Cruxy
Talk to sales
Try Cruxy
Try Cruxy
ProductsCruxyCruxy CodeCruxy CoworkCruxy BenchCruxy Guard

Cruxy. Thinks for itself.

© 2026 Cruxy. Built by the team behind mycrux.

[email protected]
PrivacyTermsUsageStatus
Jump to section
  • Introduction
  • Who we are
  • Information we collect
  • How we use your information
  • Legal basis for processing
  • Who we share with
  • Services you choose
  • International transfers
  • Data retention
  • Your rights
  • Security
  • Children's privacy
  • Cookies
  • AI services and your data
  • Memory
  • Changes to this policy
  • Contact us

Contents

  • Introduction
  • Who we are
  • Information we collect
  • How we use your information
  • Legal basis for processing
  • Who we share with
  • Services you choose
  • International transfers
  • Data retention
  • Your rights
  • Security
  • Children's privacy
  • Cookies
  • AI services and your data
  • Memory
  • Changes to this policy
  • Contact us
This policy was last updated on September 30, 2026. Questions: [email protected].

Privacy Policy

Last updated September 30, 2026

Introduction

This Privacy Policy describes how mycrux. Private Limited ("Cruxy", "we", "us", "our") collects, uses, shares, and protects information about you when you visit getcruxy.com or use any service provided under the Cruxy brand (the "Service"). It also explains the rights you have over your information and how to exercise them.

We are committed to protecting your privacy and to handling your personal data lawfully and transparently. We comply with India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and apply privacy-by-design principles in how we build the Service. Where users access the Service from outside India, we apply the same standards consistently rather than diluting them by jurisdiction.

This policy applies to the marketing site at getcruxy.com, the waitlist signup process available there, and the Cruxy products that are available today, including Cruxy Chat, the Cruxy API and Cruxy Code.

Please read this policy carefully. If you do not agree with how we handle your information, you should not use the Service. By using the Service, you confirm that you have read, understood, and accepted this policy.

Who we are

Cruxy is a product being built by mycrux. Private Limited, an Indian private limited company incorporated in Andhra Pradesh. Our Corporate Identification Number (CIN) is U47912AP2025PTC121345.

For all matters related to your personal data - including questions about this policy, requests to exercise your rights, and complaints - you may contact us at [email protected]. We aim to respond within 30 days of receiving any data-related request, and sooner where required by law.

mycrux. Private Limited is the "data fiduciary" under the DPDP Act for the personal data we process about you. This means we determine the purposes and means of processing and are responsible for compliance.

Information we collect

We collect information in three ways: information you provide directly to us, information we collect automatically when you use the Service, and information we receive from third parties. The categories below describe what we collect on the marketing site. What the Cruxy products process is described below, under "Who we share with", "AI services and your data" and "Memory".

Information you provide directly

When you interact with the Service, you may provide us with:

  • Email address. Required when signing up for the Cruxy waitlist or submitting a contact form. We use this to confirm your signup, notify you when access opens to products that are not yet available, and respond to any inquiry.
  • Full name. Optional on the waitlist form, required on the contact-sales form. Helps us address you correctly and route inquiries.
  • Company name and website. Required on the contact-sales form, used to understand who is reaching out and prepare relevant responses.
  • Country. Required on the contact-sales form, used to route to the appropriate sales region and apply correct currency assumptions.
  • Use case description. Free-text field on the contact-sales form describing what you intend to build with Cruxy. Helps us prepare a relevant response.
  • Expected volume and timeline. Selection fields on the contact-sales form, used to prioritize follow-up.
  • Any additional information you choose to share in free-text fields, support emails, or social-media outreach.

You are not legally required to provide any of this information, but without it we cannot add you to the waitlist or respond to your sales inquiry. Providing false information may cause us to suspend or remove your records.

