Privacy Policy — Crowly
Version: 1.2 Last updated: July 8, 2026
⚠️ DRAFT — English translation for reference only. This is an unofficial translation of the Portuguese Privacy Policy and has not been reviewed for legal adequacy in any jurisdiction. The Portuguese version governs and prevails in case of any conflict. This document is built around Brazilian data-protection law (LGPD, Internet Civil Framework) and the Brazilian supervisory authority (ANPD). If Crowly processes the personal data of users in the EU/UK, the United States, or other regions, the corresponding regimes (e.g., GDPR/UK GDPR, CCPA/CPRA) and their data-subject rights, legal bases, transfer mechanisms, and authority references must be reviewed and adapted by qualified counsel before this English version is published or relied upon. Do not treat this as final.
This Privacy Policy describes how Crowly collects, uses, stores, shares, and protects the personal data of its Users, in accordance with the Brazilian General Data Protection Law — LGPD (Law No. 13,709/2018) and the Internet Civil Framework (Law No. 12,965/2014).
By using the Platform, you declare that you have read and understood this Policy. Continued use represents acceptance of the practices described here.
1. Data Controller
For the purposes of art. 5, VI of the LGPD, Crowly is the Controller of the personal data processed through the Platform. Crowly is operated by a natural person resident in Brazil, identified as Lucas Oliveira.
Contact channels for exercising data-subject rights:
- Email: contato@gocrowly.com
- Correspondence address: Avenida Paulista, 1636, Sala 1504, Cerqueira César, São Paulo – SP, ZIP 01310-200, Brazil
- Brand operated: Crowly — gocrowly.com (formerly crowly.com.br)
Complete tax identification details of the operator (CPF/CNPJ) will be provided upon a substantiated electronic request or as required by legal, regulatory, or judicial demand.
2. Data Protection Officer (DPO)
In accordance with art. 41 of the LGPD, the officer responsible for personal-data processing is:
- Name: Lucas Oliveira
- Email: contato@gocrowly.com
The officer is the point of contact for data subjects, for the Brazilian National Data Protection Authority (ANPD), and for internal guidance on data protection.
3. Personal Data We Collect
3.1. Registration Data
Provided by the User when creating the Account, via email/password or Google authentication:
- Full name
- Email address
- Password (stored in encrypted form — hash)
- Profile photo and Google ID (only when the User chooses to authenticate via a Google account)
3.2. Registered Company Data
Entered by the User about the Company to be monitored:
- Legal name, trade name, industry segment
- Institutional website URL
- Competitors provided by the User
- Custom queries and monitoring settings
3.3. Payment Data
The complete credit-card data (number, CVV, expiration) is collected, processed, and stored directly by Stripe, Inc. Crowly does not store complete card data. From Stripe we receive only:
- Charge token
- Last 4 digits of the card
- Card network
- Payment status (success, failure, chargeback)
3.4. Usage Data and Logs
Collected automatically during navigation:
- IP address, browser, operating system, device
- Pages and features accessed, actions taken
- Access dates and times
- Access records (Internet Civil Framework, art. 15)
3.5. Content Entered by the User
Queries, monitoring settings, brand data, and competitor comparisons voluntarily entered by the User.
3.6. Cookies and Similar Technologies
See Section 9.
4. How We Collect Data
- Directly from the User — at registration, when filling in settings, and during use of the Platform.
- Automatically — via cookies, server logs, analytics tools.
- Via authorized integrations — Google Sign-In authentication, Stripe payment processing.
5. Purposes of Processing
Personal data is processed for the following purposes:
- Create, authenticate, and manage the User's Account
- Provide the contracted services (visibility monitoring in LLMs)
- Process payments and manage recurring charges
- Send transactional communications (billing, support, security, service changes)
- Send product communications, updates, and related offers (based on legitimate interest — see Section 6)
- Prevent fraud, abuse, and violations of the Terms of Use
- Comply with legal, regulatory, and tax obligations
- Respond to data-subject requests (LGPD, art. 18)
- Improve the Platform through aggregated and anonymized analysis
- Respond to judicial or administrative orders
6. Legal Bases (LGPD, art. 7)
| Purpose | Legal basis |
|---|---|
| Registration, authentication, and service provision | Performance of a contract (art. 7, V) |
| Billing and payment processing | Performance of a contract (art. 7, V) |
| Transactional communications | Performance of a contract (art. 7, V) |
| Marketing and product communications to clients | Legitimate interest (art. 7, IX) |
| Analytics and functional cookies | Consent (art. 7, I) |
| Compliance with legal and tax obligations | Legal obligation (art. 7, II) |
| Fraud prevention and security | Legitimate interest (art. 7, IX) |
| Product improvement via aggregated/anonymized data | Legitimate interest (art. 7, IX) |
| Defense in judicial or administrative proceedings | Regular exercise of rights (art. 7, VI) |
7. Sharing and Sub-processors
To provide the service, we share data with the sub-processors listed below, all contractually committed to data protection:
| Sub-processor | Purpose | Location | Privacy Policy |
|---|---|---|---|
| Supabase, Inc. | PostgreSQL database, authentication | USA | https://supabase.com/privacy |
| OpenAI, L.L.C. | Query processing in GPT models | USA | https://openai.com/policies/privacy-policy |
| Stripe, Inc. | Payment processing | USA / Brazil | https://stripe.com/privacy |
| Cloudflare, Inc. | Hosting, CDN, security | Global | https://www.cloudflare.com/privacypolicy/ |
| Google LLC | Google Sign-In authentication, Google Analytics 4, Google Tag Manager | Global | https://policies.google.com/privacy |
| Meta Platforms, Inc. | Meta Pixel (Facebook Pixel) — campaign measurement and remarketing | USA | https://www.facebook.com/privacy/policy/ |
7.1. We do not sell your personal data to third parties.
7.2. We may share data when required by a judicial or regulatory authority, or to defend Crowly's rights in judicial or administrative proceedings.
