Privacy policy

How information is handled when you manage business and client work in Creekwise.

Who this policy covers

This policy covers Creekwise websites, accounts, workspaces, client portals, subscriptions, support, and related services. The legal operator identified on this page controls account, billing, website, and service-operation information. A customer organization controls the business, worker, client, and project information it places in its workspace; direct questions about that information to the workspace owner first.

Creekwise is a business service intended for adults. It is not directed to children under 18, and we do not knowingly collect their personal information through an account.

Information collected

  • Account and identity information, including name, email, authentication status, workspace membership, roles, and permissions.
  • Business content entered or uploaded by authorized users, including client contacts, projects, tasks, messages, contracts, invoices, time records, staffing details, credentials, approvals, and delivery files.
  • Subscription and transaction information, including plan, payment references, subscription status, invoice details, refund records, and tax-related information. Payment-card entry occurs through Stripe.
  • Device and service information, including browser and device category, approximate network information, session and security events, feature use, error categories, timestamps, and operational logs.
  • Information you send through support, surveys, invitations, optional integrations, or AI features.

How information is used

Information is used to authenticate users; enforce access permissions; provide, secure, maintain, and troubleshoot Creekwise; run requested workflows and integrations; store and share work with authorized participants; process subscriptions and refunds; deliver invitations and notifications; prevent misuse; comply with law; and improve service reliability and usability.

Creekwise does not sell personal information or use workspace content for targeted advertising. Workspace content is not used to train a general Creekwise AI model. When you request an AI feature, the relevant context is sent to the disclosed AI provider to generate that result.

Service providers and integrations

  • Supabase provides authentication, database, and file storage. The current application database is hosted in the United States.
  • Vercel hosts and runs the application and retains hosting, request, and operational logs under its configured services.
  • Stripe handles subscription checkout, payment details, billing management, and refunds. Creekwise receives payment references and account status rather than full card numbers.
  • Resend delivers application invitations and email notifications. Authentication email is delivered through the configured authentication email service.
  • When you use AI drafting or document parsing, relevant project context or extracted document text is sent to Anthropic to produce the requested result. Review results before relying on or sharing them.
  • When a workspace owner enables an integration, selected information is sent to and received from that connected service according to the requested action.

Providers receive only the information reasonably needed for their functions and process it under their own contracts and privacy terms. Information may also be disclosed when required by law, to protect the service or others, or as part of a merger, financing, reorganization, or sale subject to appropriate protections.

Cookies, browser storage, and measurement

Authentication cookies maintain your session. Browser storage holds interface preferences, recent items, checklist notes, and some unsaved workflow drafts. Use a trusted device and clear browser data when leaving a shared device.

Optional workspace experience measurement is off until enabled in Settings. It records limited workflow events, broad route and device categories, timing, and ratings. It can be disabled to stop future optional events.

A separate optional analytics choice can link a consenting browser session to a verified account and owned workspace. It measures broad referral categories and confirmed signup, workspace, completed-task, checkout, and payment milestones. It does not collect page content, contact details, full referral URLs, or search terms. This choice is off by default and can be revoked through the Analytics control. Linked visit records expire after 30 days; a revoked token hash remains only until expiry to prevent delayed requests from restoring the linkage.

Essential error monitoring uses fixed error categories, broad application areas, timestamps, and duplicate counts. The Creekwise error signal does not include form contents, messages, names, full page URLs, or stack traces. Hosting and security providers may separately retain request logs.

Security

Creekwise uses access controls, encryption provided by its hosting and storage services, secret-management practices, logging, and operational safeguards designed to protect information. No online service can guarantee absolute security. Customers are responsible for choosing appropriate roles, removing former users, protecting account access, and avoiding unnecessary sensitive information.

Do not enter payment-card numbers, account passwords, government identification numbers, health records, or unrelated confidential documents in ordinary project fields. Contact support promptly if you suspect unauthorized access.

Retention and deletion

Active workspace records remain while needed to provide the service and meet the customer’s instructions. Archiving a workspace or record does not itself erase it. After paid access ends, Creekwise ordinarily maintains a 30-day recovery period and may then schedule workspace data for deletion from active systems.

Some account, payment, consent, fraud-prevention, security, dispute, tax, and legal records may remain as reasonably required. Provider backups and logs follow separate retention schedules, so deletion may not be immediate in disaster-recovery copies. Data in backups is not restored for ordinary use after an approved deletion except as required for recovery, security, or law.

Your choices and requests

Workspace administrators control membership, permissions, optional integrations, and organization records. You may update certain account information, disable optional measurement, cancel subscriptions, and manage connected services through Creekwise.

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or information about processing. Creekwise will verify identity and authority before disclosing or changing records and may retain information where law permits or requires. If Creekwise processes information for a customer organization, the request may be referred to that organization.

For an account, privacy, export, or deletion request, use the privacy contact below. Include your account email and request type, but do not send passwords, card details, verification codes, or identity documents in the initial message.

Email communications

Transactional messages—such as verification, invitations, security, billing, and requested workflow notices—are part of providing the service. Marketing messages, if offered, will include an unsubscribe method. Unsubscribing from marketing does not stop essential account or service notices.

Privacy contact

The public privacy contact is awaiting confirmation. Existing invited users can contact their workspace owner. Visit support for access help.

Changes

Updates will appear on this page with a new effective date. Material changes affecting use of personal information will be communicated through the service or account contact details when reasonably practicable.