CROWBOT

CrowBot · privacy notice

Privacy and data handling

CrowBot keeps a browser-local readable brain scoped to the active account and syncs sanitized text so the same creature can return on another device. Photos, provider credentials, raw media, and body pairing secrets stay outside that sync.

Updated 1 October 2026 · CrowBot is operated by an Australian individual.

Scope and contact

You may hatch and try CrowBot without creating an account. The visitor introduction uses a browser session and a server-side usage record for its free staged allowance. Your guest crow, memories, media and sensor choices are stored separately on this device; guest brain records are not synchronized to an account. If you choose to create a new account, CrowBot copies that guest crow into the new account and carries over used introduction time. Signing into an existing account does not automatically overwrite its crow with the guest crow.

This notice covers the existing CrowBot website and web app. Independently owned copies use their own installation, infrastructure and provider accounts. This notice does not replace the separate privacy terms of Stripe, Cloudflare, OpenRouter, Groq, Fish Audio, an installation's configured AI service, your browser, operating system, internet provider, or a local/private model service.

Private support route

The Support page sends only the category, subject, and plain-text message you enter. It does not collect an email address or attachment. CrowBot returns a ticket ID and private access token; only those two values are retained in this browser so you can read and reply to the ticket. Anyone with the token can access that ticket, so protect it like a password.

Human verification on protected account, support, owner, and checkout actions

CrowBot loads Cloudflare Turnstile for account creation, sign-in and recovery, new support tickets, Checkout, and new owner sessions. Cloudflare processes browser, device, and network security signals. The Worker submits the one-time verification token and connecting IP address to Siteverify and accepts only the exact CrowBot hostname and action. CrowBot does not store that token in browser storage, D1, URLs, logs, or the brain. Cloudflare’s processing applies. Passing Turnstile does not prove identity, authorize payment, or grant an entitlement. Account authentication uses your verified email/password or a supported optional sign-in method, with configured multi-factor protection where required.

Information kept in your browser

The Doctor records a local diagnostic timeline of app actions, state changes, request outcomes and errors, without field values, private messages, credentials, recordings or photos. It retains up to 2,000 events for 48 hours in this browser, subject to a storage limit. It does not send this log to a telemetry service. In Settings, open Doctor & diagnostics to inspect, export, clear or pause it. Exports are separate downloaded copies. The report identifies storage failures, dropped events and events the browser cannot observe.

CrowBot can keep the following in the browser profile you use:

Ordinary brain capture and account sync exclude provider keys and tokens, raw microphone audio, embedded image/photo data, complete provider payloads, body pairing secrets, and continuous sensor telemetry. Normal brain exports exclude photo bytes and provider credentials. Files you export or mirror are under your control.

CrowBot accounts use your own email address and a password you choose; native passkeys are optional. CrowBot never keeps your password itself: the Worker stores a salted verifier, receives no authenticator private key, and keeps neither in browser storage. Account switching saves and syncs, clears live account credentials, changes namespace, and reloads.

Private Gallery

Private Gallery encrypts its media and captions in this browser. Unlocking requires online verification of your signed-in account's current password and the account's configured multi-factor protection. A separate random encryption key is kept with your account on CrowBot's server; private media bytes are not uploaded by this feature. Password resets do not replace that key.

Closing Gallery, hiding the page, signing out or leaving Private idle locks it and clears the unlocked key from page memory. Private items do not appear in ordinary Gallery, photo recall or Brain Archive. Use Private Gallery's separate encrypted export and restore with the same account; keep that export before clearing site data. Removing the account or its server key can make encrypted copies unreadable.

Moving an item to Private cannot erase earlier downloads, backups, conversations or copies already sent to a selected AI provider. It protects the item's future use in this Gallery; it does not undo that earlier use.

Clearing the activity log clears only that extra log. It does not erase the durable local brain, saved photos, exported files, provider-held data, payment/access records, or the paid-offline key. Browser “clear site data” controls are the current whole-origin local deletion route, but using them can also remove your local brain, recovery state, and offline access.

Information processed by CrowBot’s Worker and database

Account, sign-in, and text-brain sync

  • random account ID, opaque namespace, display handle, status, and login times;
  • your account email address, its verification state, and a salted password verifier (never the password itself);
  • short-lived hashed email codes and magic-link tokens, delivery-attempt records that hold only keyed hashes of the sending source and destination, and bounded suppression records;
  • optional passkey IDs/public keys, counters/device flags, one-use challenges, hashed sessions, and keyed recovery-code hashes;
  • optional multi-factor settings and challenges, encrypted authenticator setup, verified email-factor addresses and immutable linked sign-in-provider identities;
  • one account creature with a sanitized soul and text-brain records plus revision and size metadata.

