Kreasi LogoKreasi

Privacy Policy

Last updated: May 31, 2026

1. Introduction

Welcome to Kreasi. We value your privacy and are committed to protecting your personal data. This Privacy Policy describes how we collect, use, and process your information when you use our AI-powered photoshoot generation and editing application, specifically concerning our integration with Google Drive.

2. Information We Collect

When using Kreasi, you may choose to connect one or more Google Accounts to import reference images. In doing so, we collect and process the following information:

  • Google Profile Info: We retrieve your profile email, display name, and avatar picture to display connected account information on your settings panel.
  • Google Drive Metadata & Files: Through the `drive.readonly` scope, we retrieve the file names, folders, and image thumbnails to allow you to browse your Drive within our file explorer. When you select an image to import, we download the binary file content from Google Drive.
  • Authentication Credentials: We retrieve an OAuth refresh token from Google. This refresh token is immediately encrypted on our servers using industry-standard AES-256-GCM encryption before being saved in our secure database. We do not store plain-text credentials.

3. How We Use Your Information

We use the Google Drive access solely to:

  • Provide a user-friendly browser to select images from your Google Drive files.
  • Import selected images into your active Kreasi workspace as reference images for generating or editing photoshoots.

We **never** sell, rent, or share your Google Drive data or files with third parties. All processing is transient, and images are only saved to our secure Firebase Storage workspace when explicitly imported by you.

4. Data Storage and Security

We implement strict technical and organizational measures to secure your data:

  • All data transfers between Kreasi, your browser, Google API, and our database are encrypted using SSL/TLS protocols.
  • Google OAuth refresh tokens are encrypted at the database level and are never sent to the client browser. They are accessed only by our secure backend server to generate temporary access tokens when you browse your Drive.
  • Imported files are stored in your secure, private Firebase Storage bucket.

5. User Control & Access Revocation

You have full control over your Google Account connections:

  • You can disconnect any Google Drive account at any time directly through the "Google Drive Connections" panel in your Kreasi Account Settings. This will permanently delete the encrypted refresh token and all connected profile information from our database.
  • You can also revoke Kreasi's access directly from your Google Account security settings page at myaccount.google.com/permissions.

6. Changes to this Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last updated" date at the top of this page.

7. Contact Us

If you have any questions or concerns about this Privacy Policy or our Google Drive integration, please contact us at support@kreasitorium.com.