Privacy

Updated September 8, 2026 · applies to the Crinkle app and this website

The short version: Crinkle stores your projects on your computer. Connected AI providers and services receive the information needed for the actions you authorize. If you sign in, we count how the app is used, never what you build, say, or type. Anonymous setup milestones are off unless you explicitly enable them.

Who we are

Crinkle and crinkle.dev are operated by Crinkle's developer, who is the data controller for the little personal data described on this page. Contact for anything privacy-related, including a postal address on request: support@crinkle.dev.

What stays on your machine

Everything that matters: your projects, generated code and files, chat history with the agents, uploaded documents, site credentials, and API keys. API keys and credentials are stored encrypted, bound to your machine. Project content is not automatically uploaded to Crinkle for usage reporting. Content can leave your machine through connected providers, deployments, web actions, feedback, or diagnostic reports you choose to share.

Your AI providers

Crinkle sends prompts (which can include your project files) to whichever AI you connect. Supported connections include, and are not limited to, API accounts with OpenAI, Anthropic, Google, NVIDIA (NIM), xAI and OpenRouter; subscription CLIs (Claude Code, Codex, and Antigravity, which signs in with your Google account); and local endpoints on your own hardware such as Ollama or LM Studio. Those requests go directly from your machine to the provider you chose, under their terms and privacy policy; they never pass through our servers. Inference stays on your computer when you use an endpoint hosted there. Remote endpoints, cloud fallback connections, web browsing, and deployment integrations can still transmit information; choosing a local model does not make those other features offline.

Routing services pass your prompts on. OpenRouter, and any other aggregator or self-hosted gateway you point Crinkle at, forwards your request to a further model provider of its own choosing. That downstream provider receives the prompt too, under its own terms, and we have no visibility into which one it was. If that matters for your work, connect a provider directly instead of through a router.

If you use the Web operator (below), this also includes the text and screenshots of the pages it visits — that is how it sees a page well enough to act on it.

The Web operator (off unless you turn it on)

Crinkle can browse the web for you. This feature is off by default and lives in Settings ▸ Web operator. Nothing in this section happens unless you switch it on.

When it is on, and only for the sites you allow:

Credentials you give the Web operator — site logins, your mail app password — are stored in the same encrypted, machine-bound vault as your API keys. They are sent only to the site they belong to, are not intentionally inserted into AI prompts by the credential store. Page text, screenshots, command output, or files can still contain sensitive information and may be included in provider requests.

Accounts & sign-in

Sign-in is optional for local Free-plan use and supports your plan, usage statistics, and feedback. You can sign in with an emailed code or an offered Google or GitHub connection. The authentication service receives the account information supplied by that sign-in method, such as your email and profile identifiers. We store your email address and authentication tokens (handled by Supabase, our auth and data processor). Signing in enables usage reporting, and this is disclosed at the moment you sign in.

Plans, payments, and usage metering

If you buy a paid plan, payment is handled by Stripe, our payment processor. Stripe collects your card details, billing address, and the email you check out with, under its own privacy policy; we never receive or store your card number. What we keep is the link between your account and Stripe (customer and subscription ids), your plan, its billing period, and whether it is set to cancel. Stripe's invoices and receipts are yours to view from the Manage plan page.

To apply your monthly token allowance, the app reports token counts (how many tokens were generated, how many were estimated, how many calls) for your account and the billing period, tagged with a per-install device identifier so a plan can be shared across your own devices. This identifier is derived from a machine identifier and a random installation salt; the raw machine identifier is not sent. That is the whole record: no prompts, no code, no provider details. Free-plan use without signing in is metered only on your own machine and reports nothing.

Usage statistics (while signed in)

These are counts and categories only, for example:

Not included in automatic usage reporting: your prompts, chat text, code, file contents or names, model outputs, API keys, or provider account details. When you're signed out, none of these usage statistics are collected or sent, and the app works fully.

Optional setup milestones (signed in only)

Off by default. If you explicitly enable this setting after signing in, Crinkle reports at most five one-time events per installation: app installed, setup wizard finished, an AI connected, first run started, and first project completed. Each is a count with the app version and operating system, tied to a randomly generated ID, never a machine or hardware identifier, and never anything about what you build. Each event is sent once, ever, to our Supabase data service. You can switch this off again in Settings → Setup → Account & privacy → “Share anonymous setup milestones” to stop future setup milestones. Signed-in usage reporting and billing metering are separate.

Feedback

The in-app feedback box (including reports of inappropriate AI-generated content) sends exactly what you type in it with your signed-in account ID. We receive that text because you chose to submit it. If you do not want to sign in, email support@crinkle.dev instead.

Diagnostic reports and support

The Bug report button creates a local ZIP for you to download; it does not automatically send it to us. If you email or otherwise share it with support, we receive its contents. Reports can include project details, settings, provider labels and endpoints, execution results, and recent activity and app logs, including logs from other recent projects. Logs may contain chat text, generated output, or other sensitive information. The exporter excludes stored secrets and applies redaction, but redaction cannot guarantee removal of every sensitive value. Review the archive before sharing it. Support emails also include your address and any attachments.

