# Privacy

Source: https://cruma.ai/privacy  
Last updated: 27 Sep 2026

> How Cruma handles your information: what we collect, why, who helps us run the service, and the choices you have.

On this page 

1. [1Who we are, and our role](#1-who-we-are-and-our-role)
2. [2What we collect](#2-what-we-collect)
3. [3How we use it, and our legal bases](#3-how-we-use-it-and-our-legal-bases)
4. [4AI models](#4-ai-models)
5. [5Who helps us run Cruma](#5-who-helps-us-run-cruma)
6. [6Who can see what](#6-who-can-see-what)
7. [7How long we keep it](#7-how-long-we-keep-it)
8. [8Where your information goes](#8-where-your-information-goes)
9. [9Security](#9-security)
10. [10Your rights](#10-your-rights)
11. [11Automated decisions](#11-automated-decisions)
12. [12Cookies and similar technologies](#12-cookies-and-similar-technologies)
13. [13Children](#13-children)
14. [14For companies: our DPA](#14-for-companies-our-dpa)
15. [15Changes](#15-changes)
16. [16Contact](#16-contact)

The short version

**We don’t sell your data.**

We don’t sell it or share it for advertising. We don’t train AI on your content, and neither do the model providers we use. Agents and apps you connect follow their own terms.

**You decide what goes in.**

The crew works from what your team adds or connects, and the web when it searches. In a chat, it uses only what everyone there may see.

**Everyone sees only what’s theirs.**

Inside your workspace, people and crew see only what’s meant for them. Our staff access it only when needed to support you, keep Cruma secure or meet the law.

**You stay in control.**

Your workspace’s admins can ask us to export or delete its content; you can ask us about your own personal information any time.

Cruma is a workspace where your team and AI agents work together. This policy explains what information we handle, why, who helps us, how long we keep it, and the rights you have. We’ve kept it plain on purpose.

## 1. Who we are, and our role

Cruma is run by Cruma, Inc., a Delaware corporation, 262 Chapman Rd, Ste 240, Newark, DE 19702 (“Cruma”, “we”). For anything in this policy, write to [privacy@cruma.ai](mailto:privacy@cruma.ai).

- **For your workspace, we act for your company.** When a company uses Cruma, it decides what goes into its workspace and which apps are connected. For that content we’re a “processor” (or “service provider” under US state laws): we process it only on the company’s instructions, set out in our [Terms](https://cruma.ai/terms), any DPA, and the company’s settings in Cruma. The company is the “controller”, and its own privacy notice applies. If you use Cruma through your employer, questions about your workspace content are best sent to them first.
- **For our own records, we decide.** For account and billing records, our website, early access requests, security logs and our own business contacts, we’re the controller.

## 2. What we collect

- **Account details:** your name, work email, sign-in details, role, and the workspace you belong to.
- **Workspace content:** the messages, files, records and instructions you and your team add, and what your crew produces from them.
- **Content from apps you connect:** when someone in your workspace connects an app (like email, a calendar, a file store, chat or a CRM), the crew reads the parts of it that person allows, under the permissions set for each crew member. This can include personal data about people outside your company, such as the senders of emails.
- **Memory:** the lessons and corrections your team teaches the crew, kept so they apply to future work, and scoped to the people they’re meant for.
- **Activity records:** which person or crew member made each change, what was approved, and when, and who read what through Cruma. Cruma keeps these so work can be reviewed and approvals can be checked.
- **Web searches:** when the crew searches the web or opens a link for you, the words it searches for and the pages it opens.
- **Technical information:** logs such as IP address, browser, device, timestamps, usage, spend and errors, used to keep the service running and secure.
- **Early access requests and messages:** the email address and details you send us when you ask for access or write to us.

We don’t ask for special-category data (such as health or biometric data). Please don’t put it into Cruma unless we’ve agreed in writing that Cruma is suitable for it.

