CrewParley legal information
Privacy Policy
This policy explains how CrewParley handles website visits, desktop work, configured account and cloud services, and optional connections. It distinguishes information kept on your device from information sent to us or to services you choose.
1. Operator, scope, and contact
CrewParley is operated by Buenhoj Technologies Inc., Muirland Cres, Brampton, Ontario, Canada. Contact support@buenhoj.com for privacy questions, requests, or concerns. The company is responsible for personal information under its control; an AI persona named Support is not our privacy contact.
This policy covers crewparley.com, CrewParley desktop software provided to you, configured account and hosted platform services, and communications with us. Independent AI providers and services you select have their own privacy policies.
The desktop and several connected or cloud features remain previews. This website does not provide public account registration, a paid checkout, Gmail authorization, or a public desktop installer. Information handling described for an optional feature applies when that feature is made available and you use it; visiting the website does not enable those features.
2. Information at a glance
CrewParley can handle messages, instructions, AI outputs, task records, profiles, files you supply, and connection information. The destination depends on the workflow: local desktop storage, a configured CrewParley service, or an independently selected provider.
An agent name or profile does not grant access to your email, calendar, files, or other business systems. Connections and tools require their own configuration and permissions. A desktop workspace does not mean that every request stays on your device.
- Website: network requests and limited server logs needed to deliver and protect the site.
- Desktop: local discussions, task history, configuration, attachments, and applicable credentials.
- Configured account and cloud services: authentication, account/workspace identifiers, registered installations, saved configuration, and cloud conversation or execution records.
- Selected providers and connections: the instructions, context, or permitted requests involved in the feature you invoke.
- Contact: the reply address, message, and supporting information you choose to send us.
3. Website visits, cookies, and logs
The website is served through Amazon Web Services Lightsail in its US East (Ohio) region. Requests disclose your IP address and the requested resource to the hosting infrastructure. Website access logs record the request time, method, resource path, protocol, response status, response size, and processing time for delivery, troubleshooting, and security. The website access-log format omits query strings and referrers; diagnostic error records can contain additional request details.
The site uses assets hosted on the same website and system fonts. It includes no advertising trackers, analytics service, third-party embed, newsletter signup, or account sign-in form. We do not use website activity to build an advertising profile.
The website does not intentionally set cookies or retain visitor information in local storage. Its routing library can temporarily use session storage to restore scroll positions. Your browser controls that session state; it is not used as an analytics identifier.
4. Desktop discussions, tasks, and profiles
You may supply messages, agent instructions, names, configuration, task descriptions, and context. The desktop records contributions, task status and history, results, handoffs, and preferences so you can continue or review your work.
Local workflows store information in application files, profile stores, and webview browser storage. Office evaluation features can also keep local teams, schedules, meetings, and activity records. Those evaluation features do not establish availability of an unattended production service.
People or processes with access to your Windows account, application directories, exports, or backups may be able to read local records. General conversation history does not have a verified blanket encryption-at-rest guarantee. If you configure a separately hosted manual-workflow server, information involved in that workflow can reach that server.
5. Attachments, screenshots, and browser tools
Files, pasted images, and captured screenshots can contain personal or confidential information. Local copies support the workflow you selected. When their contents are included in context or a tool request, the selected provider or configured server may receive them. Review what you supply before running a workflow.
Optional browser control is enabled in an agent profile and launches a separate agent-owned Chrome or Edge session. The browser can remain available across turns until the agent stops. This does not mean that every browser action requires a fresh human approval.
File, shell, browser, and technical tools can read or change information according to their actual permissions and configuration. Profile labels are not a universal sandbox for processes running under your Windows account. The supervised cloud-drafting workflow does not automatically upload your repositories, historical desktop files, browser sessions, or screenshots.
6. Authentication and configured cloud records
Configured account flows use Supabase Auth. Sign-in or recovery information is sent to that authentication service. The native sign-in flow does not save your password as a workspace record. Google identity sign-in, where configured, is separate from Gmail permission.
