Privacy policy
Last updated: 5 October 2026
The short version
- Our account server keeps your account (name, email, a hash of your password), your sign-ins, and a log of account and computer events.
- What you do in DeepCrew lives on your own computer in the EU. We don't look at it, unless you let our support team in for a while.
- Your AI provider and the apps you connect get what your bots send them, directly from your computer, under your own accounts.
- No analytics, no ad trackers, and no cookie banner, because we only use the cookies the site needs to work.
- We don't sell your data, and we don't use it to train AI.
- You can delete your account and your computer at any time. For anything else, write to privacy@deepcrew.so.
1. Who's responsible
DeepCrew Cloud is run by Tawhid Joarder, who is responsible for (the “controller” of) the personal data this policy describes. Write to privacy@deepcrew.so about anything in it.
What you put on your DeepCrew computer is up to you. If you use DeepCrew for a business and handle other people's personal data with it, for example in emails your bots read, you're the controller of that data. We host it for you and handle it only as our terms and this policy describe. If your business needs a separate data processing agreement, write to us.
2. What our account server keeps
| What | Why | Legal basis |
|---|---|---|
| Your account: name, email address, a hash of your password (never the password itself), whether your email is verified, which invite you came in with (never the code itself) | To give you an account and a computer, and to email you about them | Our contract with you |
| Sign-ins: for each session, the IP address and browser (user agent) it started from, and when | To keep you logged in, and to spot sign-ins that aren't yours | Our contract with you, and our legitimate interest in keeping accounts safe |
| Sign-in protection: the IP address of recent attempts, with a count | To slow down password guessing | Our legitimate interest in keeping accounts safe |
| The waitlist: your email address and when you joined | To invite you when there's room | Your consent (you asked to join) |
| An audit log of account and computer events, such as signing in, opening your DeepCrew, your computer being set up, restarted or deleted, and support grants and visits | To run your computer, investigate problems and keep a record of who did what | Our legitimate interest in security and in resolving disputes |
| Your computer's status: running or not, its DeepCrew version, disk and memory use | To keep it running and bring it back if it stops | Our contract with you |
| Support grants: when you let support in, until when, and when it ended | So support can only enter while you allow it, and you can see every visit | Our contract with you |
| Emails you send us | To answer you | Our legitimate interest in helping you |
Our servers also keep short technical logs to run and protect the service, which can include IP addresses.
We email you only about your account and the service: your invite, verifying your email, resetting your password, changes to our terms, and plans and prices before the beta ends.
We don't sell personal data, we don't use it for advertising, and we don't use your data to train AI models. We don't make automated decisions about you that have legal or similar effects.
3. What's on your computer
Your DeepCrew computer holds everything your DeepCrew does: your chats, files, uploads, your bots' instructions and memory, routines, and the sign-ins and keys for the services you connect. Sign-ins and keys are sealed in a vault on your computer, and your bots never see them.
The key that opens the vault is kept, sealed, on our account server, so that your computer can start again after a restart. It reaches your computer only in memory, encrypted for that start, and is never written to your computer's disk. We never use it to open your vault.
We don't read what's on your computer. The only ways in for us are a support visit you allow (see section 6) and what the law requires.
4. Who else handles it for us
These companies process personal data on our behalf, under contracts that limit them to doing so for us:
| Company | What for | Where |
|---|---|---|
| Boat (boat.dev) | Runs your DeepCrew computer, and everything on it | EU (Germany, Finland or France) |
| Hetzner | Runs our account server, its database and our website | EU (Germany) |
| Cloudflare | Sits in front of deepcrew.so: every request to the site and to your DeepCrew passes through its network on the way (it secures the connection and keeps attacks away), so it handles what those requests carry, including your sign-in. It also keeps copies of our account database backups (encrypted at rest, kept 30 days), and passes emails you send to our addresses on to us | Global network; backups in the EU. Cloudflare is a US company |
| Resend | Sends our emails (invites, verification, password resets, notices), so it receives your email address and those messages | United States |
| Cloudflare Turnstile | If it's switched on, checks that a person and not a bot is signing up or resetting a password. It sees your IP address and signals from your browser during the check | Global network; Cloudflare is a US company |
When paid plans start, we'll add our payment provider here before we take any payment.
