Agents: GET /api/v1 for the JSON index, or /llms.txt for the contract. The same eight searches are installable as an Agent Skill at /skill.md, the schema is at /openapi.json, and the MCP mount is at /api/v1/mcp — /agents.md carries the install artifact for every client. Reads and searches need no key.

CreateWith

Legal · privacy

Privacy policy

This policy covers two different groups of people, who deserve different answers. Section 2 is for anyone using CreateWith. Section 3 is for Twitch streamers we hold research on, who never signed up for anything — if you are a creator who found this page looking for yourself, start there.

In effect 2026-09-04 · questions to hello@createwith.dev

1. Who is responsible

CreateWith (createwith.dev) is a trading name of a sole trader based in the United Kingdom, and is the data controller for everything described here.

For any request under this policy — a copy of your data, a correction, a deletion, or an objection — email hello@createwith.dev. We answer within 30 days, and usually much sooner.

2. If you use CreateWith

What we hold about you, and why:

  • Your email address, because it is how an account is identified and how we can reach you about it. It is the only personal detail signing up requires. Lawful basis: performance of our contract with you.
  • Sign-in records — the magic-link authentication and the timestamps of when you signed in. Lawful basis: contract, and our legitimate interest in account security.
  • API key records — a key’s first few characters and a one-way hash. We never store a usable copy of your key, which is why a lost key cannot be recovered, only replaced.
  • Usage records — which endpoint was called, when, what class of call it was, what it cost, and whether it succeeded. Lawful basis: contract (we have to be able to bill correctly), and legitimate interest in preventing abuse.
  • Payment records — the Stripe customer and payment identifiers, the amount, the currency, and the credits issued. Lawful basis: contract, and a legal obligation to keep financial records. We never receive or store your card details; those go directly to Stripe.
  • A hashed IP address for keyless requests, so per-address daily caps can work without keeping a log of who read what. We store the hash, not the address. Lawful basis: legitimate interest in rate limiting.

We do not profile you, sell your details, share them for advertising, or use them to train models.

3. If you are a streamer we have researched

CreateWith exists to put creators in front of brands that might sponsor them. To do that we hold a record of channels, and for some of them a research summary. If you stream on Twitch, that may include you, and you did not ask for it. Here is exactly what that means.

From Twitch’s public API: your channel login and display name, your channel description, your broadcaster type, your language, and a history of your public streaming activity — what you streamed, when, the title, and how many people were watching at the moments we sampled.

From publicly accessible web pages, for a subset of channels, a research summary: a short description of what you do, an approximate location (usually country or city, only where you have said so publicly), your topics and interests, other public channels and social accounts you run, brand collaborations that have been publicly reported, a description of your audience, a confidence score, and a list of the sources we used.

Where it comes from. The Twitch public API, and pages anyone can open in a browser. We do not buy lists from data brokers, we do not access anything behind a login or a paywall, and we do not go looking for information about your health, beliefs, politics, sex life, or anything else the law treats as a special category.

Why we are allowed to. Our lawful basis is legitimate interests. The balance, stated plainly: the information is already public and is professional rather than private in nature; you are streaming commercially and, in most cases, actively looking for sponsorship; the audience for it is business users evaluating partnerships, not the general public; and we do not publish your dossier openly or use it to make an automated decision that has a legal effect on you. We think that is a fair trade. If you think it is not, section 4 is yours to use, and we would rather you used it than not.

4. Creators: how to see, correct or remove your record

Email hello@createwith.dev from an address we can tie to the channel, or message us from the channel itself, and tell us which one it is. You can ask us to:

  • Show you everything we hold on the channel, as a file.
  • Correct anything we got wrong. Research is compiled from public sources and public sources are sometimes wrong about people.
  • Delete the research summary we hold about you.
  • Object to the processing altogether, under Article 21. You do not have to give a reason, and we will stop unless we have a compelling basis not to — which, for a creator who has asked, we do not expect to have.

None of this costs anything and we will not ask you to justify it.

5. How long we keep things

  • Usage records: 24 months, then deleted.
  • Payment records: kept as long as UK tax and accounting law requires, currently six years. These are financial records, so they survive account deletion — but they are kept under an account identifier rather than your name or email.
  • Account details: until you close the account. On closure the email is replaced with a placeholder, the login is deleted, and the keys are revoked.
  • Channel and streaming data: for as long as the service runs, because the whole product is the history we collected. Research summaries are deleted on request.

6. Who else touches it

We keep this list short on purpose. Each of these is a processor acting on our instructions:

  • Supabase — the database and the login system. Hosted in the EU (Ireland).
  • Vercel — website and API hosting.
  • Stripe — payments. Stripe is the controller of your card data, under its own privacy policy.
  • Resend — sending the sign-in emails.
  • Anthropic and OpenRouter — the AI models that compile research summaries from public sources.

Some of these are based in the United States. Where data reaches them, the transfer relies on the UK International Data Transfer Addendum or the equivalent standard contractual clauses.

We have no advertising, no analytics product, and no third-party trackers on this site. There is nothing here selling your behaviour to anyone.

7. Cookies

Two, both strictly necessary, neither used for tracking:

  • A sign-in cookie set by Supabase when you log in, so the site knows it is still you.
  • createwith_ui, which records that a browser has access to the internal board. It lasts 30 days and cannot be read by JavaScript.

Because both are strictly necessary for a service you asked for, there is no consent banner. There is nothing to consent to.

8. Security

Access to the database is server-side only and row-level security is on with no public policies, so the anonymous and signed-in database roles can read nothing directly. API keys are stored as one-way hashes. Card data never reaches our servers.

No system is perfect. If you find a security problem, email hello@createwith.dev and we will take it seriously and credit you if you would like us to.

9. Complaints

Tell us first if you can — it is usually faster. If we do not resolve it, you can complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or to your local supervisory authority if you are in the EU.

10. Changes

When this policy changes, the date at the top changes with it. If a change materially affects how we handle your data, account holders get an email about it rather than a silently edited page. The terms of service cover the commercial side of the same relationship.

Terms of servicePrivacy policy