Global Compliance

How we adhere to GDPR, CCPA, and payment-partner security standards.

Last Updated: April 2026
v2.0 Neural Protocol

1. GDPR & EEA Rights

We aim to honor General Data Protection Regulation principles for applicable users. Citizens of the European Economic Area may request access, correction, portability, or deletion of personal data via privacy-ops@createme.pro. Infrastructure providers we use publish their own compliance attestations.

2. California Consumer Privacy

CreateMe AI does not 'sell' personal information. We honor CCPA-style requests for data disclosure and deletion. California residents can request a report of their collected metadata twice per 12-month period.

3. Content Safety Council

Beyond legal compliance, we implement automated content filters that prevent the generation of harmful or illegal imagery while supporting legitimate creative and business content production for adult professional users.

4. Payments & PCI via Partners

CreateMe is not itself a PCI-DSS Level 1 certified merchant processor. Card and wallet payments are handled by partners (such as Midtrans) that maintain PCI-DSS compliance. Full card data is not stored on CreateMe application servers. See the Security Center for checkout details and the Refund Protocol for refund eligibility.

Neural Ethics Framework Compliance

This documentation is part of the **CreateMe AI Transparency Node**. Our legal frameworks are dynamically linked to our operational ethics. In cases of discrepancy, the Master English Protocol remains the primary authority.