This Privacy Policy describes how Subcreate Inc., a Delaware corporation (“subcreate,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information in connection with the platform at subcreate.co (the “Platform”). This Policy incorporates our Cookie Policy (Section 7). Capitalized terms not defined here have the meanings given in our Terms of Service.
Summary of key points (the full policy controls):
We collect account, payment-status, usage, and content data. Creators who host a Studio provide identity and tax information directly to our payment processor, Stripe, which shares verification results with us.
Payment card numbers go to Stripe; we never receive or store them.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
You can access, correct, delete, and port your data; Florida, California, and other state residents have specific legal rights described in Section 8.
Contact for all privacy matters: privacy@subcreate.co.
Section 1: Who We Are
The controller of personal information processed through the Platform is Subcreate Inc., 28 Geary Street, Suite 650 PMB 5008, San Francisco, CA 94108, United States. For users in the European Economic Area or the United Kingdom, we act as the data controller for the processing described in this Policy. Privacy contact: privacy@subcreate.co.
Section 2: Information We Collect, and Why
We collect the following categories of information. Each category is paired with its purposes; we do not use these categories for materially different purposes without updating this Policy under Section 14.
(a) Account and contact information. Email address, password (stored in encrypted, non-plaintext form), display name, username, profile picture, and any other profile details you choose to provide. If you register or sign in through Google or Apple, we receive the account identifier and basic profile information (such as name and email address) that the provider shares with us according to your settings with that provider. We do not collect your date of birth at registration. Purposes: creating and securing your account, communicating with you, providing the service.
(b) Payment information (Subscribers). When you subscribe, our payment processor, Stripe, collects your payment card or bank details directly on its own systems. We do not receive or store card numbers or other payment credentials. We receive from Stripe the subscription and payment status information needed to operate your subscription (for example, whether a payment succeeded, the plan and billing period, and renewal and cancellation dates), and Stripe may make available to us limited billing metadata such as card brand, last four digits, and billing country. Purposes: processing subscriptions, trials, and renewals; sending the billing notices described in the Terms of Service; fraud prevention; tax calculation.
(c) Identity and tax information (Creators hosting a Studio). To host a Studio, a Creator completes Stripe’s connected-account onboarding. Stripe, not the Company, collects the government-issued identification, payout account details, and tax information and certifications (IRS Form W-9 or W-8 series information, including Social Security numbers or Employer Identification Numbers) that Stripe requires, and Stripe holds those documents on its own systems under its own privacy policy. We receive from Stripe the verification results and account status (for example, whether the account is verified, whether payouts are enabled, and whether required tax information is complete), not the underlying identification documents or tax forms. Where we receive any tax identity number for our own reporting obligations, we treat it as sensitive information: access is restricted to personnel and processors with a need to know, and it is never used for marketing or advertising. Purposes: enabling Studio hosting and payouts through Stripe, tax information reporting required by law (including Forms 1099-K and 1099-NEC), fraud prevention, payment-processor compliance.
(d) Content and communications. Content you upload or post (including any AI-generation disclosures you make under the Terms of Service), messages you send through the Platform, and reports you submit about other users through the reporting mechanism described in the Terms of Service. Purposes: providing the service, content moderation and enforcement of our content standards, safety, legal compliance including DMCA processing.
(e) Transaction and subscription data. Subscription history (for both Platform Subscriptions and Studio Subscriptions, including trial, renewal, and cancellation records and the records of your consent to automatic-renewal terms), payment status history, and, for Creators, the Studio Subscription, payout, refund, and chargeback status information that Stripe makes available to us. Purposes: operating the marketplace, accounting, tax reporting, dispute resolution, demonstrating compliance with automatic-renewal laws.
(f) Usage and device data. IP address, browser type, device identifiers, operating system, pages viewed, referring URLs, and timestamps, collected automatically through logs and the technologies described in the Cookie Policy (Section 7). Purposes: security, fraud and abuse prevention, debugging, aggregate analytics to improve the Platform.
(g) Approximate location. We derive approximate (city-level) location from your IP address. Purposes: fraud prevention, tax and regulatory compliance, applying jurisdiction-specific requirements. We do not collect precise GPS location.
We do not knowingly collect health information, biometric identifiers, or precise geolocation. To the extent Stripe processes a facial image or identification document to perform identity verification during connected-account onboarding, that processing occurs on Stripe’s systems under Stripe’s disclosed process, and we do not receive the image or document.
Section 2A: Artificial Intelligence and Automated Processing
Because the Platform hosts creator content that may be made with the assistance of artificial intelligence tools, and because AI transparency is central to how the Platform operates, we state our own AI practices here rather than folding them into general language:
No AI-model training. We do not use your personal information or your Content to train generative artificial intelligence models, whether our own or a third party’s, and we do not permit our service providers to do so with data they process for us.
