Privacy Policy
Last updated: September 23, 2026
1. What this policy covers
This policy covers both the CloudCrane website and the CloudCrane platform, the signed-in application at /app where customers import and curate their own data.
2. Information we collect
From the website
- Contact form: your name, email address and message.
- Job application: your name, email address, any links you share, and the CV you upload.
From the platform
- Account: the name, email address and profile picture your Google account gives us when you sign in. We never receive your Google password.
- The data you upload. Records you import stay yours. We process them to run the enrichment you ask for, and for nothing else. We do not use them to train any model.
- Usage: which tools were called, when, and how long they took. Never the contents of a result.
3. How we use it
- To answer your enquiry or review your application.
- To run the platform: signing you in, running the enrichment you start, serving the tools you deploy, and applying the limits on your workspace.
- To keep the service secure and working, including rate limits and abuse prevention.
- To meet legal obligations.
4. Who we share it with
We do not sell, trade or rent personal information. We use these providers, and no others. All are outside India, so your data is transferred internationally and protected by the contractual terms we hold with each.
| Provider | What it does | What it sees |
|---|---|---|
| Replit | Hosting, the database and file storage | Everything the platform stores, including uploaded files and CVs |
| OpenAI | The model behind enrichment and semantic search | Only the columns you choose for a field, plus the allowed values of that field |
| Resend | Delivering form submissions to us by email | Contact messages, and job applications with the attached CV |
| Sign-in, and the fonts on this website | Your name, email and profile picture at sign-in; your IP address when the site loads its fonts |
When an enrichment run needs a model, only the columns you chose for that field are sent, never the whole record.
5. How long we keep it
| What | How long |
|---|---|
| Contact messages and job applications, including CVs | 12 months, then deleted automatically |
| Your platform account and the records you import | Until you delete them or ask us to close your workspace |
| Sign-in sessions | 30 days, and expired sessions are deleted |
| Half-finished imports | 24 hours |
| Call logs for the tools you deploy | 12 months |
| Webhook deliveries you set up (which event, when, and the receiver's answer) | 30 days |
6. Security
Each workspace is isolated twice over: a membership check on every request, and row-level security in the database itself, so one workspace cannot read another's even if a query has a bug. Credentials you connect are encrypted at rest, API keys are stored only as a hash, and logs redact sensitive fields before they are written. The controls we have built are listed on our Trust page.
We hold no third-party security certification today. When that changes, it will say so here and on the Trust page, and not before.
7. Cookies
We use no advertising, analytics or tracking cookies. Signing in to the platform sets one cookie, cc_session, which keeps you signed in for 30 days. It is httpOnly, so scripts cannot read it. Signing out deletes it. Your browser may also store a theme preference locally on your device; that never reaches us.
8. Your rights
You can ask us for a copy of your personal data, ask us to correct it, or ask us to delete it. Platform customers can export their records as CSV from the app at any time. For anything else, email support@cloudcrane.in and we will respond within 30 days.
9. Contact
Questions about this policy, or about how your data is handled, go to support@cloudcrane.in.