Your data, handled honestly.
Last updated: 28 March 2026 · Effective: 28 March 2026
1. Who we are
Crucible is the data controller for the personal data described in this policy. Contact: support@crucible.so.
2. What we collect and why
| Data | Why we collect it | Legal basis (GDPR) |
|---|---|---|
| Email address | Authentication and account management | Contract performance |
| Quiz history & study stats | Delivering the core service — progress tracking, XP, streaks, analytics | Contract performance |
| Stripe customer ID & plan name | Managing your subscription (free, pro, or max). We never see or store card details. | Contract performance / Legitimate interest |
| Study notes (session only) | Sent to our AI provider to generate questions. Not stored beyond the session. | Contract performance |
We do not collect payment card details, sell your data, or use your data for advertising.
3. Third-party processors
We share data only with the processors needed to run the service. All processors are bound by data processing agreements.
| Processor | Purpose | Data shared |
|---|---|---|
| Supabase | Database and authentication | Email, quiz history, study stats, plan reference |
| Stripe | Payment processing | Email, plan name. Stripe handles all card data directly — we never see it. |
| Resend | Transactional email (account, receipts) | Email address |
| Anthropic | AI processing of study notes to generate questions | Your uploaded study notes (session only, not stored) |
We do not use your data with any advertising, analytics, or data-broker platforms.
4. Data retention
- Account data (email, quiz history, stats) — retained for as long as your account is active, then deleted within 30 days of account deletion.
- Study notes — processed in-session only; not persisted to our database.
- Stripe reference — retained for the period required by applicable financial regulations (typically 7 years), after which it is deleted.
- Support emails — retained for up to 2 years, then deleted.
5. International data transfers
Our processors (Supabase, Stripe, Resend, Anthropic) are US-based and operate globally. Where data is transferred outside the European Economic Area (EEA) or UK, we rely on Standard Contractual Clauses (SCCs) and/or adequacy decisions to ensure adequate protection. You may request a copy of the applicable safeguards by emailing support@crucible.so.
6. Your rights
Depending on where you live, you have the following rights. To exercise any of them, email support@crucible.so or use the in-app account deletion feature.
We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA). We will never discriminate against you for exercising your privacy rights.
7. California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to Know — the categories and specific pieces of personal information we collect.
- Right to Delete — request deletion of your personal information (subject to certain exceptions).
- Right to Correct — request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing — we do not sell or share your personal information for cross-context behavioral advertising.
- Right to Non-Discrimination — we will not discriminate against you for exercising any CCPA rights.
To submit a CCPA request, email support@crucible.so with subject line "California Privacy Request".
8. EEA & UK residents (GDPR / UK GDPR)
If you are located in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO). In the EU, contact the data protection authority in your member state.
9. Cookies
We use only essential cookies required for authentication and session management. We do not use tracking, advertising, or analytics cookies. You can disable cookies in your browser settings, but this will prevent you from signing in.
10. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, notify you by email. Continued use of Crucible after the effective date constitutes acceptance of the updated policy.
11. Contact us
For any privacy-related questions, requests, or complaints:
Email: support@crucible.so
Account deletion: Available directly within the Crucible app under account settings.
We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.