Access and abuse control

  • random browser-session identifiers represented by derived database keys;
  • visitor/account introduction phase, consumed-interaction receipts, timing, request counts, and last-seen state;
  • a keyed visitor fingerprint derived from network/browser signals, without writing the raw fingerprint inputs into application tables;
  • hashed rate-limit buckets for session creation, unlock attempts, provider use, and offline-lease issuance.

Licence and payment

  • Stripe Checkout Session, Charge, Refund, and Dispute identifiers and status metadata;
  • non-secret CrowBot purchase references, product, quantity, price, environment, and fulfilment state;
  • licence, installation-slot, one-way recovery-code hash, revocation, dispute suspension, and offline-authorization metadata.
  • membership subscription, invoice, valid-period, management/recovery and first-payment discount eligibility records;
  • purchased creature-time and premium-time balances, credits and consumption receipts;
  • independent source-package purchase status, pinned package manifest and archive hash, and verified delivery/recovery records.

Owner gifts and app authorization

  • hashed gift/grant codes, recipient account and device bindings, granted products, quantity/calendar periods, redemption, revocation and capability settings;
  • short-lived native-app authorization state, code/token hashes, proof-key challenge, callback/device metadata, expiry and consumption state;
  • separate scoped owner-app authorization/session and audit records. A recipient gift or customer app sign-in does not grant installation administration.

Installation AI configuration

  • installation origin, connection/provider settings, per-job model/voice assignments, revision and update/actor metadata;
  • encrypted owner-entered server provider keys. Environment credentials remain separate server secret bindings; these credentials are excluded from customer brain sync and ordinary brain exports.

Community and preserved lives

  • your account's Community world, resident identities and preserved life/text-memory records;
  • admission, life-transition, world-command and event receipts, revisions, and Community backup/export/import state;
  • opt-in social display name, invitations, connections, visits and their status/revision/timestamps.

Connected communities receive a limited shared world/resident view when you enable the social feature. That view excludes private memories, credentials and full brain archives. Disconnecting social access does not erase separately saved exports or historical account records.

Provider metering

  • aggregate daily request counts and failure-circuit state;
  • Premium Voice purchase, remaining-time, activation, and bounded usage counters;
  • no complete provider request/reply bodies, raw audio, camera frames or sensor streams in these metering records. Sanitized conversation memories can be saved separately in the account brain.

Support tickets

  • category, subject, plain-text customer and owner messages, ticket status, and timestamps;
  • a one-way hash of the private ticket access token rather than the raw token;
  • rate-limit counters used to cap ticket creation and replies.

D1 does not contain payment-card details; Stripe handles payment details. D1 stores your account email address for sign-in, verification and password recovery, and keeps only keyed hashes in email-delivery records. Account sync stores sanitized creature/person names and text memories, but not provider credentials, OAuth/session tokens, raw media, sensor streams, pairing secrets, or complete provider payloads. Private Gallery's separate random account-held encryption key is server-side; its media and captions remain encrypted locally. This key and the installation's encrypted server provider keys are separate from brain records and ordinary brain exports.

AI, speech, image, and search providers

Only use content you are comfortable sending to the active route. The exact recipient depends on the feature, access, saved choices and installation configuration. Hosted customers use the installation's configured AI; independently owned installations control their own compatible providers. Ordinary recognition and speech use the native browser/device route. Recorded cloud audio requires its selected feature and consent; it is not a silent fallback.

RouteWhat may be sentWhat to know
Configured CrowBot AI or compatible included routePrompt text, selected memories and requested image/media input to the installation's configured AI service or provider.The selected job and configured route determine the recipient; a trial-stage name alone does not activate a supplier or upload audio.
Existing optional premium voice/audio routeVoice text to Fish Audio or recorded microphone audio to Groq only when that supported route is deliberately selected and authorized.Availability, consent and access remain feature-specific. CrowBot does not save the raw recording in the brain or D1. New premium-minute checkout remains unavailable.
Included free OpenRouter phasePrompt text, selected local memories, and a fresh or deliberately selected image when vision is used.Free model availability and provider data policy can change. Do not send sensitive information.
Browser speech and voiceSpeech or generated-voice text as determined by the browser and operating system.“Browser” does not necessarily mean fully on-device. Browser and OS vendor behavior applies.
Your provider or local/private modelThe prompt, selected memories, image, audio, or generation request required for the feature.Your chosen endpoint, account settings, pricing, retention, training, and location rules apply.
Web searchSearch terms to supported DuckDuckGo and Wikimedia routes.Those services and network intermediaries receive the request.
Account emailYour email address, the subject, and the plain-text message carrying a short-lived verification, sign-in or password-reset code or link.Sent through Google’s Gmail service from CrowBot’s sending mailbox; Google keeps its own copies and logs under that account’s settings. CrowBot stores only keyed hashes of the delivery, never the code, link or message body.