5. Services you choose
Some companies get data because you connect them, not because we use them. They receive it directly from your own computer, under your own account with them, and their terms and privacy policies apply:
- Your AI provider. When your bots work, your computer sends your messages, files and the results of their tools to the AI you chose: Anthropic for Claude, or OpenAI for ChatGPT. Your account's settings with them decide how they keep and use it, including for training. We don't receive or store that traffic.
- The apps you connect, such as Notion or Linear, see what your bots read and do there.
- Composio, if you add your own Composio key: apps you connect through it pass their sign-ins and data through Composio.
- Websites your bots visit in the browser on your computer see that visit as they would any other.
6. Support access
Our support team can't see your DeepCrew unless you let them in. On your account page you can let support in for an hour or a day, and end it early at any time. While a grant lasts, a member of our team can open your DeepCrew to help you. Your DeepCrew shows a banner while they're in, and records what they change and which kinds of pages they view. We log each visit: who, when, and the reason they gave. You can see every grant and visit on your account page.
7. Cookies
We use only what the site needs to work:
- Our sign-in cookie keeps you logged in to your account. It lasts until you log out, or 14 days after you last use it.
- Your DeepCrew, at deepcrew.so/app, keeps its own sign-in and your display choices (such as which tab was open) in your browser's storage.
- Cloudflare Turnstile, if it's switched on, may store what its bot check needs while you sign up or reset a password.
- Cloudflare may set a security cookie (such as
__cf_bm) that helps it tell people from bots. It lasts minutes and isn't used to track you.
We use no analytics, no advertising and no tracking cookies. Because everything above is strictly necessary for the service you asked for, there's no cookie banner to click through.
8. Where your data is
Your computer runs in the EU, and so do our account server and its backups. Requests to deepcrew.so pass through Cloudflare's worldwide network, usually through a data centre near you, and Resend (email) and Cloudflare are US companies, so the data they handle may be processed outside the EU. Those transfers rely on the safeguards the GDPR requires, such as the EU's Standard Contractual Clauses or the EU–US Data Privacy Framework.
9. How long we keep it
- Your account and your computer: until you delete your account.
- Session records: deleted once the session ends: when you log out, or 14 days after you last use it.
- Your account history (the sign-ins and changes shown on your account page): a year.
- Sign-in protection counts: about a minute.
- The waitlist: until you sign up, or until you ask us to take you off it.
- Backups: roll off within 30 days.
- The audit log: as long as it's needed to keep the service secure and to resolve disputes. It holds no content from your computer.
When you delete your account, we delete your computer and everything on it, and your account. We keep only a minimal audit record of what happened to your account, with no content, for security. Backups that still hold your data roll off within 30 days.
10. Your rights
Under the GDPR and similar laws, you can:
- Delete your account on your account page (we'll ask for your password). That deletes your computer, everything on it, and your account.
- Take your data with you. You can download the files your bots made from DeepCrew. A one-click export of everything isn't built yet; until it is, write to support@deepcrew.so and we'll help you get it.
- See, correct or limit what we hold about you, object to how we use it, or withdraw your consent (for example, to leave the waitlist): write to privacy@deepcrew.so.
- Complain to the data protection authority where you live or work. We'd like the chance to help first, though.
We answer within one month. We may ask you to confirm who you are first, usually by writing from the email address on your account.
11. How we protect it
- Every connection to deepcrew.so is encrypted.
- Passwords are stored only as a hash.
- Each customer has a computer of their own, which isn't shared with anyone.
- Sign-ins and keys for your apps are sealed in your computer's vault, and your bots use your apps through DeepCrew without seeing them.
- Our own admin tools aren't reachable from the internet, and entering your DeepCrew takes your grant.
No system is perfectly secure. If a breach puts your personal data at risk, we'll tell you and the authorities as the law requires.
12. Children, and changes
DeepCrew isn't for children. You must be at least 18 to use it, and we don't knowingly collect data from anyone younger.
We'll update this policy when what we do changes, and change the date at the top. If a change matters to you, we'll email you before it takes effect.
Privacy questions and requests: privacy@deepcrew.so. Everything else: support@deepcrew.so.