This website

crinkle.dev uses Vercel Web Analytics: cookieless, aggregated page-view and product-interest counts. The download and copy-command buttons report only the aggregate event name through Vercel; Crinkle does not create its own browser identifier. Creating an account here uses the same Supabase sign-in as the app.

Optional Microsoft Clarity. If you choose ?Allow analytics,? Microsoft Clarity records page interactions, such as clicks, scrolling and mouse movement, to create session replays and heatmaps. We use these to find usability problems. Microsoft receives this data too and processes it under the Microsoft Privacy Statement, which describes Microsoft's purposes and practices. We do not send account identifiers through Clarity's identification API.

Clarity supports first- and third-party cookies and related tracking technologies. Our integration requests analytics storage only and explicitly denies advertising storage. This setting does not replace Microsoft's privacy statement or establish that every Microsoft processing purpose is controlled by us.

Clarity is not loaded until you allow it. Choose "Decline analytics" to keep it off, or use "Analytics choices" on any page to change your choice. Withdrawing permission reloads the current page to stop recording and removes accessible first-party Clarity cookies; it does not erase previously received data or cookies on Microsoft's domains. We remember your choice in browser storage. Vercel analytics remain separate.

Clarity is not loaded on the account page or pricing page, including signed-in pricing views, and is not included in the desktop app. Public marketing and policy pages are the only eligible pages.

Cookies and browser storage. Sign-in uses browser storage for authentication sessions, not just your email address. Payment and identity providers may use their own storage on their pages. We run no advertising cookies of our own and no ad network on this site; the analytics cookies Clarity sets are described above. Vercel describes its analytics as cookieless and uses a request-derived hash to distinguish visitors, reset daily. Cookieless does not mean that no request data is processed.

Hosting, sign-in, and payment services process technical request information, such as IP addresses and browser information, to deliver and protect their services. See the linked provider notices for their practices. Websites visited by the Web operator use a separate local browser profile and may set their own cookies.

Browser privacy signals and third-party tracking

Crinkle does not use cross-site behavioral advertising and does not change its own data collection in response to the legacy Do Not Track signal. We request no advertising storage from Clarity and provide the choice to keep it entirely off. If your browser sends a Global Privacy Control signal, this website does not load Microsoft Clarity at all — the tag is skipped before it runs, so no session is recorded and no Clarity cookie is set. Vercel's cookieless counts and the storage that keeps you signed in are unaffected, because neither is advertising. Identity and payment providers may recognize you across services when you use their sign-in or payment pages. Their own notices explain that processing. Vercel analytics on this website are described above.

What we don't do

Deleting your data

Email support@crinkle.dev from your account address and we'll delete your account and associated personal data, subject to records that must be retained for legal, accounting, fraud-prevention, or dispute purposes. We will explain applicable exceptions when handling your request. Cancelling a subscription and deleting local files are separate actions; request cancellation as well if you want recurring billing to stop. Local data is yours to delete anytime. Direct-download installs use %APPDATA%\Crinkle (or %APPDATA%\Relay for installs from before the rename). Microsoft Store installs use %USERPROFILE%\.crinkle so uninstalling or switching package channels does not silently destroy projects. Use Delete all local data before uninstalling if you want that retained Store data removed too.

Subscription records and service notices

We retain purchase and subscription-consent records, including the accepted disclosure version, price, currency, billing interval, and timestamp, for at least three years after acceptance and at least one year after the subscription ends, whichever is later, and longer if required for legal obligations or disputes. We use your billing contact address to send purchase acknowledgments and subscription notices. These are service messages, not advertising. Our configured email delivery service processes the address and message to deliver them. You can ask support which delivery provider is currently in use.

How long we keep things

Account data (your email and the usage counts attributed to it) is kept while your account exists and handled under the deletion process above when you request account deletion. Feedback you send is kept as long as it is useful for fixing the product. Website analytics are reported in aggregate; hosting and security records are separate. Everything on your machine is yours and follows your own delete key.

Our audience and applicable rights

Crinkle primarily targets a United States audience, but is not exclusively for US customers. Availability depends on the distribution channel and services offered. This notice describes our practices; applicable privacy and consumer rights may also depend on where you live. Contact us to exercise those rights.

Your rights

Whoever you are, you can ask us what we hold about you, get a copy of it, correct it, or have it deleted, by emailing support@crinkle.dev from your account address. We answer within a month, and we will never treat you differently for asking.

Children

Crinkle is not directed at children under 13, and we do not knowingly collect their information. If you believe a child has created an account, tell us and we will delete it.

Changes

If this policy changes materially, we'll update this page and note it in release notes. Questions: support@crinkle.dev.