Privacy Policy
Last updated: August 25, 2026
This Privacy Policy explains how Crubo, LLC ("Crubo," "we," "us"), an Indiana limited liability company, collects, uses, and shares information when you use Crubo, our deal-management service for content creators (the "Service") at crubo.io. It does not cover third-party websites, brands, or services you may reach through Crubo.
By using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Who can use Crubo
The Service is offered only to users in the United States who are 18 years of age or older. We do not offer the Service to, and do not knowingly collect information from, residents of the European Economic Area, the United Kingdom, or Switzerland, or anyone under 18. If we learn we have collected information from someone under 18 or from an excluded region, we will delete it.
This Policy covers creators (account holders), team members and managers a creator invites, and third parties whose information a creator brings into the Service (see §8).
2. Information we collect
2.1 Information you give us
- Account and profile information — your name, email, and login credentials (handled through our authentication provider), plus profile details, handle, bio, and media-kit content you add.
- Deal information — the brand deals you log: rates, deliverables, dates, exclusivity and usage terms, and notes, whether typed in or extracted from a contract you upload.
- Contracts and files — documents you upload, including brand agreements.
- Media-kit content — images, audience and demographic figures, rate cards, services, testimonials, and credentials.
- Billing information — your billing name and tax identifier if you generate invoices (see §5).
- Support communications — messages and attachments you send us.
2.2 Email you route into Crubo
Crubo gives you an intake email address so you can forward brand correspondence into your account, or share the address to receive it. When email arrives, we store its contents — body, subject, sender and recipient details, and attachments, including the raw email as received — so you can review, file, or act on it.
Your intake address can receive mail from anyone; we do not restrict who may send to it. You can regenerate it (which immediately disables the old one) or change it by changing your username (which does the same). See §8 about information this brings in about other people.
2.3 Sending email on your behalf
If you connect a Google or Microsoft account, Crubo can send email from your address at your direction. We request only permission to send email — never to read your mailbox. The access token is stored encrypted, and you can disconnect at any time. See §4.1 for how Crubo handles Google user data specifically, and §4.2 for Microsoft.
2.4 Information we generate
- Extracted deal terms — when you upload a contract or route in an email, we use automated processing (see §4) to pull out deal terms, stored with the deal.
- Brand and contact suggestions — we may generate suggested brand contacts and leads and enrich brand records using publicly available information.
2.5 Information collected automatically
Standard log data such as IP address, browser and device type, and how you interact with the Service, plus cookies and similar technologies used to keep you logged in and operate the Service.
3. How we use information
We use information to provide and operate the Service; extract, organize, and display your deals, contracts, and correspondence; send email on your behalf when you direct us to; generate invoices and reflect payment status; send notifications and Service messages; provide support; develop de-identified, aggregated pricing insights (see §7); and secure the Service, prevent abuse, and comply with law.
We do not sell your personal information, do not use your content to build advertising profiles, and do not use your content to train general-purpose AI models.
4. Automated processing and AI
Crubo uses automated processing, including a third-party AI provider, to read contracts and correspondence and extract deal terms for you. We send the relevant content to our AI provider's programming interface and return the result to your account. Crubo does not use your contract or email content to train AI models of its own.
We use Anthropic's API. Under Anthropic's Commercial Terms of Service, content Crubo submits is not used to train Anthropic's models, is treated as our confidential information, and is subject to limited retention under Anthropic's Data Processing Addendum. Because a provider's terms can change, see Anthropic's current terms to confirm the present commitment: https://www.anthropic.com/legal/commercial-terms.
Automated extraction can be wrong or incomplete. Crubo's outputs are informational and are not legal advice; review anything important yourself and consult a qualified professional before relying on it.
4.1 Google user data
Crubo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- What we access. If you connect a Google account, Crubo requests permission only to send email on your behalf (the Gmail "send" scope). Crubo does not request, and does not have, permission to read, search, or download your Gmail messages or mailbox.
- How we use it. We use this access solely to send emails you direct Crubo to send from your address, and to obtain your basic account identity to establish the connection.
- How we store it. The access credential is stored encrypted and used only to provide this feature.
- What we do not do. We do not use Google user data to serve advertising, to build advertising profiles, or to train generalized artificial-intelligence or machine-learning models. We do not sell or transfer Google user data, and we do not allow humans to read it except with your consent, for security or to comply with law, or as required to operate the feature you enabled.
- How to revoke. You can disconnect your Google account at any time within Crubo, which revokes Crubo's access, and you can also review or revoke access at https://myaccount.google.com/permissions.
4.2 Microsoft user data
If you connect a Microsoft account — Outlook, Hotmail, or a work or school account — the same limits apply.
