Effective and last updated: June 15, 2026

Privacy Policy

This Policy explains what personal information Cruxl processes, why we process it, how it is shared, and the choices available to you.

1. Scope and controller

This Policy applies to Cruxl's websites, web application, mobile application, support channels, and related services. Cruxl is the controller of personal information processed for these services unless we state otherwise.

This Policy does not cover third-party websites or services you access through links. It also does not replace notices provided at a specific collection point.

2. Information we collect

  • Account data: email address, display name, account identifiers, authentication records, and account preferences.
  • User Content: maps, nodes, edges, notes, prompts, transcripts, files, images, documents, comments, and collaboration data.
  • Voice data: audio you choose to record for transcription. Audio is sent to our AI provider for processing. Cruxl does not intentionally retain submitted audio in its server database after the request completes. Recordings you explicitly save may remain on your device until you delete them.
  • AI interaction data: prompts, relevant map context, uploaded-content excerpts, generated responses, model and token usage, latency, success status, and error details.
  • Collaboration data: invitee email addresses, roles, shared-link settings, comments, and activity needed to provide collaborative features.
  • Billing data: plan, subscription status, billing period, Stripe customer identifiers, and transaction status. Stripe collects payment-card and billing details directly.
  • Device and operational data: IP address, browser or app type, device identifiers, timestamps, request metadata, security events, crash or error information, and service logs generated by Cruxl or its providers.
  • Communications: messages and contact details you provide when requesting support, reporting a problem, or responding to a survey.
  • Local device data: authentication state, preferences, onboarding state, drafts, and any offline recordings stored through browser storage, IndexedDB, or mobile-device storage.

3. Sources of information

We receive information directly from you, automatically from your device and use of the Service, from people who invite you to collaborate, and from service providers such as Supabase and Stripe.

4. How we use information

  • Provide, personalize, synchronize, and maintain the Service.
  • Authenticate users, enforce plan limits, process subscriptions, and provide support.
  • Process voice, text, files, and map context through AI models to provide requested features.
  • Enable sharing, invitations, comments, and real-time collaboration.
  • Detect abuse, prevent fraud, secure accounts, troubleshoot errors, and enforce our policies.
  • Analyze aggregate service performance and improve reliability, usability, and features.
  • Comply with legal obligations and protect rights, safety, and property.
  • Send service, billing, security, and policy notices. We will request consent where required for marketing messages.

5. Legal bases for EEA, UK, and similar jurisdictions

  • Contract: to create your account and provide requested features.
  • Legitimate interests: to secure, operate, troubleshoot, and improve the Service, balanced against your rights.
  • Consent: where you grant device permissions or where consent is otherwise required. You may withdraw consent at any time.
  • Legal obligation: to meet tax, accounting, law-enforcement, and regulatory requirements.

6. AI processing

When you use an AI feature, Cruxl sends the information needed for that request to Google Gemini, which may include prompts, text, audio, files, images, and relevant map context. Provider processing, safety logging, retention, and use depend on the service configuration and the provider terms that apply at the time.

Do not submit information you are not authorized to disclose. Avoid highly sensitive information unless it is necessary for your use and you accept the associated processing risk. We do not use AI output to make solely automated decisions that produce legal or similarly significant effects about you.

7. How we disclose information

  • Service providers: companies that provide infrastructure, authentication, storage, AI processing, payments, and site delivery. See our Subprocessors page.
  • People you authorize: collaborators, invitees, and anyone who can access a public or shared link you create.
  • Legal and safety recipients: authorities or other parties when reasonably necessary to comply with law, respond to lawful process, enforce agreements, or protect rights and safety.
  • Business transactions: advisers, counterparties, or successors involved in a financing, acquisition, reorganization, or sale, subject to appropriate confidentiality protections.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising and do not use third-party advertising cookies.

8. Retention

We retain personal information for as long as reasonably necessary to provide the Service, maintain legitimate business and security records, resolve disputes, and meet legal obligations. Retention varies by data type. Account content generally remains until you delete it or your account.

Account deletion initiates deletion of active account records and uploaded files under Cruxl's control. Limited information may remain temporarily in backups, provider systems, security logs, transaction records, or records we must retain by law. Content copied or exported by collaborators cannot be deleted by Cruxl.

9. Your choices and rights

  • Access and update account information in the Service.
  • Delete maps, documents, recordings stored on your device, or your account.
  • Cancel a subscription through Account Settings and the Stripe customer portal.
  • Control microphone and file permissions through your browser or device settings.
  • Manage sharing settings and remove collaborators where the feature allows.
  • Request access, correction, deletion, portability, restriction, or objection where applicable law provides those rights.
  • Withdraw consent and lodge a complaint with your local data-protection authority where applicable.
  • Appeal our response to a privacy request where applicable state law provides an appeal right.

Submit a request to contact@cruxl.app. We may verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising privacy rights.

10. Cookies and local storage

Cruxl uses authentication storage, a functional sidebar cookie, local storage, and similar device technologies needed for login, preferences, drafts, offline recordings, and core functionality. We do not currently use third-party advertising or behavioral analytics cookies. Read the Cookie and Local Storage Notice.

11. Security

We use administrative and technical safeguards designed to protect information, including transport encryption, access controls, private storage configurations, and database authorization policies. No system is completely secure, and we cannot guarantee absolute security. See our Security page.

12. International transfers

Cruxl and its providers may process information in the United States and other countries. Where required, we rely on recognized transfer mechanisms or other lawful safeguards. Privacy protections may differ from those in your home jurisdiction.

13. Children

Cruxl is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a person under 18 has provided personal information, contact us so we can investigate and delete it where appropriate.

14. Changes to this Policy

We may update this Policy as the Service, providers, or law changes. We will update the date above and provide additional notice before material changes take effect when required.

15. Contact

Contact Cruxl at contact@cruxl.app for privacy questions or requests.