The free-route guardrail reduces exposure; it is not a no-retention promise

CrowBot’s Crow-funded free route is server-allowlisted to a small set of reviewed :free model identifiers. Arbitrary, stale, or known privacy-ineligible free-model identifiers are rejected, and house requests are size-limited and stripped of unsupported media fields. This guardrail reduces unintended routing. It does not guarantee zero data retention, no training, a particular processing country, or that a provider policy will never change.

OpenRouter’s current public documentation says its own prompt/output logging and product-improvement use are off by default unless enabled, while request metadata is stored and underlying model-provider practices vary. CrowBot does not convert that general statement into an account-specific guarantee. Review OpenRouter’s data-collection documentation and the current policy for the exact model endpoint before sending private or confidential content.

Camera, microphone, movement, and location

Browser or operating-system permission controls can refuse or revoke camera, microphone, motion, or speech access.

Foreground autonomy is a local opt-in and is off by default. The accepted daytime Lab can display foreground-only local brain capture/consolidation and never calls a model. Hiding the web page stops sensor/model autonomy: CrowBot does not listen, watch, speak, or call a model while hidden. Age and schedules recalculate when reopened. Any future background mode needs separate permission and disclosure.

Why information is used and disclosed

CrowBot uses the information above to run the local creature, enforce the trial and paid access, fulfil and recover purchases, operate chosen AI/speech/image features, prevent abuse, investigate failures, protect security, process refunds and disputes, and meet legal obligations. It is disclosed only as required for those functions, to the service selected for a request, or where disclosure is required by law.

Cloudflare, Stripe, OpenRouter, Groq, Fish Audio, browser/OS services, and other selected providers can process data outside Australia. Exact countries and subprocessors depend on the provider, route, and current account configuration. CrowBot does not promise Australian-only processing.

Retention and deletion

Browser data remains until overwritten, cleared, evicted, or exported files are removed. The synchronized soul/text brain remains in D1 while the account is active or until verified deletion, subject to backup and required-record limits. Provider retention follows provider settings.

CrowBot’s bounded scheduled cleanup is designed to remove short-lived application metadata on these maximum inactivity or age windows:

Hourly bounded cleanup removes expired/used passkey challenges, account attempt windows after 2 days, expired/revoked sessions after 30 inactive days, and sync-replay rows after 365 days. Replay history is also capped at 512 rows per account. Active account, licence, passkey, recovery, and brain data remains while needed.

Support tickets and messages are deleted by bounded scheduled cleanup 2 years after the ticket’s last activity. There is no separate legal-hold exception in the Initial Release. Successful purchase, licence, installation-slot, refund, dispute, recovery-audit, fraud-prevention, and accounting records can be retained longer while reasonably needed to provide access, resolve claims, prevent abuse, keep financial records, or meet legal obligations. Cloudflare logs and backups, Stripe records, and provider records have separate retention.

Active membership, gift, source-package, Community and installation-configuration records are separate from the short-lived metadata listed above. Clearing a local log, deleting a brain record or disconnecting a community does not delete those server records, backups or third-party copies. Use the private support route for verified access, correction or deletion requests; a submitted request or local Clear action is not confirmation of account-wide deletion.

Your choices and requests

Information about Australian privacy policies, access, correction, and complaints is available from the Office of the Australian Information Commissioner.

Security and changes

Controls include HTTPS, exact account origins, verified passkeys, one-use challenges/codes, hashed sessions, account-scoped storage, bounded revisioned sync, restrictive headers, signed account/licence/device offline authorization, size limits, allowlists, rate limits, and fail-closed payment checks. No system is risk-free. See Security.

Do not send another person’s personal or sensitive information without authority.

This notice will be updated when a material data path, provider, support process, or retention period changes. The effective date at the top identifies this version.