Cresvern Reach Privacy Policy
Cresvern Reach lets you write a post once and publish it to your connected social accounts. This policy explains what we collect, why, how long we keep it, and the rights you have over it — especially the credentials you connect so we can publish on your behalf.
Cresvern Reach, a product by Cresvern. Last updated: 6 September 2026.
This policy explains what Cresvern Reach collects, why, how long we keep it, and the rights you have over it — especially the credentials you connect so we can publish on your behalf. We aim to collect as little as possible and to keep your connected accounts secure.
1. Who we are
Cresvern Reach is operated by Cresvern, the data controller for the personal information described here. Contact: support@cresvern.com or via cresvern.com/contact.
2. What we collect
- Account details — your name and email. Your password is stored only as a secure one-way hash (bcrypt); we never store it in readable form.
- Email verification & transactional email — when you register we send a confirmation link to verify your email address, plus service emails such as password resets. We process your email address to send these; we do not use it for marketing without your consent.
- Social connections — when you connect LinkedIn, Facebook, Instagram, YouTube, TikTok, Threads or Pinterest, we store the access tokens those platforms give us. We never see or store your social-media passwords — sign-in happens on the platform's own site.
- Content you create — the posts you write and the images/videos you attach for publishing.
- Scheduled posts — if you schedule a post for a future time, the text and any attached image or video are held on our servers until that time, so we can publish for you even if your device is offline or switched off. The text is encrypted in our database. You can cancel a scheduled post at any time before it is sent.
- Camera and photos — if you use Create, the app accesses your camera or photo library only for the image you choose. Nothing is uploaded until you send it to a post.
- Usage and diagnostics — sign-in count, last sign-in, the number of AI generations used (to apply plan limits), and app events such as "post published" or "account connected". These are processed through Microsoft Azure Application Insights and are tied to an internal account identifier, not to your email or post content.
- Purchase records — confirmation from Google Play or the App Store that a subscription is valid. We never receive your card details.
- Consent record — the date and time you accepted this Privacy Policy.
- Advertising data (free plan only) — if you are on the free plan, Google AdMob processes your device advertising identifier and similar signals to select and measure ads. Pro accounts serve no ads and this never happens. See section 14.
3. Why we use it, and our legal basis
- To provide the service (publishing your posts, storing drafts, applying your plan) — performance of our contract with you.
- To keep the service secure and working (diagnostics, abuse prevention, enforcing plan limits) — our legitimate interests.
- To meet legal and tax obligations (purchase records) — legal obligation.
- Optional features you switch on, such as AI optimisation — your consent, which you can withdraw by not using the feature.
We do not sell your personal data, and we do not use your content to train AI models. Some US state privacy laws (such as California's CPRA) treat personalised advertising as “sharing”; you can opt out of it through the consent controls described in section 14, or by upgrading to Pro (which serves no ads).
4. How your credentials are protected
- Access tokens are encrypted at rest and are only ever used server-side to publish the posts you ask us to.
- Tokens are never sent to the app on your device and never shared with third parties. A compromised device cannot expose your posting credentials.
- You can disconnect any platform at any time in Accounts, which deletes its stored tokens.
5. Media handling
Images and videos you attach are uploaded to our server so the platforms can publish them. For platforms that fetch media by link (e.g. Instagram), the file is served from a signed link that expires — the address alone is not enough to open it, and the link issued for publishing is valid for about 30 minutes. Media is deleted from our servers once the post has been published. If you cancel a scheduled post its media is deleted immediately; if a post fails to publish, its media is deleted within 6 hours.
6. TikTok integration
When you connect TikTok, you authorise us through TikTok's own login and consent screen. We request
only the permissions the app uses: user.info.basic (to confirm the connected account) and
video.publish (to post the videos you choose to publish, via TikTok's Content Posting API).
We receive an access token, which is encrypted at rest and used only server-side to publish on your
instruction; we never receive your TikTok password. Your use of TikTok is also governed by
TikTok's own terms and privacy policy. You can disconnect TikTok at any time in Accounts, which
deletes its stored token.
7. AI features
When you switch on AI optimisation, the text you submit is sent to our AI providers (Google Gemini, Groq and/or OpenAI) to generate suggestions, and is subject to their policies. It is used only to return your result. To keep the service safe and within each platform's rules, that text is also passed through an automated content-moderation check (provided by OpenAI) that flags abusive or disallowed content; this is an automated screen with no human review of your content, and it is not used to make decisions producing legal or similarly significant effects about you. We record a count of AI generations to apply plan limits. AI output can be inaccurate — please review posts before publishing. Don't put sensitive personal data in content you send to the AI. You can turn AI off in Compose at any time.
8. Who we share with
- Social platforms you connect (LinkedIn, Meta/Facebook & Instagram, Google/YouTube, TikTok, Threads, Pinterest) — to publish your posts, on your instruction.