Automated tools in moderation. We may use automated tools to help detect content that violates our Terms of Service (including undisclosed AI-generated content, prohibited content, and copyright issues). Enforcement decisions that remove content or restrict an account are subject to human review through the appeal channel described in the Terms of Service (moderation@subcreate.co).
No solely automated legal-effect decisions. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
Creator AI disclosures. The AI-generation disclosures Creators make when posting Content are handled as Content and communications data under Section 2(d).
Section 3: Sources of Information
We collect information (a) directly from you; (b) automatically from your device as described in the Cookie Policy; (c) from the identity provider (Google or Apple) you use to sign in, if any; (d) from our payment processor, Stripe (verification results, account status, payment and subscription status, fraud signals); and (e) from other users (for example, reports submitted about content or conduct).
Section 4: How We Share Information
We share personal information only as follows:
(a) Service providers (processors). We share information with vendors that process it on our instructions under contractual confidentiality and security obligations, in these categories:
Payment processing (Stripe): processing of Platform Subscription and Studio Subscription billing, trials, renewals, payouts, and related fraud prevention and compliance.
Cloud hosting and infrastructure: providers of server infrastructure, database storage, and cloud computing resources that host the Platform.
Authentication and identity services: third-party identity providers (such as Google and Apple single sign-on) used to authenticate you and facilitate secure account creation and login.
Email and notifications: infrastructure providers that deliver automated system messages, transactional emails (including billing, renewal, and cancellation notices), and account status updates.
Analytics: the analytics tool named in the Cookie Policy (Section 7), used for aggregate understanding of Platform usage.
(b) Other users. Your display name, username, profile, and Content are visible to other users according to your settings and, for Creators, to your subscribers. Creators can see the usernames of their Studio subscribers through the Platform. Because Studio Subscription payments are charged directly to the Studio-owning Creator’s Stripe account, that Creator’s Stripe account receives the billing information Stripe provides to a merchant of record (which may include the name and email address associated with your payment, billing country, card brand, and last four digits), but never your full card number.
(c) Legal and safety disclosures. We disclose information where required by law, subpoena, or court order; to tax authorities as described in Section 2(c); to enforce our Terms; or where necessary to protect the rights, safety, or property of users, the public, or the Company. Where legally permitted, we will make reasonable efforts to notify you of legal demands for your information.
(d) Payment-processor compliance. We share information with Stripe as required for underwriting, fraud prevention, chargeback processing, and compliance with its restricted-business requirements.
(e) Business transfers. If the Company is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy. We will notify you of any transaction that results in your information becoming subject to a materially different privacy policy, before it takes effect.
We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising.
Section 5: Our Legal Bases (EEA and UK Users)
Where the GDPR or UK GDPR applies, we process personal information on these bases: contract performance (providing the Platform, processing payments and payouts); legal obligation (tax information reporting, responding to lawful demands, automatic-renewal notice and record-keeping obligations); legitimate interests, specifically: securing the Platform against fraud and abuse, enforcing our Terms and content standards, and performing aggregate service analytics, in each case balanced against your rights and subject to your right to object; and consent, for non-essential cookies (Section 7) and marketing communications, which you may withdraw at any time without affecting the service.
Section 6: Marketing and Advertising
We may send you marketing emails about the Platform with your consent or as otherwise permitted by law; every marketing email includes a functioning unsubscribe link, and we honor unsubscribe requests within ten (10) business days. Billing notices required by law or by our Terms of Service (such as subscription acknowledgments, renewal notices, annual reminders, price-change notices, and cancellation confirmations) are service messages, not marketing, and are sent for as long as you hold the relevant subscription. We do not engage in cross-context behavioral advertising and do not participate in interest-based advertising networks.
Section 7: Cookie Policy
This Section is our Cookie Policy and covers cookies and all similar technologies (pixels, tags, software development kits, local storage, and fingerprinting techniques, collectively “Tracking Technologies”).
(a) What we use.
(b) Your choices. Where consent is required (including for users in the EEA, UK, and other consent jurisdictions), non-essential Tracking Technologies are not set until you consent through the cookie banner, and you may withdraw consent as easily as you gave it through the persistent “Cookie Settings” link in the Platform footer. You may also control cookies through your browser settings; disabling strictly necessary cookies may break sign-in and payment functions.
(c) Global Privacy Control. We honor the Global Privacy Control (GPC) signal as a valid opt-out of sale or sharing where applicable law gives it that effect. Because we do not sell or share personal information for behavioral advertising, the practical effect of a GPC signal on the Platform is currently limited, but we recognize it as a legal opt-out signal.
