Privacy Policy

Creed is a service that helps people create and maintain a structured personal context file for use with connected AI agents. This notice explains what personal information Creed collects, how it is used, who it is shared with, and the choices you have under UK GDPR.

What this notice covers

Creed Open is self-hosted software. This notice describes the data the software can process and the limited data handled by the official Creed website.

Who controls your information

The person or organisation operating a Creed Open installation controls the information stored in that installation. They choose its Supabase project, hosting provider, environment, and optional integrations.

Questions about the official Creed website can be sent to . Questions about a particular installation should go to its operator.

What an installation stores

  1. Creed file contents and profile pictures
  2. onboarding answers
  3. proposal, revision, and activity history
  4. settings and connection metadata
  5. hashed and encrypted connection credentials

Creed Open has no public accounts, managed payments, advertising, or analytics cookies by default.

Services chosen by the operator

Creed Open requires Supabase and can be run locally or through a hosting provider such as Vercel. Optional OpenRouter and GitHub connections send only the information needed for the feature the owner chooses to use.

Those providers process information under their own terms and the operator's configuration.

Agent access

Connected agents can access only the Creed and permissions granted through OAuth or a scoped token.

  1. read access returns the authorised Creed payload
  2. proposal access can submit a suggested change
  3. direct-edit access can update content only where the owner allows it
  4. connection activity can be stored so the owner can review access

Security and owner responsibility

The owner is responsible for protecting installation secrets, keeping dependencies and migrations current, using HTTPS for public deployments, and controlling access to the connected Supabase project and hosting account.

Retention and deletion

Data remains in the operator's configured services until it is deleted through Creed or those services. Creed supports Markdown export, but complete backup and deletion depend on the operator's database and storage configuration.

Your rights

Privacy rights depend on the operator, location, and reason for processing. Requests about data in a self-hosted installation should be sent to its operator.

Official project contact

For questions about the official Creed website or this notice, contact .

For security reports, follow the private reporting instructions in the repository Security Policy.

Changes to this notice

This notice may be updated when Creed Open's default data flows or official website change.