CreateDeck
Privacy Policy
Effective date: launch day.
CreateDeck is a creator productivity tool. We take privacy seriously and the product is designed around the principle that your raw ideas stay on your device.
This policy describes what information CreateDeck collects, how it's used, and your choices. By using CreateDeck you agree to this policy.
What we collect
On your device (never sent to us)
- Voice memos stored as audio files in
Documents/Audio/ on your device. Deleted when you delete the corresponding idea or wipe the app.
- Ideas, hooks, posts, beats, platform adaptations in the app's local SwiftData store.
- Voice samples, voice modes, templates, series + theme tags.
If a future update offers iCloud sync and you enable it, the above would be mirrored to your private iCloud container. Apple would store it; we don't. In the current version, this data stays on your device.
Sent to third-party services (only for processing, not retained)
- Voice memo transcription runs on-device with Apple's speech engine. Your raw audio is not uploaded to us or to any transcription service.
- Idea text goes to Anthropic Claude for hook generation, idea distillation, beat-structure generation, and platform-specific adaptations. Anthropic does not train on API data per their API terms.
Sent to our backend (when you sign in)
Building hooks, scripts, and platform versions runs through your private account, so the app asks you to sign in with Apple the first time you build hooks. Capture and on-device transcription work without signing in.
- Apple ID identity token is sent to our backend to verify your identity and issue a session token. We store: a hashed user ID, your name (if you choose to share it during Apple Sign In), and your email (if you choose to share it).
- Generation requests: when you build hooks, a script, or platform versions, the idea text is relayed through our backend to Anthropic and returned to your device. We keep a usage record (task type, model, token counts, cost) to run your monthly allowance. We do not store the text.
- Device attestation: an Apple App Attest key for your device, used to confirm generation requests come from a genuine copy of the app.
- Purchase verification: your App Store transaction is verified with Apple to unlock your plan; we store the transaction identifier, tier, and expiry.
- Studio review URLs: post body + timestamp stored so the recipient can view them. Deletable any time.
- Integration tokens (Notion, Slack): encrypted in our token vault. The iOS app never sees the raw tokens.
- Social auto-publishing (optional): if you connect social accounts and schedule an auto-publish, the finished video, caption, platform, and scheduled time are sent to our publishing pipeline. The video is staged in Cloudflare R2 and deleted after it posts. Your social logins live with the publishing provider (Upload-Post), never in the app or our database.
- Referral data: referral code + invitee's anonymized conversion status.
Not collected
- No IDFA or cross-app advertising identifiers.
- No third-party advertising or behavioral-profiling SDKs. Anonymous product analytics only (see below).
- No sale, rental, or sharing of your information with advertisers.
How we use the information
| Information | Purpose |
| Voice memos + transcripts | To generate hooks, distill ideas, build first cuts |
| Apple ID token | To verify identity once for Studio features |
| Studio review URL contents | To render the post for collaborators |
| Integration tokens | To send your posts to your chosen tools |
| Referral data | To credit you a free month when an invitee converts |
Third-party processors
- Apple Speech (on-device): transcription. Apple privacy.
- Anthropic Claude API: hook + adaptation generation. No training on API data.
- Apple Sign In: identity verification.
- Vercel (backend host): anonymized logs.
- Supabase (Postgres host): encrypted at rest.
- StoreKit (Apple): subscription state management.
- Upload-Post (optional social auto-publishing): holds the OAuth tokens for the social accounts you connect and posts on your behalf.
- Cloudflare R2 (optional, auto-publish only): temporary video staging, deleted after publish.
- Notion / Slack (optional integrations).
Your choices
- Delete any idea, post, or piece of content at any time from inside the app. Audio files are deleted along with the idea.
- Sign out in Settings clears your session token from the Keychain.
- Revoke Sign in with Apple from iPhone Settings → Apple ID → Password & Security → Apps Using Apple ID.
- Request export: email privacy@createdeck.app.
- Request deletion: email privacy@createdeck.app. Uninstalling the app deletes the on-device store automatically.
Anonymous product analytics
We record anonymous product events (for example, that an onboarding step was completed, a paywall was shown, or a reminder was accepted) so we can see where people get stuck. Events carry no name, email, transcript, hook, or script text, and no advertising identifier; they are keyed to a one-way hashed identifier and processed by TelemetryDeck. You can turn this off at any time in Personalize → Account → Data & Privacy.
Children
CreateDeck is not directed at children under 13. We do not knowingly collect information from anyone under 13.
International transfers
Our backend (Vercel + Supabase) is hosted in the United States. By using CreateDeck you consent to your information being processed in the United States.
Changes
We'll post any material change to this policy at this URL with the updated effective date. For significant changes affecting your privacy, we'll notify you in the app.
Contact
privacy@createdeck.app
CreateDeck, made by Perry.