Skip to content
Legal

Privacy policy

Last updated: July 30, 2026

1. Who we are

Crescive is operated by Vasan AI Technologies, LLC, a Delaware limited liability company ("Crescive", "we", "us"). This policy describes how we handle personal data across crescive.ai and the Crescive application. It is written to be read, not skimmed past — it is short because we collect little.

2. What we collect

Account data: your email address (used for passwordless sign-in) and workspace name. We do not require names, phone numbers, or job titles to use the product.

Product configuration: the brands, competitors, topics, prompts, and domains you configure for measurement. This is business data about public entities, not personal data, but we protect it with the same controls.

Measurement data: AI answer text, citations, and derived metrics collected through official, documented interfaces about the public brands you track.

Crawler analytics: server-log events (user agent, IP, path, timestamp) for domains you connect. Bot-verification requires source IPs; human-visitor log lines are aggregated, and raw entries age out on a fixed schedule.

Forms: if you request a demo we collect what you type into the form, use it to schedule the conversation, and nothing else. If you write to us through the contact form, we collect your name, email, and the answers you provide — including any details you volunteer about your business or challenges — and use them only to reply to your message; we don't add you to a mailing list or share the contents outside the team handling your message.

Operational telemetry: standard web logs and error traces necessary to run the service securely (NIST CSF 'Detect' function). We do not run third-party advertising trackers on this site.

3. What we never do

We never sell personal data. We never share it for cross-context behavioral advertising as defined by the CCPA/CPRA.

We never use your workspace data — prompts, measurements, documents, or logs — to train AI models, ours or anyone else's.

We never scrape consumer applications in violation of their terms to build our datasets, so your reporting never inherits that liability.

4. Legal bases and purposes (GDPR)

We process account data to perform our contract with you (Art. 6(1)(b)); operational telemetry and security logging under legitimate interest in running a secure service (Art. 6(1)(f)); and optional communications only with consent (Art. 6(1)(a)), withdrawable at any time.

5. Retention

Account data persists while your account is active and is deleted within 30 days of a verified deletion request. Measurement history is retained for the life of the workspace because trend continuity is the product; export it at any time. Raw crawler-log lines are retained for 90 days, aggregates thereafter. Backups age out within 35 days.

6. Subprocessors and transfers

We use a small set of infrastructure subprocessors (cloud hosting, database, email delivery), each under a data-processing agreement. A current list is available on request from [email protected]. Where data crosses borders from the EEA/UK, transfers rely on adequacy decisions or Standard Contractual Clauses.

7. Security

Controls follow the NIST Cybersecurity Framework: tenant isolation enforced at the database layer (row-level security), encryption in transit (TLS 1.2+) and at rest, secrets kept server-side and out of browsers, least-privilege access, audit logging, and periodic access review. Details live on our security page; responsible-disclosure instructions are published in our security.txt.

Support access: a small number of authorized Crescive staff can open a temporary session inside your workspace to help resolve a support request. That access is never standing — each session is time-boxed, requires a stated reason, and is designed to expire automatically at the end of that window, with a manual end available at any time as well. It is logged twice: internally, and in your own workspace's audit log, so your team can see that Crescive Support acted, by whom, and when. A visible banner is shown across your workspace for as long as a session is active.

8. Your rights

Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may request access, correction, deletion, portability, restriction of processing, or object to processing. Write to [email protected] from your account email; we verify and respond within 30 days. We do not discriminate against you for exercising any right.

This site sends no data to advertising networks, so there is nothing to opt out of under 'Do Not Sell or Share' — the honest kind of compliance.

9. Cookies

We use strictly necessary, first-party cookies for authentication and session security. No advertising cookies, no cross-site tracking, no cookie banner theater required.

10. Children

Crescive is a business tool, not directed at children under 16, and we do not knowingly collect their data.

11. Changes and contact

Material changes to this policy are announced in-product and by email before they take effect, with the revision date updated below. Questions: [email protected] · Vasan AI Technologies, LLC, Delaware, USA.