Privacy Policy

Your data, handled honestly.

Last updated: 28 March 2026  ·  Effective: 28 March 2026

This policy explains what information Crucible ("we", "us") collects, how we use it, and the rights you have over it. We operate the website at about.crucible.so and the application at crucible.so. We keep this short and plain-English. If you have questions, email us at support@crucible.so.

1. Who we are

Crucible is the data controller for the personal data described in this policy. Contact: support@crucible.so.

2. What we collect and why

Data Why we collect it Legal basis (GDPR)
Email address Authentication and account management Contract performance
Quiz history & study stats Delivering the core service — progress tracking, XP, streaks, analytics Contract performance
Stripe customer ID & plan name Managing your subscription (free, pro, or max). We never see or store card details. Contract performance / Legitimate interest
Study notes (session only) Sent to our AI provider to generate questions. Not stored beyond the session. Contract performance

We do not collect payment card details, sell your data, or use your data for advertising.

3. Third-party processors

We share data only with the processors needed to run the service. All processors are bound by data processing agreements.

Processor Purpose Data shared
Supabase Database and authentication Email, quiz history, study stats, plan reference
Stripe Payment processing Email, plan name. Stripe handles all card data directly — we never see it.
Resend Transactional email (account, receipts) Email address
Anthropic AI processing of study notes to generate questions Your uploaded study notes (session only, not stored)

We do not use your data with any advertising, analytics, or data-broker platforms.

4. Data retention

  • Account data (email, quiz history, stats) — retained for as long as your account is active, then deleted within 30 days of account deletion.
  • Study notes — processed in-session only; not persisted to our database.
  • Stripe reference — retained for the period required by applicable financial regulations (typically 7 years), after which it is deleted.
  • Support emails — retained for up to 2 years, then deleted.

5. International data transfers

Our processors (Supabase, Stripe, Resend, Anthropic) are US-based and operate globally. Where data is transferred outside the European Economic Area (EEA) or UK, we rely on Standard Contractual Clauses (SCCs) and/or adequacy decisions to ensure adequate protection. You may request a copy of the applicable safeguards by emailing support@crucible.so.

6. Your rights

Depending on where you live, you have the following rights. To exercise any of them, email support@crucible.so or use the in-app account deletion feature.

Access Request a copy of the personal data we hold about you.
Rectification Ask us to correct inaccurate or incomplete data.
Erasure ("Right to be forgotten") Delete your account and all associated data from within the app, or contact us directly.
Portability Receive your data in a structured, machine-readable format.
Objection / Restriction Object to or restrict certain processing where it relies on legitimate interest.
Withdraw consent Where processing is based on consent, you may withdraw it at any time without affecting prior processing.

We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA). We will never discriminate against you for exercising your privacy rights.

7. California residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to Know — the categories and specific pieces of personal information we collect.
  • Right to Delete — request deletion of your personal information (subject to certain exceptions).
  • Right to Correct — request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing — we do not sell or share your personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination — we will not discriminate against you for exercising any CCPA rights.

To submit a CCPA request, email support@crucible.so with subject line "California Privacy Request".

8. EEA & UK residents (GDPR / UK GDPR)

If you are located in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO). In the EU, contact the data protection authority in your member state.

9. Cookies

We use only essential cookies required for authentication and session management. We do not use tracking, advertising, or analytics cookies. You can disable cookies in your browser settings, but this will prevent you from signing in.

10. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, notify you by email. Continued use of Crucible after the effective date constitutes acceptance of the updated policy.

11. Contact us

For any privacy-related questions, requests, or complaints:

Email: support@crucible.so

Account deletion: Available directly within the Crucible app under account settings.

We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.