01Who we are
crisp ("we", "us") is responsible for the personal information described in this policy. If you have a question or want to use your rights, write to us through our contact form.
02What we collect
- Account details: your name, email address and profile picture, and your username if you sign in with GitHub.
- What you build: your messages to crisp, files you upload, the code of your projects, the data stored in your apps, and their version history.
- Billing details: your plan, invoices and billing address. Card payments are handled by our payment provider; we never see or store your full card number.
- Usage: the requests you make, what each one cost, and errors that happened, so we can show your usage, keep crisp working and fix problems.
- Technical details: your IP address, browser and device type, and the times you used crisp, recorded in security and access logs.
- Messages you send us, for example support requests.
03How we use it
- To provide crisp: to sign you in, build and run your apps, keep versions, publish your apps and show your usage.
- To bill you for paid plans and keep the records the law requires.
- To keep crisp safe: to prevent fraud and abuse, such as phishing apps, and to protect your account.
- To support you when you ask for help.
- To improve crisp, using usage figures that are combined or do not identify you. We look at an individual project only when you ask us to, or to investigate abuse or a fault.
- To send you messages about your account and the service. We send product news only if you agree, and every such email has an unsubscribe link.
We do not sell your personal information, share it for advertising, or use it to build advertising profiles.
Where the law requires a legal basis, we rely on: the contract with you (to provide crisp and bill you), our legitimate interests (security, abuse prevention, improving crisp), your consent (product news), and legal obligations (tax and accounting records).
04AI models
When you ask crisp to build or change something, we send your instructions and the relevant parts of your project, such as code, error messages and the structure of your data, to AI model providers so they can produce a response.
Our agreements with these providers do not allow them to train their models on this content. They may keep it for a short time, usually no more than 30 days, to detect abuse, and then delete it. We do not train AI models on your private projects.
Avoid putting passwords or other secrets in chat messages. Add them in your project settings under Secrets, where they are encrypted and are not sent to AI models.
05Data in the apps you build
Apps you publish may collect information about their own users. For that information, you decide what is collected and why, and you are responsible for telling your users. We process it only on your behalf: to store it, run your app, keep versions and back it up. We do not use it for any other purpose.
If a user of your app contacts us about their data, we will refer them to you, unless the law requires us to act directly.
07International transfers
Our providers may process information in countries other than yours. When information leaves the European Economic Area, the United Kingdom or Switzerland, we use the legal safeguards that apply, such as the European Commission's standard contractual clauses.
08How long we keep it
- Account details: for as long as your account is open.
- Projects, versions and app data: until you delete them or your account. Version history is also limited by your plan.
- After you delete a project or your account, we remove it from the live service immediately and from backups within 30 days.
- Security and access logs: up to 90 days.
- Billing records: as long as tax and accounting law requires, usually up to 10 years.
- Support messages: up to 2 years after the conversation ends.
09How we protect it
Information is encrypted when it travels over the internet and when it is stored. Each project runs separately from every other project. Secrets are encrypted and only given to your app when it runs. Only the people at crisp who need access to do their work have it, and that access is logged.
If a security incident affects your personal information, we will tell you and the relevant authorities as the law requires.
10Your rights
Depending on where you live, you have the right to:
- See the personal information we hold about you, and get a copy.
- Correct information that is wrong.
- Delete your information.
- Take your information with you in a common format.
- Object to, or ask us to limit, some uses of your information.
- Withdraw consent you gave, such as for product news, at any time.
- Complain to your data protection authority.
You can export and delete most of your information yourself in your account settings. For anything else, write to us through our contact form. We answer within 30 days and do not charge for it.
12Children
crisp is not for children under 16, and we do not knowingly collect information from them. If you think a child has given us information, write to us and we will delete it.
13Changes to this policy
If we change this policy in a way that matters, we will email you before the change takes effect. The date at the top of this page shows when it last changed.
14Contact
Questions or requests about your privacy: our contact form.