Privacy Policy
What we collect, why, who else touches it, and how to make us delete it.
Effective 17 August 2026 · Last updated 17 August 2026
Who we are
RedCrown.ai is operated by Method Data Science LLC, a California limited liability company, trading as RedCrown.ai. We are the data controller for the personal information described here. Contact privacy@redcrown.ai for anything in this policy, including to request our postal address for formal correspondence.
What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Email address, password hash, workspace and role membership | To create your account, authenticate you, and scope your data to your workspace |
| Billing | Plan, subscription status, Stripe customer and subscription identifiers | To bill you and apply the right plan limits. We never see or store card numbers. |
| Workload content | The datasets, prompts, documents, audio, model outputs, scores, and reviewer verdicts you submit or generate | To run your evaluations and build your decision records. May contain personal information if you put it there. |
| Provider credentials | API keys you connect, encrypted at rest | To run evaluation calls under your own provider accounts. Write-only: the API returns the provider and last four characters, never the key. |
| Usage | Run counts, timestamps, errors, and an audit log of workspace actions | To operate the service, enforce plan limits, debug, and secure accounts |
| Website analytics | Page views, referrer, approximate location, device and browser type | To understand which pages are useful. Collected by HeyCatch. We do not build advertising profiles. |
| Contact form | Name, email, company, what you say you are interested in, and what you write. Submitted to and stored by Netlify Forms. | To reply to you |
How we use it, and our legal bases
- To provide the service you asked for, including running evaluations, storing results, and minting proofs. Basis: performance of a contract.
- To bill you and prevent payment fraud. Basis: performance of a contract, and legal obligation for tax records.
- To keep the service secure and working, including rate limiting, audit logging, and debugging. Basis: legitimate interests.
- To improve the product using aggregate usage patterns. Basis: legitimate interests.
- To email you about service changes, billing, and security. Basis: performance of a contract. Marketing email, if we ever send it, will be opt-in and one-click unsubscribable.
Subprocessors
These providers process data on our behalf. The model providers you evaluate are connected with your own keys and are under your control, not ours.
| Subprocessor | Purpose | Location |
|---|---|---|
| Railway | Backend application compute | United States |
| Supabase | Application database, authentication, and encrypted eval-input storage | United States |
| Netlify | Static hosting for the marketing site and the app, and receiving and storing the contact form you submit | United States |
| Stripe | Subscription billing and payment processing | United States |
| HeyCatch | Website and product analytics | United States |
| Google Fonts | Serves the typefaces used on this website and in the app. Receives your IP address and browser details when a page loads. | United States |
| esm.sh | Content delivery network that serves the HeyCatch analytics script on this website. Receives your IP address and browser details when a page loads. | Global edge network |
| Model providers you connect | Run your evaluation calls under your own keys, for example OpenAI, Anthropic, AWS, Deepgram, OpenRouter | Per that provider |
We will update this table before adding a subprocessor that handles customer content.
Where your data is held, and international transfers
Data is stored in the United States. If you are in the United Kingdom, the European Economic Area, or Switzerland, your information is transferred to the US under Standard Contractual Clauses or an equivalent lawful transfer mechanism with each subprocessor.
Retention
We are a small team and we would rather tell you exactly how this works than imply an automation we have not built. Today there is no scheduled deletion job: outside of the self-serve deletions listed below, erasure is a manual process we run when you ask. Email privacy@redcrown.ai and we will action it within 30 days.
- Account and workspace records: retained for as long as your account exists. There is no self-serve account-closure button yet. Email privacy@redcrown.ai to close your account and we will delete these records within 30 days of your request.
- Workload content, runs, and reports: retained until you ask us to delete them, or until 30 days after you ask us to close your account. The app has no self-serve delete for runs or reports today, so this route is by email.
- Provider credentials: until you delete them, which you can do yourself at any time in the app. Deletion removes the stored record immediately and is irreversible.
- Proof links: you can revoke a proof link yourself at any time in the app, and a link can be minted with an expiry date through our API. A revoked or expired link stops resolving immediately and the report behind it is no longer served. The link record itself is retained alongside the run so the revocation is auditable.
- Billing records: retained as long as tax and accounting law requires, typically seven years.
- Audit logs: retained for at least 12 months. We do not currently prune them on a schedule, so in practice they are kept for the life of the workspace.
- Analytics: retained by HeyCatch under their own retention settings, in aggregate form. We do not hold a separate copy.
Security
Provider keys and stored eval inputs are encrypted at rest with authenticated symmetric encryption. Eval-input storage is siloed per workspace and a cross-workspace request is rejected at the storage boundary. Card data never reaches us. The full detail, including what stays on your own machine when you run the CLI locally, is on the Security and Trust page. We hold no formal certification and claim none.
Your rights
Wherever you are, you can ask us to give you a copy of your personal information, correct it, delete it, or export it. Email privacy@redcrown.ai and we will respond within 30 days.
If you are in the UK, EEA, or Switzerland you also have the right to restrict or object to processing, to withdraw consent where we relied on it, and to complain to your local supervisory authority.
If you are a California resident you have the right to know what we collect and why, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of.
Cookies, local storage, and analytics
The app does not use a cookie to keep you signed in. Your session is held in your browser's local storage by our authentication provider, Supabase, and is sent to our API with each request. Clearing your browser storage for the site signs you out. This storage is strictly necessary to run the service.
Analytics is provided by HeyCatch, which is used to count page views and understand which pages help. HeyCatch is not strictly necessary to run the service, and it may set a cookie or use browser storage of its own to recognise a repeat visit. We do not run advertising cookies, third-party ad pixels, or cross-site tracking, and we do not build advertising profiles.
Loading a page also sends your IP address and browser details to the providers that serve that page's assets, which is unavoidable for any hosted asset. Google Fonts serves our typefaces on both this website and the app. esm.sh serves the HeyCatch script on this website; the app bundles that script instead, so esm.sh is not called there. Both are listed in the subprocessor table above.
Children
RedCrown is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, email privacy@redcrown.ai and we will delete it.
Changes to this policy
We will update this page when our practices change and move the "Last updated" date. For material changes affecting how we use your information we will give notice by email or in-product before they take effect.