## 3. How we use it, and our legal bases

Where the GDPR or UK GDPR applies, we rely on these legal bases for the information we control. For workspace content, the company that controls it is responsible for its legal basis.

| What we do                                                                                                        | Legal basis                                                                                        |
| ----------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- |
| Run the service: answer requests, carry out work your team approves, and show everyone what happened              | Performing our contract with your company; our legitimate interest in providing Cruma to its users |
| Remember what your team teaches the crew, so the same correction applies next time, for the people it’s meant for | Performing our contract                                                                            |
| Keep Cruma secure, prevent abuse and fraud, and fix problems                                                      | Legitimate interests (keeping the service and its users safe)                                      |
| Understand how Cruma is used so we can improve it, using usage data rather than your content                      | Legitimate interests (improving our product)                                                       |
| Contact you about your account, the service, changes and early access                                             | Performing our contract; legitimate interests                                                      |
| Send product news, where you’ve asked for it or the law allows                                                    | Consent, or legitimate interests where allowed; you can opt out at any time                        |
| Meet legal obligations, and establish or defend legal claims                                                      | Legal obligation; legitimate interests                                                             |

**We do not use your workspace content to train AI models.** We don’t sell your information, we don’t share it for cross-context behavioural advertising, and we don’t use it for advertising.

## 4. AI models

To produce answers, Cruma sends the relevant part of your content to the AI model chosen for that task, through Amazon Bedrock or Groq. These providers process it only to return a response to us, under terms that don’t allow them to train on it. Some may keep inputs and outputs for a short time under their terms, for example to detect abuse. When the crew searches the web, the words it searches for go to our search provider.

The no-training promise covers Cruma and the providers we use. Outside agents and apps you connect (such as Claude Code, Codex or your email) get what you share with them under their own terms, which you choose.

## 5. Who helps us run Cruma

These companies (“subprocessors”) process information for us, only to provide their part of the service, under contracts that require them to protect it:

| Provider            | What for                                                                 | Where                                                          |
| ------------------- | ------------------------------------------------------------------------ | -------------------------------------------------------------- |
| Supabase            | Database, sign-in (including sign-in and invite emails) and file storage | United States (Ohio)                                           |
| Vercel              | Hosting the Cruma app and its API, and this website                      | United States (Ohio) for the API; global network for web pages |
| Amazon Web Services | AI models through Amazon Bedrock                                         | United States                                                  |
| Groq                | AI models, when chosen for a task                                        | United States                                                  |
| TinyFish            | Web search and reading web pages for the crew                            | United States                                                  |
| Google Workspace    | Our email, including early access requests                               | United States                                                  |

**Changes.** We’ll keep this list current. Before we add or replace a subprocessor that handles workspace content, we’ll update this page and tell workspace admins by email at least 30 days in advance (less only in an emergency, such as a provider outage). If you have a reasonable data-protection objection, tell us and we’ll work with you on it; if we can’t resolve it, you can close your workspace.

**Others we may share with:**

- **At your direction.** When your crew sends a message, updates a record or shares a file through an app you’ve connected, it goes where you told it to. Those apps (for example Gmail, Slack or Google Drive) are governed by your own agreements with their providers.
- **Outside agents you connect** (like Claude Code or Codex) receive what they’re given for the work you hand them. Inside Cruma they go through the same permission checks as your own crew; what their providers do with it is governed by their terms. Data a crew member or connected agent sends to other services on your instructions is handled under those services’ terms, not this policy.
- **For legal reasons.** When the law, a court or a valid government request requires it, or to protect people’s safety or our rights. Where we can, we’ll tell the affected company first and challenge requests that are too broad.
- **In a business change.** If Cruma is merged, acquired or sells assets, information may transfer as part of that deal, under this policy’s protections.

## 6. Who can see what

Inside a workspace, each person and each crew member sees only what’s meant for them. When the crew answers in a chat, it uses only what everyone in that chat may see, and lessons in memory reach only the chats they’re meant for. Outside agents you connect go through the same checks as your own crew and see only what they’re given. Cruma staff access workspace content only when needed to support you, keep Cruma secure or meet a legal duty.

