Privacy Policy
- We collect what you give us to do the job: your account details, your business profile, and the media you upload.
- Your content is sent to AI providers to generate work for you. They do not train their models on it.
- We never sell your data, and we do not use it to train any model of our own.
- You can export or delete everything yourself at any time from Settings → Your data — the export is a single file and deletion is immediate and permanent. If you would rather we did it, email hello@cravim.ai.
This policy explains what Cravim does with your information. It describes the service as it actually works — the providers named below are the ones your data genuinely passes through, not a generic list.
Cravim is a product of C2Z LABS LLC. In this policy, "we" and "us" mean C2Z LABS LLC — the company you are dealing with and the data controller for the information described below. "Cravim" means the service itself. If you use Cravim, this policy applies to you.
1. What we collect
Account information
Your email address, your name, and a password — stored only as a bcrypt hash, so we cannot read it and neither could anyone who obtained our database. If you sign in with Google we store your Google account identifier and profile picture URL instead of a password, and we only ever request your name, email address and profile picture from Google.
Your business profile
During onboarding you tell us about your business: its name, category, website, location, what you sell, who your customers are, your brand voice, your brand colours, your logo, your goals, and your monthly ad budget. Everything Cravimcreates is built from this, which is why we ask for it.
Content you upload and content we generate
Images, video and audio you upload; the reference photos and character images you provide for films; and everything Cravim produces for you — captions, images, videos, plans and ads.
Connected accounts
If you connect Facebook, Instagram or Google Business, we store the access tokens needed to publish on your behalf. Those tokens are encrypted at rest. We only ever use them to do things you have explicitly approved — Cravim never publishes anything without your approval.
Usage and billing records
Which pages you visited, which models you used, what was generated, errors that occurred, and how many credits were spent. Payment card details are handled entirely by Stripe and never reach our servers — we store only a Stripe customer identifier.
2. Why we use it, and on what legal basis
| Purpose | Basis (UK/EU GDPR) |
|---|---|
| Running your account and generating your content | Performance of our contract with you |
| Publishing to accounts you connected | Performance of our contract, on your explicit instruction |
| Taking payment and preventing fraud | Performance of our contract; legal obligation |
| Keeping the service secure and diagnosing faults | Our legitimate interest in a working, secure product |
| Service emails — password resets, sign-in codes, payment failures | Performance of our contract |
We do not run behavioural advertising, we do not sell your information, and we do not use your content to train any Cravim model.
3. How your content reaches AI providers
Generating a video or an image means sending your prompt, your business profile and any reference images to a model provider. There is no way to do this without sharing that information — so here is exactly who receives what.
| Provider | What they receive | Where |
|---|---|---|
| Anthropic (Claude) | Prompts, your business profile, transcripts — for captions, plans and story planning | United States |
| fal.ai | Prompts and reference images — for image, video, speech and transcription models | United States |
| OpenAI | Text and image URLs — content-safety checks only | United States |
These providers do not train their models on your content. They process it to return a result and retain it only briefly for abuse monitoring, under their own API terms.
4. Everyone else we share data with
| Who | What for | What they get |
|---|---|---|
| Amazon Web Services | Hosting, database, media storage | Everything — this is where Cravim runs |
| Vercel | Hosting cravim.ai (this site) | Standard web request logs |
| Stripe | Payments and subscriptions | Your email, business name, and card details you give them directly |
| Resend | Service emails | Your email address and the message |
| Sign-in; Google Business posting if connected | Your identity; content you approve for publishing | |
| Meta | Facebook and Instagram publishing if connected | Content you approve for publishing |
We may also disclose information if the law requires it, or to protect our rights or someone's safety. If C2Z LABS LLC is ever sold or merged, your information may transfer with the business — we will tell you before that happens.
5. International transfers
Cravim runs in AWS's US East (N. Virginia) region and the providers above are largely US-based. If you are in the UK, EU or another region with transfer rules, your information will be processed in the United States. We rely on the Standard Contractual Clauses, or the providers' equivalent transfer mechanisms, to make those transfers lawful.
6. How long we keep things
- Account and business profile — while your account is open, then deleted within 30 days of closure.
- Generated and uploaded media — while your account is open. Deleted with your account.
- Sign-in codes and password-reset links — 10 and 60 minutes respectively; they are single-use, and only a hash is ever stored.
- Billing records — up to 7 years, because tax law requires it. This survives account deletion.
- Usage and error logs — up to 12 months.
7. Your rights
Depending on where you live, you can ask us to:
- Give you a copy of your information
- Correct anything that is wrong
- Delete your account and its content
- Restrict or object to how we use it
- Export it in a portable format
Email hello@cravim.ai and we will respond within 30 days. We will not charge you or make it difficult. If you are in the UK or EU and you are unhappy with our response, you may complain to your data protection authority.
California residents: under the CCPA as amended by the CPRA you have the rights to know, delete, correct, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by that law — including for cross-context behavioural advertising — and we have not done so in the preceding 12 months. We will never discriminate against you for exercising any of these rights. You may use an authorised agent, and we honour Global Privacy Control signals.
8. Security
- Passwords are stored as bcrypt hashes; we cannot read them.
- API keys and sign-in codes are stored as SHA-256 hashes, shown once and never recoverable — including by us.
- Social publishing tokens are encrypted at rest.
- Everything is served over HTTPS.
- Card details never touch our servers.
No system is perfectly secure, and we would rather say so than imply otherwise. If a breach affects you, we will tell you and the relevant regulator without undue delay.
9. Cookies
Cravim uses one cookie: cravim_session, which keeps you signed in. It is strictly necessary, HTTP-only, and expires after 30 days. We do not run advertising or third-party analytics cookies, which is why you are not being asked to dismiss a consent banner.
10. Children
Cravim is a business tool and is not for anyone under 16. We do not knowingly collect information from children. If you believe a child has given us information, email us and we will delete it.
11. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.
12. Contact
C2Z LABS LLC — the company behind Cravim
6701 Koll Center Parkway, Suite 250
Pleasanton, CA, 94566
United States
hello@cravim.ai
Questions about this page? Email hello@cravim.ai and a person will answer.
TermsPrivacyAcceptable useCookiesRefundsSecurityAboutContactHome