Privacy Policy
Last updated: September 23, 2026 | Effective: July 30, 2026
1. Data Controller
The data controller for the personal data processed through crewkit is:
This Privacy Policy describes how we collect, use, and protect your information when you use crewkit services. It applies to our website, dashboard, API, and CLI. By using crewkit, you agree to the practices described in this policy and our Terms of Service.
2. Information We Collect
We collect information you provide directly to us, including:
- Account Information: Email address, name, organization details
- Usage Data: Agent configurations, experiment results, session logs
- Technical Data: IP addresses, browser type, device information
- Project Data: Git repository information, project metadata
- Payment Data: Billing details processed securely through Stripe (we do not store full card numbers)
3. CLI Data Collection
When you use the crewkit CLI, we collect additional data to provide analytics and improve the service:
- Session Telemetry: Token counts (input/output), estimated costs, session duration, agent used, outcome status, the CLI version and launch mode used to start the session, and basic environment details (operating system, architecture, shell, terminal, machine hostname)
- Session Files: JSONL session files may be uploaded to provide session history and analytics features
- Error Reports: Crash reports and error details are sent to our error tracking service (Sentry) to help us fix bugs
- Git Metadata: Repository remote URL and branch information for project detection (not repository contents)
LLM Gateway (Optional): If enabled by your organization, the LLM Gateway feature routes AI requests through our servers. When active, prompts and responses are processed by both crewkit and Anthropic for cost tracking and analytics. This feature is opt-in and disabled by default. When enabled, data is subject to both this Privacy Policy and Anthropic's Privacy Policy.
4. Legal Basis for Processing
We process your personal data under the following legal bases (GDPR Article 6):
| Data Category | Legal Basis |
|---|---|
| Account information | Contractual necessity (to provide the service) |
| Session telemetry & analytics | Contractual necessity (core service feature) |
| JSONL session files | Legitimate interest (session history and analytics) — enabled by default, can be disabled per organization |
| Error reports (Sentry) | Legitimate interest (service reliability) |
| Technical/device data | Legitimate interest (security, fraud prevention) |
| Payment data | Contractual necessity (billing) |
| LLM Gateway data | Consent (opt-in feature, disabled by default) |
| Marketing communications | Consent (opt-in) |
5. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve crewkit services
- Process transactions and send related information
- Send technical notices, updates, and support messages
- Monitor and analyze usage patterns and trends
- Calculate and display cost analytics and session metrics
- Detect, prevent, and address technical issues and security threats
6. Subprocessors and Third Parties
We use the following third-party services to process your data:
| Provider | Purpose | Location |
|---|---|---|
| Anthropic | AI model provider (LLM Gateway, session analysis) | USA |
| Voyage AI | Embedding provider (semantic search over sessions and uploaded documents) | USA |
| DigitalOcean | Application hosting, database, and object storage (Spaces) holding session-derived documents indexed for search | USA |
| Cloudflare | DNS, CDN, and DDoS protection | USA / Global |
| Stripe | Payment processing | USA |
| Sentry | Error tracking and monitoring | USA |
| GitHub | Git integration, OAuth, CLI distribution | USA |
| PostHog | Product analytics and usage tracking | USA / EU |
| ipapi.co | IP geolocation for analytics | EU |
Subprocessor updates: We will update this list when adding or changing subprocessors. Subscribe to subprocessor change notifications by emailing privacy@crewkit.io with the subject line "Subscribe: Subprocessor Updates."
For enterprise customers requiring a Data Processing Agreement (DPA), contact us at privacy@crewkit.io.
7. International Data Transfers
crewkit is operated from Quebec, Canada. Our subprocessors are primarily located in the United States, so your data will be transferred to and processed in the United States and other countries where our subprocessors operate.
For transfers of personal data from the European Economic Area (EEA), United Kingdom (UK), or Switzerland to the United States, we rely on:
- EU-US Data Privacy Framework (DPF): Where our subprocessors are certified under the DPF
- Standard Contractual Clauses (SCCs): As approved by the European Commission, incorporated into our Data Processing Agreements
By using crewkit, you consent to the transfer of your information to the United States and other countries as described above.
