Privacy Policy

Last updated: 9 October 2026

This policy explains what information CREATE FTW ("we", "us") collects when you visit createftw.com, use the SPEKTRA chat, submit a project enquiry, or sign in to a client project workspace at createftw.com/tracker; why we collect it; who processes it; how long we keep it; and how you can ask for a copy or deletion.

1. Information you give us directly

We only collect what you deliberately send us. There are four ways that happens.

  • Project enquiries and contact forms. When you use "Start a project" or a contact form, you type your name, email address and a description of what you need. That information is delivered to our team by email so we can reply. The email address you submit is also recorded in our own usage log (see section 4) so we can tell which enquiries turn into conversations.
  • Messages to SPEKTRA. What you type into the chat on our site is saved, together with the reply, so the conversation can continue and so we can see which questions people actually ask. Do not send us sensitive information such as payment card numbers, national identity numbers, or health data through the chat.
  • Sign-in details. If you sign in to a project workspace with Google, Google passes us your name, email address and, when you allow it, your profile photo and a language preference. If an administrator account signs in with email and password, we store your email address and a cryptographic hash of your password — never the password itself in readable form. Workspace access is granted only by an administrator; signing in never grants admin rights on its own.
  • Files you upload. Inside a project workspace you can attach files to comments, deliverables and reviews. We store the file, its name and its size. Attachments are held in private storage that only your workspace members and our team can open — they are not publicly listable or searchable.

2. Information we receive from other sources

When you sign in with Google, we receive the account details described above from Google under Google's own terms and privacy policy. We do not buy personal data from data brokers, and we receive no personal data from advertising networks.

3. What we do with your information

  • Reply to enquiries, proposals and messages you send us.
  • Run the client project workspace: show you only your own project's work, updates, resources and comments, and record who reviewed or approved a deliverable and when.
  • Keep chat history and enquiry records so nothing you send us gets lost between visits.
  • Understand which parts of the site are useful and which are ignored, so we can improve them.
  • Keep the service safe — for example detecting repeated failed sign-in attempts or misuse of upload and chat features.

We do not use your information for automated decisions that have legal or similarly significant effect on you, and we do not build advertising profiles about you.

4. Usage data we collect ourselves (first-party only)

We measure the site with our own system, stored in our own database. For each visit we may record:

  • The page you viewed and the page you came from.
  • Which buttons, links and capsules you clicked or hovered, and which chat suggestion you chose.
  • How far down a page you scrolled and how long you stayed without moving (a rough attention signal, not a surveillance tool).
  • The email address submitted through a form, and its source.

To connect events from one visit we save a randomly generated anonymous identifier in your browser's local storage under spektra_session_id (or create_ftw_session_id). It is not a cookie, it is not sent to third parties, and it carries no name or email by itself. Your chosen colour theme is also saved locally under spektra-theme.

We do not use third-party analytics or advertising trackers — no Google Analytics, no Meta (Facebook) pixel, no advertising cookies, and no cross-site or cross-app tracking. Nothing on this site responds to a "do not track" signal from an ad network because there is no ad network present; if you clear your browser storage, the anonymous visit identifier is deleted.

5. Who processes your information

Your information is processed by our team and by the following service providers, each of which handles only what it needs to do its job:

  • Supabase. Hosts our database, the sign-in system and private file storage. Files and records are not publicly listable; access is enforced by database-level rules, not only by the page you see.
  • Google (Workspace / OAuth). Confirms your identity when you choose "Continue with Google" and delivers our team email.
  • Resend. Delivers enquiry and notification emails to our team.

We never sell, rent or trade personal information. We may disclose it if we are legally required to, or to protect our rights, your safety or the safety of others. If we ever engaged a new processor for personal data, we would name it here.

6. Where your information is kept and how it is protected

  • Data is stored on Supabase infrastructure. Sign-in tokens and passwords are protected in transit by HTTPS and at rest by the database provider's controls.
  • Workspace files live in private storage buckets. A file can only be opened by someone the access rules recognise as a member of the workspace that owns it — links are time-limited rather than permanently public.
  • Permissions are checked in the database itself, so a workspace member cannot read another client's records by guessing a web address, and a visitor who is not approved sees no project data at all.
  • Admin and AI activity is logged so changes can be traced back to the person who made them.
  • No method of storage or transmission is perfectly secure. If a breach ever affected your personal data, we would tell you promptly and explain what happened and what we are doing.

7. How long we keep your information

  • Enquiries and chat messages: kept while we operate the business and for a short period afterwards, so we can pick up a conversation that pauses.
  • Project workspace records and files: kept while the client relationship lasts and afterwards for our own records; access is revoked the moment an administrator removes an approved email, and removal does not silently restore itself on a later sign-in.
  • Usage records: kept in aggregate form for as long as we need to compare the site over time.
  • Sign-in records for an account that never became active: removed when the corresponding approved contact is revoked.

If we must retain something for a legal or contractual obligation, we keep only that item and only for as long as that obligation lasts.

8. Your choices and rights

Wherever you live, you can write to fm@createftw.com and ask us to:

  • Tell you what personal information we hold about you and why.
  • Correct anything inaccurate.
  • Delete it — we will do so unless a specific legal or contractual reason requires us to keep it, in which case we will tell you what that reason is.
  • Stop recording your usage, or stop emailing you about a project you no longer want to hear from.
  • Give you a copy of your information in a portable format, or move it elsewhere.

We will respond within 30 days and we will not charge you for a reasonable request. To verify your identity we may ask you to write from the email address already on file. If you are in the EEA, UK or Switzerland you may also complain to your local data protection authority; if you are in California you have equivalent rights under the CCPA/CPRA, and we do not "sell" or "share" personal information as those terms are defined there.

9. Children

The site and the project workspace are business tools and are not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has sent us personal information, write to us and we will delete it.

10. Changes to this policy

If this policy changes, we will update the "Last updated" date above and, for material changes, note it on the site so people returning here can see it.

11. Contact us

Questions, requests or complaints about this policy: fm@createftw.com. Write "Privacy" in the subject line and we will route it to the person responsible.