Crate StudioBack to the site

Privacy

Last updated 12 August 2026

Crate Studio builds workflows that act on your behalf inside systems you already use — your mailbox, your documents, your spreadsheets. That only works if you hand us access to real things, so you are owed a straight account of what we do with them.

This policy covers the crate platform and this website. It is written to be read, not to be survived.

Who we are

Crate Studios Limited, a company registered in Ireland (company number 638584), trading as Crate Studio. We are the data controller for your account and this website, and a data processor for the content your workflows read and write on your instruction.

Questions, requests, or complaints: support@cratestudio.com.

What we hold

Account data
Your email address, your workspace name and your role in it, and the record of who invited whom. Sign-in is handled by Google — we never see or store a password.
Workflow definitions
The workflows you build: their steps, their configuration, and the instructions you give an agent.
Run history
What happened each time a workflow ran — which steps ran, in what order, what each produced, and any documents it generated. This is the audit trail, and it is the point of the product.
Connected credentials
The access tokens a workflow uses to reach a connected system. See “How credentials are protected” below.
Content from connected systems
Whatever a workflow you built reads in order to do its job — for example the emails matching a search you configured. We hold it because a run has to record what it acted on.

We do not sell anything to anyone, we do not use your content or your run history to train machine-learning models, and we do not run advertising.

Your Google data

When you connect a Google account, Google shows you exactly which permissions are being asked for and you grant them explicitly. We ask for the narrowest set a workflow needs, and you can see the granted list at any time on the Connections screen.

We use Google user data only to operate the workflows you have built: to read what a step is configured to read, and to write what a step is configured to write. Nothing is read speculatively, and no Google data is used for any purpose you have not set up.

Crate Studio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect a Google account at any time from the Connections screen, which revokes the token with Google, or from your Google account permissions page.

How credentials are protected

Access tokens are encrypted before they are stored, with a key derived for your workspace alone, and the encryption is bound to both the workspace and the specific connection — a credential lifted out of one workspace cannot be decrypted in another. They are decrypted only at the moment a step needs them.

A credential is write-only from the moment it is saved. There is no screen that displays it, no button that copies it, and no API that returns it — not to you, and not to us.

Where it lives

Your data is stored in the United Kingdom (London), on infrastructure provided by Supabase. This website and the application front end are served by Vercel's global network. The United Kingdom holds an EU adequacy decision, so transfers there from the EEA need no further safeguard.

Some of the services below process data outside the UK and EEA. Where they do, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, as set out in each provider's own terms.

Who else sees it

We use a small number of providers to run the service. Each receives only what its job requires.

Supabase
Database, authentication and backend hosting. Holds everything described above.
Vercel
Serves this website and the application. Sees requests, not workflow content.
Model providers
Where a workflow includes an agent step, the instructions and the data that step needs are sent to a language-model provider through OpenRouter, which routes to the model configured for your workspace. Content sent to a model is not used to train it.
Langfuse
Tells us whether runs are working. It receives timings, model names, token counts and step outcomes — never the content of a step's input or output.
Sentry
Error reporting, so a crash reaches us rather than only you.
Resend
Sends the transactional email we send you — invitations, and notice when a run needs your attention.
Google
Sign-in, and the APIs of whichever Google services you connect.

How long we keep it

Account data and workflow definitions are kept while your workspace exists. Run history and the documents runs produce are kept so the audit trail stays intact, and you can delete a run or a document yourself at any time.

Delete your workspace and we delete its data within 30 days, other than anything we are required to keep for longer by law (for example, invoices). Backups roll off on their own schedule and are not restored selectively.

Why we are allowed to hold it

Under the UK and EU GDPR we rely on: contract, for everything needed to provide the service you signed up for; legitimate interests, for keeping the service secure, debugging failures and preventing abuse; and consent, for connecting a third-party account, which you give in that provider's own screen and can withdraw at any time by disconnecting.

What you can ask for

You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, or object to processing we base on legitimate interests. Write to support@cratestudio.com and we will respond within one month.

If we get it wrong you can complain to the Irish Data Protection Commission (dataprotection.ie), or to the supervisory authority where you live.

Children

Crate Studio is a tool for businesses. It is not for anyone under 16, and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects you, we will tell you by email before it takes effect rather than quietly changing the date at the top. The date at the top is the date of the current version.