Die deutsche Fassung dieser Seite steht unter /datenschutz.
The short version: we store what you give us — your email for the waitlist, what you put in your account, the content you upload. We sell none of it, we set no advertising cookies and we pass nothing on to ad networks. This notice covers both the website and the app.
Who is responsible
Limitless Agency - F.Z.E, Office C1-1F-SF11789, Ajman Free Zone C1 Building, Ajman Free Zone, Ajman, UAE. Represented by Laura Butera. Questions to contact@creative-stocks.com.
Until 24 September 2026 the controller was BAYLUN - FZCO (Dubai). Since then Limitless Agency - F.Z.E operates Creative Stocks; customer data and running subscriptions have moved over for that purpose, and their purpose has not changed.
We are based outside the EU. For people in the EU we apply the GDPR regardless. As long as we address people in the EU we need a representative in the EU under Art. 27 GDPR. We will name them here with name and address as soon as one is appointed; until then you can reach us directly at contact@creative-stocks.com for anything about your data.
Waitlist
When you sign up on the start page we store your email address, your language, the time and where you came from (the src parameter or the referral code in the link). We send you a confirmation email; you are only on the list once you click the link in it (double opt-in). After that you hear from us about the launch — nothing else.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time: use the unsubscribe link in our emails or write to contact@creative-stocks.com. We then stop emailing you. Your address stays on a suppression list only so that a later import does not accidentally sign you up again — tell us if you do not want that either and we delete it entirely. If you sign up again yourself, that is fresh consent and you get another confirmation email.
If you never click the link, we delete your entry automatically 30 days after our last email. Someone who never confirmed never consented.
If you refer other people, we count how many signed up and confirmed through your code. We show you the number, not the addresses.
Creator applications
When you submit the application form: name, email address and — if you provide them — country, social profiles, portfolio link, the niches you picked, work samples and your message. Plus the time and where the link came from.
The legal basis is Art. 6(1)(b) GDPR (steps before a possible contract — you are applying to us). We keep the application until the founding creator programme is closed, at most twelve months. If you become a creator it stays attached to your account as a record of the basis on which we approved you.
Account and app
For an account we need your email address. Optionally: name, handle, profile picture, location, links to your profiles, the niches you chose. Using the app also creates: downloads, likes, comments, saved content, who you follow, credit movements and technical logs (time, app version, device type, error messages).
Legal basis: Art. 6(1)(b) GDPR (performing the contract you enter into by using the service). Error logs rest on Art. 6(1)(f) GDPR — we have a legitimate interest in the app actually working. We delete them after 90 days.
You can delete your account in the settings. We then delete your profile, your uploads and your activity. What we have to keep: billing records and payout documentation — for as long as tax and commercial law at the operator's seat requires us to.
What we measure about your usage
We look at how the app is used so we can make it better. We record: which screens you open and how long you stay, which videos you watch and how far, what you search for and how many results came back, which error messages you were shown, and whether you opened a notification. Plus device type, operating system and app version.
This runs on our own servers in Frankfurt. We send nothing to Google, to Facebook or to an analytics company, and we combine it with nothing from elsewhere. That is also why the app never asks for tracking permission: there is nothing we would need it for.
We only measure while you are signed in. Nothing extra is stored on or read from your device for this.
The legal basis is Art. 6(1)(f) GDPR. We have a legitimate interest in knowing what works and what does not. You can object at any time without writing to us: in the app under Settings, “Privacy & Safety”. Flip the switch and the measuring stops immediately.
Screen views are deleted after 30 days, everything else after 90 days. How often a video was watched we keep for 180 days. That is what we use to decide which content to show you. What creators earn depends on downloads alone, not on how long anyone watches.
Content you upload
If you upload videos or images as a creator, we store the file, a preview image, the details you enter and your confirmation that you hold the rights and that the people shown agreed. The file sits with our media provider (see below). Before it goes live, a person on our team looks at it.
Identity checks
Creators who want a verification mark upload images of an ID document and a selfie. These files sit in a separate, private store that only full administrators can reach; every access is logged. The basis is your explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR), which you give during the process. We delete rejected checks after 30 days and confirmed ones after 3 years. You can have them deleted earlier at any time: in the app under Settings → Account → “Delete ID data”. The images are gone right away and the verification mark goes with them — which means no publishing and no payouts until you do a new check.
Payments
Purchases in the app are handled by Apple (App Store) and Google (Google Play). Those companies are controllers in their own right; all we receive from them is the confirmation that a purchase happened, with a transaction number. We never see your payment details.
Purchases on the website run through Stripe Payments Europe, Ltd. We transmit the amount, the product and your email address; you enter card details directly with Stripe. Payouts to creators run through Stripe Connect or by bank transfer, for which we need name, address and bank details. Legal basis in each case: Art. 6(1)(b) GDPR.
Refund requests from Apple
When you request a refund in the App Store, Apple asks us whether we delivered and how much you have already used. We reply with: delivery status, the share of credits spent, the age of your account, how long you have used the app, account status (active or suspended), whether a free period ran, and the total of your past purchases and refunds.
Kept coarse, as Apple intends: time spans and amounts are sent as brackets (for example "account older than one year" rather than a date). We do not send content, search terms, individual downloads or uploads. The recipient is Apple Inc. in the USA; the transfer relies on your consent under Art. 49(1)(a) GDPR.
The legal basis is your consent (Art. 6(1)(a) GDPR), given when you buy credits; we store the time and the version of the terms as a record. Without consent we send nothing about your usage and Apple decides on its own. You can withdraw at any time at contact@creative-stocks.com, with effect for the future.
Notifications and email
We send push notifications through Firebase Cloud Messaging (Google) and Apple Push. For that we store a device token. You can turn push off at any time in your operating system or in the app settings. Emails are sent by Resend. We do not measure whether you opened an email.
Who else processes the data
- Supabase — database, sign-in, file storage. Data centre in Frankfurt am Main, Germany.
- Vercel Inc. (USA) — running the website.
- Cloudflare — delivering videos and images.
- Apple, Google, Stripe — payments and notifications (see above).
- Resend — sending our emails.
We have processor agreements under Art. 28 GDPR with all of them. For transfers to countries outside the EU — including the USA and the United Arab Emirates — the European Commission’s standard contractual clauses apply. There is no adequacy decision for the UAE; we base that transfer on Art. 46(2)(c) GDPR.
Cookies and measurement
We set no cookies, embed no third-party analytics and let no outside providers onto our pages. How we measure things ourselves is explained above under “What we measure about your usage”. Until September 2026 there was exactly one (cs_ref, for referral links) — the referral code now travels in the address instead of sitting on your device.
What you type into a form is remembered by your browser until you close the tab, so an accidental reload does not wipe your input — that never leaves your device. In the app we store your sign-in on the device so you do not have to log in every time.
Abuse protection
When you submit a form or sign in, we briefly process your IP address to slow down bulk submissions and automated access. It is not stored permanently and not linked to your entry. Legal basis: Art. 6(1)(f) GDPR.
Automated decisions
There are none. Applications, uploads and identity checks are decided by people.
Children
Creative Stocks is meant for adults. We do not create accounts for people under 18.
Your rights
Access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR), plus withdrawal of any consent with effect for the future. Write to contact@creative-stocks.com — we reply within a month. You can also complain to a data protection authority; in Germany, the authority of your federal state.
We are based in the United Arab Emirates. There, the UAE Data Office is the competent body for personal data protection. You may turn to the authority of your country of residence or to that one — both are open to you.
Changes
As the app grows, this notice grows with it. We announce material changes in the app or by email. Last updated: September 2026.
As of 22/09/2026