Tireless Crew ("we", "us", "our") operates the AI agent platform available at https://app.tirelesscrew.com. We are the data controller for personal data collected through the Service.
This Privacy Policy describes how we collect, use, store, and share your personal data when you use our website and platform. It applies to all users of the Service, including customers, trial users, and visitors.
When you register for an account, we collect:
We do not store your full credit card numbers. Payment processing is handled by Stripe, which provides us with:
Stripe's privacy practices are governed by Stripe's Privacy Policy.
When you connect your WooCommerce store, we receive data necessary for agent operation, which may include:
We access your WooCommerce data only to execute the agent tasks you configure. We do not aggregate or analyze your store data across accounts.
API keys and OAuth tokens you provide for connected tools (e.g., Google, Slack, Yelp) are encrypted at rest using AES-256 and stored in our database. They are decrypted transiently in memory only during agent execution.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing and operating the Service | Account, agent config, credentials, WooCommerce data | Contract performance |
| Billing and subscription management | Email, Stripe Customer ID, plan data | Contract performance |
| Sending transactional emails (run failures, expiry alerts) | Email, agent run outcomes | Contract performance / Legitimate interest |
| Security, fraud prevention, and rate limiting | IP address, API key usage, request logs | Legitimate interest |
| Service improvement and debugging | Anonymized usage statistics, error logs | Legitimate interest |
| Legal compliance | Account and billing data | Legal obligation |
We do not use your data for behavioral advertising, do not build advertising profiles, and do not sell or rent personal data to third parties.
If you are located in the European Economic Area (EEA) or United Kingdom, we rely on the following legal bases under GDPR:
We share personal data only with the sub-processors necessary to deliver the Service. All sub-processors are contractually bound to appropriate data protection standards.
| Sub-Processor | Purpose | Data Transferred |
|---|---|---|
| Stripe | Payment processing | Email, billing address, payment method |
| Anthropic | Claude AI model API | Agent prompts and tool call payloads (see §6) |
| OpenAI | GPT model API (if configured) | Agent prompts and tool call payloads (see §6) |
| Database Host | Data storage (MariaDB) | All Customer Data (encrypted at rest) |
| Redis Host | Queue, cache, session | Session tokens, job payloads |
| Email Provider | Transactional email delivery | Email address, notification content |
We do not share your data with analytics advertisers, data brokers, or marketing platforms. We may disclose data to law enforcement or government authorities if required by applicable law, court order, or to protect our legal rights.
When your agents execute, we send prompts and tool call results to the configured AI provider (Anthropic Claude or OpenAI GPT). This may include content from your WooCommerce store, your agent instructions, and tool outputs.
Important: We use the API-only access tier with both Anthropic and OpenAI. Under their API terms, prompt data submitted via API is not used to train their models by default. We do not opt in to any data training programs on your behalf.
You should not configure agents to process or transmit highly sensitive personal data (such as payment card numbers, government IDs, or medical records) through the AI models, as those providers' data handling policies apply to content sent to their APIs.
We implement industry-standard technical and organizational measures to protect your data:
No system is perfectly secure. If you discover a security vulnerability, please report it responsibly to [email protected].
| Data Type | Retention Period |
|---|---|
| Account data (name, email) | Duration of account + 90 days after closure |
| Agent run history and logs | 12 months on active account; 90 days after closure |
| Billing records | 7 years (legal/tax obligation) |
| HTTP access logs | 30 days |
| Session tokens | 120 minutes of inactivity |
| Third-party credentials | Until deleted by user or account closure |
Depending on your location, you may have the following rights regarding your personal data:
California residents have additional rights under the California Consumer Privacy Act, including the right to know, delete, correct, and opt out of sale of personal information. We do not sell personal information. To exercise your rights, contact us at the address below.
Submit your request by emailing [email protected]. We will respond within 30 days. We may request identity verification before processing sensitive requests.
We use a minimal set of cookies required for Service functionality:
| Cookie | Purpose | Duration |
|---|---|---|
tireless-crew-session |
Authenticated session (stored in Redis) | 120 min of inactivity |
XSRF-TOKEN |
CSRF protection for form submissions | Session |
We do not use third-party advertising cookies, tracking pixels, or analytics SDKs that report to external services.
The Service is not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it promptly.
Our servers are located in the United States. If you are accessing the Service from outside the US, your data will be transferred to and processed in the US.
For transfers of personal data from the EEA or UK, we rely on standard contractual clauses (SCCs) approved by the European Commission, or other appropriate safeguards as required by applicable law.
We may update this Privacy Policy periodically. When we make material changes, we will notify you by email or by posting a notice in the Service at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Continued use of the Service after the effective date constitutes acceptance of the revised Privacy Policy.
For privacy-related questions, data subject requests, or to report a concern, please contact our privacy team:
If you are an EEA resident and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority (data protection regulator).