- What we access. Crubo requests permission only to send email on your behalf (the Microsoft Graph Mail.Send permission), together with your basic profile so we can read the address you send from. Crubo does not request, and does not have, permission to read, search, or download your mailbox.
- How we use it. We use this access solely to send emails you direct Crubo to send from your address, and to obtain your basic account identity to establish the connection.
- How we store it. The access credential is stored encrypted and used only to provide this feature.
- What we do not do. We do not use Microsoft user data to serve advertising, to build advertising profiles, or to train generalized artificial-intelligence or machine-learning models. We do not sell or transfer Microsoft user data, and we do not allow humans to read it except with your consent, for security or to comply with law, or as required to operate the feature you enabled.
- How to revoke. You can disconnect your Microsoft account at any time within Crubo, which deletes the stored credential. Unlike Google, Microsoft does not offer a way for an application to revoke its own consent record, so to remove Crubo from your account's permissions as well, visit https://account.live.com/consent/Manage for a personal account or https://myaccount.microsoft.com/privacy for a work or school account.
5. Payments
If you use Crubo to invoice a brand, payment is handled by Stripe, not by Crubo. The brand pays through a Stripe link and funds settle directly to you. Crubo never receives, holds, or moves your money, and never receives or stores card or bank-account numbers. Stripe processes payment details under its own terms.
Crubo receives only limited confirmation from Stripe — such as whether and when a payment was made and its amount — to update the related deal's status. Because payment can also happen by methods Crubo never sees, payment status in Crubo may be incomplete, and you can mark payments manually.
6. How long we keep information, and how to delete it
We keep your information while your account is active and as needed to provide the Service.
Deleting your account. When you delete your account, we delete your associated data — profile, deals, contracts, uploaded files, media kits, routed email, and related records — from our database and file storage, and we revoke your login identity. Deletion is permanent.
Data we may retain. After deletion we may keep limited information where the law requires it, in routine backups that cycle out over time, and de-identified pricing data that can no longer be linked to you (see §7).
Deleting individual items. You can delete individual deals, files, and routed emails within the Service; deleting a routed email removes its content and attachments.
Your choices. You can access and update most information within the Service, and you can request a copy or deletion by contacting hello@crubo.io.
7. Pricing insights (de-identified aggregate data)
Crubo is developing pricing insights — general benchmarks about what deals of a given kind tend to be worth — to help creators understand their market. Where we develop these insights, we first transform deal information into de-identified, aggregated data: we remove identifying details and reduce values to coarse groupings (for example, a follower-count band rather than an exact count, a price range rather than an exact figure, a period rather than an exact date). This data contains no names, handles, emails, brand identities, or account identifiers, and no key linking a record back to you. It is used only in aggregate, such that no individual creator or deal can be singled out.
Because this data is de-identified and cannot be traced to you or any individual deal, it does not expose your personal information. Deleting your account stops your future deals from contributing; data already de-identified and pooled cannot be linked back to you.
8. Information about people who don't use Crubo
Crubo necessarily holds information about people who never signed up — most often brand representatives and contacts — when a creator forwards or receives email including their details, uploads a contract naming them, adds them as a contact, or when someone requests access to a media kit.
If you are one of these people: the creator who brought your information into Crubo controls it within their account. We store it to provide the Service to that creator. We do not use it to build advertising profiles, we do not sell it, and we do not use it to contact you on our own behalf. To ask what information relating to you a creator holds, or to request removal, contact hello@crubo.io and we will work with you and the relevant creator.
9. How we share information
We share information only as needed to run the Service:
- Service providers who host and operate Crubo under contract — including hosting, database, file storage, authentication, email delivery, our payment processor (Stripe), and our AI provider (Anthropic).
- At your direction — such as sending email from your connected account or serving a media kit you publish.
- For legal reasons — to comply with law, enforce our terms, or protect the rights, safety, and security of Crubo, our users, and the public.
- Business transfers — if Crubo is involved in a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell your personal information and do not share it for cross-context behavioral advertising.
10. Security
We protect information with measures including encryption in transit, access controls, encrypted storage of sensitive credentials such as email tokens, and internal access limits. No system is perfectly secure, and we cannot guarantee absolute security.
11. Published media kits
If you publish a media kit, content you mark public becomes visible to anyone with the link, and content you mark private is withheld from public view. If you password-protect a media kit, its content, including images, is served only to viewers who unlock it. If you grant a brand access, the information you chose to share is disclosed to them. Treat anything you publish as public.
12. Changes to this Policy
We may update this Policy. If we make material changes, we will take reasonable steps to notify you, such as by posting the updated Policy with a new date or notifying you within the Service. Changes are effective when posted unless stated otherwise.
13. Contact us
Questions or requests about this Policy or your information:
Crubo, LLC (Indiana) hello@crubo.io