Skip to content
Omnicrea
Log in
Omnicrea

Privacy Policy

Last updated: 2026-06-27

Who we are

Omnicrea is a creator marketing platform headquartered in Beirut, Lebanon. We connect brands with niche creators across the MENA region. This policy explains what personal information we collect from brands and creators, how we use it, and the choices you have. For any privacy question, write to us at [email protected].

What we collect

Brands: We collect the company name, the primary contact's name and email, the country of operation, the website, and the content of any campaign briefs you submit. We may also collect billing details when an engagement begins.

Creators: We collect your name, email, social handles, declared audience demographics, payout method details, and any screenshots of your analytics that you upload to verify reach and engagement. We also store your declared red lines and content categories.

Both: We store authentication tokens issued by our login provider (NextAuth sessions) and basic technical data such as IP address and user agent. We use these to keep your account secure and to detect abuse.

How we use it

We use your information to run the matching engine that surfaces creators to brands and briefs to creators, to send transactional emails through our delivery provider (Resend), and to coordinate payments. Payout details (IBANs, account numbers and wallet addresses) are encrypted before they are written to our database. We do not use your data for advertising, and we do not run behavioral profiling.

Who we share it with

When a match progresses, the matched counterparty sees the data needed to evaluate the engagement: brands see the creator card you have built, and creators see the brief you have been matched to. We share operational data with our infrastructure providers strictly to deliver the service. Our processors are: Railway (application hosting and the primary database), Resend (transactional email), Cloudflare R2 (screenshot and image storage), PostHog (product analytics, EU-hosted), Sentry (crash and error reporting), and Expo (mobile app delivery and push notification relay). We never sell your data to third parties, and we do not share it with advertisers.

Your rights

You can download everything we hold about you at any time: sign in on omnicrea.app and open omnicrea.app/api/mobile/me/export, which returns a JSON file of your account, profile, deals, payments and notifications. You can also ask us to correct anything inaccurate, or delete your account, which you can do yourself in the app or at omnicrea.app/delete-account. If you would rather email a request, we will respond within thirty days. Some requests may take longer if we need to confirm your identity or untangle data that is shared with a counterparty in an active engagement.

Contact: [email protected]

Cookies and tracking

We use cookies that are strictly necessary to keep you signed in and to keep your session secure. These are always on. We also use PostHog for product analytics, hosted in the EU, and it is loaded ONLY after you accept the cookie banner. If you decline, it never starts, and we do not track you. Even once accepted, we do not autocapture your clicks or page views indiscriminately; we record a small set of named product events. We use Sentry to collect crash and error reports, which may include your IP address and browser details. We do not run advertising pixels or cross-site trackers of any kind, and we do not sell or share your data with advertisers.

Data retention

We keep your account data for as long as your account is active. When you delete your account we anonymise it straight away, unless you still have a deal in progress, in which case it is hidden from discovery immediately and fully anonymised once those deals close, or after ninety days at the latest. Your screenshots and profile photos are deleted from storage at the same time. Payment-related records are kept for seven years in line with typical regional finance and tax obligations, because we are required to keep them.

Cross-border data

Our application and primary database are hosted on Railway infrastructure in the European Union. If you access Omnicrea from outside the EU, your data is transferred to and processed in the EU. We work to honor the data-protection principles you would expect under GDPR-aligned frameworks, regardless of where you sign up from.

The mobile app

Our iOS and Android apps collect the same account information described above, and three things specific to a device. A push notification token, if you turn notifications on, so we can tell you about a brief or a payment; you can turn this off at any time in your device settings. Crash and error reports, which include the error, the screen you were on, and your app version, so we can fix what broke; these are always on, because an app that only hears about crashes from people who opted in hears about them last. And usage analytics, which record which setup screens you reach so we can see where people get stuck. Analytics are OFF until you agree, and you can change your mind at any time from your profile screen. Neither the analytics nor the crash reports go to a third-party tracker inside the app: the app sends them to our own servers, which forward them to PostHog and Sentry. The app contains no advertising identifiers and no cross-app tracking of any kind.

Changes to this policy

We may update this policy as the product evolves. If we make a material change, we will email registered users before the change takes effect and update the date at the top of this page.