longer than 12 months after the last contact with the relevant creator, after which it is deleted or anonymized, unless a creator has an active, ongoing negotiation or collaboration with the Customer, or the data has been aggregated and de-identified as described in Section 4.3.
- Website and cookie data: retained according to the retention periods of the specific cookie or tool involved — see Section 10.
9. Your Rights
Subject to applicable law, Customers, Authorized Users, and website visitors have the right to:
- access the personal data we hold about them and receive a copy of it;
- correct inaccurate or incomplete personal data;
- request deletion of their personal data;
- restrict or object to certain processing, including processing based on legitimate interests or for direct marketing;
- receive certain personal data in a portable format; and
- withdraw consent at any time, where processing is based on consent, without affecting processing that already took place.
To exercise these rights, contact us at support@creostar.pro. We will respond within the time required by applicable law (generally one month under the GDPR).
10. Cookies and Similar Technologies
We use cookies and similar technologies on creostar.pro and within the Service for: essential functionality (for example, keeping you logged in); analytics (to understand how the site and Service are used); and, on the website, marketing and attribution (to understand which channels bring visitors to our site). Where required by law, we will ask for your consent to non-essential cookies through a cookie banner, and you can change your preferences at any time through that banner or your browser settings.
11. Children's Data
The Service is intended for business use by adults acting on behalf of a company or other organization, and is not directed at, or knowingly used to collect personal data directly from, individuals under 18 in connection with account registration.
12. Data Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit, access controls, and regular review of our security practices. No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting personal data, we will notify affected individuals and any relevant authority as required by applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice by email or through a notice within the Service before the changes take effect. The "Draft prepared" / effective date at the top of this Policy shows when it was last updated. The current version of this Policy is always available at creostar.pro/privacy.
14. Contact Us
Questions about this Privacy Policy, or requests relating to your personal data, can be sent to support@creostar.pro.