(d) Do Not Track. Legacy browser “Do Not Track” signals lack a settled standard; we respond to GPC as described above rather than to DNT.
Section 8: Your Privacy Rights and How to Exercise Them
(a) Rights available to everyone. Regardless of where you live, you may access and update your account information in Account settings, request a copy of your personal information, request deletion of your account and associated personal information (subject to Section 11 retention requirements), and opt out of marketing email.
(b) How to submit a request (all rights). Submit requests by email to privacy@subcreate.co with the subject line “Privacy Rights Request.” We describe this workflow specifically so you know what to expect:
Acknowledgment. We acknowledge your request within ten (10) business days.
Identity verification. We verify your identity by confirming control of the email address associated with your account, and, where the request involves sensitive information or the requester is not the account holder, by requesting additional matching information. We do not require government identification except where reasonably necessary to prevent fraudulent requests, and any identification submitted for verification is deleted after verification completes.
Substantive response. We respond within forty-five (45) days of receipt. If we need additional time, we will notify you within the initial period and may extend once by up to forty-five (45) days, or by any shorter extension period applicable law allows (for Florida residents whose requests are governed by the Florida Digital Bill of Rights, a single extension of no more than fifteen (15) days), explaining the reason.
Confirmation of processing and access. Where you request it, our response will confirm whether we process personal information about you and will provide access to that information in a portable and, to the extent technically feasible, readily usable format.
Refusals and appeals. If we decline any part of your request, we will explain why. You may appeal by replying with “Appeal” in the subject line; a different reviewer will decide your appeal within sixty (60) days and will explain the outcome. If your appeal is denied and you are a Florida resident, we will provide a mechanism to submit a complaint to the Florida Attorney General; residents of other states will be directed to their state Attorney General or applicable regulator.
No discrimination. We will not deny services, charge different prices, or degrade service quality because you exercised any privacy right.
Authorized agents. Where applicable law permits, an authorized agent may submit a request on your behalf with proof of authorization; we may still verify your identity directly.
(c) Scope statement. The state-specific rights below apply to residents of the listed states and, in some cases, only where we meet that state’s applicability thresholds. Submitting a request under a law that does not apply to you is not necessary: the baseline rights in subsection (a) are available to all users through the same workflow.
(d) Florida residents (Florida Digital Bill of Rights, Fla. Stat. §§ 501.701 through 501.722). Florida residents may have the right to: confirm whether we process your personal data and access that data; correct inaccuracies; delete personal data provided by or obtained about you; obtain a copy of your data in a portable format; and opt out of the sale of personal data, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not sell personal data or engage in targeted advertising as defined by that law, and we do not conduct such profiling. Confirmation-of-processing and access requests follow the workflow in subsection (b), including the appeal mechanism.
(e) California residents (CCPA/CPRA). California residents have the right to know/access, correct, delete, and port personal information; the right to opt out of sale or sharing (we do not sell or share personal information); the right to limit use of sensitive personal information (we use sensitive personal information only for the purposes permitted by regulation, including providing the service and complying with law, and not for inferring characteristics); and the right to non-discrimination. Categories of personal information collected and purposes are described in Section 2; categories of recipients in Section 4. We honor GPC signals as a request to opt out of any sale or sharing.
(f) Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Indiana, Kentucky, Rhode Island, and other state privacy law residents. Where a state comprehensive privacy law applies to us and to you, you have the rights that law provides (typically access/confirmation, correction, deletion, portability, and opt-outs of sale, targeted advertising, and certain profiling), exercisable through the workflow in subsection (b), including appeal rights where the law provides them.
(g) EEA and UK users (GDPR / UK GDPR). You have the rights of access, rectification, erasure, restriction, portability, and objection (including to legitimate-interest processing), and the right to withdraw consent at any time. You may lodge a complaint with your local supervisory authority or, in the UK, the Information Commissioner’s Office. Requests follow the workflow in subsection (b), with responses within one month, extendable by two further months for complex requests with notice.
Section 9: Children and Minors
The Platform is restricted to users eighteen (18) years of age and older. We do not knowingly collect personal information from anyone under eighteen (18), and we do not direct any part of the Platform to children under thirteen (13). We do not collect a date of birth at registration; users represent that they are at least eighteen (18) by accepting the Terms of Service. If we learn that a person under eighteen (18) has created an account, we will terminate the account and delete the associated personal information, subject only to narrow legal retention obligations. Parents or guardians who believe a minor has used the Platform may contact us at privacy@subcreate.co.
