Privacy Policy
Effective July 20, 2026 · Crew Labs LLC · hello@crewlabs.net
1. Overview
Last updated: July 20, 2026.
This Privacy Policy explains what information CrewLabs, a product of Crew Labs LLC ("CrewLabs," "we," or "us"), collects and how we use it. CrewLabs is a bring-your-own-key product, so how we handle data depends on which tier you use: the self-run (free) tier or the hosted Enterprise tier. We explain both below. For any privacy question or request, email hello@crewlabs.net.
2. What we collect
The information we hold depends on your tier.
- Account data. When you sign up, we collect your email address and basic account details, and we use Supabase to store and authenticate your account. This is the core data we hold for every user, including on the self-run tier.
- Billing and usage metadata (Enterprise). For the paid Enterprise tier, we collect billing details and operational metadata such as plan, invoices, and high-level usage needed to run and bill the service. Payments are processed by Stripe, and we do not store full card numbers.
- Product analytics. We use PostHog to understand how people use our website and app (for example pages viewed, features used, and general interaction patterns) so we can improve the product. This is usage information about the product itself, not the content of your AI conversations.
- Hosted data (Enterprise only). Because we run the Enterprise tier for you, we process the data you route through your hosted agent so the service can function. We handle that data to operate the service for you and under any agreement we sign with you.
- Support and communications. If you email us or contact support, we keep those messages so we can help you.
3. What we do not collect on the self-run tier
On the self-run (free) tier, your agent runs on your own machine and talks directly to the AI provider you chose using your own key. Because of that:
- We do not receive or store the content of your AI model usage or your agent's conversations. That content stays between you, your machine, and your AI provider.
- Your AI provider API keys and channel credentials stay on your machine. We do not collect them for the self-run tier.
- Your use of your AI provider is governed by that provider's own privacy policy, not ours.
Beyond the account and authentication basics described above, and product analytics about how you use the app, we do not collect your self-run agent's activity.
4. How we use information
We use the information we collect to:
- Create and secure your account and let you sign in.
- Operate, maintain, and improve the CrewLabs website and app.
- Run and bill the Enterprise service for customers on that tier.
- Provide support when you ask for it.
- Detect and prevent fraud, abuse, and security issues.
- Send you service-related messages (for example account, security, or billing notices).
We do not sell your personal information.
5. Cookies and analytics
We use a small number of cookies and similar technologies. Essential cookies keep you signed in and keep the app working (handled through Supabase). Analytics identifiers, through PostHog, help us understand how the site and app are used so we can improve them. You can control cookies through your browser settings, though disabling essential cookies may break sign-in.
6. Third-party processors
We rely on a small set of trusted service providers to run CrewLabs. Each processes only what it needs for its role:
- Supabase: account authentication and database (account data).
- Vercel: hosting for our website and app.
- PostHog: product analytics.
- Stripe: payment and billing processing for the Enterprise tier.
- Resend: sending transactional and account emails.
- Your chosen AI provider (for example OpenAI or Anthropic): processes your AI usage. On the self-run tier this happens directly between you and them, under their own privacy policy.
If we add or change a processor that handles personal data, we will update this list.
7. Data retention
We keep account data for as long as your account is active. If you delete your account or ask us to, we delete the personal data we hold about you from our production systems, except where we need to keep certain records to meet legal, tax, or accounting obligations. Backups roll off on a normal cycle. Aggregated or anonymized analytics that cannot be tied back to you may be kept to help us understand product usage.
8. Your rights
You can ask us to access, correct, export, or delete the personal data we hold about you. To make a request, email hello@crewlabs.net and tell us what you need. We will respond within a reasonable time, and within any period required by applicable law.
If you are in a region with specific privacy rights (for example the EU under GDPR, California under CCPA/CPRA, or Brazil under LGPD), those rights still apply to you, and the same email reaches a real person who will handle your request.
9. Security and data location
We protect the data we hold using encryption in transit and at rest, access controls, and reputable infrastructure providers. Our systems and providers (such as Supabase and Vercel) are US-based, so if you use CrewLabs from outside the United States, the account data we hold may be processed in the US. No system is perfectly secure, but if a breach affects your data we will notify you without undue delay and explain what happened.
10. Changes to this policy
We may update this policy as our product and practices change. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you. The date at the top always reflects the current version.
11. Contact
Questions, requests, or complaints about privacy? Email hello@crewlabs.net. A real person will read it.