Legal
Privacy Policy
Last updated June 28, 2026
Cran provides an AI control plane that routes, benchmarks, and governs the LLM calls in your product. Because we sit in front of your AI traffic, we keep what we collect deliberately narrow. This policy explains what we collect, how we use it, and the choices you have. Questions: privacy@trycran.in.
1. Information we collect
- Account. When you sign in (via Clerk), we receive your name and email address.
- Access requests. If you request access, we store the name, email, company, and website you submit.
- Usage metadata. For calls routed through the gateway we record the model, token counts, latency, cost, and status — not your prompts or completions by default.
- Optional captured samples. If you turn on real-traffic capture for a workflow, we store redacted samples to power benchmarking. This is off by default and per-workflow.
- Code metadata. The scanner runs locally and sends only call-site metadata (file paths, models, prompt templates) — never your source code.
- Technical. Authentication/session cookies, and basic logs and error diagnostics to keep the service running.
2. How we use it
To provide and operate the service (routing, benchmarking, governance), to bill usage, to secure the platform and prevent abuse, to provide support, and to improve the product. We do not sell your data, and we do not use your prompts or outputs to train models.
3. LLM providers
When you route a request, its content is sent to the model provider you select (e.g. OpenAI, Anthropic, or Google) to fulfill it, subject to that provider’s own terms and data-handling policies. Choose models accordingly for sensitive workloads.
4. Service providers (subprocessors)
We rely on a small set of providers that process data only to deliver their part of the service: Clerk (authentication), Supabase (database and storage), Vercel (hosting), the model providers above (inference), an email provider for transactional mail, and error monitoring. We add subprocessors only as needed to run the service.
5. Data retention & deletion
Account and project data is retained while your account is active. Usage metadata is retained for analytics and billing. Captured samples are kept until you delete the workflow or project. Deleting a project removes its data, and you can request deletion of your account data at any time.
6. Security
Data is encrypted in transit and at rest, provider keys are held server-side, connection tokens are hashed, and access is invite-only. See our Security page for details.
7. Your rights
You can access, correct, export, or delete your data — much of it self-serve in the dashboard (for example, deleting a project) or by contacting us. Depending on where you live, you may have additional rights under laws such as GDPR or CCPA; we honor valid requests.
8. Children
Cran is not directed to anyone under 18, and we do not knowingly collect their data.
9. Changes
We may update this policy; we’ll post the new version here and update the date above. Material changes will be communicated where appropriate.
10. Contact
Cran · privacy@trycran.in