Last updated: 2026-07-13 · Version: draft-2
Who we are
Cruma (“Cruma”, “we”) provides the Cruma workspace platform: an AI crew that works inside your business under human approval gates. Cruma is based in California, United States. This policy explains what we collect, why, and the controls you have. For business customers, the Data Processing Addendum also applies: for your workspace content, you are the controller and Cruma processes it on your instructions.
Contact: privacy@cruma.ai (or hello@cruma.ai).
What we collect
- Account data: name, email, and authentication identity (via Supabase Auth). If you sign in with Google or Microsoft, we receive the identity and email your provider shares; we never receive your password from them.
- Workspace content: the rooms, files, artifacts, memory, task history, decisions, and approvals your workspace creates while the crew works.
- Connected-account data: content the crew reads or drafts in systems you connect (for example Gmail, Google Drive, QuickBooks). Access is scoped to what a workspace admin explicitly grants, read/draft/act permissions are separate, and provider credentials never enter model prompts; Cruma’s model context is credential-free by construction. Disconnecting a tool stops all further access.
- Run records: to make agent work auditable and replayable, Cruma records what the model was shown and produced for each task, with outcomes and approvals. Bodies are retained inline for a 30-day operational window, then archived to cold storage; audit material is archived, not silently deleted.
- Billing data: handled by Stripe. Cruma stores your plan and credit ledger, never your card details.
- Support and communications: messages you send us (email, support escalations). Support tickets carry identifiers, never workspace content.
- Technical data: standard service logs and error events (via Sentry) carrying technical identifiers such as trace and run ids, not message bodies.
How we use it
To operate your workspace and the crew’s runs; to meter usage in credits and bill you; to keep the crew’s work auditable and replayable for you; to secure the service and prevent abuse; to provide support; and to improve reliability through error monitoring. We do not sell personal data, and we do not run third-party advertising or cross-site tracking.
Training data: opt-in only
We do not use your workspace’s run history to train models unless you explicitly opt in. The default is OFF for every plan. The switch lives in workspace settings, and its state is enforced in the export machinery itself: no consent flag, no export, fail-closed. Opting out later stops all future exports, including of past data.
AI processing
The crew’s reasoning runs on large language models served by our model subprocessors (see the subprocessor list). Prompts and completions are processed to perform the task you asked for and are subject to the training rule above. Model outputs can be wrong; that is why consequential actions sit behind human approval gates and receipts.
Sharing
Only with the subprocessors needed to run the service, under contracts that limit them to providing it. We disclose data if the law genuinely requires it, and we will tell you unless we are legally barred from doing so. If Cruma is ever part of a merger or acquisition, this policy continues to apply to data collected under it.
Visibility inside your workspace
Access inside Cruma follows one rule: visibility is decided at write time, enforced at read time, and never widened by derivation. The crew cannot retrieve content the asking person is not allowed to see. Personal account memory (your work-style preferences) is visible only to you and never carries business facts.
Retention
Workspace content persists for the life of the workspace. Run-record bodies stay inline for 30 days, then move to archival storage. Cancellation never deletes your workspace data automatically: it is retained so you can export it or come back, and deleted on your request.
Security
Data is encrypted in transit and at rest by our infrastructure providers. Provider credentials for connected accounts are stored by the integration broker, never in model context. Access to production systems is restricted and logged. External actions run through typed capabilities with policy checks, approvals, idempotency, and audit trails.
Your controls
Workspace admins control connected-account grants, member roles, memory review and retraction, training consent, and can request export or deletion of workspace data. Individuals can ask us to access, correct, export, or delete their personal data at privacy@cruma.ai; we answer within the timelines the applicable law sets (including GDPR and CCPA/CPRA where they apply). We do not discriminate for exercising privacy rights.
California residents
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how it is used (this policy is that disclosure), to access it, to correct it, to delete it, to receive it in a portable form, and to not be discriminated against for exercising any of these rights. We do not sell personal information, and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of under “Do Not Sell or Share”. We do not use or disclose sensitive personal information beyond what is necessary to provide the service. To exercise any right, email privacy@cruma.ai; we verify requests against your account identity and respond within the statutory window.
EEA and UK residents
Where GDPR or UK GDPR applies, our legal bases are: performing our contract with you (operating your workspace), legitimate interests (securing and improving the service, in ways you would reasonably expect), and consent where we ask for it (for example, training-data opt-in, which is consent-based and revocable). You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing. You can also lodge a complaint with your supervisory authority. For workspace content, your business is the controller and Cruma is the processor under the DPA; rights requests about workspace content go to the workspace owner, and we help them respond.
International transfers
Our subprocessors operate primarily in the United States. Where data moves across borders, we rely on our subprocessors’ standard transfer mechanisms; the DPA covers this for business customers.
Cookies
Cruma uses cookies and similar storage only to keep you signed in and to remember product preferences (like theme). No advertising cookies, no cross-site trackers. The public website runs without analytics cookies.
Children
Cruma is a business tool, not directed to children, and not intended for anyone under 16.
Changes
We will post changes here with a new version and date. Material changes to what we collect or how we use it (especially anything touching the training rule) restart acceptance: you will be asked to review again.