Privacy
Crewly Privacy Policy
Effective May 31, 2026. Crewly Labs, Inc. (“Crewly,” “we”) operates the Crewly AI assistant for Slack. This policy explains what we collect, why, how long we keep it, and who we share it with. Email 404kidwiz@gmail.com with any question.
1. What we collect
Slack workspace data. When a user @-mentions Crewly, Slack sends us the message text, the channel/user/team IDs, and the message timestamp. We do not read channels Crewly was not invited to, and we do not receive messages that do not mention Crewly directly (or that are not in a DM with Crewly).
OAuth tokens. When your workspace installs Crewly, Slack issues us a bot token. We store it encrypted at rest (Fernet, AES-128-CBC + HMAC) and decrypt it only in memory for the request that needs it. It is never logged or sent to any third party.
Memory you ask us to keep. When a user writes @Crewly remember: …, we store that text as a memory chunk plus a vector embedding. Memory is scoped to one workspace by Postgres row-level security. You can delete a memory at any time; deletes are immediate from primary storage.
Account & identity (web app). If you sign in to crewly.live, Clerk handles authentication and stores your email, name, organization membership, and role. We receive a session token; we do not see your password.
Billing (if you pay). Stripe stores your card, address, and invoice history. We receive a Stripe customer ID, subscription status, plan, seat count, and billing-period dates. We never see card numbers.
Operational telemetry. For each Crewly turn we log: which skill ran, whether the model needed a human, the token usage and cost in cents, and a timestamp. We do not log the message text, the model output, or any memory in telemetry.
Error reports. When the service crashes, Sentry captures a stack trace and request metadata. We scrub message contents and tokens before they leave the process.
2. Why we collect it
- To answer your @-mentions (the product itself).
- To remember what your team asked us to remember.
- To enforce per-workspace usage caps and kill-switch settings (cost control).
- To bill your subscription accurately (seat count, plan).
- To detect and fix bugs (error reports, latency traces).
We do not sell your data. We do not use it for advertising. We do not profile you.
3. How long we keep it
- Memory chunks: until you delete them or close the workspace account.
- Conversation history (Slack thread context we keep for follow-ups): 90 days, then purged.
- Telemetry & usage events: 12 months (for billing audit + capacity planning), then aggregated and the row-level data deleted.
- Error reports: 30 days.
- OAuth tokens: for the lifetime of your installation; deleted within 7 days of uninstall.
- Billing records: 7 years (US tax/accounting requirement).
4. AI providers & no model training
To generate replies and embeddings, we send your message text to language model providers. Our contracts with these providers prohibit them from using your data to train models. Specifically:
- Anthropic (Claude Sonnet 4.6 + Haiku 4.5) — accessed directly or via OpenRouter with
data_collection=denyset on every call. - Voyage AI (voyage-3 embeddings) — no training on customer data per their terms.
- Tavily (web search, for the deep-research skill only) — query strings only; no workspace data sent.
5. Sub-processors
We use these companies to operate Crewly:
- Anthropic & OpenRouter — language model inference.
- Voyage AI — text embeddings for memory recall.
- Tavily — web search (deep-research skill).
- Neon — managed Postgres (US-East).
- Railway — application hosting (US compute).
- Vercel — web app hosting.
- Clerk — web authentication and organization membership.
- Stripe — billing and payment processing.
- Sentry — error monitoring.
We will add new sub-processors only when needed and will update this list. Paying customers can email 404kidwiz@gmail.com to receive notifications of sub-processor changes.
6. Your rights
- Access & export. Email us and we will return your workspace memory as Markdown + JSON.
- Delete. Delete any memory in-app, or email us to wipe the workspace. Deletion is purged from primary storage immediately and queued out of backups within 30 days.
- Correct. Memory contents are user-authored; you can edit or re-record any fact.
- Object / restrict. Uninstall Crewly from Slack to stop all processing.
- Portability. Exports use open formats. No vendor lock-in.
California (CCPA), EU (GDPR), and UK (UK-GDPR) residents have these same rights under those laws.
7. Security
TLS in transit. Postgres row-level security forces per-workspace isolation at the database. OAuth tokens encrypted at rest. Per-workspace usage caps + kill switch. Least- privilege Slack scopes. See Security & trust for the full posture and honest status of what we have not yet built (SOC 2 is in progress; SSO/DPA available on the Company plan).
8. Children
Crewly is built for workplace use and is not intended for children under 13. We do not knowingly collect data from anyone under 13.
9. International transfers
We process and store data in the United States. If you use Crewly from outside the US, your data crosses borders to be processed here.
10. Changes to this policy
We will post material changes to this page and update the effective date. For paying customers we will also email a primary admin at least 30 days before a material change takes effect.
11. Contact
Privacy: 404kidwiz@gmail.com
Security: 404kidwiz@gmail.com
Mailing address: Crewly Labs, Inc., Atlanta, GA, USA