Privacy policy
Last updated: 28 September 2026
Who we are
The CribleAI project, ahead of the creation of its company ("CribleAI", "we"). Privacy contact: hello@cribleai.com.
We play two roles. For this website and our commercial relationships we are the controller. For the CribleAI service, the organisation that subscribes (your employer, if you use CribleAI at work) is the controller and we are its processor, acting only on its instructions under a data processing agreement (GDPR art. 28).
This website and demo requests (we are controller)
- What: the details you give in the demo form (name, work email, company, team size, message), and technical data needed to serve the site (IP address in server logs).
- Why and on what basis: answering your request and following up with your company (legitimate interest in business-to-business prospecting, GDPR art. 6(1)(f), and steps prior to a contract, art. 6(1)(b)); keeping the site secure (legitimate interest).
- How long: prospect data for 3 years after our last contact with you, as the CNIL recommends; server logs for up to 12 months.
- Marketing emails only if you ask for them, with an unsubscribe link in each one.
The CribleAI service (we are processor)
When your organisation uses CribleAI, it decides what is processed and why. We process, on its behalf: account data (name, work email, team, role), conversations and attached files, and the metadata of each inspection (which categories were detected, which rule applied, which model was used). Detection runs on our infrastructure; it does not send your text to any third party to be classified.
Depending on your organisation's rules, a message is sent to an external AI model (after sensitive values are removed where the rules say so), to a private model your organisation controls, or not at all. Which external models are enabled, and any transfer outside the EU they involve, is your organisation's decision, documented in its contract with us.
Retention is set by your organisation. Questions about how your employer uses CribleAI, including any monitoring, go first to your employer or its data protection officer; we will help them answer.
Who receives data
Our staff who need it, and these sub-processors, all bound by data processing agreements:
- Netlify, Inc.: Hosting of the website and of demo requests (United States (global network))
- Our email provider: Email, including demo requests and our replies
This website and your demo requests are hosted by Netlify, Inc. (United States (global network)). Where a recipient is outside the European Union, the transfer relies on the European Commission's safeguards (an adequacy decision such as the EU-US Data Privacy Framework, or standard contractual clauses). We do not sell personal data or use it to train AI models.
Security
Encryption in transit, access limited to those who need it, passwords stored only as hashes, invitation links stored only as hashes and valid once for 48 hours, and a record of every administrative change.
Your rights
You can ask to access, correct or delete your data, to restrict or object to its processing, to receive it in a portable format, and to withdraw any consent you gave. In France you can also set directives for what happens to your data after your death. Write to hello@cribleai.com; we answer within one month.
You can also complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr, or to the data protection authority of your EU country.
Changes
We will update this page when our processing changes, and tell customers of any material change.