Cookie Policy

This policy explains what CreArt stores on your device and why. The first part covers the website at creartai.com; the last section covers the mobile app, which does not use cookies but does use device identifiers.

Cookies and similar technologies

Cookies are small text files a website stores on your device. Browsers offer other storage of the same kind — localStorage and IndexedDB — and this policy covers those too, because from your point of view there is no difference: it is data kept on your device between visits.

What the website stores

Strictly necessary

Required for the site to work; they cannot be switched off from within it.

Firebase Authentication keeps your sign-in session in your browser (IndexedDB, "firebaseLocalStorageDb") so you are not signed out between pages. It appears only once you sign in.

Google reCAPTCHA Enterprise sets its own cookies through Firebase App Check. It is what stops the generators being driven by scripts, and it runs on every page that can reach them. These cookies are set by Google and governed by Google's privacy policy.

If you are an operator of the site, signing in to the admin area sets "creart_admin_session": a signed, HTTP-only cookie that expires after 12 hours. Ordinary visitors never receive it.

"creart.fingerprint" (localStorage) holds a device identifier we calculate to apply the free daily allowance to people generating without an account. Without it, clearing site data would reset the allowance indefinitely and we could not offer free generations at all. It is deliberately designed to survive private browsing. We delete our copy after 7 days without activity; yours goes when you clear this site’s data. The Privacy Policy explains it in full.

Functional

These remember choices you make. The site works without them; it simply forgets your preferences.

"lang-pref" stores the language you chose, so the home page opens in it next time. "sidebar-expanded" remembers whether you collapsed the sidebar. "creart.topbar.*" keeps the last known state of the top bar — your initial, avatar and credit balance — so it does not flicker while the page loads. "creart:brand-kit" and "creart:brand-assets" keep the colours, fonts and logo you set for the ad tools. "creart:local-generations" keeps a local list of what you generated before signing in, so it is not lost. "creart.navlog" keeps the last few pages you visited, which we use to diagnose navigation problems. In sessionStorage, "creart.homeComposer.inputImage" holds the photo you attached on the home page so it survives moving to a tool, and it is cleared when you close the tab.

Analytics

We use Vercel Analytics and Vercel Speed Insights to count page views and measure loading performance. Neither sets cookies, and neither builds a profile of you or follows you across sites.

If you accept analytics in the banner, we also load PostHog (hosted in the European Union), which measures how the site is used and records browsing sessions — pages, clicks and interface behaviour. Text you type is masked and not recorded. It stores a "ph_*" cookie and matching localStorage entries to recognise the same session, and your answer to the banner is kept in "creart-analytics-consent" for 180 days. Nothing of PostHog is downloaded before you accept, a refusal is remembered and not asked again, and you can withdraw consent from the link in the footer.

The website runs no Google Analytics, no Google Tag Manager, and no advertising or cross-site tracking of any kind. Analytics never load until you agree to them.

Third parties your browser contacts

Fonts are served from our own domain, not from a third party. If you buy a subscription on the website, the payment is handled by Paddle under their own policies. Generated images are stored on Cloudflare R2 and delivered through links that expire.

The mobile app

The app does not use cookies, but it does use your device's advertising identifier — IDFA on iOS, Advertising ID on Android — for advertising and to measure which campaigns bring people to CreArt. This involves Google AdMob and Meta.

On iOS, personalised advertising requires your permission through Apple's App Tracking Transparency prompt, and you can change your answer under Settings › Privacy & Security › Tracking. On Android you can reset or delete your Advertising ID under Settings › Google › Ads. Buying a paid plan removes the ads.

The app also stores your sign-in session, your preferences, and a push notification token if you allow notifications.

Controlling what is stored

Every browser lets you view, block and delete cookies and site data, usually under privacy settings. Blocking the strictly necessary items above will sign you out and may stop the generators working; blocking the functional ones only means your preferences are forgotten.

Because the website sets no advertising or tracking cookies, the only choice to make here is the analytics one in the banner, which you can change at any time from the footer.

Changes to this policy

We update this page when what we store changes, rather than on a schedule.

Last updated: 11 August 2026.

Contact

Questions about anything on this page: yawaiapps@gmail.com.