Section 10: International Users and Data Transfers
We are based in the United States, and the Platform is operated from the United States. If you use the Platform from outside the United States, your personal information is transferred to and processed in the United States and in other countries where our service providers operate.
Where we transfer personal information from the EEA, the United Kingdom, or Switzerland to the United States or other countries not deemed adequate, we rely on the following specific mechanisms: the European Commission’s Standard Contractual Clauses with our service providers; the UK International Data Transfer Addendum to the SCCs for UK transfers; and, for any service provider certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions), that certification for the transfers it covers, for so long as the framework remains in effect. We assess our transfer stack for each material vendor rather than relying on a single blanket mechanism, and we do not represent that a transfer is “adequately safeguarded” beyond what the underlying mechanism actually covers.
Section 11: Data Retention
We retain personal information for as long as your account is active and thereafter only as needed for the purposes below:
Account and profile data: deleted or de-identified within thirty (30) days after verified account deletion, except as below.
Transaction, subscription, and tax records: retained for seven (7) years after the transaction or the tax year to which they relate, as required by tax and accounting law. Records of your consent to automatic-renewal terms are retained for at least three (3) years after the consent is given, as required by California law.
Creator verification status records: the verification results and account status we receive from Stripe are retained for the period required by applicable law and our payment processor’s requirements, then deleted. The underlying identification documents and tax forms are held by Stripe under Stripe’s own retention practices.
Content: deleted when you delete it or your account, except material preserved under a legal hold, material subject to an active DMCA or law-enforcement process, and backup copies purged on a rolling ninety (90) day cycle.
Security logs: retained for twelve (12) months.
Section 12: Security and Incident Response
We implement security measures matched to the nature of the data we handle, and we describe them here at the level of specificity we can stand behind:
Encryption in transit. All traffic between your device and the Platform’s infrastructure is encrypted using TLS.
Credential protection. Account passwords are stored in encrypted, non-plaintext form. If you sign in through Google or Apple, we do not receive or store a password for that provider.
Payment data isolation. Full payment card data is collected and processed by our PCI-DSS-compliant payment processor, Stripe, and never touches our servers; we hold only payment status information and the limited billing metadata described in Section 2(b).
Sensitive-data handling. Creator identification documents and tax forms are collected and held by Stripe on Stripe’s systems and are not stored on Company systems. Verification results and account status information received from Stripe are never exported to analytics or marketing systems.
Infrastructure providers. The Platform is hosted on third-party cloud infrastructure, and payments are processed by Stripe; each of those providers maintains its own security certifications and controls governing how and where it stores data.
Access controls. Access to personal information is limited to personnel and processors with a defined need for it.
Incident response. If we determine that a breach of security compromises personal information, we will: (a) investigate and contain the incident; (b) notify affected users without unreasonable delay, and in any event within the timelines required by applicable law, including notification within thirty (30) days as required by the Florida Information Protection Act, Fla. Stat. § 501.171, unless law enforcement requests delay; (c) notify regulators where required, including the Florida Department of Legal Affairs for breaches affecting five hundred (500) or more Florida residents, and applicable EU or UK authorities within seventy-two (72) hours where the GDPR or UK GDPR applies; and (d) describe in our notice what happened, what information was involved, and what steps we and you can take.
No absolute guarantee. No security program eliminates all risk, and we cannot guarantee absolute security; the commitments above describe our program, not a warranty against every attack.
Section 13: Your Choices Summary
You may: update account information in settings; delete your account in settings or by request; manage cookies through the Cookie Settings link and your browser; unsubscribe from marketing email via the link in any message; use the GPC signal (Section 7(c)); and exercise the rights in Section 8 through the described workflow.
Section 14: Changes to This Policy
We may update this Policy from time to time. For material changes (including any new category of data collected, any new sharing practice, or any change to the “we do not sell or share” statements), we will provide at least fifteen (15) days’ advance notice by email to registered users and by prominent notice on the Platform before the change takes effect, and, where required by law, we will obtain consent. We will not apply material changes retroactively to previously collected information without a lawful basis. Non-material changes will be reflected by an updated “Last Updated” date. This Section states our actual change-notification practice; we do not treat a silent date change as notice of a material change.
Section 15: Contact
Privacy questions and rights requests: privacy@subcreate.co
Mailing address: Subcreate Inc., 28 Geary Street, Suite 650 PMB 5008, San Francisco, CA 94108, USA
DMCA notices (copyright only): Copyright Agent, Subcreate Inc., at the address above or copyright@subcreate.co (U.S. Copyright Office designated agent registration number DMCA-1079781); see Terms of Service Section A-9 for notice requirements.