Privacy Policy

Last updated: July 22, 2026

This Privacy Policy describes how Crewlet ("Crewlet", "we", "us", or "our") — the operator of the Crewlet platform at https://crewlet.io — collects, uses, discloses, and safeguards your information when you visit our website, use our autonomous multi-agent product, or connect third-party integrations (including Meta, Google, YouTube, GitHub, Slack, Stripe, and others). It applies to all users of Crewlet worldwide.

1. Who we are

Crewlet is an autonomous AI agent platform that connects to your existing business tools and runs day-to-day operations on your behalf. We are the data controller for personal information processed through the Crewlet website and product. You can reach us at hello@crewlet.io.

2. Information we collect

Account information. When you create an account we collect your name, email address, and authentication credentials provided by third-party OAuth providers such as Google or GitHub.

Usage data. We automatically collect information about how you interact with our service, including pages visited, features used, timestamps, and device/browser information.

Workspace data. Data you provide through connected integrations (e.g., Meta, Google, GitHub, Slack, PostHog, Stripe) is processed within your isolated workspace instance. We do not access workspace data except as necessary to provide the service or as required by law.

Meta Platform data. If you connect a Meta (Facebook / Instagram) Business account, we receive only the data scopes you explicitly grant — for example, ad account performance metrics, ad campaign metadata, and Page-level engagement information needed to run your Crewlet ads workflows. We do not request or store passwords. We do not sell, rent, or share Meta Platform data with any third party for advertising or marketing purposes outside of your own ad account.

Cookies & local storage. We use cookies and browser local storage for authentication, theme preferences, and product analytics.

3. How we use your information

4. Data sharing & disclosure

We do not sell your personal information. We may share it with:

5. Data security

Each workspace runs on an isolated compute instance with dedicated storage. We use encryption in transit (TLS) and at rest. OAuth tokens for connected services (including Meta, Google, YouTube, GitHub, and Slack) are stored encrypted at rest on our credential proxy and are never returned to your browser, never handed to the AI agent, and never exposed to other tenants or third parties. No method of transmission over the Internet is 100% secure, but we follow industry best practices.

6. Data retention & deletion

We retain account information for as long as your account is active. Workspace data is retained within your instance and deleted when you delete your workspace or account. You may request deletion of your data at any time by contacting hello@crewlet.io, or by following the step-by-step instructions on our Data Deletion page. We will delete or anonymize your data within 30 days of a verified request, unless retention is required by law.

7. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, email hello@crewlet.io. To revoke Crewlet's access to your Meta account, you can also visit Facebook Business Integrations and remove Crewlet.

8. Third-party services

Our service integrates with third-party platforms (Meta, Google, YouTube, GitHub, Slack, Stripe, PostHog, and others). Your use of these integrations is also subject to their respective privacy policies. We only access data from these services as authorized by you and only as necessary to provide our features.

When you connect a provider you choose a capability — read-only, publish, or full access — and Crewlet requests only the scopes that capability needs. The resulting OAuth token is stored encrypted at rest on our credential proxy and is injected server-side when we relay a call you initiated. The token is never returned to your browser and is never given to the AI agent; the agent can only ask the proxy to make a call on your behalf.

Google and YouTube user data — Limited Use

Limited Use. Crewlet's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the features you connected it for; it is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you; it is not used for advertising and is not used to develop, improve, or train generalized AI and/or ML models; and no human reads it except with your explicit consent for a specific support issue, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymized.

YouTube

The Crewlet YouTube connection uses YouTube API Services. By connecting a channel you additionally agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.

9. Children's privacy

Crewlet is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will delete it.

10. International transfers

Crewlet operates internationally. By using the service you consent to the processing of your data in jurisdictions where we, our service providers, or connected third-party platforms are located.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date above.

12. Contact us

If you have questions about this Privacy Policy or our data practices, please contact us at hello@crewlet.io.