Privacy Policy

Last Updated: May 14, 2026

At CrowdAI, your privacy matters. This policy describes exactly what data we collect, how we handle it, and your rights.

⚠️ Important AI Output Disclaimer

AI-generated responses on CrowdAI are for informational purposes only and do not constitute medical, legal, financial, psychological, or professional advice of any kind. Do not rely on AI outputs for decisions that require professional expertise. Always consult a qualified professional for such matters.

1. Introduction

CrowdAI ("CrowdAI," "we," "us," or "our") is operated by SAFTech LLC, a Virginia-based limited liability company. We are committed to protecting and respecting your privacy.

This Privacy Policy applies to all users of our Service — whether you access it through our website, mobile applications, or API — and explains how we collect, use, disclose, and safeguard your information.

Key Point: We are the data controller for the personal information we collect and process. We do not sell your personal information to third parties.

2. Information We Collect (Specific)

2.1 Account Data

  • Full name
  • Email address (e.g., the address used to sign in via Google OAuth)
  • Profile picture (from OAuth providers, if applicable)
  • Account preferences and settings (e.g., selected AI models, dark mode preference)
  • Role within the platform (user or admin)
  • Date of account creation

2.2 Usage & AI Interaction Data

  • Prompts and messages you send to AI models
  • Full conversation history (stored in our database)
  • AI model responses received
  • Models selected per conversation (e.g., GPT-4, Claude, Gemini)
  • Token counts per request and total tokens used
  • Credits consumed per session and overall
  • Estimated cost per interaction (for internal billing)
  • Workflows (AI chains) you create and execute
  • Workflow execution results and step-by-step outputs
  • Projects and organizational structures you create

2.3 Payment & Billing Data

  • Subscription tier (Free, Pro, Enterprise)
  • Billing cycle and payment status
  • Stripe Customer ID (a tokenized reference — we do not store full card numbers)
  • Transaction history and invoice records
  • Refund or dispute history

Payment card details are processed exclusively by Stripe and never stored on our servers.

2.4 Uploaded File Data

  • CSV and Excel files uploaded to the Data Analysis feature
  • Word documents and text files uploaded to the Presentation feature
  • File metadata (name, type, size, upload timestamp)
  • Extracted content from uploaded files for AI processing

See Section 5 for full details on file handling and retention.

2.5 Automatically Collected Data

  • IP address and approximate geographic location (country-level)
  • Browser type, version, and operating system
  • Device type and screen resolution
  • Pages visited and time spent on each page
  • Referring website or source
  • Session identifiers and authentication tokens
  • Error logs and diagnostic information
  • Feature usage (e.g., number of chats started, workflows run, presentations created)

2.6 Admin-Visible Analytics

Our admin panel collects and displays aggregated and per-user data including:

  • Per-user token and credit consumption
  • Estimated revenue and cost per user
  • Feature adoption metrics
  • Conversation counts and model usage breakdown
  • User registration and activity trends
3. How We Use Your Information
Service Provision
  • Operate and maintain the platform
  • Process AI requests and return responses
  • Track and enforce credit usage limits
  • Manage your account and subscription
  • Process payments and prevent fraud
  • Provide customer support
Service Improvement
  • Analyze usage patterns and trends
  • Develop new features
  • Fix bugs and improve performance
  • Test and optimize user experience
  • We do NOT use your prompts to train our own AI models
Communications
  • Send service-related notifications
  • Respond to your inquiries
  • Provide product updates (with consent)
  • Send security and system alerts
  • Notify you of policy changes
Legal & Security
  • Comply with legal obligations
  • Prevent fraud and abuse
  • Enforce our Terms of Service
  • Protect user safety and security
  • Respond to legal requests

GDPR Lawful Basis: We process your data based on: (a) contractual necessity (to provide the Service), (b) your consent (for marketing), (c) legitimate interests (analytics, security), and (d) legal obligations (financial records).

4. How Prompts Are Handled — Critical

What Happens When You Send a Prompt

Every prompt you submit is transmitted over encrypted HTTPS to one or more of the third-party AI providers listed below. This is the core function of our Service.

Transmission

Your prompts and conversation context are sent to the AI provider(s) you select at the time of the request. We cannot intercept or alter the provider's processing of your data once transmitted.

Storage

Yes — we store your prompts and AI responses in our database as part of your Conversation History (visible in the History tab). This is required to display your past conversations and support session continuity.

Retention Period

Conversations are retained indefinitely unless you delete them. You can delete individual conversations from your History page at any time. Account deletion triggers removal of all associated conversations within 90 days.

Model Training — We Do NOT Use Your Prompts

CrowdAI does not use your prompts, responses, or conversation history to train any AI models — our own or third-party. Your content is used solely to deliver the Service to you.

Third-Party Provider Training Policies

Each AI provider has its own data usage policy. Most major providers (OpenAI, Anthropic, Google, Mistral) do not use API-submitted data to train their public models by default, but this may vary. We strongly encourage you to review each provider's API data policy linked in Section 7.