Information collected automatically

When you visit getcruxy.com, we automatically collect a limited set of technical information necessary to operate the site, prevent abuse, and understand aggregate usage patterns:

  • User agent string. The identifier sent by your browser describing the browser version, operating system, and device type. We use this for compatibility, security, and aggregate analytics.
  • Approximate country. Derived from your IP address by our infrastructure provider Cloudflare and passed to us as a country code, which we use to choose the currency prices are shown in.
  • IP address. When you submit the contact-sales form, we store only the country code derived from your IP address, never the IP address itself, and the notification email our team receives shows the country only. The rate limits on our waitlist and contact-sales forms record the IP address each submission comes from; those records are deleted 24 hours after their rate-limit window ends.
  • Server logs. Standard request logs containing timestamps, requested URLs, response status codes, and user-agent strings. Server logs have no fixed retention period.
  • Referrer information. The URL that referred you to our site, where your browser sends it. Helps us understand how visitors find Cruxy.

Information we explicitly do not collect

To set clear expectations, we want to be specific about what we do not do:

  • We do not use third-party advertising trackers, advertising pixels, or marketing cookies on our marketing site.
  • We do not currently use Google Analytics, Facebook Pixel, or similar profiling services.
  • We do not collect biometric data, health data, financial account information, or government-issued ID numbers through the marketing site.
  • We do not buy lists of email addresses or other personal data from data brokers.
  • We do not track you across other websites you visit.

The Cruxy products also process usage telemetry, billing details, API call logs, and content you submit to the AI service. See "AI services and your data" and "Memory" below.

How we use your information

We use the information we collect for clearly defined purposes. We do not use your information for purposes incompatible with what we describe here.

To provide the Service

We use your email address to add you to the waitlist, send the confirmation email, and notify you when access opens to products that are not yet available. If you submit a contact-sales form, we use the information to research your inquiry and respond to it. These are the core operational uses without which the Service cannot function.

To communicate with you

We may send you transactional emails directly related to your interaction with us - for example, confirming a waitlist signup, replying to a contact-sales submission, or notifying you of material changes to this policy. We do not send marketing emails to people who have not specifically signed up for marketing communications. The waitlist itself is not a marketing list; it is a launch-notification list.

To improve the Service

We analyze aggregate, non-identifying usage patterns to understand how visitors use the marketing site and where we can make it better. This includes things like which pages get the most traffic, how long visitors stay, and what device types they use. We do not analyze individual user behavior unless we are responding to a specific inquiry from that user.

To prevent abuse and fraud

We use limited technical information (user-agent strings, request patterns, country signals) to detect and block automated signups, denial-of-service attacks, and other abuse. This is essential to keep the Service running for legitimate users and to protect our infrastructure.

To comply with law

Where Indian law requires us to retain, disclose, or share information - including in response to lawful requests from courts, regulators, or law enforcement - we will do so. We will not share your information with government authorities outside such lawful processes.

What we will not do with your information

  • We will not sell your personal data to anyone.
  • We will not share your data with third parties for their own marketing purposes.
  • We will not use your data to train AI models without your specific, separate consent - and never as part of the marketing site or waitlist.
  • We will not surveil, profile, or score you in ways that materially affect your access to our Service or to third-party services.

Legal basis for processing

The DPDP Act requires us to process personal data only with a clear legal basis. We rely on the following bases:

  • Your consent. When you submit a form on our site (waitlist, contact sales), you are providing consent for us to use your information for the purposes described at the point of collection. Consent is freely given, specific, informed, and you may withdraw it at any time.
  • Performance of a service. Once you have signed up, processing your information to deliver the service you requested (sending the confirmation email, notifying you when access opens) is necessary to perform what you asked us to do.
  • Legitimate purposes. Limited processing for security, fraud prevention, system administration, and aggregate analytics is permitted as a "legitimate use" under the DPDP Act because it is necessary for operating the Service safely and these uses do not override your reasonable privacy expectations.
  • Compliance with law. Where Indian law obligates us to process or retain specific information, we do so to comply with that obligation.

Where we rely on your consent, you may withdraw it at any time by emailing [email protected]. Withdrawal of consent does not affect the lawfulness of processing before withdrawal but will stop further processing of your data for the purpose you withdrew consent for.

