Legal

Privacy Policy

Last updated: June 24, 2026·Version 2.0·Terms of Service

Plain-language summary

We collect only what we need to run the Platform. We never sell your personal data. We use Supabase for auth and storage, Vercel for hosting, Stripe for payments, and Groq for AI processing. No online system is 100% secure — we take reasonable measures to protect your data but cannot guarantee absolute security. You can request access to, correction of, or deletion of your data at any time.

1. Introduction

MG Creative Labs (“we,” “us,” or “our”) operates the MG Creative Labs website and learning platform (the “Platform”). This Privacy Policy explains what personal information we collect, how we use and protect it, and the rights you have regarding your data.

By using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you have questions or concerns about how we handle your data, please contact us at mgcreativelabs@technologist.com before continuing to use the Platform.

2. Information We Collect

2.1 Account information

When you create an account, we collect your name, email address, and a hashed password. If you sign in via Google OAuth, we receive your name, email address, and profile picture URL from Google — we do not receive your Google password. Authentication and account data storage are handled by Supabase.

2.2 Content you provide

We store content you create or submit on the Platform, including:

  • Prompts you save to your personal library
  • Community posts, comments, and replies
  • Contact form messages and support enquiries
  • Newsletter sign-up information
  • Profile information you choose to add (display name, bio)

2.3 AI chat messages (MG Labs AI)

Messages you send to MG Labs AI (available at /mg-ai) are transmitted in real time to Groq, Inc. for inference (AI response generation). We do not store the content of your AI chat sessions in our database. Groq processes messages under its own privacy policy. Do not submit sensitive personal information (such as financial data, government ID numbers, or health information) in AI chat.

2.4 Usage and technical data

Like all websites, we automatically receive standard technical information when you visit the Platform, including:

  • IP address and approximate geographic location (country or region)
  • Browser type, version, and device type
  • Pages viewed, time on page, and navigation path
  • Referring URL (the page that linked you to us)
  • Timestamps of visits and actions

This data is collected by Vercel (our hosting provider) and any analytics tools we use, and is used in aggregate form to understand how the Platform is used and to improve it.

3. How We Use Your Information

We use collected information to:

  • Create, authenticate, and maintain your account
  • Provide and improve Platform features including courses, the prompt library, community, and AI tools
  • Process payments and manage your subscription via Stripe
  • Send transactional emails (account confirmation, password reset, payment receipts, security notifications)
  • Send the MG Creative Labs newsletter and product updates, if you have opted in
  • Respond to support requests, feedback, and contact form messages
  • Detect, investigate, and prevent fraudulent, abusive, or illegal activity
  • Comply with legal obligations and respond to lawful requests from authorities
  • Analyse aggregate usage patterns (never at an individual-identified level) to improve the Platform

We do not use your data for automated decision-making that produces legal or similarly significant effects on you without your explicit consent.

4. How We Share Your Information

We do not sell your personal information to third parties. We do not share your data with advertisers or data brokers.

We share data only in the following limited circumstances:

  • Service providers: We share necessary data with our technical processors (listed in § 5) solely to operate the Platform.
  • Legal compliance: We may disclose personal data to comply with a legal obligation, court order, or lawful government request, or to protect the rights, safety, or property of MG Creative Labs, our users, or the public.
  • Business transfers: If MG Creative Labs is involved in a merger, acquisition, or sale of all or substantially all of its assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Platform before your data becomes subject to a different privacy policy.
  • With your consent: We may share data in other circumstances with your explicit prior consent.

5. Data Processors

We rely on the following sub-processors to operate the Platform. Each processes your data only as necessary to provide their service, under their own privacy policies and applicable data protection law:

Supabase

Database, authentication, file storage, and row-level security

SOC 2 Type II certified. Data stored on AWS infrastructure.

Vercel

Website hosting, CDN, edge functions, and server-side rendering

Infrastructure based in the US and globally distributed via edge.

Stripe, Inc.

Payment processing and subscription management

PCI DSS Level 1 certified. MG Creative Labs does not store raw card data.

Groq, Inc.

AI language model inference for the MG Labs AI chat feature

Your chat messages are transmitted to Groq for processing. See § 2.3.

Google

Optional OAuth single sign-on

Only used if you choose to sign in with Google.

6. Payment and Billing Data

Payment transactions are processed by Stripe, Inc. When you subscribe to a paid plan, Stripe collects and stores your payment card details directly. MG Creative Labs does not store, process, or have access to your raw credit card number, CVV, or full card data.

We receive from Stripe limited non-sensitive billing information including: your name, billing postal code, last four digits of your card, card brand, expiry date, subscription status, and payment history. This information is stored in our database and used to manage your subscription and provide billing support.

Stripe is PCI DSS Level 1 certified — the highest available security standard for payment processors. For more information, see Stripe's Privacy Policy.

7. Cookies and Tracking Technologies

7.1 Essential cookies

We use session cookies and local storage to keep you signed in and maintain your user preferences. These are essential to the functioning of the Platform and cannot be disabled without preventing you from using authenticated features.

7.2 Analytics

We may use privacy-respecting analytics tools to understand aggregate usage patterns (page views, popular content, traffic sources). Where analytics are used, we configure them to minimise personal data collection and, where possible, to process data without individual-level identification.

7.3 No advertising cookies

We do not use third-party advertising networks, retargeting pixels, or behavioural tracking cookies. MG Creative Labs does not participate in programmatic advertising.

