A note on why we built Cruma
Legal

Privacy Policy

What Cruma collects, what it never does with your workspace data, and the subprocessors that power the service.

Last updated: 2026-07-13 · Version: draft-2

Who we are

Cruma (“Cruma”, “we”) provides the Cruma workspace platform: an AI crew that works inside your business under human approval gates. Cruma is based in California, United States. This policy explains what we collect, why, and the controls you have. For business customers, the Data Processing Addendum also applies: for your workspace content, you are the controller and Cruma processes it on your instructions.

Contact: privacy@cruma.ai (or hello@cruma.ai).

What we collect

  • Account data: name, email, and authentication identity (via Supabase Auth). If you sign in with Google or Microsoft, we receive the identity and email your provider shares; we never receive your password from them.
  • Workspace content: the rooms, files, artifacts, memory, task history, decisions, and approvals your workspace creates while the crew works.
  • Connected-account data: content the crew reads or drafts in systems you connect (for example Gmail, Google Drive, QuickBooks). Access is scoped to what a workspace admin explicitly grants, read/draft/act permissions are separate, and provider credentials never enter model prompts; Cruma’s model context is credential-free by construction. Disconnecting a tool stops all further access.
  • Run records: to make agent work auditable and replayable, Cruma records what the model was shown and produced for each task, with outcomes and approvals. Bodies are retained inline for a 30-day operational window, then archived to cold storage; audit material is archived, not silently deleted.
  • Billing data: handled by Stripe. Cruma stores your plan and credit ledger, never your card details.
  • Support and communications: messages you send us (email, support escalations). Support tickets carry identifiers, never workspace content.
  • Technical data: standard service logs and error events (via Sentry) carrying technical identifiers such as trace and run ids, not message bodies.

How we use it

To operate your workspace and the crew’s runs; to meter usage in credits and bill you; to keep the crew’s work auditable and replayable for you; to secure the service and prevent abuse; to provide support; and to improve reliability through error monitoring. We do not sell personal data, and we do not run third-party advertising or cross-site tracking.

Training data: opt-in only

We do not use your workspace’s run history to train models unless you explicitly opt in. The default is OFF for every plan. The switch lives in workspace settings, and its state is enforced in the export machinery itself: no consent flag, no export, fail-closed. Opting out later stops all future exports, including of past data.

AI processing

The crew’s reasoning runs on large language models served by our model subprocessors (see the subprocessor list). Prompts and completions are processed to perform the task you asked for and are subject to the training rule above. Model outputs can be wrong; that is why consequential actions sit behind human approval gates and receipts.

Sharing

Only with the subprocessors needed to run the service, under contracts that limit them to providing it. We disclose data if the law genuinely requires it, and we will tell you unless we are legally barred from doing so. If Cruma is ever part of a merger or acquisition, this policy continues to apply to data collected under it.

Visibility inside your workspace

Access inside Cruma follows one rule: visibility is decided at write time, enforced at read time, and never widened by derivation. The crew cannot retrieve content the asking person is not allowed to see. Personal account memory (your work-style preferences) is visible only to you and never carries business facts.

Retention

Workspace content persists for the life of the workspace. Run-record bodies stay inline for 30 days, then move to archival storage. Cancellation never deletes your workspace data automatically: it is retained so you can export it or come back, and deleted on your request.

Security

Data is encrypted in transit and at rest by our infrastructure providers. Provider credentials for connected accounts are stored by the integration broker, never in model context. Access to production systems is restricted and logged. External actions run through typed capabilities with policy checks, approvals, idempotency, and audit trails.

Your controls

Workspace admins control connected-account grants, member roles, memory review and retraction, training consent, and can request export or deletion of workspace data. Individuals can ask us to access, correct, export, or delete their personal data at privacy@cruma.ai; we answer within the timelines the applicable law sets (including GDPR and CCPA/CPRA where they apply). We do not discriminate for exercising privacy rights.

California residents

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how it is used (this policy is that disclosure), to access it, to correct it, to delete it, to receive it in a portable form, and to not be discriminated against for exercising any of these rights. We do not sell personal information, and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of under “Do Not Sell or Share”. We do not use or disclose sensitive personal information beyond what is necessary to provide the service. To exercise any right, email privacy@cruma.ai; we verify requests against your account identity and respond within the statutory window.

EEA and UK residents

Where GDPR or UK GDPR applies, our legal bases are: performing our contract with you (operating your workspace), legitimate interests (securing and improving the service, in ways you would reasonably expect), and consent where we ask for it (for example, training-data opt-in, which is consent-based and revocable). You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing. You can also lodge a complaint with your supervisory authority. For workspace content, your business is the controller and Cruma is the processor under the DPA; rights requests about workspace content go to the workspace owner, and we help them respond.

International transfers

Our subprocessors operate primarily in the United States. Where data moves across borders, we rely on our subprocessors’ standard transfer mechanisms; the DPA covers this for business customers.

Cookies

Cruma uses cookies and similar storage only to keep you signed in and to remember product preferences (like theme). No advertising cookies, no cross-site trackers. The public website runs without analytics cookies.

Children

Cruma is a business tool, not directed to children, and not intended for anyone under 16.

Changes

We will post changes here with a new version and date. Material changes to what we collect or how we use it (especially anything touching the training rule) restart acceptance: you will be asked to review again.

The work moves
while you sleep.

Point Cruma at the business. It works across the tools you already use and speaks up before you ask. Your mornings can start somewhere else.

  • Works across the tools you already use
  • Advises, unasked, with its sources
  • Nothing consequential without you
Request your invite

Two fields. You'll hear from a real person within two days.

We onboard in small waves, with real help getting set up. Read why we built this.

Already have an invite? Open Cruma