Sensitive Prompts Advisory

Avoid submitting sensitive personal information (SSNs, passwords, health records, financial details) in prompts. We cannot guarantee how third-party providers will handle such data once transmitted.

5. Uploaded File Data

When you upload files through our Data Analysis or Presentation features, the following applies:

What Files We Receive

CSV, Excel (.xlsx), Word documents (.docx), and plain text files. We do not currently support files containing raw executables or password-protected archives.

Transmission to AI Providers

File contents (text extracted from your uploaded files) may be sent to third-party AI providers as part of processing your analysis or presentation request. This transmission is encrypted via TLS.

Storage Duration

Uploaded files are stored in our cloud infrastructure for the duration required to complete your request and for up to 30 days thereafter for caching and session recovery. After that, file binaries are purged. Extracted text or analysis results may be retained longer as part of your conversation or project history.

Deletion

You can request deletion of uploaded file data by contacting info@crowdai.io. Deleting your account also triggers deletion of associated file data within 90 days.

Advisory on Sensitive Files

Do not upload files containing confidential business data, personally identifiable information (PII), or proprietary information unless you have appropriate rights and understand that the content will be transmitted to third-party AI providers for processing.

6. Information Sharing and Disclosure

Our Core Commitment

We do not sell, trade, or rent your personal information to third parties. Ever.

6.1 AI Model Providers

Your prompts and file contents are shared with third-party AI providers to deliver the core Service. See Section 7 for a full list with privacy policy links.

6.2 Payment Processors

Billing details are processed by Stripe, Inc. We share only what Stripe needs to process payments and manage subscriptions.

6.3 Infrastructure & Analytics

We use cloud hosting and analytics services (see Section 15). These providers are bound by confidentiality agreements and may only process your data on our behalf.

6.4 Legal Requirements

We may disclose information in response to valid legal processes (subpoenas, court orders), government requests, or to protect the safety of our users or the public.

6.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.

7. Third-Party AI Providers

Your Prompts Are Sent to These Providers

When you use CrowdAI, your prompts are transmitted to one or more of the following AI providers depending on your model selection. Each provider has its own privacy policy and data handling practices.

Anthropic (Claude 3, Claude 3.5)

Privacy Policy: https://www.anthropic.com/legal/privacy

Google DeepMind (Gemini)

Privacy Policy: https://policies.google.com/privacy

API Data Policy: https://ai.google.dev/gemini-api/terms

Mistral AI

Privacy Policy: https://mistral.ai/terms/

Perplexity AI

Privacy Policy: https://www.perplexity.ai/privacy

DeepSeek

Privacy Policy: https://www.deepseek.com/en/privacy

xAI (Grok)

Privacy Policy: https://x.ai/legal/privacy-policy

What This Means for You:

  • All transmissions to providers are encrypted via TLS
  • We cannot control how providers retain or use your prompts
  • Most providers' API terms prohibit using API data for model training — but policies vary and may change
  • We recommend reviewing each provider's policy before submitting sensitive content
8. Admin Access to User Data

CrowdAI has an internal admin panel for authorized SAFTech LLC personnel (users with the admin role). Admins can access:

  • User account details: name, email address, registration date
  • Subscription tier and payment status
  • Token usage, credits consumed, and estimated cost per user
  • Aggregated conversation metrics (counts, dates, titles you set, model usage — not message bodies)
  • Feedback and support submissions

🔒 Prompt and message content

The admin analytics UI does not display the text of your prompts or AI replies. Only you can read full conversation content in your account. Admins may still have technical database access for security, abuse investigation, or legal compliance when required — such access is limited to authorized personnel and logged where feasible.

Access limitations

Admin privileges are granted only to authorized SAFTech LLC staff for operating the Service, support, billing, fraud prevention, and platform integrity. Contact privacy@crowdai.io for privacy-related questions.

9. Data Retention

Account Data

Retained while your account is active and for 90 days after deletion to allow recovery and prevent abuse.

Conversations & Prompts

Retained indefinitely unless you manually delete them from the History page. Account deletion triggers removal within 90 days.

Uploaded Files

File binaries are deleted after 30 days. Extracted analysis content or outputs may be retained as part of your project/conversation history.

Usage Logs & Analytics

Retained for 24 months for security, fraud prevention, and service improvement.

Financial Records

Retained for 7 years as required by applicable tax and financial regulations.

Backup Data

Deleted data may persist in encrypted backups for up to 90 days before being permanently purged.

To request early deletion of your data, contact us at info@crowdai.io. We will comply unless a legal obligation requires us to retain certain information.

10. Your Privacy Rights (GDPR & CCPA)

10.1 Rights for All Users

Access Your Data
Correct Your Data
Delete Your Data
Export Your Data
Opt-Out of Marketing
Object to Processing

10.2 EU/EEA Users — GDPR Rights

Right to Rectification

Correct inaccurate personal data without undue delay.

Right to Erasure

Request deletion of your data under GDPR Article 17.

