Kreela

Privacy Policy

Last updated: 2026-09-04

Kreela is a service that helps small businesses prepare social media content. This document explains what data is collected when you use the service, where it is stored, and how to delete it.

Data we collect

Account details: your email address, your name (if provided) and a bcrypt hash of your password. We do not store your password in plain text and cannot read it.

Business details: business name, sector, city, country and Instagram handle.

Brand kit: your logo, colours, fonts, tone preferences, sample captions and words you don't want used.

Media you upload: photos and videos, together with their file names.

Content you create: caption text, drafts, scheduled publish times and publish results.

Instagram connection: the ID and username of the Instagram business account you connect, the ID and name of the linked Facebook Page, the profile picture URL, and the access token used to publish on your behalf.

How we protect access tokens

The access token we receive from Meta is written to the database encrypted with AES-256-GCM. The encryption key is held in a server environment variable, not in the database, so a database copy alone cannot decrypt the token.

The token is decrypted only to send a request to Meta on your instruction — when you publish an item or at a time you scheduled. It is never written to logs and never shown in the interface.

What we use your data for

To provide the service: generating, previewing and saving content, and publishing it to Instagram with your approval.

Caption text is generated by an AI provider; what is sent to it is listed below.

Nothing is published without your approval. Even with automatic mode enabled, everything generated arrives as a draft first; it only goes live when you schedule it.

We do not sell your data, do not share it with third parties for advertising, and do not use it to generate content for other customers.

Where your data is stored

Database: hosted on Neon (PostgreSQL).

Media files: hosted on Cloudinary, which generates public URLs for display.

Application server: runs on Vercel.

Meta Platforms: requests are sent only to publish to Instagram and to verify your connected account.

AI provider (Google Gemini): when a caption is generated, your business name, sector, tone preferences, product list and sample captions are included in the request. Your photos are never sent. We currently use the free tier, which means Google may use the submitted text to improve its products — so we advise against putting personal data or trade secrets in your brand kit.

These providers are required to operate the service; each is subject to its own privacy terms.

Retention and deletion

Your data is retained for as long as your account is open.

You can remove the Instagram connection at any time from the Connections page; the access token is deleted from the database immediately.

You can close your account from Settings → Delete account. This permanently deletes every record belonging to your business — users, brand kit, media records, content and social connections — and cannot be undone.

You can also submit a deletion request in writing; see the data deletion page for instructions.

Your rights

You have the right to access, correct, delete and object to the processing of your data. You can correct account and brand details directly in the application.

For requests and questions, you can write to us.

Changes

If we update this document the date on this page changes. For significant changes we notify the email address on your account.

Contact

Ilgaz&Smirnova DOO Beograd
Pena Studio
Deligradska 1b, Savski Venac, Beograd, Srbija
MB: 22082779 · PIB: 114869873
support@kreela.info