DeepCrew

Privacy policy

Last updated: 5 October 2026

The short version

1. Who's responsible

DeepCrew Cloud is run by Tawhid Joarder, who is responsible for (the “controller” of) the personal data this policy describes. Write to privacy@deepcrew.so about anything in it.

What you put on your DeepCrew computer is up to you. If you use DeepCrew for a business and handle other people's personal data with it, for example in emails your bots read, you're the controller of that data. We host it for you and handle it only as our terms and this policy describe. If your business needs a separate data processing agreement, write to us.

2. What our account server keeps

WhatWhyLegal basis
Your account: name, email address, a hash of your password (never the password itself), whether your email is verified, which invite you came in with (never the code itself)To give you an account and a computer, and to email you about themOur contract with you
Sign-ins: for each session, the IP address and browser (user agent) it started from, and whenTo keep you logged in, and to spot sign-ins that aren't yoursOur contract with you, and our legitimate interest in keeping accounts safe
Sign-in protection: the IP address of recent attempts, with a countTo slow down password guessingOur legitimate interest in keeping accounts safe
The waitlist: your email address and when you joinedTo invite you when there's roomYour consent (you asked to join)
An audit log of account and computer events, such as signing in, opening your DeepCrew, your computer being set up, restarted or deleted, and support grants and visitsTo run your computer, investigate problems and keep a record of who did whatOur legitimate interest in security and in resolving disputes
Your computer's status: running or not, its DeepCrew version, disk and memory useTo keep it running and bring it back if it stopsOur contract with you
Support grants: when you let support in, until when, and when it endedSo support can only enter while you allow it, and you can see every visitOur contract with you
Emails you send usTo answer youOur legitimate interest in helping you

Our servers also keep short technical logs to run and protect the service, which can include IP addresses.

We email you only about your account and the service: your invite, verifying your email, resetting your password, changes to our terms, and plans and prices before the beta ends.

We don't sell personal data, we don't use it for advertising, and we don't use your data to train AI models. We don't make automated decisions about you that have legal or similar effects.

3. What's on your computer

Your DeepCrew computer holds everything your DeepCrew does: your chats, files, uploads, your bots' instructions and memory, routines, and the sign-ins and keys for the services you connect. Sign-ins and keys are sealed in a vault on your computer, and your bots never see them.

The key that opens the vault is kept, sealed, on our account server, so that your computer can start again after a restart. It reaches your computer only in memory, encrypted for that start, and is never written to your computer's disk. We never use it to open your vault.

We don't read what's on your computer. The only ways in for us are a support visit you allow (see section 6) and what the law requires.

4. Who else handles it for us

These companies process personal data on our behalf, under contracts that limit them to doing so for us:

CompanyWhat forWhere
Boat (boat.dev)Runs your DeepCrew computer, and everything on itEU (Germany, Finland or France)
HetznerRuns our account server, its database and our websiteEU (Germany)
CloudflareSits in front of deepcrew.so: every request to the site and to your DeepCrew passes through its network on the way (it secures the connection and keeps attacks away), so it handles what those requests carry, including your sign-in. It also keeps copies of our account database backups (encrypted at rest, kept 30 days), and passes emails you send to our addresses on to usGlobal network; backups in the EU. Cloudflare is a US company
ResendSends our emails (invites, verification, password resets, notices), so it receives your email address and those messagesUnited States
Cloudflare TurnstileIf it's switched on, checks that a person and not a bot is signing up or resetting a password. It sees your IP address and signals from your browser during the checkGlobal network; Cloudflare is a US company

When paid plans start, we'll add our payment provider here before we take any payment.

5. Services you choose

Some companies get data because you connect them, not because we use them. They receive it directly from your own computer, under your own account with them, and their terms and privacy policies apply:

6. Support access

Our support team can't see your DeepCrew unless you let them in. On your account page you can let support in for an hour or a day, and end it early at any time. While a grant lasts, a member of our team can open your DeepCrew to help you. Your DeepCrew shows a banner while they're in, and records what they change and which kinds of pages they view. We log each visit: who, when, and the reason they gave. You can see every grant and visit on your account page.

7. Cookies

We use only what the site needs to work:

We use no analytics, no advertising and no tracking cookies. Because everything above is strictly necessary for the service you asked for, there's no cookie banner to click through.

8. Where your data is

Your computer runs in the EU, and so do our account server and its backups. Requests to deepcrew.so pass through Cloudflare's worldwide network, usually through a data centre near you, and Resend (email) and Cloudflare are US companies, so the data they handle may be processed outside the EU. Those transfers rely on the safeguards the GDPR requires, such as the EU's Standard Contractual Clauses or the EU–US Data Privacy Framework.

9. How long we keep it

When you delete your account, we delete your computer and everything on it, and your account. We keep only a minimal audit record of what happened to your account, with no content, for security. Backups that still hold your data roll off within 30 days.

10. Your rights

Under the GDPR and similar laws, you can:

We answer within one month. We may ask you to confirm who you are first, usually by writing from the email address on your account.

11. How we protect it

No system is perfectly secure. If a breach puts your personal data at risk, we'll tell you and the authorities as the law requires.

12. Children, and changes

DeepCrew isn't for children. You must be at least 18 to use it, and we don't knowingly collect data from anyone younger.

We'll update this policy when what we do changes, and change the date at the top. If a change matters to you, we'll email you before it takes effect.

Privacy questions and requests: privacy@deepcrew.so. Everything else: support@deepcrew.so.