Privacy Policy
Last updated: 2026-09-04
Kreela is a service that helps small businesses prepare social media content. This document explains what data is collected when you use the service, where it is stored, and how to delete it.
Data we collect
Account details: your email address, your name (if provided) and a bcrypt hash of your password. We do not store your password in plain text and cannot read it.
Business details: business name, sector, city, country and Instagram handle.
Brand kit: your logo, colours, fonts, tone preferences, sample captions and words you don't want used.
Media you upload: photos and videos, together with their file names.
Content you create: caption text, drafts, scheduled publish times and publish results.
Instagram connection: the ID and username of the Instagram business account you connect, the ID and name of the linked Facebook Page, the profile picture URL, and the access token used to publish on your behalf.
How we protect access tokens
The access token we receive from Meta is written to the database encrypted with AES-256-GCM. The encryption key is held in a server environment variable, not in the database, so a database copy alone cannot decrypt the token.
The token is decrypted only to send a request to Meta on your instruction — when you publish an item or at a time you scheduled. It is never written to logs and never shown in the interface.
What we use your data for
To provide the service: generating, previewing and saving content, and publishing it to Instagram with your approval.
Caption text is generated by an AI provider; what is sent to it is listed below.
Nothing is published without your approval. Even with automatic mode enabled, everything generated arrives as a draft first; it only goes live when you schedule it.
We do not sell your data, do not share it with third parties for advertising, and do not use it to generate content for other customers.
Where your data is stored
Database: hosted on Neon (PostgreSQL).
Media files: hosted on Cloudinary, which generates public URLs for display.
Application server: runs on Vercel.
Meta Platforms: requests are sent only to publish to Instagram and to verify your connected account.
AI provider (Google Gemini): when a caption is generated, your business name, sector, tone preferences, product list and sample captions are included in the request. Your photos are never sent. We currently use the free tier, which means Google may use the submitted text to improve its products — so we advise against putting personal data or trade secrets in your brand kit.
These providers are required to operate the service; each is subject to its own privacy terms.
Retention and deletion
Your data is retained for as long as your account is open.
You can remove the Instagram connection at any time from the Connections page; the access token is deleted from the database immediately.
You can close your account from Settings → Delete account. This permanently deletes every record belonging to your business — users, brand kit, media records, content and social connections — and cannot be undone.
You can also submit a deletion request in writing; see the data deletion page for instructions.
Your rights
You have the right to access, correct, delete and object to the processing of your data. You can correct account and brand details directly in the application.
For requests and questions, you can write to us.
Changes
If we update this document the date on this page changes. For significant changes we notify the email address on your account.
Contact
Ilgaz&Smirnova DOO Beograd
Pena Studio
Deligradska 1b, Savski Venac, Beograd, Srbija
MB: 22082779 · PIB: 114869873
support@kreela.info