7.4 Managing cookies

You can control cookies through your browser settings. Note that disabling all cookies will prevent certain features (including staying signed in) from working.

8. Security of Your Information

8.1 Measures we take

We take the security of your personal information seriously and implement a range of technical and organisational measures designed to protect it, including:

  • Encryption of data in transit using TLS/HTTPS on all Platform connections
  • Encryption of data at rest via Supabase (AES-256)
  • Row-level security (RLS) policies to ensure users can only access their own data
  • Environment variable management for credentials — secrets are never committed to source code
  • Two-factor authentication available for user accounts
  • Regular review of access controls and third-party processor security practices

8.2 No absolute security guarantee

No method of electronic transmission or storage is 100% secure. While we take reasonable measures to protect your personal information, we cannot guarantee its absolute security. Risks inherent to the internet — including interception, unauthorised access, data loss, or corruption — cannot be entirely eliminated.

You use the Platform and transmit personal information at your own risk. You are also responsible for maintaining the security of your account credentials and for choosing a strong, unique password.

8.3 Limitation of liability for security incidents

To the fullest extent permitted by applicable law, MG Creative Labs shall not be liable for any unauthorised access to, disclosure of, alteration of, or destruction of personal information that results from circumstances beyond our reasonable control, including attacks by third parties on our infrastructure or the infrastructure of our data processors. This limitation does not apply where the incident results from our gross negligence, wilful misconduct, or intentional wrongdoing.

8.4 Data breach notification

In the event of a security breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and, where required by law, relevant supervisory authorities, within the timeframes required by applicable data protection legislation. Notification will be made via email to the address on your account and/or via a prominent notice on the Platform.

9. Your Privacy Rights

Depending on where you are located, you may have the following rights regarding your personal data:

9.1 Rights for all users

  • Access: Request a copy of the personal data we hold about you
  • Correction: Ask us to correct inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention obligations)
  • Portability: Request your data in a portable, machine-readable format
  • Withdraw consent: Opt out of the newsletter or other consent-based processing at any time

9.2 EEA, UK, and Swiss residents (GDPR / UK GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under GDPR or UK GDPR, including:

  • Right to restrict processing: Ask us to restrict how we process your data in certain circumstances
  • Right to object: Object to processing based on legitimate interests, including profiling
  • Right to lodge a complaint: File a complaint with your local supervisory authority (e.g., the ICO in the UK, or your national DPA in the EU)

Our legal basis for processing your personal data is primarily: (a) performance of a contract (to provide the Platform features you have signed up for), (b) legitimate interests (to improve the Platform and prevent abuse), and (c) consent (for newsletter communications and optional features).

9.3 California residents (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how we use it
  • Request deletion of your personal information
  • Opt out of the “sale” or “sharing” of personal information — we do not sell or share personal information for cross-context behavioural advertising
  • Non-discrimination in service quality for exercising your CCPA rights

9.4 How to exercise your rights

To exercise any of the above rights, email us at mgcreativelabs@technologist.com with the subject line “Privacy Request” and a description of your request. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing the request.

10. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Platform services. Specifically:

  • Account data is retained while your account exists and for up to 30 days after account deletion to allow for recovery if deletion was unintentional
  • Billing records and transaction history are retained for up to 7 years to meet financial and tax reporting obligations
  • Support and contact records are retained for up to 3 years after the resolution of the relevant matter
  • Aggregate, anonymised analytics data may be retained indefinitely as it does not identify individual users

When you delete your account, we delete or anonymise your personal data within 30 days, except where retention is required by law or where data cannot be immediately deleted due to technical backup processes (in which case it is securely isolated and deleted as soon as practically possible).

11. International Data Transfers

MG Creative Labs is operated with infrastructure providers based primarily in the United States and globally distributed via cloud infrastructure. If you are located outside the United States — including in the European Economic Area or United Kingdom — your personal data is transferred to and processed in the United States and potentially other jurisdictions.

Where such transfers involve data from the EEA or UK, we rely on appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) where applicable with our sub-processors
  • The adequacy decisions, binding corporate rules, or other mechanisms recognised under applicable data protection law for transfers from your jurisdiction

By using the Platform, you acknowledge that your data may be transferred to and processed in jurisdictions with data protection laws that may differ from those in your country.

12. Children's Privacy

The Platform is not directed at children under 13 years of age (or the minimum digital consent age in your jurisdiction, if higher). We do not knowingly collect personal information from children under these ages.

If you believe we have inadvertently collected personal information from a child, please contact us immediately at mgcreativelabs@technologist.com and we will take appropriate steps to delete that information.

13. Third-Party Links and Services

The Platform may contain links to third-party websites, tools, and resources (including AI tools listed in our directory and links in blog posts). These third-party sites are not operated by us and have their own privacy policies.

We are not responsible for the privacy practices, content, or security of third-party sites. We encourage you to review the privacy policy of any site you visit from a link on our Platform before submitting personal information to it.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time as our practices change, as new features are introduced, or as required by applicable law. When we make changes, we will:

  • Update the “Last updated” date at the top of this page
  • For material changes, notify you via email (to the address on your account) and/or via a prominent in-platform notice, at least 14 days before the changes take effect where reasonably practicable

Your continued use of the Platform after any revised policy takes effect constitutes your acceptance of the updated policy.

15. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, please contact us:

MG Creative Labs — Privacy

Email: mgcreativelabs@technologist.com

Subject line: “Privacy Request”

We aim to respond to all privacy enquiries within 30 days.