CROOMA

Privacy Policy

Last Updated: August 2026

Crooma GmbH (i.G.), Munich, Germany ("Crooma", "we", "us", or "our") operates the platform crooma.cloud. This Privacy Policy outlines how we collect, process, isolate, and secure personal data in accordance with the European Union's General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).


1. Relational Sovereignty: Privacy by Architecture

At Crooma, privacy is not a compliance checkbox—it is a load-bearing architectural invariant. Our platform is engineered to keep your business context and customer data completely secure:

  1. Strict 1:1 Tenant Isolation: Every registered workspace is mapped exactly 1:1 to an independent, path-isolated database directory (~/.continuum/<tenantId>/) on disk. Your search queries, metadata, observations, and transcripts are physically separated from all other customers. Cross-tenant leakage is structurally impossible.
  2. Write-Time Privacy Choke-Point: Crooma implements a global, 11-pattern write-time scrubbing engine. Before any observation, git log, document, or transcript is written to your database, it passes through our filter to redact:
  1. Local-First Sovereignty: The core trust engine operates local-first over SQLite and local embedding generation. No raw files or documents are ever transmitted to third-party AI cloud systems; only specific, highly compressed vector query dimensions are sent on an as-needed basis to execute programmatic rendering.

2. Personal Data We Process

When you interact with the Crooma visual shell, we process the following categories of data:

A. Account and Registration Information

When you create a workspace, we store your name, business email address, company profile, and encrypted authentication credentials (managed via Supabase Auth with Row-Level Security).

B. Billing and Payment Telemetry

To process paid subscriptions (Pro and Team tiers), we integrate with Stripe, Inc. We do not store credit card or raw bank information on our servers; Stripe securely manages this data. We store only billing indicators, transaction statuses, and invoice references.

C. Creative Assets and Metadata

When you upload shoots, photos, or documents to Crooma, we store the physical files on secure cloud servers (Supabase/Vercel). The associated comments, ranks, and selection logs are written as Observations to your isolated Continuum database.


3. Data Sharing and Third-Party Processors

To deliver our services, we share data with trusted sub-processors under strict Data Processing Agreements (DPA) that guarantee GDPR compliance:


4. Your Rights Under the GDPR

As a resident of the European Economic Area (EEA), you possess absolute rights regarding your personal data under the GDPR:

To exercise any of these rights, please contact our Data Protection Officer at privacy@crooma.cloud.


5. Security Measures

Crooma employs state-of-the-art administrative and cryptographic safeguards to protect your workspace:

← crooma.cloud