7.3. In the event of corporate reorganization, merger, acquisition, or sale of assets, data may be transferred to the successor, with prior notice to the User.
7.4. This list of sub-processors may be updated. Material changes will be communicated in accordance with Section 14.
8. International Data Transfer
As indicated in Section 7, part of the processing takes place on servers located outside Brazil (notably in the United States). Such international transfers are carried out in accordance with art. 33 of the LGPD, on the basis of:
- Performance of a contract with the data subject (art. 33, IX);
- Contractual safeguards offered by the sub-processors, including standard contractual clauses and international data-protection standards;
- The need for international cooperation, where applicable.
9. Cookies and Tracking Technologies
9.1. Crowly uses cookies and similar technologies to:
- Essential cookies — necessary for the operation of the Platform (session, authentication, security). They do not require consent.
- Functional cookies — store User preferences (language, settings).
- Analytics and measurement cookies — analyze Platform usage and measure campaign performance, including:
- Google Analytics 4 (Google LLC) — aggregated behavior and funnel metrics
- Google Tag Manager (Google LLC) — measurement-tag orchestrator
- Meta Pixel (Meta Platforms, Inc.) — Meta Ads campaign measurement and remarketing on Facebook/Instagram
- Marketing and remarketing cookies — used by the tools above for ad personalization and conversion attribution.
9.2. Analytics, measurement, and marketing cookies are only activated with express consent, given through the cookie banner shown on your first visit. We have implemented Google Consent Mode v2 and Meta Consent Mode, ensuring that no personal data is shared with Google or Meta before the User's decision.
9.3. You may revoke consent or change your cookie preferences at any time by clearing your browser cookies (the banner will reappear) or through the Platform settings.
9.4. We may add or replace analytics, measurement, and remarketing tools in the future. Such changes will be reflected in this Policy and, where they involve new cookies that require consent, the banner will be updated and the User will be asked to renew their choice.
10. Data-Subject Rights (LGPD, art. 18)
You, as the data subject, have the right to:
- Confirm the existence of processing of your personal data
- Access the data we hold about you
- Correct incomplete, inaccurate, or outdated data
- Request anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD
- Request portability of the data to another service provider
- Request deletion of personal data processed on the basis of your consent
- Be informed about the public and private entities with which Crowly shares your data
- Be informed about the possibility of not providing consent and about the consequences of refusal
- Revoke consent at any time, by express request
- File a complaint with the Brazilian National Data Protection Authority (ANPD)
To exercise any of these rights, contact us by email at contato@gocrowly.com, identifying yourself and describing your request. We will respond to your request within up to 15 (fifteen) days, in accordance with art. 19 of the LGPD.
To verify the authenticity of the request and protect your data, we may ask for additional information confirming your identity.
11. Retention Period
We keep your data for as long as necessary to fulfill the stated purposes, subject to the following periods:
- Financial and contractual data (invoices, receipts, contracts): 5 (five) years, in accordance with art. 206, §5, I of the Brazilian Civil Code.
- Access records and navigation logs: 6 (six) months, in accordance with art. 15 of the Internet Civil Framework.
- Other personal data: kept for the duration of the contractual relationship with the client Company, and deleted within up to 90 (ninety) days after Account closure, unless another applicable legal basis exists (compliance with a legal obligation, regular exercise of rights in judicial or administrative proceedings).
- Anonymized data: may be kept indefinitely for statistical purposes and product improvement, since it no longer allows identification of the data subject.
12. Information Security
We adopt technical and administrative measures to protect your data against unauthorized access, loss, alteration, or destruction, including:
- Encryption of data in transit (HTTPS/TLS)
- Password storage using hashing algorithms
- Row-Level Security (RLS) access control in the database
- Periodic backups and recovery procedures
- Regular review of permissions and administrative access
- Least-privilege principle for internal access
12.1. Despite these efforts, no system is completely secure. In the event of a security incident that compromises personal data and causes relevant risk or harm to data subjects, we will notify those affected and the ANPD within a reasonable time, in accordance with art. 48 of the LGPD.
13. Children and Adolescents
Crowly is not intended for anyone under 18 (eighteen) years of age and does not intentionally collect data from minors. If we identify that an Account was created by a minor, it will be immediately closed and the associated data deleted.
14. Changes to this Policy
This Policy may be updated to reflect changes in the service, in legislation, or in privacy practices. In the event of a material change, we will notify Users by email or a prominent notice on the Platform at least 15 (fifteen) days before it takes effect.
The date of the last update is indicated at the top of this document. Continued use of the Platform after the changes take effect implies agreement with the updated version.
15. Contact and Exercise of Rights
For questions about this Policy, exercising data-subject rights, or reporting incidents:
- Email: contato@gocrowly.com
- Address: Avenida Paulista, 1636, Sala 1504, Cerqueira César, São Paulo – SP, ZIP 01310-200, Brazil
You may also contact the Brazilian National Data Protection Authority (ANPD) directly:
- Website: https://www.gov.br/anpd
- Complaints channel: available on the ANPD website
This English version is an unofficial DRAFT translation pending legal review. The Portuguese version was legally reviewed and validated; last review: 05/03/2026.