← crontent.co

Privacy policy

Last updated 27 July 2026

Crontent researches your niche and drafts content on a schedule. That needs your account details, the briefs you write, and the output we generate for you. This page says exactly what we hold, who else touches it, and how to get it back or deleted.

Who we are

Crontent operates this service. For anything on this page, including access and deletion requests, contact us.

What we collect

Account information

When you sign in we store the email address, name, and profile picture your identity provider gives us, plus an opaque provider user ID. We record when you last signed in and when we last saw a request from you, so we can tell an abandoned account from a live one.

The content you create

Projects, briefs, the research runs they trigger, the stories we discover, drafts, and finished pieces. Briefs are the substantive part: whatever you write about your product, audience, and voice is stored so runs can use it.

Billing information

Card numbers never reach our servers and we could not show you one if you asked. Payment details are entered on Stripe's own checkout pages. We store a Stripe customer identifier, a subscription identifier, your plan, its status, and its renewal date — enough to know what you are entitled to and when.

Integration credentials

If you create API keys we store a hash and a short display prefix, never the key itself — which is why a lost key must be replaced rather than recovered. Webhook signing secrets are stored encrypted.

What we do not collect

We run no advertising or analytics trackers and set no third-party cookies. The only cookie is the session cookie that keeps you signed in; removing it signs you out. We do not buy data about you, we do not sell or rent your data, and we do not build advertising profiles.

How we use it

  • Running the research and drafting pipeline you asked for.
  • Enforcing plan limits, such as how many runs a week you get.
  • Taking payment, and emailing you about your subscription. These are service messages, not marketing, so they are not optional while you have an account.
  • Nudging you by email when a run is waiting on your input. You can turn this off in settings.
  • Investigating faults, abuse, and security incidents.

We do not use your briefs or your generated content to train our own models, and we do not use one customer's content to produce another's.

Who else processes your data

Running this service means sending some of your data to other companies. These are all of them:

ServiceWhat it doesWhat it sees
Auth0 (Okta)Sign-in and sessionsEmail, name, profile picture
SupabaseDatabase hostingEverything we store
VercelApplication hostingRequests, IP addresses, server logs
StripePayments and subscriptionsEmail, payment details, billing history
OpenAIContent generationBrief text and research material sent as prompts
ExaWeb search during researchSearch queries derived from your brief
FirecrawlReading discovered pagesURLs to fetch
SendGrid (Twilio)Transactional emailEmail address, message contents
SanityOur public blogNo customer data

Where your data is stored

Our database is hosted in Tokyo, Japan (ap-northeast-1). The services above operate globally, so your data is processed outside your own country and outside Japan. If you are in the EU, UK, or another region with data-transfer rules, treat this as an international transfer.

Your rights

You can ask us to:

  • Give you a copy of what we hold about you.
  • Correct anything wrong.
  • Delete your account and its contents.
  • Stop sending optional email.

Contact us and we will action it. Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to a regulator — in Australia that is the Office of the Australian Information Commissioner.

Security

Traffic is encrypted in transit. API keys are hashed, webhook secrets encrypted, and database access is restricted. No system is perfectly secure, and we would rather say that plainly than imply otherwise. If you find a vulnerability, please report it to us before disclosing it publicly.

Changes

If we change this policy we will update the date at the top, and email you if the change is significant. Continuing to use Crontent after a change means you accept the updated policy.