This Privacy Policy explains how Crest88 LLC ("Crest88," "we," "us") collects, uses, and protects information across our website — crest88.com — and the Crest88 platform: our AI agent platform, sometimes called "Central Brain," available to clients at brain.crest88.com and related subdomains (the "Platform").
The Platform is a business product. We provide it to companies ("Clients") under a signed engagement letter or services agreement, and the people who use it ("Users") do so on behalf of a Client. Where this Policy and a Client's signed agreement differ, the signed agreement controls for that Client's data.
If you have any questions, contact us at hello@crest88.com.
1. The short version
- We collect the minimum account information needed to sign you in: your email address, your role, and login timestamps. Names, photos, and passwords are handled by our identity provider, not stored in our application database.
- The Platform works with your business content — email, calendars, tasks, documents, meetings, chat — only after your organization explicitly connects those systems. You choose what to connect, and you can disconnect at any time.
- We use third-party AI providers (currently OpenAI and Anthropic) to power the Platform's assistant, drafting, and voice features. We do not permit these providers to use your data to train their models.
- We do not sell your data. We do not run advertising. We use no advertising or marketing cookies, and no third-party product-analytics trackers.
- Your organization owns its data and can export it or request full deletion at any time. Crest88 owns the underlying engine — the prompts, agent architectures, and software that make the Platform work.
2. Information we collect
On the website (crest88.com)
If you submit our contact form, we collect what you enter: your name, email address, and any optional details (company, website, revenue range, message). The website itself sets no analytics or advertising cookies.
On the Platform — account information
When your organization invites you to the Platform, we create an account holding:
- Your email address and your role within your organization's workspace (owner, admin, or member)
- Sign-in and activity timestamps (last login, last seen)
Sign-in itself is handled by our identity service using industry-standard OpenID Connect. If your organization signs in with Microsoft, Microsoft acts as your identity provider under its own privacy policy. We do not store your password.
On the Platform — content you and your organization provide
The Platform exists to work with your business information. Depending on what your organization sets up, this can include:
- Documents and files you upload or connect, and the searchable indexes we build from them
- Tasks, projects, and records (for example jobs, customers, contacts, and other business entities), including notes and change history
- Meetings — agendas, attendees, action items, and written transcripts
- Chat and assistant conversations with the Platform, in text or by voice
- Knowledge the Platform is configured with — facts, policies, and workflows specific to your business
- Learned preferences — for example, how you like emails drafted, so the assistant improves for you over time
On the Platform — connected services
Your organization can authorize the Platform to access outside systems. Nothing is connected unless an authorized person in your organization approves it, and each connection can be revoked. Currently supported connections:
| Connected service | What the Platform accesses |
|---|---|
| Gmail / Google Workspace | Reads mail and calendar events; sends email on your behalf when you approve it |
| Microsoft 365 / Outlook | Reads mail; sends email on your behalf when you approve it |
| Slack | Reads channels and messages; can post messages |
| Asana | Reads projects, tasks, and attachments; can sync updates back |
| QuickBooks / Xero | Reads customers, invoices, and attachments |
Access tokens for these connections are stored encrypted in a dedicated secrets vault (AWS Secrets Manager), never in plain form in our application database.
Google user data. When your organization connects a Google account, Crest88 accesses Gmail and Google Calendar only to provide the features described above: reading and organizing mail, preparing drafts for your approval, sending email you approve, and managing calendar events. Crest88's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not permit humans to read it except with your permission, for security purposes, to comply with law, or as necessary to operate the service.
On the Platform — collected automatically
- Audit logs — a record of significant actions taken in your workspace (who did what, when), kept for security and accountability
- Usage metering — counts of AI usage (for example, token counts) for operations and billing
- Error and diagnostic data — we may use error-monitoring software (Sentry) to capture crash reports so we can fix problems
- Voice telemetry — for voice features we log technical events (connection status, latency, errors). We do not store raw audio recordings, and voice telemetry excludes message content and personal details. What you say through voice features is stored only as written transcript, in your workspace, where the feature is designed to keep one (for example meeting transcripts)
3. How we use information
We use information to:
- Provide, operate, and secure the Platform for your organization
- Power AI features: triaging and drafting email, answering questions, running meetings, extracting and organizing business records, and voice interaction
- Take actions you or your organization approve — for example sending an email you have reviewed
- Maintain audit trails, prevent abuse, and meet legal obligations
- Improve the Platform for your organization (for example, learning your drafting preferences)
- Respond when you contact us
We do not sell personal information, and we do not use your information for third-party advertising. We do not use your organization's content to build products for other customers.
4. AI processing — what leaves our systems
To provide AI features, relevant content is sent to our AI providers for processing:
- OpenAI — text generation, embeddings (the math that powers search), web search within the assistant, and real-time voice (your speech is streamed to OpenAI to be understood and transcribed)
- Anthropic — text generation
Depending on the feature in use, the content processed can include chat messages, email text, document excerpts, meeting speech, and the on-screen values needed for voice control to work. We use these providers through their business APIs under terms that do not permit them to use your data to train their models.