## 7. How long we keep it

| Information                                              | How long                                                                                                                                                                                                                                                             |
| -------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Workspace content, memory and activity records           | For as long as the workspace exists. Closing or cancelling doesn’t delete it, so you can ask for an export or come back. Deletion happens on request: when an admin asks us to delete the workspace, we wait 30 days so the request can be cancelled, then delete it |
| Backups                                                  | Deleted information can stay in our database provider’s backups until they expire on its schedule                                                                                                                                                                    |
| Account details                                          | For as long as the account exists. If you ask us to delete your account, we do so within 30 days                                                                                                                                                                     |
| Records of each crew run (what each step read and wrote) | 90 days                                                                                                                                                                                                                                                              |
| Records of who read what                                 | For as long as the workspace exists                                                                                                                                                                                                                                  |
| Early access requests and emails                         | Up to 24 months after our last contact, unless you become a customer                                                                                                                                                                                                 |

We keep something longer only where the law requires it, or to resolve a dispute or enforce our terms. Workspace admins can ask us to erase specific content sooner. Removing a message in Cruma hides it, but it stays in the workspace’s history until it’s erased.

## 8. Where your information goes

We’re based in the United States, and our providers may process information in the United States and other countries. When we transfer personal data from the EEA, UK or Switzerland to a country without an adequacy decision, we use a recognised safeguard: the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider’s certification under the EU–US Data Privacy Framework (and its UK and Swiss extensions) where that applies. You can ask us for a copy of the safeguards we use.

## 9. Security

Information is encrypted in transit and at rest by our infrastructure providers. Each workspace is kept separate from every other in the database, every change is recorded with who made it, and reads through Cruma are recorded too. We limit who at Cruma can access production systems. No system is perfectly secure.

**If something goes wrong.** If we become aware of a breach that affects personal data we hold for a company, we’ll tell that company’s admins without undue delay, and within 72 hours of confirming it, with what we know and what we’re doing about it. Where we’re the controller, we’ll notify regulators and affected people as the law requires. To report a security issue, write to [security@cruma.ai](mailto:security@cruma.ai).

## 10. Your rights

Depending on where you live, you may have the right to:

- know what information we hold about you and get a copy, including in a portable format;
- correct it, or have it deleted;
- object to or restrict how we use it, including for direct marketing;
- withdraw consent, where we rely on it; and
- complain to your data protection authority (in the UK, the Information Commissioner’s Office; in the EU, the authority where you live or work).

**US state privacy laws** (including California’s CCPA as amended by the CPRA, where it applies): you can ask to know, access, correct and delete your personal information. We don’t sell personal information or share it for cross-context behavioural advertising, and haven’t in the past 12 months. We don’t use sensitive personal information to infer things about you. We won’t treat you differently for using your rights. You can use an authorised agent, and we’ll verify requests before acting on them.

**How to ask.** Write to [privacy@cruma.ai](mailto:privacy@cruma.ai). We’ll answer within one month (45 days under US state laws), and tell you if we need longer as the law allows. If your request is about content in a company’s workspace, we’ll pass it to that company, which decides how to respond, and help it do so.

## 11. Automated decisions

Cruma’s crew carries out work your team gives it, under the permissions your team sets. We don’t use it to make decisions based solely on automated processing that have legal or similarly significant effects on you. If a company uses Cruma in its own processes, it’s responsible for how it uses the results and for human review, as our [Terms](https://cruma.ai/terms) require.

## 12. Cookies and similar technologies

- **This website** (cruma.ai) sets no cookies and uses no analytics, advertising or tracking tools. Everything it loads, fonts included, comes from cruma.ai itself. Our hosting provider (Vercel) keeps standard server logs to deliver the site and keep it secure.
- **The Cruma app** uses one cookie to keep you signed in, and your browser’s storage to remember preferences on your device (such as light or dark mode, the layout and the last workspace you opened). We don’t use advertising or cross-site tracking there either.

If we ever add analytics or other non-essential cookies, we’ll update this policy first and ask for consent where the law requires.

## 13. Children

Cruma is for work and isn’t meant for anyone under 16\. We don’t knowingly collect information from children. If you think a child has given us information, write to us and we’ll delete it.

## 14. For companies: our DPA

If your company needs a data processing agreement (for example under the GDPR or UK GDPR), write to [privacy@cruma.ai](mailto:privacy@cruma.ai) and we’ll provide one. It covers our processor commitments, subprocessors, transfers, security, breach notice and help with requests from individuals.

## 15. Changes

If we change this policy in a way that matters, we’ll tell you by email or in Cruma before it takes effect. The date at the top shows the latest version.

## 16. Contact

Cruma, Inc., 262 Chapman Rd, Ste 240, Newark, DE 19702\. Email [privacy@cruma.ai](mailto:privacy@cruma.ai).
