Trust · Transparency

Transparency

Subprocessors, regional data flow, and our retention schedule — audited and updated as our infrastructure changes.

Subprocessors

A subprocessor is a third-party vendor that may process customer data on RunMyCrew’s behalf. We use the minimum viable set. Each has a Data Processing Agreement in place.

VendorServiceData processedRegionDPA
DigitalOceanVPS hosting + block storageAll product data (in-memory + at-rest disk).EU (Frankfurt)link
CloudflareDNS + TLS edge + bot mitigationIP address, request metadata. No request body inspection.Global edgelink
GitHubSource code repository + container registry (GHCR)Source code + built container images. No customer data.USlink
StripePayment processingEmail, name, card details (held by Stripe — never on our servers).US / EUlink
Google (LLC)Optional: Google Sign-In OIDC, Gemini LLM (Crew AI), connected-account APIsOpenID profile fields; LLM prompts only when Crew AI uses Gemini; user data only via connectors you authorized.US / EUlink
AnthropicOptional: Claude LLM (Crew AI)LLM prompts only when Crew AI uses Claude. Anthropic does not train on API inputs by default.USlink
OpenAIOptional: GPT LLM (Crew AI)LLM prompts only when Crew AI uses GPT. API inputs are not used for training.USlink
Meta PlatformsOptional: Meta API (Facebook / Instagram / WhatsApp / Ads)Only data your workflows explicitly read or write.US / EUlink
Sentry / GlitchTip (optional)Error trackingStack traces, request paths, sanitized error context. No request bodies.EU (self-hosted on same VPS when GLITCHTIP_DSN unset)link

When we add or change a subprocessor we publish the change here at least 30 days in advance. Object via privacy@runmycrew.com.

Data retention schedule

Data classRetentionAfter retention
Account profileWhile account is activeDeleted within 30 days of account deletion
Workflow definitions, knowledge basesWhile account is activeDeleted on user action / account deletion
Run history (free)7 daysHard-deleted
Run history (pro)30 daysHard-deleted
Run history (enterprise)Configurable, up to 1 yearHard-deleted
OAuth tokens, API keysUntil disconnected by userEncryption key destroyed
Operational logs (IP, UA, request path)30 daysRolled off automatically
Encrypted database backups14 days rollingOverwritten
Invoices (tax compliance)Up to 10 years per jurisdictionRetained for legal obligation only
Support correspondence24 monthsDeleted

Where data is processed

The primary production region is the European Union (Frankfurt). LLM API calls reach the provider’s nearest region (typically US). Meta and Google API calls follow the connected account’s home region.

Disclosed incidents

None to date. Any future incident that meaningfully affects customer data will be disclosed here and notified to affected users by email within 72 hours of discovery, as required by GDPR Art. 33.

Government & law-enforcement requests

None to date. If we receive a request that requires us to hand over customer data, we will notify the affected customer immediately unless legally prohibited.

Contact

Privacy / DPA / subprocessor questions: privacy@runmycrew.com