Draft: this privacy policy is awaiting legal review. It describes what CRM For AI actually does today, but it is not final and is not yet in force. Items marked like this are placeholders still to be filled in.

Privacy policy

Last updated: [date of publication]

Who we are

CRM For AI is operated by [legal entity name], [registered address], [company registration number] (“we”). Contact us about privacy at privacy@crmfor.ai. [EU/UK representative, if required]

Two kinds of data, two roles

What we collect

Account and sign-in

Billing

When you buy a plan, Stripe collects your payment details and billing address; we never see full card numbers. We keep the plan, subscription status, invoice references and refund records.

Your CRM records

Whatever you or your assistant store: contacts, companies, deals, timeline notes, tags, lists, custom fields, message templates and files you upload for import. This often includes personal data about other people (your contacts). You are responsible for having a lawful basis to store it.

Text your assistant records from your email

CRM For AI never reads your mailbox and never sends email to your contacts. If you connect your email to your AI assistant and ask it to record something, the text your assistant chooses to record (for example a summary of a thread, a contact's address or a reply) reaches CRM For AI as ordinary record text, like anything else you store.

Email examples require connecting your email account (for example Gmail or Outlook) to your AI assistant. CRM For AI never reads or sends email itself; your assistant reads your mail and records what you ask it to in CRM For AI.

Feature requests

When CRM For AI can't do something, your assistant may send us a feature request describing what you wanted. We keep its text with your account so we can follow up. If you delete your account, we keep the request for counting: its one-line summary stays, while its details, any quote from you and anything that links it to you are removed. Please keep personal details out of feature requests.

Usage data

We count how the product is used: which tools are called, which screens and reports are opened, imports and exports, plan limits reached, and errors. These events carry identifiers, categories and numbers only, never names, email addresses, record text or the values you searched for. Product analytics use a pseudonymous account id. Our website sets no cookies and runs no analytics or advertising scripts.

Support

If you email us, we keep the conversation to help you.

Why we use it

PurposeDataLegal basis [confirm]
Provide the service: sign-in, your workspace, tools, screens, imports and exportsAccount data, CRM recordsContract
Billing and taxBilling dataContract; legal obligation
Account emails (codes, invitations, export links, limit and billing notices)Email addressContract
Security, abuse prevention and auditSign-in and security recordsLegitimate interests
Improving the productUsage data, feature requestsLegitimate interests

We do not sell personal data, share it for advertising, or use your CRM records to train AI models.

Who receives it

Where it is stored

With our hosting provider, Cloudflare. We do not choose a country for each account's database today: Cloudflare places it, usually near where the account is first used, so it may be outside your country. The account directory and stored files are kept with a location hint for eastern North America, which Cloudflare treats as a preference, not a guarantee. [transfer mechanism for EU/UK users, e.g. Standard Contractual Clauses / Data Privacy Framework] Choosing storage in the European Union is planned for v1.1.

We keep no backups of our own. Cloudflare's point-in-time recovery lets us restore a database to any moment in the last 30 days; that is the only copy beyond the live data.

How long we keep it

DataKept
CRM recordsUntil you delete them. Deleted records stay in a trash for 30 days, then are erased.
Your whole accountUntil you delete it. Deletion runs 30 days after you ask (cancellable until then) and removes the database, files, connections, sessions and usage records. Point-in-time recovery copies of the databases expire up to 30 days after that, so nothing restorable remains about 60 days after you ask.
Files uploaded for importAbout one day.
ExportsDownload links work for 24 hours; the files are erased after 7 days.
Activity log of changes in your workspaceOne year.
Account page sessionsUp to 7 days (24 hours without use); the record of an ended session is deleted a day later.
Sign-in codes and failed sign-in attempts (with the email address entered, also when no account exists)7 days.
Usage dataDaily counts per account: 13 months, then folded into product-wide counts with no account in them, which are kept. Detailed events, when usage analytics are enabled: kept indefinitely under a salted, one-way hash of the account id, and deleted within a week after your account is deleted.
Billing and refund recordsAs long as tax and accounting law requires [period], also after account deletion.
Security and audit records[period]; after account deletion they are kept without your account or user id.
Feature requestsKept. When you delete your account, the details, any quote and the link to you are removed; the one-line summary stays.
Support emails[period]

Your choices and rights

Cookies

The website sets no cookies. Signing in and the account page use strictly necessary cookies only: a short-lived sign-in cookie and, on the account page, a session cookie (up to 7 days). No analytics or advertising cookies.

Children

CRM For AI is a business tool and is not meant for children under [16].

Changes

We will post changes here and email account owners about material ones before they take effect.

Contact

Privacy: privacy@crmfor.ai. Everything else: support@crmfor.ai. Postal address: [registered address].