- AI providers (Google Gemini, Groq, OpenAI) — only content you submit for optimisation.
- Microsoft Azure — hosting, database and diagnostics.
- Email delivery — our email provider transmits verification and service emails.
- App stores (Google Play, Apple) — subscription verification.
- Google AdMob — advertising on the free plan only. See section 14.
9. International transfers
Our service is hosted in Australia, and some providers above process data in other countries including the United States and the EU. Where required, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. How long we keep it
- Account data — kept while your account is active. You can delete your account at any time, either in the app (Profile → Delete account) or from our public delete-account page without opening the app. Deletion is immediate and permanent: your profile, connected-account tokens, drafts held with us and scheduled posts are removed. If you subscribed through Google Play we also cancel the subscription so you are not billed again; Apple does not allow us to cancel for you, so App Store subscriptions must be cancelled by you in your Apple settings. Any residual copies are removed within 30 days.
- Access tokens — until you disconnect the platform or delete your account.
- Uploaded media — deleted immediately after the post is published.
- Scheduled posts — kept only until their scheduled time. Once published the post and any attached media are deleted immediately. If you cancel a scheduled post it is deleted straight away. If it fails to publish we keep it for 6 hours so you can see why, then delete it.
- Diagnostics/usage events — retained up to 90 days.
- Error reports — technical details of a failure (what went wrong, which screen, your account identifier) so we can fix it. Retained up to 90 days. These do not include the content of your posts.
- Purchase records — as long as tax and accounting law requires.
For full details on deleting your account and data — including how to request deletion if you no longer have the app — see our Data Deletion page.
11. Your rights
Depending on where you live (including under the GDPR, the UK GDPR, the Australian Privacy Act and the CCPA/CPRA), you may have the right to access, correct, delete, export or restrict your personal information, to object to processing, and to withdraw consent. You also have the right to complain to your local data protection authority. To exercise any of these, contact us at support@cresvern.com — we respond within 30 days. We do not discriminate against you for exercising these rights.
12. Children
Cresvern Reach is not directed at children. You must be at least 16 (or the minimum age of digital consent in your country) to create an account. If we learn we have collected data from a child below that age, we will delete it.
13. Security
We use encryption in transit (HTTPS), hashed passwords, and least-privilege access to production systems. Access tokens for your connected accounts and the text of any scheduled post are encrypted at rest, so they are not readable from the database alone. Media is served only through signed links that expire, and is never cached by intermediaries. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant regulator as required by law.
14. Advertising
The free plan shows advertising supplied by Google AdMob — a banner, and occasionally a full-screen ad shown at a natural break (such as moving to the preview of your post). Pro subscribers see no advertising at all — on a Pro account the advertising software is never started and no ad request is ever made from your device.
- What Google receives — to select and measure an ad, Google may process your device's advertising identifier, approximate location derived from IP address, device type and operating system, and interactions with the ad. This happens between your device and Google; the content of your posts is never involved.
- Your choice — where the law requires it (including the EU, UK and certain US states) we show Google's consent form before any ad loads, and you decide whether ads may be personalised. You can change this later; declining personalisation means you see non-personalised ads rather than none.
- Device-level controls — Android's Settings → Privacy → Ads lets you delete or opt out of your advertising ID entirely, which applies across every app on the device.
- The simplest opt-out — upgrading to Pro removes advertising completely.
- We do not share your account details, your posts, your media or your connected social accounts with any advertiser or advertising network.
Google acts as an independent controller for the advertising data it collects. Its handling is governed by Google's privacy terms.
15. Biometric unlock (optional)
Cresvern Reach offers an optional biometric lock (fingerprint or face) as an extra layer of security on your device. Your fingerprint or face data is handled entirely by your device's operating system (Apple Face ID / Touch ID, Android BiometricPrompt) — we never receive, see or store your biometric data; the OS only tells the app whether an unlock succeeded. Biometric unlock only controls access to the app on your device and sends nothing to us. You can turn it off at any time in Profile settings.
16. Changes to this policy
We may update this policy as the product evolves. The "Last updated" date above always reflects the current version, and we will notify you in-app of material changes before they take effect.
17. EU and UK representative
If you are in the European Economic Area (EEA) or the United Kingdom, you may contact our representative — appointed under Article 27 of the GDPR and the UK GDPR — about how we handle your personal data:
- EEA representative: Nikita, 3338, contact@cresvern.com
- UK representative: Nikita, 3338, contact@cresvern.com
Contacting the representative does not affect your right to reach us directly (see Contact below) or to complain to your local data protection authority (section 11).
18. Contact
Questions, data requests or complaints: support@cresvern.com or cresvern.com/contact. See also our Terms of Service and Data Deletion page.