Privacy Policy
Last updated: 12 August 2026
This Privacy Policy describes how Crewmate ("we", "us", "our") collects, uses, and shares information when you use our products and services. By using Crewmate, you agree to the practices described here.
Information we collect
We collect information you provide directly, information collected automatically as you use the product, and information from third parties (e.g. payment processors).
- Account data — name, email address, password (stored hashed), and avatar.
- Workspace data — the name and configuration of any workspaces you create or join, plus content you and your team create inside them (agents, knowledge bases, chat transcripts, etc.).
- Usage data — pages visited, features used, IP address, device and browser information, and timestamps.
- Billing data — handled by our payment processor (Stripe). We store invoice metadata but never see full card numbers.
How we use information
We use the information we collect to:
- Provide, maintain, and improve the product.
- Respond to your support requests and communicate about your account.
- Analyse usage to develop new features and improve existing ones.
- Comply with legal obligations and enforce our terms.
Sharing information
We do not sell your personal information. We share information only with: service providers acting on our behalf (hosting, email, analytics, payments), other users in your workspace when you take actions visible to them, and authorities when required by law.
Data retention
We keep your data for as long as your account is active. After account deletion, most data is removed within 30 days; some records (billing, audit logs) may be retained longer where required by law.
Your rights
Depending on where you live, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correct — ask us to fix data that is inaccurate.
- Delete — ask us to delete your account and associated personal data.
- Export — request a portable copy of your data.
Security
We use industry-standard safeguards (encryption in transit, password hashing with Argon2id, session controls). No system is perfectly secure, however, and we cannot guarantee absolute security.
Google Workspace data and Limited Use
When you connect a Google account, Crewmate requests the Google Calendar scope (https://www.googleapis.com/auth/calendar) alongside basic sign-in scopes (openid, email). We request Calendar access so that our AI workers can read your availability and create, update, or cancel appointments on your behalf when you ask them to. This is the narrowest scope that supports those read-and-write scheduling actions; no Gmail, Drive, Contacts, or Photos scopes are requested.
- Crewmate's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
- We access your Google Calendar data only to provide and improve user-facing features that you have explicitly requested — viewing availability and managing appointments. We do not use it for advertising, profiling, or any purpose you did not ask for.
- We do not sell Google user data, and we do not transfer it to third parties except as needed to provide the features you requested, to comply with applicable law, or as part of a merger or acquisition with prior notice.
- No human at Crewmate reads your Google Calendar data, except with your explicit consent for a support request we are actively handling, for security investigations, or where required by law.
- Google Calendar content is fetched on demand to answer your request and is not copied into a permanent Crewmate store. We retain only the OAuth tokens needed to keep the connection alive, encrypted at rest.
- You can disconnect Google at any time from your workspace Integrations settings, or from your Google Account permissions page at myaccount.google.com/permissions. Disconnecting deletes the stored tokens immediately.
AI and your data
Crewmate's AI workers are powered by third-party large language models. To answer a request that involves your calendar, the relevant calendar details are sent to the configured model provider as part of the prompt for that single request.
- We never use, transfer, or sell Google user data — raw, aggregated, anonymised, or derived — to develop, train, improve, or fine-tune any generalised or foundational AI or ML model, whether our own or a third party's.
- We use model providers under their enterprise or paid API terms, which contractually exclude API inputs and outputs from provider model training by default. We do not enable any opt-in setting that would allow training on submitted data.
- Where a workspace is configured to use a self-hosted or offline model, that model runs inside our own isolated infrastructure. Google user data is processed locally and is never transmitted back to the model's original provider for training or any other secondary purpose.
- We do not send Google user data to any AI service that retains it for training. Where a provider offers zero-data-retention or no-training controls, we enable them.
- AI output may be incorrect. Please review any appointment an AI worker creates or changes before relying on it.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email or in-product notice. Continued use of the product after changes constitutes acceptance.
Contact us
Questions about this policy or about your data? Email us at anbunaturalsclinic@gmail.com.
This is placeholder content provided for development purposes only. It is not legal advice and must be replaced with a policy reviewed by qualified legal counsel before production use.
