Privacy policy
Last updated: [date of publication]
Who we are
CRM For AI is operated by [legal entity name], [registered address], [company registration number] (“we”). Contact us about privacy at privacy@crmfor.ai. [EU/UK representative, if required]
Two kinds of data, two roles
- Your CRM records (contacts, companies, deals, notes, templates and the people in them). You decide what goes in; we store and process it on your instructions. For this data you are the controller and we are your processor.
- Your account data (who you are as our customer, your plan, billing and how you use the product). For this data we are the controller.
What we collect
Account and sign-in
- Your email address (to sign you in with one-time codes and to send account notices) and, if you give it, your name.
- The workspaces you belong to, your role in each, and invitations you send or receive.
- The assistants you connect (their name and when they connected) and the access you granted them.
- Sign-in and security records: when you signed in, a one-way hash of your IP address, used to limit abuse, and an audit trail of account changes.
Billing
When you buy a plan, Stripe collects your payment details and billing address; we never see full card numbers. We keep the plan, subscription status, invoice references and refund records.
Your CRM records
Whatever you or your assistant store: contacts, companies, deals, timeline notes, tags, lists, custom fields, message templates and files you upload for import. This often includes personal data about other people (your contacts). You are responsible for having a lawful basis to store it.
Text your assistant records from your email
CRM For AI never reads your mailbox and never sends email to your contacts. If you connect your email to your AI assistant and ask it to record something, the text your assistant chooses to record (for example a summary of a thread, a contact's address or a reply) reaches CRM For AI as ordinary record text, like anything else you store.
Email examples require connecting your email account (for example Gmail or Outlook) to your AI assistant. CRM For AI never reads or sends email itself; your assistant reads your mail and records what you ask it to in CRM For AI.
Feature requests
When CRM For AI can't do something, your assistant may send us a feature request describing what you wanted. We keep its text with your account so we can follow up. If you delete your account, we keep the request for counting: its one-line summary stays, while its details, any quote from you and anything that links it to you are removed. Please keep personal details out of feature requests.
Usage data
We count how the product is used: which tools are called, which screens and reports are opened, imports and exports, plan limits reached, and errors. These events carry identifiers, categories and numbers only, never names, email addresses, record text or the values you searched for. Product analytics use a pseudonymous account id. Our website sets no cookies and runs no analytics or advertising scripts.
Support
If you email us, we keep the conversation to help you.
Why we use it
| Purpose | Data | Legal basis [confirm] |
|---|---|---|
| Provide the service: sign-in, your workspace, tools, screens, imports and exports | Account data, CRM records | Contract |
| Billing and tax | Billing data | Contract; legal obligation |
| Account emails (codes, invitations, export links, limit and billing notices) | Email address | Contract |
| Security, abuse prevention and audit | Sign-in and security records | Legitimate interests |
| Improving the product | Usage data, feature requests | Legitimate interests |
We do not sell personal data, share it for advertising, or use your CRM records to train AI models.
Who receives it
- Our sub-processors, listed with their roles on the security page: Cloudflare (hosting and storage), Stripe (payments), Resend (email delivery) and, only when usage analytics are enabled, Google BigQuery (pseudonymous usage events). Planned changes are listed there too (sending our emails through Google Workspace, and automated support), and we will give notice before any of them starts.
- Your AI assistant. When you ask your assistant something, CRM For AI returns the requested records to that assistant. The assistant's provider (for example OpenAI or Anthropic) handles that conversation under its own terms and privacy policy; it is your choice of tool, not our sub-processor.
- People in your workspace see the workspace's records according to their role.
- Authorities, when the law requires it.
- A successor business. If CRM For AI or the business that runs it is sold, merged or transferred, accounts and data may pass to the successor, who must keep the commitments in this policy. We will email account owners at least 30 days before the transfer takes effect; export and deletion stay available throughout.
Where it is stored
With our hosting provider, Cloudflare. We do not choose a country for each account's database today: Cloudflare places it, usually near where the account is first used, so it may be outside your country. The account directory and stored files are kept with a location hint for eastern North America, which Cloudflare treats as a preference, not a guarantee. [transfer mechanism for EU/UK users, e.g. Standard Contractual Clauses / Data Privacy Framework] Choosing storage in the European Union is planned for v1.1.
We keep no backups of our own. Cloudflare's point-in-time recovery lets us restore a database to any moment in the last 30 days; that is the only copy beyond the live data.
How long we keep it
| Data | Kept |
|---|---|
| CRM records | Until you delete them. Deleted records stay in a trash for 30 days, then are erased. |
| Your whole account | Until you delete it. Deletion runs 30 days after you ask (cancellable until then) and removes the database, files, connections, sessions and usage records. Point-in-time recovery copies of the databases expire up to 30 days after that, so nothing restorable remains about 60 days after you ask. |
| Files uploaded for import | About one day. |
| Exports | Download links work for 24 hours; the files are erased after 7 days. |
| Activity log of changes in your workspace | One year. |
| Account page sessions | Up to 7 days (24 hours without use); the record of an ended session is deleted a day later. |
| Sign-in codes and failed sign-in attempts (with the email address entered, also when no account exists) | 7 days. |
| Usage data | Daily counts per account: 13 months, then folded into product-wide counts with no account in them, which are kept. Detailed events, when usage analytics are enabled: kept indefinitely under a salted, one-way hash of the account id, and deleted within a week after your account is deleted. |
| Billing and refund records | As long as tax and accounting law requires [period], also after account deletion. |
| Security and audit records | [period]; after account deletion they are kept without your account or user id. |
| Feature requests | Kept. When you delete your account, the details, any quote and the link to you are removed; the one-line summary stays. |
| Support emails | [period] |
Your choices and rights
- See and take your data: export contacts, companies, deals, notes and templates any time on any plan; the account owner can request a full export from the account page.
- Correct it: ask your assistant to change any record.
- Delete it: delete any record, or your whole account from the account page.
- Disconnect assistants from the account page.
- Depending on where you live, you may also have the right to object, to restrict processing and to complain to a data protection authority. To exercise any right, email privacy@crmfor.ai.
- If you are a contact stored in someone else's CRM For AI workspace, please contact that person or business first; we will help them respond.
Cookies
The website sets no cookies. Signing in and the account page use strictly necessary cookies only: a short-lived sign-in cookie and, on the account page, a session cookie (up to 7 days). No analytics or advertising cookies.
Children
CRM For AI is a business tool and is not meant for children under [16].
Changes
We will post changes here and email account owners about material ones before they take effect.
Contact
Privacy: privacy@crmfor.ai. Everything else: support@crmfor.ai. Postal address: [registered address].