Legal
Privacy policy
Cruo stores what you put into it so that you and your team can work on it. It does not track you, sell your data, show you ads, or train AI on your work.
Last updated 24 September 2026
1. Who we are
Cruo (“we”, “us”) runs Cruo Projects, Drive and Mindmap, the Cruo MCP servers and the Cruo agent supervisor. For anything about your data, write to support@cruo.space.
2. What we store
- Your account — your email address, name and username, and your profile picture if you sign in with Google. If you sign in with a password, we store only a hash of it.
- Your work — the workspaces, projects, issues, comments, attachments, boards and files you and your team create, and the history of changes to them.
- Agents and tokens — the agent accounts you create in a workspace and the access tokens you issue for them or for MCP clients.
- Billing — your plan, seat counts, subscription status and the amounts you paid. Card details go to our payment provider and are never seen or stored by us.
- Technical logs — our hosting providers keep standard request logs (such as IP address, time and the page requested) for a short time, to keep the service running and secure. We also count requests to our API to enforce rate limits.
3. What we do not do
- No analytics, tracking pixels or advertising scripts, on any Cruo site or app.
- We do not sell or rent your data, or share it for anyone's marketing.
- We do not use your content to train AI models.
- Cruo runs no AI model itself. Agents run on your own machine through a harness you choose, using your own account with your own model provider. What your agent sends to that provider is governed by your agreement with them, not by us.
5. Who can see your data
Your workspace. Content in a workspace is visible to its members according to the roles and project access the workspace gives them, including the agent accounts added to it.
Us. Our support tooling shows account and billing information — which workspaces an account belongs to, its plan and its storage use — and every lookup is logged. It does not show workspace content. We look at your content only when you ask us to as part of a support request, or when the law requires it.
The providers that run Cruo, only as needed to provide it:
- Supabase — database and sign-in (Singapore)
- Vercel — hosting (Singapore)
- Cloudflare R2 — file storage for attachments and Drive
- Resend — email, such as invitations and support replies
- Polar — payments, tax and receipts, as merchant of record
- Google — sign-in, if you choose to sign in with Google
Some of these process data outside your country. We use them because they protect the data they hold under their own security and privacy commitments.
6. How long we keep it
- Your data is kept for as long as your account and workspaces exist. Downgrading or cancelling a plan never deletes anything.
- Deleted issues and Drive files stay in trash for 30 days, then are removed.
- A workspace owner can delete a workspace, which permanently removes its projects, issues, comments and boards.
- You can delete your account yourself, under Account in any Cruo app. That removes your account, your Drive files, the boards you own and any workspace where you are the only person, and deletes the stored copies of your files. Issues and comments you wrote in other workspaces stay, without your name. If you would rather we did it, write to support@cruo.space.
7. Your rights
You can ask us for a copy of your data, to correct it, to export it, or to delete it. Write to support@cruo.space and we will answer within 30 days. Depending on where you live, you may also have the right to complain to your local data protection authority.
8. Changes
If we change this policy, the new version appears here with a new date. If a change affects how we use data you have already given us, we will email account owners before it takes effect.