Who we share with

We share your personal data only with carefully selected service providers that help us operate the Service, and only to the extent necessary. Our current sub-processors are:

Hostinger (server and database hosting)

Purpose: runs our application servers and the databases behind your account and your chats. Data it receives: everything the Service stores, held on its infrastructure. Hostinger does not access the data itself in normal operations. Location: our servers are in Mumbai, India. Hostinger's privacy policy is at hostinger.com/privacy-policy.

Cloudflare (CDN, security, DNS, file storage, and backups)

Purpose: delivers getcruxy.com, cruxy.in, cruxy.ai and api.cruxy.ai, caches static assets, blocks attacks, and provides DNS. Cloudflare R2 also stores files uploaded through the Cruxy API, and our encrypted database backups. Data it receives: IP addresses, request headers, and country signals for every request, the content of files uploaded through the API, and our database backups, which are encrypted before they are uploaded. Location: Cloudflare, Inc., United States, on a global network. Cloudflare's privacy policy is at cloudflare.com/privacypolicy.

DeepInfra (AI model inference)

Your account and chat databases are hosted on our servers in Mumbai, India. When you send a prompt, it is processed by DeepInfra, Inc. in the United States, which runs the model inference behind Cruxy's models. DeepInfra's privacy policy is at deepinfra.com/privacy.

Brave Search (web search)

Purpose: runs web searches in Cruxy Chat when you turn on web search for a message. Data it receives: the text of your message, up to its first 400 characters, as the search query. The request comes from our servers, so Brave does not receive your IP address, name, or email address. Location: Brave Software, Inc., United States. Brave Search's privacy notice is at search.brave.com/help/privacy-policy.

Razorpay (payments)

Purpose: processes subscription payments by UPI and card. Data it receives: your email address, your Cruxy account ID and chosen plan, and the payment details you enter in Razorpay's checkout, which go to Razorpay directly, not to us. Location: Razorpay Software Private Limited, India. Razorpay's privacy policy is at razorpay.com/privacy-policy.

Resend (transactional email)

Purpose: delivers our emails: waitlist and contact-form confirmations, sign-up and sign-in codes, password resets, email-change notices, invitations, receipts, and billing notices. Data it receives: your email address, your name if provided, and the message content. Location: Resend, Inc., United States. Resend's privacy policy is at resend.com/legal/privacy-policy.

WorkOS (enterprise single sign-on)

Purpose: runs single sign-on for organizations that turn it on. Data it receives: for people who sign in through their organization's identity provider, their email address, name, and sign-in details from that provider. Location: WorkOS, Inc., United States. WorkOS's privacy policy is at workos.com/legal/privacy.

Google, Microsoft, and GitHub (sign-in)

Purpose: lets you sign in with your Google, Microsoft, or GitHub account. Data they receive: the request to sign in to Cruxy, after which they return your email address, name, and account ID to us. Location: Google LLC, Microsoft Corporation, and GitHub, Inc., United States. Their privacy policies are at policies.google.com/privacy, microsoft.com/privacy, and GitHub's privacy statement.

Sentry (error tracking)

Purpose: records errors in the Cruxy app so we can find and fix them. Data it receives: technical details of the error and of the request it happened in, and internal identifiers for your account and the records involved. Cookies and authorization headers are removed before an error report is sent. Location: Functional Software, Inc. (Sentry), United States. Sentry's privacy policy is at sentry.io/privacy.

Slack (internal notifications)

Purpose: notifies our team when someone submits the contact-sales form. Data it receives: what you enter in that form: your name, role, work email address, company, company size, use case, expected volume, timeline, and note. Location: Slack Technologies, LLC, United States. Slack's privacy policy is at slack.com/trust/privacy/privacy-policy.

Healthchecks.io (operational monitoring)

Purpose: alerts us when one of our scheduled jobs, such as the daily billing job or a database backup, does not run or fails. Data it receives: each run's outcome and summary, which for the billing job can include Razorpay subscription ids and our internal plan-change ids. It does not receive names, email addresses, or payment details. Location: SIA Monkey See Monkey Do, Latvia, European Union. Healthchecks.io's privacy policy is at healthchecks.io/privacy.