8. Information Sharing and Disclosure
We do not sell your personal information. We may share information:
- With your consent: When you explicitly authorize sharing
- Within your organization: With team members in your organization as determined by your admin's settings
- Service providers: Third parties listed in our subprocessor list who perform services on our behalf, under contractual obligations to protect your data
- Legal requirements: When required by law, regulation, or legal process, or to protect the rights, safety, or property of crewkit, our users, or the public
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users
9. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption in transit (TLS) and at rest
- Regular security audits and vulnerability assessments
- Access controls and authentication requirements
- Secure data centers and infrastructure
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
10. Your Privacy Controls
You have control over what data is collected by crewkit:
- Privacy Mode: Enable privacy mode in your organization settings to prevent logging of prompts and responses. Metrics like token counts, costs, and session duration are still collected to power analytics features.
- Session Uploads: JSONL session file uploads can be disabled in your organization settings. This will prevent session replay and detailed session history features.
- LLM Gateway: This feature is opt-in and must be explicitly enabled by your organization admin. When disabled, no prompts or responses are routed through crewkit servers.
Note: These settings only affect data collected by crewkit. Claude Code has its own telemetry which is governed by Anthropic's privacy policy.
11. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Essential cookies: Maintain your session and authentication state (required for service functionality)
- Preference cookies: Remember your settings and preferences
- Analytics cookies: Analyze site traffic and usage patterns to improve the service
You can control non-essential cookies through your browser settings. Disabling essential cookies may prevent you from using the service. We do not use third-party advertising cookies.
12. Data Retention
We retain your information for as long as your account is active or as needed to provide services:
- Session telemetry: Retained for 365 days by default, configurable per organization down to a 7-day minimum
- Error reports (Sentry): Retained for 90 days
- Account data: Retained until account deletion
- Acceptable-use policy consent: The record that you accepted our acceptable-use policy is kept for 3 years after your account is deleted. It holds the policy version, the language you read it in, a fingerprint of the exact wording shown, the time you accepted, and the machine name, crewkit version and IP address recorded at that moment. Your name, email address and user account are not part of the retained record.
- GitHub access-token audit: Each time crewkit mints a short-lived GitHub App token for your organization, we record which installation and repository ids it covered, what it was for and with which permissions, when it expires, the job it served, the orchestrator worker it was issued to, the internal id of the account that requested it, and a one-way fingerprint of the token. The record never holds the token, a login, email address, name or IP address. We keep it as a security audit, so that a leaked or misused token can be traced to the mint that issued it. It is kept for 13 months, then deleted; if you delete your account, the record stays with your organization and your account id is removed from it.
- Payment records: Retained as required by applicable tax and financial regulations
You may request deletion of your data by contacting us. We will process deletion requests within 30 days. Some information may be retained where required by law or for legitimate business purposes (e.g., fraud prevention, financial records).
What survives an account deletion, and why. When you delete your account, your organization keeps the work records created while you were a member — they are that organization's business records, and your name is removed from them. Because those records remain, we also keep the evidence that they were created under an accepted acceptable-use policy: the consent record described above. We rely on this only to establish, exercise or defend legal claims (GDPR Art. 17(3)(e); Loi 25). It is not used for any other purpose, it is never used to contact you, and it is deleted automatically 3 years after your account is.
13. Children's Privacy
crewkit is designed for professional use by software developers and engineering teams. Our services are not directed at individuals under 18 years of age, and we do not knowingly collect personal information from children.
If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@crewkit.io.
14. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data. One record is kept after deletion — your acceptable-use policy consent — for the reason and the period set out in section 12.
- Restriction: Request that we limit processing of your data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
To exercise your rights: Contact privacy@crewkit.io with your request. We will respond within 30 days. We may need to verify your identity before processing your request.
Right to lodge a complaint: If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been processed in violation of applicable data protection laws.
California residents: Under the CCPA, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.
15. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by GDPR
- Notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms
- Provide details of the breach, its likely consequences, and the measures taken to address it
For enterprise customers with a Data Processing Agreement (DPA), breach notification procedures may be governed by the terms of that agreement.
16. Updates to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice by posting the updated policy on this page, through in-app notification, or by email. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of crewkit after changes take effect constitutes acceptance of the updated policy.
17. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
Karibew Inc.
Privacy & Data Protection: privacy@crewkit.io
DPA Requests: privacy@crewkit.io
Subprocessor Update Subscription: Email privacy@crewkit.io with subject "Subscribe: Subprocessor Updates"
General: support@crewkit.io