If your organization uses the meeting-notes feature, a notetaker bot from Recall.ai joins the meeting you invite it to and delivers the transcript to your workspace. Meeting audio is processed by Recall.ai for that purpose.
5. Who we share information with
We share information only with the service providers that make the Platform run ("subprocessors"), with connected services you have authorized, and where the law requires it. We never sell it. Current subprocessors:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage, encrypted secrets vault | United States |
| OpenAI | AI text, embeddings, assistant web search, real-time voice | United States |
| Anthropic | AI text | United States |
| Recall.ai | Meeting notetaker bot and transcription (only if used) | United States |
| Resend | System email (invitations, notifications) | United States |
| Sentry | Error monitoring | United States |
| Google Maps | Converting business addresses to map locations (only if the map feature is used) | United States |
We will update this list as our providers change. We may also disclose information if required by law, or in connection with a corporate transaction such as a merger — in which case this Policy continues to apply to the transferred data.
6. Who at Crest88 can see your data
Crest88 operators (our team) can access a Client workspace to provide the service — for setup, support, and operating agents on your behalf, as agreed in your engagement. This access is deliberately constrained:
- Operator access runs in time-boxed sessions (30 minutes) that are individually recorded
- Sensitive actions require an explicit extra confirmation, recorded per action; anything sent outside your organization (like approving an outbound email) is confirmed per recipient
- The most destructive operations (removing users, revoking connections, deleting a workspace) are blocked entirely in operator-access mode
- All operator access is audit-logged
Server access is equally restricted: there is no open SSH port; administrative access goes through AWS's identity-controlled session manager and is logged in AWS CloudTrail.
7. Data ownership
Consistent with our client agreements:
- Your organization owns its data — the raw business content it brings, and the configured knowledge built from it (facts, records, transcripts, indexes, workflows configured for your business). This is exportable by your organization.
- Crest88 owns the engine — the software, prompts, agent architectures, evaluation systems, and operational telemetry that make the Platform work. Engine internals are never included in exports.
8. Security
- Encryption in transit — all traffic to the Platform uses TLS (HTTPS)
- Encryption of secrets at rest — connection credentials and sensitive secrets are envelope-encrypted with AES-256-GCM using per-tenant keys; OAuth tokens live in AWS Secrets Manager, not the application database
- Tenant isolation — every Client workspace is isolated at the database layer with enforced row-level security, plus a second application-level check on every query
- Least-access operations — no open SSH; identity-gated, fully audited administrative access
- Audit trails — significant actions are logged and retained
No system is perfectly secure, and we cannot guarantee absolute security — but security is designed into the Platform's architecture, not bolted on.
9. How long we keep information
| Data | Retention |
|---|---|
| Your workspace content (documents, records, transcripts, conversations) | For the life of your organization's engagement, until deleted by your organization or offboarded |
| Audit logs | 90 days on a rolling basis |
| Email triage log (a short technical record of how each email was routed) | 30 days on a rolling basis |
| Export bundles you generate | Download links expire after 24 hours |
| Usage/metering records | Retained as business records (billing, tax) |
| Website contact-form submissions | As long as needed to respond, up to one year after our last interaction |
Offboarding and deletion
When an engagement ends (or on request by an authorized owner), we run a formal offboarding process:
- Export first — your organization can take a complete export of its data
- Deletion — connected-account tokens are revoked at the provider (Google/Microsoft) and invalidated; documents, extracted knowledge, and search indexes are deleted; the workspace's encryption keys are destroyed, rendering any remaining encrypted material permanently unreadable
- Receipt — we produce a deletion receipt recording what was deleted, in what quantities, by whom, and when
We retain only what security and law sensibly require after offboarding: audit logs (on their normal schedule), usage records (billing/tax), and the deletion receipt itself.
10. Your rights and choices
- Access and export — your organization's authorized users can export its data at any time from within the Platform
- Disconnect — any connected service can be disconnected by an authorized user
- Correction and deletion — most content can be edited or deleted directly in the Platform; for anything else, contact us
- Account questions — because Platform accounts belong to a Client workspace, we may route requests about workspace data through your organization's administrator
Depending on where you live, you may have additional legal rights over your personal information (such as rights of access, correction, deletion, or portability). To exercise any right, email hello@crest88.com — we will respond to verifiable requests as required by applicable law, and we do not discriminate against you for exercising them.
The Platform is a business tool and is not directed to children under 16; we do not knowingly collect information from them.
11. Where data is processed
We are a U.S. company and process data in the United States. If you access the Platform from outside the U.S., you understand your information will be transferred to and processed in the U.S.
12. Changes to this Policy
If we make material changes, we will update the date above and notify Platform users through the product or by email. Continued use after changes take effect means the updated Policy applies.
13. Contact
Crest88 LLC · hello@crest88.com
If you have a concern we haven't resolved, you can also contact your local data-protection authority where applicable.