Future sub-processors

We may engage additional sub-processors, for example for customer support. We will update this policy and the sub-processor list before we begin sharing data with any new sub-processor.

Other disclosure

We may also disclose your information in the following situations:

  • Legal compliance. Where required by law, court order, or government request that meets the standards of the DPDP Act and applicable Indian law.
  • Protection of rights. To enforce our terms, protect Cruxy's or others' rights and safety, or prevent fraud and security incidents.
  • Business transfers. In the event of a merger, acquisition, or sale of all or substantially all of mycrux. Private Limited's assets, your information may be transferred to the acquiring entity, subject to confidentiality obligations and your continued rights under this policy.

We do not sell, rent, or trade your personal data. There is no Cruxy revenue model that depends on monetizing your data.

Services you choose

Some features send data to services that you choose and that Cruxy does not operate. They are not our sub-processors.

  • MCP servers. If you connect an MCP server to Cruxy, the app sends that server the tool requests Cruxy makes on your behalf, which can include content from your conversation, and receives its replies. The server receives that data under its operator's own terms and privacy policy.
  • Dictation. Dictation uses your browser's own speech service (for example Google in Chrome, or Apple in Safari) to turn your speech into text. Cruxy does not operate that service and receives no audio, only the text you send.

International transfers

Cruxy's primary infrastructure is in India. Some of our sub-processors operate globally and may process data outside India. Where this happens, we rely on the contractual obligations these providers have under their own terms of service to maintain security and confidentiality standards. We assess each provider's privacy practices before engaging them.

When the DPDP Act's cross-border transfer restrictions are formally activated (the Government of India has the power to designate countries to which transfers are restricted), we will reassess our sub-processor relationships and update them as needed.

Data retention

We keep personal data for the periods set out below. Where a period below says a record is deleted, a job that runs once a day deletes it, so a record can outlast its period by up to a day.

  • Waitlist entries. Deleted 12 months after you sign up.
  • Contact sales submissions. Deleted 24 months after submission. A submission stores the country code derived from your IP address, never the IP address itself.
  • Rate-limit records. Our forms record the IP address a request comes from, and for the contact-sales form the email address entered, to block abuse. Each record is deleted 24 hours after its rate-limit window ends.
  • Email correspondence. Kept until deleted; no fixed retention period.
  • Server logs. Server logs have no fixed retention period.
  • API usage records. For each request to the Cruxy API we record your account, API key and workspace identifiers, the model used, token counts, cost, timing, status, any error message, and the client name and version your tool reports. These records hold no prompt or response content. Today we keep them indefinitely, including after you delete your account. This will change when we anonymise them.
  • Backups. Database backups are encrypted. A backup is deleted once it is more than 30 days old, except that the newest 7 backups are always kept. Data deleted from active systems remains in backups until those backups are deleted.

You may request earlier deletion of your information at any time by contacting us. We will comply unless a legal obligation requires us to retain it for longer.

Your rights

The DPDP Act gives you specific rights over your personal data. We honor these rights regardless of where you are located, applying the highest standard.

Right to access

You may request a copy of the personal data we hold about you, the purposes of processing, the categories of recipients with whom it has been shared, and the retention period.

Right to correction

You may ask us to correct any personal data that is inaccurate, incomplete, or misleading.

Right to erasure

You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when the processing is unlawful. We will comply unless we have a legal obligation to retain it.

Right to grievance redressal

If you believe we have not adequately addressed a request or complaint, you may escalate to the Data Protection Board of India, which is being established under the DPDP Act.

Right to nominate

You may nominate another individual to exercise your rights in the event of your death or incapacity.

How to exercise your rights

To exercise any of these rights, send an email to [email protected] with the subject line "Data subject request" and include enough information for us to identify you (typically the email address you used). We will respond within 30 days. There is no cost to exercise these rights, except in cases of clearly excessive or repeated requests, where we may charge a reasonable administrative fee.