Right to Restrict Processing

Limit how we process your data in specific situations.

Right to Data Portability

Receive your data in a structured, machine-readable format (JSON/CSV).

Right to Object

Object to processing based on legitimate interests or direct marketing.

Right to Withdraw Consent

Withdraw consent for consent-based processing at any time.

Right to Lodge a Complaint

File a complaint with your local data protection authority (DPA).

Data Protection Contact: info@crowdai.io

10.3 California Users — CCPA/CPRA Rights

Right to Know

Know what personal information we collect, use, disclose, and share.

Right to Delete

Request deletion of personal information we have collected.

Do Not Sell My Personal Information

We do not sell personal information. No opt-out action is needed.

Right to Non-Discrimination

Equal service and pricing regardless of your privacy choices.

Right to Correct

Correct inaccurate personal information.

Right to Limit Sensitive Data Use

Limit use of sensitive personal information.

How to Exercise Your Rights

Email info@crowdai.io with your request. We will respond within 30 days (or sooner as required by applicable law). Identity verification may be required.

11. Data Security & Breach Notification
Encryption
  • TLS 1.3 for all data in transit
  • AES-256 encryption for data at rest
  • Encrypted database backups
Access Controls
  • Role-based access control (RBAC)
  • Least privilege principle enforced
  • Admin access restricted to authorized staff

Breach Notification Commitment

  • GDPR users: We will notify affected EU users and the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.
  • CCPA/US users: We will notify affected users in an "expedient" manner, as required by applicable state law.
  • Notification will describe the nature of the breach, data affected, and steps taken.

Limitation: No method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to industry best practices.

Suspect a breach or account compromise? Contact us immediately at info@crowdai.io.

12. International Data Transfers

Our Service is operated from the United States. If you access CrowdAI from outside the US, your data will be transferred to, processed, and stored in the US and in countries where our infrastructure and AI providers operate.

EEA, UK, and Switzerland Users:

We ensure appropriate safeguards through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Other legally recognized transfer mechanisms
13. Cookies & Tracking Technologies

We use cookies and similar technologies to operate our Service. Analytics cookies (Google Analytics) are loaded only after you choose Accept all on our cookie banner. See our Cookie Policy for details.

Essential Cookies (Required)

Authentication tokens, session management, security features, user preferences. These cannot be disabled without breaking core functionality.

Analytics Cookies (Optional)

Google Analytics (with anonymized IP) to understand feature usage, page performance, and user flows. Used to improve the Service.

Marketing / Conversion Cookies (Optional)

May include conversion tracking pixels from advertising platforms to measure campaign effectiveness. These are only active if you came from a paid advertisement.

Managing Cookies

You can disable non-essential cookies via your browser settings. Blocking essential cookies may prevent you from signing in or using certain features.

EU/EEA users: Non-essential cookies are used only with your consent via the cookie banner. You may change your choice by clearing site data or using browser controls.

14. Children's Privacy (COPPA)

Age Requirement

CrowdAI is not directed at or intended for children under the age of 13 (or under 16 for users in the European Union). We do not knowingly collect, solicit, or process personal information from minors.

By using our Service, you represent and warrant that you are at least 13 years of age (or 16 if in the EU/EEA).

If you are a parent or guardian and believe your child has provided us with personal information, contact us immediately at info@crowdai.io. We will promptly delete that information from our systems upon verification.

15. Third-Party Services We Use

The following third-party services process data on our behalf or in conjunction with delivering the Service:

ServiceProviderPurpose
PaymentsStripe, Inc.Billing and subscription management
AI ProcessingOpenAIGPT-4 / GPT-4o model inference
AI ProcessingAnthropicClaude model inference
AI ProcessingGoogle DeepMindGemini model inference
AI ProcessingMistral AIMistral model inference
AI ProcessingPerplexity AIPerplexity model inference
AI ProcessingDeepSeekDeepSeek model inference
AI ProcessingxAIGrok model inference
Cloud HostingSupabase / AWSDatabase and file storage infrastructure
AnalyticsGoogle Analytics (GA4)Anonymized usage and performance analytics
AuthenticationGoogle OAuthSecure sign-in via Google accounts
EmailResend / SMTPTransactional email delivery (welcome, notifications)
16. Changes to This Privacy Policy

We may update this policy to reflect changes in our practices, legal requirements, or the services we offer.

How We Notify You:

  • Updated "Last Updated" date on this page
  • Email notification for material changes
  • In-app notice for significant changes
  • Re-acceptance required for fundamental changes affecting user rights

Continued use of the Service after changes constitutes acceptance of the updated policy.

17. Contact Information

For privacy questions, GDPR/CCPA requests (access, deletion, or portability), or other data concerns, email privacy@crowdai.io. For general support, email info@crowdai.io. We aim to respond within 30 days, or sooner where required by law.

Mailing address: SAFTech LLC, Virginia, United States.

EU residents may lodge a complaint with their local supervisory authority if they believe their data rights have not been respected.