The platform uses Supabase PostgreSQL and a CrewParley API hosted on AWS Lightsail. It can store authentication-linked account and workspace identifiers, membership, installation UUIDs and public signing keys, saved departments or agent profiles, and cloud configuration you deliberately submit.
Cloud conversations and accepted runs can contain messages, supplied context, profile revisions, model/provider choices, status, timing, and results. These support ownership checks, coordination, recovery, and display of history. Authorized platform/database operators can read stored cloud content; it is not end-to-end encrypted.
Access grants, restrictions, retry information, event journals, and audit records support service operation and security. The existence of billing or artifact tables does not mean a payment or upload service is available. Public customer cloud workflows and provider execution remain subject to their separate release controls.
7. AI providers and supplied context
Invoking an AI tool can send selected role instructions, relevant conversation context, task content, attachments used by that workflow, and permitted tool information to the chosen tool/provider. The provider uses the request to generate a contribution or perform permitted tool work. Context is bounded and need not contain your complete history.
Independent provider accounts, subscriptions, settings, and agreements govern that provider’s processing, including retention, training, human access, subprocessors, and locations. We do not promise that every provider disables training or keeps information in Canada. Review the provider’s terms and configuration before supplying sensitive information.
The supervised cloud-drafting path uses a separately reviewed turn and disables tools, MCP, browser access, connections, and delegation. These controls do not apply universally to local workflows. Your selected tools and global provider settings can create additional recipients or access.
8. Google identity and Gmail preview
Google identity sign-in does not authorize Gmail access. The separate Windows Gmail preview requests the gmail.readonly permission for owner-initiated mailbox checks and a bounded read-only mail preview. It remains a restricted preview requiring separately configured Google client credentials and validation, rather than a publicly available connector.
The native connection checks mailbox identity and stores mailbox metadata plus an opaque credential reference locally. A refresh token is protected in a Windows DPAPI-backed file; access tokens are used natively for Google requests. Previewed message text is displayed in the trusted desktop window, not stored as message bodies in the connection registry, profiles, or Office data.
This preview does not grant agents mailbox access, forward Gmail-derived content to an AI provider, send mail, create drafts, organize mail, or perform attachment actions. Broader access or onward transfer requires a separate implemented workflow, relevant permissions, and contextual disclosure and consent. Publishing this policy does not establish Google verification or Limited Use compliance for a future production connector.
9. Credentials and connection metadata
The Windows cloud adapter protects native access/refresh tokens, private installation signing keys, and recovery state using DPAPI and owner/SYSTEM file permissions. That adapter does not place bearer tokens or private keys in the renderer’s local storage.
Gmail refresh tokens have a separate DPAPI-backed native store. Its registry contains mailbox and connection metadata rather than the token value. DPAPI does not isolate secrets from every process running as the same Windows user.
Independent CLI tools, provider settings, and custom MCP servers can manage credentials differently. Review their configuration individually. Do not send passwords, OAuth tokens, API keys, or unnecessary sensitive files to our public contact address.
10. Purposes and recipients
We use information for the feature or request that produces it: delivering the website, saving work you ask to retain, authenticating permitted users, checking ownership, coordinating configured tasks, restoring state, answering correspondence, and investigating security or operational problems. This policy does not authorize unrelated collection merely because it could improve a future product.
Our service-provider categories include AWS hosting, Supabase authentication/database infrastructure, and business email services used to receive and answer correspondence. Authorized company personnel or contractors may access information needed for their assigned support, administrative, or security responsibilities.
AI providers, Google, and technical servers you independently select receive information within their respective workflows. They are distinct from vendors hosting services for us. We may disclose relevant information where legally required or necessary to address a security incident, subject to applicable law and appropriate scope.
The website has no advertising-data sale or marketing-list collection. We do not use the current Gmail preview to sell mailbox data, target advertisements, or train an unrelated general-purpose AI model.
11. Support and access correspondence
Email support@buenhoj.com for support, access questions, or privacy requests. We receive your address, message, and any information or attachments you choose to provide. We use these to understand, answer, and document the request, and to address related security or legal obligations.