We will not retaliate against you for exercising your rights. Exercising your rights does not affect any other dealings you have with us.

Security

We use industry-standard security measures to protect your information:

  • TLS encryption for all data in transit between your browser and our servers.
  • Encrypted storage at rest in our database.
  • Strict access controls - only authorized personnel can access production systems, and access is logged.
  • Secrets and credentials are kept out of source control and rotated when team members change.
  • Regular security updates to operating systems, runtimes, and dependencies.
  • Backup procedures with encrypted storage.
  • Incident response procedures for handling security events.

No system is perfectly secure, and we cannot guarantee that information will never be accessed by unauthorized parties. We will notify affected users of a security incident that materially affects their personal data, in line with timing and content requirements of the DPDP Act, generally within 72 hours of becoming aware.

You play a part in security too. Use a strong, unique email password, do not share confirmation links from us, and let us know immediately if you receive a suspicious email claiming to be from Cruxy or mycrux.

Children's privacy

Cruxy is not directed at children under the age of 18. We do not knowingly collect personal data from children. The DPDP Act requires verifiable parental consent for processing the personal data of children, and our marketing site does not implement such consent flows because we do not invite children to use the Service.

If you believe we have inadvertently collected information from a child, contact us at [email protected] and we will delete it.

Cookies

getcruxy.com (this site)

The marketing site at getcruxy.com sets no cookies for visitors. Your theme preference (light or dark, light by default) is kept in your browser's local storage, not in a cookie, and is never sent to us. The only cookie on getcruxy.com is a sign-in cookie for Cruxy staff who use our internal admin area.

cruxy.ai (the Cruxy app)

The Cruxy app sets only its own cookies, to sign you in and to run the app. None is used for analytics, advertising, or tracking.

CookiePurposeLifetime
cruxy_sidKeeps you signed in. Set when you sign in, for cruxy.ai and its subdomains.30 days, renewed while you use the app
cruxy_mfaHolds a two-step sign-in between your first step and your authentication code.5 minutes
cruxy_oauth_stateProtects signing in with Google, Microsoft, GitHub or your organisation's single sign-on, and connecting GitHub, against forged requests.10 minutes
cruxy_pending_linkHolds a request to add a new sign-in method to your account until you confirm it.10 minutes
cruxy_webauthn_challengeA single-use challenge for signing in with, or adding, a passkey.5 minutes
cruxy_active_orgRemembers which of your organisations you last switched to.1 year
cruxy_login_errorCarries a sign-in error message to the sign-in page.60 seconds, cleared once shown
cruxy_sessionAn older sign-in cookie. The app no longer sets it, and deletes it when it finds it.Deleted when found

The app also keeps a few preferences in your browser's local storage rather than in cookies: your theme, your cookie choice, whether you have read the note about dictation, and the width of the artifact panel. When you pay for a plan, Razorpay's checkout opens in a window served by Razorpay, which may set its own cookies under Razorpay's privacy policy.

Both sites

We do not use analytics cookies, marketing cookies, or tracking cookies. Apart from Razorpay's checkout, we do not embed third-party widgets that set cookies (no Facebook Like buttons, no Twitter share embeds that set cookies, no chatbot widgets that profile you).

If we add analytics in the future, we will choose privacy-respecting providers like Plausible or Fathom that do not use cookies, or we will add a clear cookie consent banner.

AI services and your data

The Cruxy AI services process the input you send (prompts, files) to generate responses. Our commitments about how that data is handled:

  • Your prompts and outputs are not used to train Cruxy's models without your explicit, separate consent.
  • You own the outputs you generate, subject to our Usage Policy.
  • We keep a conversation and its messages until you delete it, or until 365 days after its last activity, whichever comes first. Adding a message, or changing its title or model, is activity; archiving it is not. A job that runs once a day deletes conversations past that point. Deleting a conversation removes it and its messages immediately and permanently; there is no trash. Deleted conversations remain in database backups until those backups are deleted.
  • Enterprise customers will have separate data processing agreements (DPAs) with stronger guarantees about data residency, retention, and deletion.

