Legal

Privacy & Cookie Policy

Last updated: 23 August 2026

1. Who we are and how to reach us

Crystal Heart Flow ("we", "us", "our") is an AI-powered content creation and publishing platform that turns one piece of source content into ready-to-publish posts for your social channels and blog.

For the purposes of the UK GDPR, Crystal Heart Flow is the data controller responsible for the personal data you provide when you use this platform.

If you have any questions about this policy or want to exercise any of your data rights, contact us through the Contact page on this site. We will respond without undue delay and in any case within one month.

2. What personal data we collect

We only collect the personal data we need to run the service for you:

  • Account & subscriber data — your name and email address when you register, the role assigned to your account, and your subscription plan and credit balance.
  • Brand Profile data — the brand name, description, website, tone of voice, default hashtags, logo and brand colours you enter to tailor generated content.
  • Source & generated content — the content you paste or write to be repurposed, and the AI-generated outputs (social posts and blog drafts) produced from it.
  • Social account connections — when you connect a social account (such as LinkedIn, Facebook Pages or Instagram Business), we store the connected account name and a platform identifier so the app can publish on your behalf. This is always under your control and can be disconnected at any time from the Connections page.
  • Payment & billing data — subscription and one-off credit top-ups are processed by our payment provider (Stripe). We store your plan, credit totals and Stripe customer/subscription identifiers; we never see or store your full card details.
  • Usage & analytics data — anonymised, aggregated information about how the platform is used (for example, which features are most popular), collected by Google Analytics only after you allow analytics cookies. We do not use this to identify you as an individual.
  • Technical & security data — basic device and access information needed to keep you logged in securely and to protect the service from abuse.

3. How we use your data

We use your personal data to:

  • Provide, maintain and improve the Crystal Heart Flow service, including generating and repurposing your content into platform-specific posts.
  • Manage your subscription, credit allowance, connected social accounts and publishing.
  • Process payments for subscriptions and credit top-ups through Stripe.
  • Understand platform usage in aggregate so we can improve features and performance.
  • Protect the security of the service and prevent abuse, fraud and unauthorised access.
  • Respond to your requests and provide account support when you contact us.

4. Legal basis for processing (UK GDPR)

We rely on the following lawful bases when we process your personal data:

  • Contract (UK GDPR Art. 6(1)(b)) — to provide the service you signed up for and to process subscription payments.
  • Consent (UK GDPR Art. 6(1)(a)) — for analytics cookies (given or refused via the cookie banner) and, where relevant, when you choose to connect a social account.
  • Legitimate interests (UK GDPR Art. 6(1)(f)) — for basic service security, fraud and abuse prevention, and platform improvement using aggregated data.
  • Legal obligation (UK GDPR Art. 6(1)(c)) — where we are required to retain limited records for tax, billing or legal compliance.

5. How we store your data

Your account, Brand Profiles, generated content and connected-account references are stored in a secure cloud database provided by our platform hosting provider (Base44). Data is encrypted in transit using HTTPS/TLS and at rest within the hosted environment.

Connected social account identifiers are stored so the app can publish on your behalf. We request the minimum access needed to post content; you can revoke access at any time from the Connections page or from the social platform's own settings, and we will remove the connection on request.

Payment data is handled entirely by Stripe, which is certified to PCI DSS standards. We never receive or store your full card number, expiry or CVV — only Stripe does. We retain enough billing identifiers to manage your subscription and fulfil your right to tax records.

Access to personal data is restricted to authorised personnel who need it to operate the service, and all access is logged.

6. Subscribers and billing

When you subscribe to a paid plan or buy credit top-ups, we record your plan, your monthly credit allowance and usage, and the Stripe customer and subscription identifiers linked to your account. This lets us show your plan and credits in the app, reset your monthly allowance, and manage renewals and cancellations.

If you cancel, your subscription ends at the end of the current billing period. You can continue to use any remaining credits, and your account reverts to the free tier.

We do not sell your personal data to third parties.

7. AI content generation

To generate and repurpose your content, the text you provide and the relevant Brand Profile settings are sent to our AI model provider. The provider processes this to return your generated outputs.

