Privacy Policy
Last updated 29 September 2026
This policy covers Kreova, the hosted service at kreova.app that lets you build and run web apps by describing them to an AI agent. It explains what we hold, why we hold it, and who else sees it. It is written to be read, not to be survived.
Who we are
Kreova is a product of Weblogix Digital LLC, a limited liability company registered in Wyoming, United States, at 30 N Gould St, Ste R, Sheridan, WY 82801, United States. Weblogix Digital LLC is the data controller for the information described below.
For any question about this policy or about your data, contact support@kreova.app.
What we collect
Your account. Your name, email address, and a hash of your password. We never store your password itself. If you sign in with Google, we receive your name, email address, and Google account identifier instead of a password. If you belong to an organisation, we store your membership and role.
Payment information. Paid subscriptions are processed by Stripe, Inc. We never receive or store your full card number, expiry date, or security code. Those go directly to Stripe, which is PCI-DSS compliant and acts as our payment processor. What we store is what Stripe tells us: a customer reference, a subscription reference, which plan you are on, its status, and the current billing period. Stripe's own handling of your payment details is governed by Stripe's privacy policy.
What you tell the agent. Every message you send in the builder, including any images or documents you attach, and every reply the agent gives. These are stored so your project history survives you closing the tab.
What the agent builds. Your project files, kept in a version-controlled repository so every build is a checkpoint you can look back at. We keep the full history, not just the current state.
Your project's own data. Each project gets its own database and file storage. Whatever your app writes there - form submissions, uploads, records - is stored by us on your behalf. We do not inspect it, and it is isolated from every other project.
Your app's users. If your app has accounts, the people who sign up to your app have their email, name, and password hash stored inside your project's database. You are the controller of that data and are responsible for telling those people how you use it. We process it only to run your app.
Operational records. An audit log of significant actions - project created, share link rotated, run started - including the IP address the request came from. Token counts and timings for each agent run, so we can measure cost.
Cookies and analytics
We set a small number of cookies that the service cannot work without: a session cookie that keeps you signed in, and a security cookie used by the check that keeps bots off the sign-in and sign-up forms. These are strictly necessary and are not used to track you across other websites.
We do not run third-party advertising trackers, and we do not sell or share your browsing behaviour. If we add product analytics to measure how the service is used, this policy will be updated before it goes live, and anything non-essential will be behind a choice you make.
Separately, sites you build with Kreova may set their own cookies or include analytics you configure. Those are yours: telling your visitors about them is your responsibility, not ours.
Who else sees it
Our AI provider. This is the important one. To build anything, we send your instructions, your attached files, and the contents of the project files the agent needs to the third-party AI model provider that powers our build agent. If the agent searches the web, the search query goes to that provider's search infrastructure too. We do not send your project's database rows or your app users' details to the model unless you ask the agent to work with them. The provider processes this data under our commercial agreement with them and their own privacy commitments.
Stripe. For paid plans, to take payment and manage the subscription, as described above.
Our hosting provider. Kreova runs on servers rented from Leaseweb. They host the data but do not process it for their own purposes.
Our text-message provider. If you give us a mobile number for text messages, it and the messages we send to it pass through Telnyx LLC, which delivers them to your carrier. Telnyx processes them only to deliver our messages.
Services you connect. If you link an account such as Google Sheets, Google Drive, or GitHub, or configure your own mail server, we send only what is needed to perform the action you asked for, to that service.
We do not sell your data, we do not share it with advertisers, and we do not use your projects or prompts to train models.
Google Workspace data
If you connect Google Sheets, Google Drive or Google Calendar, we receive an access token for the permissions you granted and nothing wider. That token stays on our servers. We call Google's APIs ourselves and never hand it to another company.
When you ask the agent to work with a spreadsheet, a document or a calendar, what it reads is included in the request we send to our AI model provider, in the same way your own project files are. Under our agreement with that provider, your inputs and outputs are not used to train their models.
Limited Use. Kreova's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Raw or derived data from Google Workspace APIs is never used to develop, improve or train generalised or foundational artificial intelligence or machine learning models, by us or by anyone we send it to.
Notifications keep working after a build finishes: a new row in your app can be appended to a spreadsheet or turned into a calendar event. That path does not involve the AI provider at all. Our servers read the row and call Google directly.
Text messages (SMS)
If you choose to receive text messages from Kreova, we store your mobile number, the date and way you agreed, and a record of the messages we send and any replies (such as STOP). We use them only to send what you signed up for: sign-in and verification codes, and notices about your account and your projects.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, except the text-message provider named below that delivers the messages for us.
Reply STOP to any message to stop receiving them, or HELP for help. Message frequency varies. Message and data rates may apply.
Apps you build with Kreova may send texts of their own, from a text-message account you connect. Those messages, the numbers they go to and the consent behind them are yours: you are responsible for having each recipient's permission and for telling them how you use their number.
Where it is kept and for how long
Data is stored on servers located in Canada. If you are outside Canada, using Kreova means your data is transferred there.
We keep your account and projects for as long as your account is open. Deleting a project marks it deleted immediately and removes it from your dashboard; the underlying files and database are purged within 30 days. Deleting your account removes your projects and their data on the same schedule. Backups are kept for 14 days and are overwritten on rotation, so a deleted item can persist in a backup for up to that long.
Records we are required to keep for tax and accounting - invoices and payment references, not card details - are retained for 7 years as US law requires.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account and everything in it. Email support@kreova.app and we will respond within 30 days. We will not charge you for this, and we will not discriminate against you for asking.
Depending on where you live you may have additional rights. If you are in the European Economic Area or the United Kingdom, you have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to complain to your national data protection authority. If you are a California resident, you have the right to know what we collect, to delete it, and to opt out of its sale - we do not sell personal information. Exercise any of these by emailing the address above.
Security
Traffic is encrypted in transit. Passwords are hashed. Each project's database has its own credentials and cannot reach another project's data. Public share links use unguessable tokens that you can rotate or switch off at any time. Payment details never touch our servers.
Kreova is not currently certified for regulated workloads, so projects should not be used to store data subject to specific compliance regimes such as health records or full card numbers. Payment details are always processed by Stripe, never by Kreova.
Children
Kreova is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child has given us data, email us and we will delete it.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.
Contact
Weblogix Digital LLC
30 N Gould St, Ste R, Sheridan, WY 82801, United States
support@kreova.app
See also our Terms of Service and Refund & Cancellation Policy.