Certireel
Sign in

Privacy Policy

Last updated: August 20, 2026

1 · What we collect

Account data (your email, name, and sign-in identifiers), workspace data (products, photos, and videos you submit, and the videos and captions we generate), billing data (handled by Stripe — we never see or store card numbers), and operational logs kept free of personal information beyond what is needed to run and secure the service.

2 · How we use it

To generate and check your videos, deliver them to you, bill you correctly, prevent abuse, and provide support. Product photos are sent to the AI providers that paint and judge your videos solely to produce your output. We do not sell personal information, and we do not use your products or photos to advertise to anyone else.

3 · Where data lives

Data is stored on Cloudflare's global network, with media in object storage scoped to your workspace and served through time-limited signed URLs. Payment records live with Stripe. Email delivery providers process recipient addresses to send the messages you request.

4 · Cookies and sessions

We use one first-party session cookie to keep you signed in, and no third-party advertising cookies inside the app. Marketing pages may carry conversion measurement as disclosed on those pages.

5 · Retention and deletion

Workspace data is kept while your account is active. You can request deletion of a workspace at any time; this wipes its products, media, jobs, and receipts, keeping only the billing records the law requires us to retain. Magic sign-in links expire after 15 minutes and are stored only as hashes.

6 · Your rights

You may access, correct, export, or delete your personal information. We honour these rights under PIPEDA, GDPR, UK GDPR, and the Australian Privacy Act, whichever applies to you. Write to hello@certireel.com and we will respond within 30 days.

7 · Security

Sessions are signed and HTTP-only; secrets are stored in the platform's secret store; access to production data is limited and audited; sign-in tokens and invite tokens are single-use and hashed at rest. Report a vulnerability to hello@certireel.com and we will respond within 24 hours.

8 · Changes and contact

If this policy changes materially, we will email account holders before the change takes effect. Privacy questions: hello@certireel.com.