Generated content is stored against your account so you can edit, schedule, publish and revisit it. If you delete a content piece, we remove it from your account.

We do not knowingly use your personal data to train third-party AI models. Where our providers apply their own retention windows to API inputs, that is governed by the provider's terms and described in the sub-processors section below.

8. Cookies and analytics

We use two categories of cookies and similar storage:

  • Essential cookies — required for the app to function (keeping you logged in and remembering your consent choice). These cannot be switched off.
  • Analytics cookies — Google Analytics cookies that help us understand which features are used most and where we can improve. These are only set after you give consent via the cookie banner, in line with the UK's PECR rules.
  • You can review and change your consent choice at any time by clearing your browser storage for this site, which will show the consent banner again.

9. Third parties and sub-processors

We rely on trusted providers to operate the service. Each acts as either a processor on our instructions or, for services you connect yourself (such as a social platform), an independent controller of your data under that service's own terms:

  • Platform hosting & database — Base44, which hosts the app, database and backend functions.
  • Payments — Stripe, which processes subscriptions and credit top-ups and stores card data securely.
  • AI generation — third-party large language model providers used to generate and repurpose content.
  • Analytics — Google Analytics, which processes anonymised usage data only after you allow analytics cookies.
  • Social platforms — when you choose to connect and publish to LinkedIn, Facebook Page or Instagram Business, that platform processes your post and account data under its own privacy policy.

10. International data transfers

Some of our providers process data outside the UK. We only use providers that offer appropriate safeguards — for example Standard Contractual Clauses or equivalent protections — so your data remains protected to UK GDPR standards wherever it is processed.

Where you connect a social account, your published content is processed by that platform under its own terms and in the country where it operates.

11. How long we keep your data

We keep your personal data only for as long as we need it for the purposes set out in this policy:

  • Account, Brand Profile, content and connection data — kept while your account is active. When you delete your account, we remove this within a reasonable period.
  • Subscription & billing identifiers — retained for as long as needed to manage your subscription, and then for the period required for tax and accounting records.
  • Analytics data — kept in aggregated, anonymised form and not linked to your individual identity.
  • Where we are required to keep limited records for legal, billing or security reasons, we retain only what is necessary and then delete the rest.

12. Security

We take reasonable technical and organisational measures to protect your personal data, including encryption in transit, restricted and logged access, and regular review of our provider configurations.

No system can be guaranteed completely secure, but we act promptly to investigate and address any suspected breach affecting your personal data and will notify you where required by law.

13. Children

Crystal Heart Flow is not intended for children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will remove it.

14. Your rights under the UK GDPR

You have the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data (also called the 'right to be forgotten'), subject to legal retention duties.
  • Restriction — ask us to limit processing in certain circumstances.
  • Portability — receive your personal data in a structured, machine-readable format and reuse it elsewhere.
  • Object — object to processing based on legitimate interests or for direct purposes you disagree with.
  • Withdraw consent — withdraw consent for analytics cookies or a connected social account at any time, without affecting processing already carried out.
  • Complain — you can complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk if you are unhappy with how we handle your data.

15. Exercising your rights

To exercise any of these rights, contact us through the Contact page on this site. We aim to respond within one month; some requests may take longer where they are complex, and we will let you know if that is the case.

You can manage much of your data yourself: contact details in your Profile, brand details in Brand Profiles, and connected accounts in Connections. You can also request a full export or complete deletion of your account and data by contacting us.

For Meta-connected platforms, our public User Data Deletion page explains how to remove your account and data. You can view it here: crystalheartflow.com/DataDeletion.

16. Changes to this policy

We may update this policy from time to time to reflect changes in the service, the law, or how we work. We will update the 'Last updated' date above whenever we do. Significant changes will be highlighted on the platform or communicated to active subscribers.

© 2026 Crystal Heart Flow. Registered in England & Wales.

We value your privacy

We use essential cookies to make Crystal Heart Flow work. With your permission, we also use analytics cookies to understand how the app is used and improve it. You can change your choice at any time. See our privacy policy.