Privacy Policy
Last updated: September 8, 2026
This policy explains what personal data Templated collects, why we collect it, who receives it, how long we keep it and the controls you have. It covers the website at https://templated.io, the application at https://app.templated.io, the API, the embedded editor and our integrations with automation tools and AI assistants.
- Who we are
Templated is operated by Fields Apps LTDA, a company based in Brazil (“Templated”, “we”, “us”). For your account data we are the controller. For the content you upload or generate (templates, images, renders and the data you merge into them) you are the controller and we process it on your instructions to provide the service.
Contact for anything in this policy: support@templated.io.
- What we collect
Account data. Name, email address, password (stored hashed) or Google sign-in identifier, company name, country, the page and referrer that brought you to Templated, and the answers you give during onboarding (role, use case, how you heard about us, tools you plan to integrate). Team accounts also store the names and emails of the members you invite.
Billing data. Plan, billing period, invoices and the customer identifiers issued by our payment processors. Card numbers are entered directly with the processor and never reach our servers. For customers invoiced in Brazil we also collect the tax number (CPF or CNPJ) and billing address required by law.
Content. The templates you design or import (including Canva, Figma, PSD, PowerPoint and PDF imports), the images, videos and fonts you upload, the values you send when rendering (text, image URLs, colors) and the rendered files. Content may contain personal data about you or third parties (for example a customer name on a certificate); you are responsible for having the right to use it.
Integration data. API keys, webhook URLs, the external identifiers you attach to templates, and the OAuth authorizations you grant to automation tools and AI assistants.
Usage and technical data. Product analytics events (which features you use, render counts, errors), support conversations, and standard server logs with IP address, browser type and request path. Marketing attribution data such as UTM parameters and, when you opt in, the identifiers used by our advertising measurement tools.
Prompts. When you use AI features (template generation, image description, background removal), the text and images you submit to those features.
- Why we use it
- To provide the service: authenticate you, store and render your templates, deliver files, run your automations and integrations.
- To bill you and issue invoices.
- To support you and answer your requests.
- To understand how the product is used, fix problems and improve it.
- To measure which channels bring new customers and to send product updates and marketing emails, which you can unsubscribe from at any time.
- To keep the service secure, prevent abuse and enforce our terms.
- To comply with legal obligations, including tax and accounting rules.
We do not sell personal data and we do not show third-party advertising inside the product.
- AI assistants and automation tools
Templated can be connected to AI assistants (ChatGPT, Claude, Cursor and other MCP clients) and to automation tools (Zapier, Make, n8n and similar). When you connect one:
- Authorization. You sign in to your Templated account and approve the connection. The tool receives a token or API key that only works for your account. You can revoke it at any time by regenerating your API key in the Templated app or by removing the connection in the tool.
- What the tool can access. On your instruction, the tool can list, inspect, create, update and delete your templates, folders, renders, uploads and fonts, and read your render usage for the current period. It receives template names, sizes, thumbnails, layer contents, render file URLs, asset names and usage counts.
- What the tool does not receive. We do not send your email address, name, password, API key, team members, plan or billing details to the assistant through these connections.
- What we receive from the tool. The instructions and values the tool sends (text, image URLs, template settings). They are stored as part of the templates and renders they create, like any other content.
- The assistant’s own processing. The conversation you have with the assistant is processed by its provider (for example OpenAI or Anthropic) under that provider’s privacy policy, including anything Templated returns to it.
- Who receives your data
We share data only with the providers we need to run the service, each limited to what its role requires:
- Hosting, storage and rendering: Amazon Web Services (servers, database, file storage, rendering functions) and Cloudflare (file storage and delivery). Templates, uploads and rendered files are stored here.
- Payments and invoicing: Stripe and Creem (subscription payments; they receive your email, billing name and address, and process card data directly) and Spedy (Brazilian tax invoices; receives name, tax number, address and invoice amounts).
- Email: Mailjet, for transactional and product emails (receives your email address and name).
- Support and feedback: Crisp (support chat) and Featurebase (feedback and roadmap). They receive your name, email and account context so we can help you.
- Product analytics: PostHog and Plausible, to understand how the product and website are used.
- Sign-in and security: Google (Google sign-in and reCAPTCHA).
- Marketing measurement: Google Ads, Meta and OpenAI advertising pixels on the website and, where allowed, in the application, to measure campaigns. Our affiliate program is run with PromoteKit.
- AI features: Google (Gemini), OpenAI, Anthropic and DeepSeek receive the prompts and images you submit to AI features; Photoroom receives images you send to background removal. They receive only the content of that request, not your account details.
- Imports and stock media: Canva and Figma when you import a design from them; Pixabay and Magnific receive the search terms you type when browsing stock images and icons.
- Your own storage: if you configure your own S3 or R2 bucket, rendered files are copied there under your control.
We may also disclose data when required by law, to protect our rights or users, or as part of a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy.
- How long we keep it
- Account data: while your account exists. When an account is deleted we remove the account, team, templates, renders, uploads and fonts from our systems and keep only a hashed copy of the email address to prevent abuse, plus the billing records described below.
- Content: templates, uploads, fonts and renders stay in your account until you delete them or delete your account. Deleted items disappear from your account immediately and their files are removed from our storage within 90 days.
- Billing records: invoices and payment records are kept for the period required by Brazilian tax and accounting law, currently five years.
- Server logs: kept for up to 90 days for security and troubleshooting.
- Support and analytics data: kept according to each provider’s retention settings and deleted when you delete your account or ask us to.
- Your rights and controls
- Access and correction: update your name, email, password and team settings in the application at any time.
- Export: download your templates, renders and uploads from the application or through the API.
- Deletion: delete templates, renders, uploads and fonts yourself. To delete your account, email support@templated.io from the account’s address; we complete the deletion within 30 days.
- Integrations: revoke any API key, webhook or AI assistant connection from the application.
- Marketing: unsubscribe from marketing emails using the link in each email. Transactional emails about your account and billing are still sent.
- Cookies: manage analytics and advertising cookies in the banner on our website and in your browser settings.
If you are in the European Economic Area, the United Kingdom, Brazil (LGPD) or California (CCPA), you also have the right to ask what personal data we hold about you, to receive a copy, to restrict or object to processing and to complain to your data protection authority. Write to support@templated.io and we answer within the legal deadline, at most 30 days.
- Security
Data is encrypted in transit. Passwords are stored hashed, two-factor authentication is available for every account, and API keys can be regenerated at any time. Access to production systems is limited to the people who operate the service. No method of storage or transmission is completely secure, so please keep your credentials safe and contact us immediately if you suspect misuse.
- International transfers
Our infrastructure providers store data primarily in the United States. When we transfer personal data across borders we rely on the safeguards available under the applicable law, including the providers’ standard contractual clauses.
- Children
Templated is not directed to children under 13 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
- Cookies
The application uses session cookies to keep you signed in and preference cookies for choices such as language. The website and application also use analytics and advertising cookies through our tag manager to measure usage and campaigns; you can decline them in the cookie banner and in your browser. Embedded editors placed on our customers’ sites use only the cookies needed to load the editor.
- Changes and contact
We update this policy when our practices change and post the new version on this page with a new date. Material changes are announced by email or in the application before they take effect.
Questions or requests: support@templated.io.