Privacy Policy
Last updated: September 10, 2026
Create Well ("the CR8W Dashboard", "the app") is the private team dashboard of the Create Well co-creation collective, operated by the collective's members. This policy explains what data the app collects, how it is used, where it is stored, and the choices you have.
1. Data we collect
- Account data. When a member registers, we store their email address, display name, chosen team profile, and an encrypted password hash. Authentication is handled by Supabase Auth.
- Workspace mirror data. The dashboard displays read-only snapshots of the collective's Notion workspace (people, projects, flows, content, and finance records) so members can see the team's week in one place. The app never writes to Notion.
- Google Calendar data (optional). If a member chooses to connect Google Calendar, the
app requests the
calendar.readonlyandcalendar.eventsscopes. This allows the app to read calendar events and to create or update events the member explicitly chooses to sync for collective scheduling. - Basic technical data. Standard hosting logs (IP address, browser type, timestamps) collected by our hosting provider, Vercel, for security and reliability.
2. How we use data
- To sign members in and keep their session secure.
- To display the collective's shared dashboard to signed-in members.
- To show upcoming collective events and to sync events a member chooses to schedule, when Google Calendar is connected.
Google Calendar data is used only to provide these in-dashboard features. We do not sell any data, do not use it for advertising, and do not share it with third parties beyond the service providers listed below. The app's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Where data is stored
- Supabase (database and authentication) hosts account records and the read-only workspace mirror.
- Vercel hosts the application and its API endpoints.
- Google Calendar access tokens are used to call the Google Calendar API and are handled only for the connected member's session and sync features.
4. Who can see what
The dashboard is limited to registered members of the collective. Finance records are further restricted inside the team. No part of the workspace mirror is public.
5. Your choices
- You can disconnect Google Calendar at any time from the dashboard, and you can revoke the app's access entirely at myaccount.google.com/permissions.
- You can ask a team admin to delete your account; this removes your login and profile from Supabase Auth.
6. Data retention
Account data is kept while you remain a member of the collective. Workspace mirror snapshots are overwritten on each sync. Server logs are retained by our hosting providers according to their own policies.
7. Contact
Questions about this policy or your data: mtb.tablante@gmail.com.