CREATEMASCOT / LEGAL
Privacy Policy
What you share, why we need it, and the choices you have.
Last updated
Draft — contact email pending. support@createmascot.art is a placeholder and is not yet monitored. These pages need a working contact address before customer launch.
1. Who is responsible
Metin Ferati, based in Skopje, North Macedonia, operates CreateMascot at createmascot.art and is responsible for the personal information described here. Contact support@createmascot.art for privacy questions or requests.
2. Information we handle
- Account details: your name, email address, password hash, verification status and any profile details you choose to provide. If an external sign-in option is available and you use it, we receive the account details needed to sign you in.
- Creative work: uploaded references, prompts, mascot descriptions, style instructions, generated images, approvals and saved project history.
- Generation records: request settings, job status, errors, provider request identifiers, usage and credit deductions or restorations.
- Purchase records: payment and customer identifiers, purchased packs, amounts, currency, payment or refund status and your credit ledger. Polar handles payment-card details; CreateMascot does not receive your full card number.
- Technical and support information: session identifiers, IP address, browser information, request and security logs, and information you send when asking for help.
3. Why we use it
We use account and creative information to provide the service you request: sign you in, save your work, generate images, deliver downloads and maintain your credit balance. Where a legal basis is required, this processing is necessary to perform our agreement with you or take steps at your request before you buy.
We use relevant technical records to secure accounts, prevent fraud and misuse, investigate failures and answer support requests. Our legitimate interests are operating a reliable service and protecting customers, balanced against your privacy rights. We retain and disclose records where necessary to meet legal obligations, such as accounting requirements or lawful requests.
When an optional activity requires consent, we will ask separately and you may withdraw it. We do not sell personal information, run advertising trackers on the app, or use your private artwork in a public showcase without permission. Image generation is automated; we do not use it to make legal or similarly significant decisions about you.
4. Providers and sharing
We share the information needed for the feature you use with these providers. A disabled feature does not send a request to its provider.
- OpenAI: receives prompts and the reference images needed to generate or edit your illustration. Its API data controls describe provider retention, safety review and training defaults. API content is not used for training by default, but provider processing is not a promise of zero retention. CreateMascot does not run its own model training on your content.
- UploadThing: stores and delivers uploaded references and generated images when hosted image storage is enabled. The app uses private storage and authorized image access. Removing a reference from a draft or archiving a mascot does not itself delete every stored copy.
- Resend: processes recipients and message content for transactional email, such as verification and password resets. See its Privacy Policy.
- Polar: handles checkout as merchant of record, including payment, tax, fraud checks, receipts and refunds. We share the account and purchase information needed to connect your payment to your credits. Polar also handles information under its own Privacy Policy.
- Hosting infrastructure: the application server, database and background-job infrastructure process account, project and technical data to operate the service.
Authorized operators may access information to provide support, investigate misuse or maintain the service. We may disclose relevant information when legally required or necessary to protect legal rights. We do not make customer libraries publicly browsable.
6. Retention and deletion
Your account, saved projects, references and generated images remain stored so you can return to your library. There is currently no automatic deletion timer for saved projects. Archiving hides a mascot from your active library; it does not erase its data.
You can request account closure and deletion at support@createmascot.art. Deletion requests are handled manually after we verify ownership. We remove information that is no longer needed, subject to legal obligations and any unresolved transaction, fraud investigation or dispute. A deletion request does not automatically refund purchases.
Retention depends on the type of record: project data supports your saved library; payment and credit records support accounting, refunds and dispute resolution; security and support records are retained for investigating incidents and resolving requests. Any retained copies must be limited to those purposes. Providers may keep separate records under their own policies and legal obligations. Contact us for information about a particular record or request.
7. Security and international processing
We use HTTPS, authenticated access and account ownership checks to protect the service. Passwords are stored as hashes. No online service can guarantee absolute security. Keep your login private and avoid submitting sensitive personal information or content you do not have permission to share.
Our providers may process information outside North Macedonia or your country, including in the United States. Local protections may differ. International transfers must meet applicable data-protection requirements, including required contractual safeguards or other permitted transfer mechanisms. Contact us for details about the providers and safeguards relevant to your data.
8. Your choices and rights
Depending on the law that applies to you, you may request access, correction, deletion, restriction or a portable copy of your personal information, and object to processing based on legitimate interests. You may withdraw consent for an activity that relies on consent without affecting earlier lawful processing.
Email support@createmascot.art from your account address and describe your request. We may need to verify your identity and will respond within the applicable legal deadline. Some records may need to be retained; if an exception applies, we will explain it. You can also download generated images from your library.
You may complain to North Macedonia’s Agency for Personal Data Protection or another competent data-protection authority where you live. Contacting us first does not remove that right.
9. Children
CreateMascot is intended for adults aged 18 and over. We do not knowingly collect children’s information. If you believe a child has provided personal information, contact support@createmascot.art so we can investigate and remove it where appropriate.
10. Updates to this policy
We will update this page and its date when our practices change. We will provide additional notice or request consent where the law requires it. For questions about this policy, contact support@createmascot.art.