The detailed terms governing AI services will be published as a separate addendum to this policy.

Memory

Cruxy can remember durable facts about you and your work, such as a preference you have stated, a setting you use, or a constraint on your projects, and use them as context in later conversations. Memories are personal data, and this section explains how they are created, what they are drawn from, and how you control them.

How memories are created

  • By you. You can save a memory from a chat with "Remember this", or add one yourself in Settings, under Memory.
  • Automatically. After Cruxy answers a message, your latest message and Cruxy's reply are sent to a model that decides whether they contain a durable fact that you stated. Most exchanges produce nothing; at most three short facts are kept from one exchange. Email addresses, phone numbers and card numbers are filtered out before anything is stored.

Automatic capture runs in Cruxy Chat, in Cruxy Code (command-line) sessions, and on requests to the Cruxy API's chat endpoints made with your API key. It does not run on the API's OpenAI-compatible chat completions endpoint.

In Cruxy Code sessions, the agent reads files in your project in order to work on them. The results of those file reads are not themselves passed to memory capture. However, if your message or the agent's reply contains file contents, that text is part of what the capture model reads, and a fact drawn from it can be stored as a memory.

The capture model runs on DeepInfra, our AI inference sub-processor (see "Who we share with"). Memories are stored in our database, together with a numerical representation used to find the memories relevant to a conversation, which DeepInfra also computes.

Who can see a memory

A memory captured from your own conversations is personal: only you can see it and only you can remove it. A memory captured while you work in a shared vault you can write to is stored in that vault and is visible to everyone who can see the vault. Memories added to your organisation are visible to everyone in it. Automatic capture never writes to your organisation's memory.

Reviewing and deleting memories

Settings, under Memory, lists everything Cruxy remembers and applies as context, whatever its source: personal memories, and memories shared with you through a vault or your organisation. You can delete any personal memory there, one at a time. A memory shared through a vault can be removed by an owner or admin, and one shared through your organisation by an owner. Through the Cruxy API you can also delete all of your personal memories at once. You can also ask us to erase your memories, as described under "Your rights".

Turning capture off

  • In Cruxy Chat, a temporary chat saves nothing to memory. A personalized temporary chat can still use what is already in your memory; an unpersonalized one does not.
  • In Settings, under Privacy, turning off "Save new chats" makes every new chat a temporary chat, except a chat filed into a vault, which is always saved.
  • On the Cruxy API, a request can turn capture off for that request by sending "memory": {"capture": false}.

How long memories are kept

Memories have no expiry. They are kept until they are deleted. Deleting your Cruxy account does not currently delete your memories automatically: delete them in Settings first, or ask us to erase them. Memories stored in a shared vault or in your organisation stay with that vault or organisation.

Changes to this policy

We may update this Privacy Policy as Cruxy evolves and as our practices change. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Email subscribers to the waitlist or active users (where the change materially affects them).
  • Post a clear notice on getcruxy.com for at least 30 days for major changes.

For non-material changes (clarifying language, fixing typos, updating sub-processor links), we will simply update the page without separate notification. The version history of this policy is maintained internally.

Continued use of the Service after a policy change becomes effective constitutes acceptance of the change. If you disagree with the change, you may stop using the Service and request deletion of your data.

Contact us

For privacy questions, data subject requests, or to report a concern:

Email: [email protected]
Subject line: "Data subject request" or "Privacy question" - helps us route quickly.

mycrux. Private Limited
CIN: U47912AP2025PTC121345
GSTIN: 37AATCM9031H1ZZ
Registered office: 14-4-28/1, Sy No 86/P, Bhanoji Thota, B.C Road, Gajuwaka, Visakhapatnam, Andhra Pradesh 530044

Grievance officer

Complaints about the Service, or about how we handle your personal data, can be sent to our grievance officer. We acknowledge a complaint within 48 hours of receiving it and resolve it within one month of receiving it.

Grievance officer: Dinesh Srisanth Adari
Email: [email protected]

If you do not receive a satisfactory response from us, you have the right to lodge a complaint with the Data Protection Board of India once it is operational.