CrewBrief is operated by Max Eriksson (sole proprietor as of this version). Contact for any privacy matter: security@crewbrief.co.
We process your data under the following bases (GDPR Articles 6 and 9):
As of this version, CrewBrief operates on servers located in Finland (European Union), hosted by Hetzner Online GmbH. Data is transferred to and from your device using TLS 1.3 encryption.
If you are located outside the EU/EEA, your data is transferred to the EU under the Standard Contractual Clauses (SCCs) approved by the European Commission. The SCCs provide GDPR-equivalent protection for the transfer.
Application-layer encryption (AES-256-GCM) protects uploaded documents and the most sensitive structured fields. Full-disk encryption on the database volume is planned for implementation before scaling beyond the initial pilot cohort.
We share only to third parties that are necessary to provide the service:
| Recipient | What | Why |
|---|---|---|
| Anthropic, PBC (USA) | Snapshots of your health context for AI chat and insight generation | You can opt out of bloodwork being included via Settings |
| Plaid, Inc. (USA) | OAuth tokens for bank account linkage | Only if you connect a bank account |
| Stripe, Inc. (USA) (planned) | Payment processing | Only if you subscribe to paid features |
| Hetzner Online GmbH (Germany/Finland) | Infrastructure hosting | Server hosting only; no application-layer access |
| Apple Inc. / Google LLC | App distribution (when native app launches) | Standard app-store distribution; no application data shared |
We do not sell your data. We do not share data with advertising or marketing intermediaries. We do not use your data for credit decisioning, employment decisioning, or insurance underwriting.
If you connect a family or spouse account, you control granular sharing toggles per data category (location, schedule, tasks, nutrition, workouts, sleep, finance, health summary). Bloodwork data is never shared with linked accounts, regardless of toggle state, by default.
Full retention details: see CrewBrief's Data Retention and Deletion Policy.
You can at any time:
To exercise any right, email security@crewbrief.co. We respond within 30 days.
We use minimal session cookies necessary for authentication (per-device tokens). We do not use advertising cookies, analytics trackers, or cross-site identifiers.
CrewBrief is intended for adults (16+ in the EU, 13+ in the US under COPPA). We do not knowingly collect data from children below these ages. If we learn we have collected such data, we will delete it.
We protect your data using the safeguards documented in our Information Security Policy: TLS in transit, AES-256-GCM application-layer encryption at rest for sensitive blobs, two-factor authentication on administrative systems, SSH-key-only access to production, principle of least privilege, and 72-hour breach notification.
A copy of our Information Security Policy is available on request.
We will notify you of material changes by email and via a dashboard notification at least 14 days before they take effect. Continued use after the effective date constitutes acceptance of the new version. Prior versions are retained for reference.
For any privacy question or to exercise your rights:
security@crewbrief.co
Max Eriksson, Founder
CrewBrief