Privacy policy
Last updated: August 22, 2026
Information we process
We process account and report-recipient email addresses, authentication records, workspace membership, encrypted request credentials, schedules, endpoint URLs, execution results, response excerpts, alerts, incidents, usage events, subscription records, referral attribution, and support communications.
Purposes
We use data to authenticate accounts, dispatch and monitor jobs, enforce plan limits, generate and deliver reports, send alerts, prevent abuse, operate billing, diagnose failures, improve onboarding, and maintain service security.
Client report links
Scheduled client reports contain frozen, bounded outcome metrics rather than endpoint URLs, request or response bodies, credentials, or internal investigation evidence. Each recipient receives an independent random access link. CronClaw stores only its hash; links expire automatically and workspace owners can revoke them. Opening a link records its first and latest view time and aggregate view count.
Secrets and endpoint responses
Job secrets and protected request credentials are encrypted at rest. Job secrets are shown once. Execution responses are limited to operational excerpts; configure endpoints to avoid returning passwords, tokens, personal records, or other unnecessary sensitive data.
Service providers
We use providers for hosting, transactional email, payments, error monitoring, backups, and customer-requested alert destinations. Paddle acts as merchant of record when Paddle checkout is used. We do not sell personal information.
Retention
Execution history follows the subscribed plan. Report-delivery audit records may be retained after a schedule is removed, while access links are revoked. Security, billing, audit, backup, and legal records may be kept longer where required to prevent fraud, resolve disputes, restore service, or meet legal obligations. Expired operational data is removed through scheduled cleanup.
Customer controls
Workspace owners can manage jobs, monitors, members, integrations, report recipients and links, and API keys. You may request access, correction, export, or account deletion by contacting support. Some billing and security records may need to be retained.
International processing
Providers may process data in multiple countries. We select providers and contractual safeguards appropriate to the service and applicable requirements.
Security
Controls include HTTPS, HMAC-signed requests, timestamp replay protection, encrypted credentials, scoped workspace access, expiring report capabilities, CSRF protection, rate limits, SSRF protection, audit events, bounded responses, and operational monitoring. No system can eliminate all risk.
Contact
Privacy requests can be sent to support@cronclaw.com.