Legal

Privacy Policy

Effective date: 25 September 2026

What we collect, why, who processes it, and how to exercise your rights.

1. Who we are

Creobot (creobot.ai, with the application at app.creobot.ai) is operated by CREOGLYPH TECHNOLOGIES PRIVATE LIMITED (CIN U62099KA2023PTC180391), a company with its registered office in Koppal, Karnataka, India ("Creoglyph", "we", "us").

This Privacy Policy explains how we collect, use, share and protect personal data when you visit our website, create an account, use the Creobot application, or talk to a Creobot chat widget on a customer's website. For privacy questions or requests, email support@creobot.ai.

2. Our role: controller and processor

  • Customer account data. For information about our customers and their team members (account, billing and usage data), Creoglyph decides how and why the data is processed. We are the controller (a "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023).
  • Widget visitor data. When a visitor chats with a Creobot widget on a customer's website, the customer who installed the widget decides what is collected and why. The customer is the controller of that data, and Creobot processes it on the customer's behalf as a processor. If you are a visitor to one of our customers' websites, please read that website's privacy policy and send requests about your data to that business. If you contact us, we will pass your request to the customer where we can.

3. Data we collect

Account data. Your name, email address, login credentials (email and password, or your Google sign-in details), workspace and team information, two-factor authentication settings, and your communications with us.

Billing data. Paid subscriptions are billed through Stripe. Stripe collects and processes your payment card details; Creobot never receives or stores your full card number. We receive limited billing information from Stripe, such as your plan, billing contact, billing address, the card's brand and last four digits, and your payment history.

Customer content used for training. The website pages you ask us to crawl, the files you upload, and the instructions and settings you give your agent. This content may include personal data if your website or files contain it.

Widget visitor conversations and lead data. Messages visitors send through a widget, the agent's responses, and any lead-form details the customer chooses to collect, such as name, email address and other fields. We process this on behalf of our customers (see section 2).

Usage and analytics data. Information about how the website and application are used, such as pages viewed, features used, device and browser type, IP address, approximate location derived from IP, timestamps, and error reports. We use Google Analytics for analytics and Sentry for error monitoring.

Cookies and similar technologies. See section 11.

4. How we use data

  • To create and manage your account, authenticate you, and keep your account secure, including 2FA.
  • To provide the Service: crawl and index your content, create embeddings, generate AI responses, run the widget, and deliver conversations and leads to you and your connected integrations.
  • To process payments and manage subscriptions through Stripe.
  • To send transactional emails, such as sign-in, security, billing and service notices.
  • To provide support and respond to your requests.
  • To monitor, troubleshoot, secure and improve the Service, and to prevent fraud and abuse.
  • To comply with legal obligations and enforce our Terms of Service.

We do not sell personal data. We do not use widget visitor data or customer content for any purpose other than providing the Service to the customer it belongs to.

Where the EU or UK General Data Protection Regulation (GDPR) applies, we rely on these legal bases:

  • Contract: to provide the Service you signed up for and to bill you.
  • Legitimate interests: to secure, maintain and improve the Service, prevent abuse, and communicate with you about your account, where those interests are not overridden by your rights.
  • Consent: where required, for example for non-essential cookies and analytics. You can withdraw consent at any time.
  • Legal obligation: to keep records and respond to lawful requests.

Under India's DPDP Act 2023, we process personal data on the basis of your consent or for legitimate uses permitted by the Act, such as where you have voluntarily provided data for a specified purpose.

For widget visitor data, the customer (as controller) is responsible for having a legal basis and giving visitors any required notice.

6. Sub-processors

We use the following service providers to run Creobot. They process personal data on our instructions and only as needed to provide their services.

  • OpenAI: AI responses and embeddings
  • Cohere: search re-ranking
  • Qdrant Cloud: vector search
  • MongoDB Atlas: database
  • Amazon Web Services (S3): file storage
  • Upstash: Redis job queue
  • Render: API hosting
  • Vercel: application hosting
  • Cloudflare: DNS, email routing and marketing site hosting
  • Stripe: payments
  • Resend: transactional email
  • Sentry: error monitoring
  • Google: Google sign-in and Google Analytics

If you turn on an integration (such as Slack, Cal.com, Calendly, Webflow, Framer or WordPress), data is shared with that product as needed for the integration to work, under that provider's own terms and privacy policy.

We may also disclose personal data if required by law, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of assets, subject to appropriate confidentiality protections.

7. International transfers

Creoglyph is based in India, and several of our sub-processors operate infrastructure in other countries. Your data may therefore be processed outside India and outside your own country. Where GDPR applies, we rely on appropriate safeguards for such transfers, such as standard contractual clauses. Transfers from India are made in line with the DPDP Act 2023 and any restrictions notified under it.

8. Retention and deletion

  • Deleting an agent or workspace. When you delete an agent or a workspace, the content belonging to it, including its crawled pages, uploaded files, embeddings, conversations and lead data, is deleted.
  • Account data. We keep account data while your account is active. [TODO: retention period for account data after account closure]
  • Billing records. We keep billing records as long as required for tax and accounting law. [TODO: billing record retention period]
  • Logs, analytics and error reports. [TODO: retention periods for logs, analytics and error-monitoring data]
  • Backups. [TODO: backup retention and deletion timeline]

9. Security

We use technical and organisational measures designed to protect personal data, including encryption in transit, access controls and optional two-factor authentication for your account. Card details are handled by Stripe and never stored by Creobot. No system is completely secure; if we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as the law requires.

10. Your rights

Under India's Digital Personal Data Protection Act, 2023, you have the right to:

  • obtain a summary of the personal data we process about you and how we process it, and the identities of those we have shared it with;
  • have your personal data corrected, completed, updated or erased;
  • withdraw consent at any time, where processing is based on consent;
  • have grievances addressed by us, and, if not resolved, complain to the Data Protection Board of India;
  • nominate another person to exercise your rights in the event of your death or incapacity.

Where GDPR applies, you also have the right to access, rectify or erase your data, restrict or object to processing, receive your data in a portable format, withdraw consent, and lodge a complaint with your local data protection authority.

To exercise these rights, email support@creobot.ai. We may need to verify your identity before acting on a request. If your request relates to data collected through a customer's widget, we will refer it to that customer, who is the controller.

11. Cookies

We use cookies and similar technologies that are necessary to sign you in, keep your session secure and remember your preferences. We also use Google Analytics, which sets cookies to help us understand how our website and application are used. You can control or delete cookies through your browser settings; blocking necessary cookies may stop parts of the Service from working. Where the law requires consent for non-essential cookies, we ask for it.

12. Children

Creobot is a business service and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it. Customers must not use the widget to knowingly collect children's personal data without the consent the law requires.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will change the effective date at the top of this page, and if a change is material we will let you know in advance, for example by email or in the app.

14. Contact

For privacy questions, requests or complaints, email support@creobot.ai.

CREOGLYPH TECHNOLOGIES PRIVATE LIMITED
CIN U62099KA2023PTC180391
Registered office: Koppal, Karnataka, India