Privacy Policy
Last updated
Createrun Identity is the single sign-on layer that connects you to every Createrun product. We collect only the information needed to authenticate you and authorise your access — never for advertising, never to sell to third parties.
What we store
- Account profile — your email address, display name and the tenant (organisation) you belong to.
- Authentication metadata — password hashes (never the plaintext), MFA enrolment status, last sign-in timestamp and locale preferences.
- Audit trail — sign-ins, password resets, consent decisions and session revocations, kept for security forensics.
- Active sessions — the relying-party applications you are currently signed into so you can review and revoke them yourself.
What we do not store
- Browsing history inside the applications you sign into.
- Tracking pixels, advertising identifiers or analytics cookies tied to a third-party network.
- Plaintext passwords, security questions or biometric templates.
How long we keep your data
Profile and credential data lives until your tenant administrator deletes the account. Audit records are retained for 180 days by default; tenants on regulated plans can extend this window from the Admin UI.
Your rights
You can request a full export of your personal data, correction of any inaccurate field or deletion of your account from your tenant administrator. Deletion is irreversible and removes you from every relying party that trusts Createrun Identity.
Contact
Privacy questions go to privacy@createrun.com. We aim to respond within two business days.