Email opens your own mail service and is processed by the email services involved in delivery. The website does not operate a submission form or collect payment-card information. Send only information needed for your request; we can arrange an appropriate method if further sensitive information is necessary.
Requesting help or access does not subscribe you to a marketing list or authorize a connection. Any future optional marketing permission must be separate.
12. Retention, archives, and backups
Local discussions, task history, profiles, files, and evaluation records remain in their respective stores until removed through available controls or local file management. Capacity bounds on history are not a time-based deletion schedule. Exports, backups, and copies held by a provider or another configured server have separate lifecycles.
Website logs rotate daily and retain up to 14 rotated archives under the current host configuration. Empty logs may not rotate, and removal follows successful rotation rather than an exact per-request timer. Copies in infrastructure backups and information retained for a specific security incident or legal requirement can remain separately; ordinary log rotation does not erase those copies.
Cloud preview records persist in the configured project and can be archived or handled by its operator. Archiving is not erasure. A complete automated customer account-deletion, cloud-export, object-deletion, and backup-expiry process is not currently available. These limitations are a reason public customer cloud workflows remain restricted; this policy does not promise a self-service deletion function that has not been implemented.
We keep support/privacy correspondence while needed to handle the request and document its outcome, and afterward only where needed for a continuing legal, security, or dispute-related purpose. Contact us to discuss information held about your request. We assess removal and any lawful retention exception for the records concerned rather than promising immediate deletion from every system.
13. Disconnecting, revoking, and deleting
Disconnecting the Gmail preview disables local use before attempting Google token revocation and removing its local credential. A failed remote revocation is distinct from local disconnection. You can also revoke permission through your Google account; revocation may affect other scopes granted to the same Google project.
Revoking permission does not retract information already viewed, copied, exported, or sent to another recipient. Removing an imported copy does not delete the original service record. Deleting a local chat does not establish deletion from an independent provider, configured server, backup, or cloud archive.
Signing out, disconnecting a service, uninstalling the desktop, and requesting account/data deletion are different actions. Uninstallation is not a verified erasure of every local application file and is not an account-deletion request. Use our privacy contact for records under our control; contact an independent provider for its records.
14. Privacy requests and complaints
Contact support@buenhoj.com to ask about personal information under our control, request access or correction, withdraw applicable consent, discuss deletion, or raise a concern. Describe the relevant service and records without including passwords or tokens.
We may reasonably verify your identity and authority, using only information needed to prevent disclosure to the wrong person. We address requests within applicable legal time limits and explain relevant restrictions, exceptions, or information we cannot locate or control. Consent withdrawal can prevent a dependent feature from operating.
Rights and remedies depend on applicable law; not every right applies to every record or jurisdiction. Local-only records may require action in your installation, and independent providers handle requests for their own information. You may raise an unresolved Canadian privacy concern with the Office of the Privacy Commissioner of Canada or another privacy authority having jurisdiction.
15. Safeguards and processing locations
The website uses HTTPS and restricted web-server headers. Configured native/platform paths use specific safeguards such as Windows credential protection and scoped ownership checks. These measures do not guarantee perfect security or isolation of every workflow. Protect your device, account, provider permissions, and backups, and report suspected exposure to our contact address.
The website and CrewParley API are hosted in AWS US East (Ohio). Supabase services and independently selected providers can process information in other locations according to their configuration and agreements. We do not promise Canadian-only storage or processing. Information processed elsewhere may be accessible under the laws of that location.
We assess reported incidents and take the protective, notification, and other steps required by applicable law. A policy statement does not replace implemented consent, authorization, or security controls.
16. Versions and changes
This is Privacy Policy version privacy-1, effective and last updated October 3, 2026. The current version and canonical URL are identified in the public document-version manifest. We retain prior approved versions when the policy changes.
We will publish changes with an updated version and date. Material changes will receive appropriate notice and any new consent required before a changed use of information. Questions about this policy can be sent to support@buenhoj.com.