Privacy

Effective July 10, 2026 · applies to the Crinkle app and this website

The short version: Crinkle runs on your computer, and your work stays there. If you sign in, we count how the app is used, never what you build, say, or type. Anonymous setup milestones are off unless you explicitly enable them.

Who we are

Crinkle and crinkle.dev are operated by Crinkle's developer, who is the data controller for the little personal data described on this page. Contact for anything privacy-related, including a postal address on request: support@crinkle.dev.

What stays on your machine

Everything that matters: your projects, generated code and files, chat history with the agents, uploaded documents, site credentials, and API keys. API keys and credentials are stored encrypted, bound to your machine. None of this is uploaded to us. Crinkle has no server that ever sees your work.

Your AI providers

Crinkle sends prompts (which can include your project files) to whichever AI you connect: your OpenAI, Anthropic, or Google API account, your ChatGPT/Claude subscription via their CLIs, or a local model on your own hardware. Those requests go directly from your machine to your chosen provider under their terms and privacy policy; they never pass through our servers. With a local model, prompts never leave your computer at all.

Accounts & sign-in

Sign-in is optional and exists to attribute usage statistics and feedback to an account. We store your email address and authentication tokens (handled by Supabase, our auth and data processor). Signing in enables usage reporting, and this is disclosed at the moment you sign in.

Usage statistics (while signed in)

These are counts and categories only, for example:

Never collected: your prompts, chat text, code, file contents or names, model outputs, API keys, or provider account details. When you're signed out, none of these usage statistics are collected or sent, and the app works fully.

Optional setup milestones (signed in only)

Off by default. If you explicitly enable this setting after signing in, Crinkle reports at most five one-time events per installation: app installed, setup wizard finished, an AI connected, first run started, and first project completed. Each is a count with the app version and operating system, tied to a randomly generated ID, never a machine or hardware identifier, and never anything about what you build. Each event is sent once, ever, to our Supabase data service. You can switch this off again in Settings → Setup → Account & privacy → “Share anonymous setup milestones” and after that, nothing is sent at all.

Feedback

The in-app feedback box (including reports of inappropriate AI-generated content) sends exactly what you type in it with your signed-in account ID. That's the one place actual text leaves your machine because you wrote it and pressed Send. If you do not want to sign in, email support@crinkle.dev instead.

This website

crinkle.dev uses Vercel Web Analytics: cookieless, aggregated page-view and product-interest counts. The download and copy-command buttons report only the aggregate event name through Vercel; Crinkle does not create its own browser identifier. Creating an account here uses the same Supabase sign-in as the app.

Why there is no cookie banner: we set no advertising or tracking cookies at all. The only browser storage we use is the strictly necessary kind: remembering your verified email on this site after you sign in, and your appearance preferences in the app. Nothing to consent to means nothing to nag about.

What we don't do

Deleting your data

Email support@crinkle.dev from your account address and we'll delete your account and every row attributed to it. Local data is yours to delete anytime. Direct-download installs use %APPDATA%\Crinkle (or %APPDATA%\Relay for installs from before the rename). Microsoft Store installs use %USERPROFILE%\.crinkle so uninstalling or switching package channels does not silently destroy projects. Use Delete all local data before uninstalling if you want that retained Store data removed too.

How long we keep things

Account data (your email and the usage counts attributed to it) is kept while your account exists and deleted when you ask us to delete the account. Feedback you send is kept as long as it is useful for fixing the product. Website analytics exist only as aggregates that identify nobody. Everything on your machine is yours and follows your own delete key.

Your rights

Wherever you live, we honor the full set: you can ask us what we hold about you, get a copy of it, correct it, or have it deleted, by emailing support@crinkle.dev from your account address. We answer within a month.

Children

Crinkle is not directed at children under 13, and we do not knowingly collect their information. If you believe a child has created an account, tell us and we will delete it.

Changes

If this policy changes materially, we'll update this page and note it in release notes. Questions: support@crinkle.dev.