Privacy
Privacy Policy
What we collect, why we collect it, how we protect it, and the choices you have.
Our guiding rule is simple. We collect only the minimum data necessary to provide our service, and we do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
01Our Commitment to Your Privacy
CyrstalPrivacy LLC built this product with privacy as a core principle, not an afterthought. This Privacy Policy explains what information we collect, why we collect it, how we protect it, and the choices you have.
If you have questions about this policy, contact us at support@crystalprivacy.com.
02Information We Collect
We follow a data minimization principle: we only collect what is strictly necessary to operate the service, secure your account, and comply with legal obligations.
2.1 Information you provide directly
- Account information (e.g., name, email address, password — stored as a salted hash, never in plain text);
- Information you submit through the app’s core features (e.g., content you create or upload); and
- Communications you send us (e.g., support requests).
2.2 Information collected automatically
- Basic device and usage data needed for security and reliability (e.g., login timestamps, error logs, IP address at time of authentication).
- We do not use tracking pixels, third-party advertising cookies, or cross-site trackers.
2.3 Information we do not collect
- We do not collect data unrelated to providing the service (e.g., browsing history outside our app, contacts, precise location) unless you explicitly opt in for a specific feature, and we will clearly disclose that at the time.
03How We Use Your Information
We use the limited data we collect only to:
- Provide, maintain, and improve the core functionality of the service;
- Authenticate your identity and secure your account;
- Respond to support requests;
- Comply with legal obligations (e.g., tax, fraud prevention); and
- Send essential service communications (e.g., security alerts, password resets).
We do not use your personal data to build advertising profiles, and we do not use it to train generalized AI/ML models without your explicit, separate consent.
04How We Protect Your Data
We implement industry-standard technical and organizational safeguards appropriate to the sensitivity of the data:
- Encryption in transit. All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest. Data stored in our databases and backups is encrypted using AES-256 (or equivalent industry-standard encryption).
- Access controls. Access to production systems and customer data is restricted on a least-privilege basis, logged, and reviewed periodically.
- Secrets management. Credentials, API keys, and tokens are stored in dedicated secrets management systems, never in plaintext config files or source code.
- Vulnerability management. We apply security patches promptly and periodically review our systems for vulnerabilities.
- Incident response. We maintain a process to detect, respond to, and notify affected users of any data breach as required by applicable law.
No system can guarantee absolute security, but we are committed to using best practices to protect your information and to being transparent if something goes wrong.
05Data Sharing and Disclosure
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes. Limited exceptions:
- Service providers (sub-processors). We may use a small number of vetted infrastructure providers (e.g., cloud hosting) strictly to operate the service. These providers are contractually bound to use your data only to perform services for us and are prohibited from using it for their own purposes.
- Legal requirements. We may disclose data if required by law, subpoena, or court order, or to protect the rights, safety, or property of [Company Name] or others. We will notify you of such requests unless legally prohibited from doing so.
- Business transfers. In the event of a merger, acquisition, or sale of assets, your data may be transferred, subject to the same privacy protections described here. We will notify you in advance of any such change.
We will never share your data with third parties for advertising or data-broker purposes.
06Data Retention
We retain personal data only for as long as necessary to provide the service or to comply with legal, accounting, or reporting obligations. When data is no longer needed, we securely delete or anonymize it. You may request deletion of your account and associated data at any time (see Section 8).
07Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Request deletion of your data (“right to be forgotten”);
- Export your data in a portable format;
- Withdraw consent for optional features at any time; and
- Object to or restrict certain processing.
To exercise any of these rights, contact us at support@crystalprivacy.com. We will respond within the timeframe required by applicable law (e.g., 30 days under GDPR/CCPA).
08Account Deletion
You may delete your account at any time through [in-app setting / by contacting support]. Upon deletion, we will permanently remove your personal data from active systems within [X days], except where retention is required by law.
09Children’s Privacy
Our service is not directed to children under 13 (or the applicable age in your jurisdiction), and we do not knowingly collect personal data from children. If we learn we have collected such data, we will delete it promptly.
10International Data Transfers
If data is transferred across borders, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) to protect your data consistent with this policy.
11Changes to This Policy
We may update this policy as our service evolves. We will notify you of material changes via email or in-app notice before they take effect, and we will post the updated policy with a new “Last updated” date.